installer_eurotraductor_english.exe

Vittalia Internet S.L

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_eurotraductor_english.exe by Vittalia Internet S.L has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Vittalia Internet S.L  (signed and verified)

MD5:
d9e5efff49005c0e7643983125609aeb

SHA-1:
b02152d7bec73e4835e893ee62ff11fec761f964

SHA-256:
94b262e8ee06af296e5e0ebc50a2902b6c0c8cb125ccbde8dcc0e1f13040c769

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/24/2024 6:17:48 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.177.168

AVG
Generic
2015.0.3314

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.141022

Dr.Web
Trojan.Packed.28459
9.0.1.0295

ESET NOD32
Win32/InstallCore.QH (variant)
8.10546

Fortinet FortiGate
Riskware/InstallCore
10/22/2014

F-Prot
W32/InstallCore.AC.gen
v6.4.7.1.166

K7 AntiVirus
Unwanted-Program
13.183.13642

Malwarebytes
PUP.Optional.Vittalia
v2014.10.22.05

McAfee
Artemis!D9E5EFFF4900
5600.6970

Qihoo 360 Security
Win32/Trojan.Adware.37e
1.0.0.1015

Reason Heuristics
PUP.VittaliaInternetSL.FF
14.10.22.5

Sophos
Generic PUA LA
4.98

VIPRE Antivirus
Vittalia Installer
33826

File size:
762 KB (780,288 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\installer_eurotraductor_english.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/9/2014 1:18:24 PM

Valid to:
8/9/2015 1:18:24 PM

Subject:
CN=Vittalia Internet S.L, O=Vittalia Internet S.L, L=Mostoles, S=Madrid, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121296DFC83F15C4B1C19CE7B920AA7D12F

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:nPFafJduqBYuk26xsMmJDIYfM8N7NvI/0ILAtWTuSbIQHdFzZ+OV36:nPFKJduJ1xefzm0F8TFXdP+OV36

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8814

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)

Remove installer_eurotraductor_english.exe - Powered by Reason Core Security