installer_gimp_french.exe

Vittalia Internet S.L.

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_gimp_french.exe by Vittalia Internet S.L has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. The file has been seen being downloaded from telechargerstop.com. While running, it connects to the Internet address services.upd4ter.com on port 80 using the HTTP protocol.
Publisher:
Vittalia Internet S.L.  (signed and verified)

MD5:
e1f1a7be61457ad66f33ae1e19b024c8

SHA-1:
06e938624763bb137610f11efce9af127326c5d7

SHA-256:
13cc480ddca8af8234e8410847115c8ee5b833eacca947bbb37004763d33c19e

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/20/2024 3:20:39 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Kryptik
7.1.1

AVG
AdInstaller.Vitalia
2015.0.3486

Comodo Security
Application.Win32.Vittalia.AB
18205

Dr.Web
Adware.Downware.1139
9.0.1.0122

ESET NOD32
Win32/Vittalia (variant)
8.9750

Fortinet FortiGate
Riskware/Vittalia
5/2/2014

IKARUS anti.virus
AdWare.Win32.Vittalia
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.Vittalia
v2014.05.02.01

NANO AntiVirus
Trojan.Win32.Downware.bxpixu
0.28.0.59608

Qihoo 360 Security
Malware.QVM01.Gen
1.0.0.1015

Reason Heuristics
PUP.VittaliaInternetSL.V
14.8.7.21

SUPERAntiSpyware
Adware.Downware/Variant
10630

Vba32 AntiVirus
Downware.Vittalia
3.12.26.0

VIPRE Antivirus
Vittalia Installer
28788

File size:
2.5 MB (2,588,096 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Common path:
C:\users\{user}\downloads\installer_gimp_french.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/1/2012 2:00:00 AM

Valid to:
10/2/2015 1:59:59 AM

Subject:
CN=Vittalia Internet S.L., OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Vittalia Internet S.L., L=Mostoles, S=Madrid, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
00B5B17F6085B2B530BA3A0FF637EE1A

File PE Metadata
Compilation timestamp:
4/17/2013 12:46:00 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:MPfeB0e+K3l5Tkug1n/99QTl28SzMV1jb8zxQdOc:MjckSJ

Entry address:
0x65070

Entry point:
60, BE, 00, 20, 44, 00, 8D, BE, 00, F0, FB, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA]

Code size:
144 KB (147,456 bytes)

The file installer_gimp_french.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)

Remove installer_gimp_french.exe - Powered by Reason Core Security