installer_utorrent_portuguese.exe

100Blogs SL

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_utorrent_portuguese.exe by 100Blogs SL has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from utorrent.begin.pro.
Publisher:
100Blogs SL  (signed and verified)

MD5:
435d764e0515ed25aefd94bbff0d0e96

SHA-1:
1368aed9eb6656ebaf0ffb9bc8f285c723ab858c

SHA-256:
f43055342c302c80777dd8679593e3f1cd5e6b03b57be26282356135cbbc555e

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 4:09:27 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
7.11.163.226

AVG
InstallC
2015.0.3403

Clam AntiVirus
Win.Adware.Agent-7643
0.98/21411

ESET NOD32
Win32/InstallCore.OZ potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUA.Vittalia
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.181.12834

Malwarebytes
v2014.07.24.04

McAfee
Adware-DomaIQ
5600.7059

NANO AntiVirus
Riskware.Win32.InstallCore.dcipvw
0.28.2.60990

Reason Heuristics
PUP.100BlogsSL.DD
14.7.24.16

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4782551
31208

File size:
860.5 KB (881,160 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\installer_utorrent_portuguese.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
10/14/2013 5:18:59 AM

Valid to:
10/14/2016 5:18:59 AM

Subject:
CN=100Blogs SL, O=100Blogs SL, L=CERDANYOLA DEL VALLES, S=BARCELONA, C=ES

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B93142DC69C91

File PE Metadata
Compilation timestamp:
12/5/2009 8:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:b5MIJIV0zsM+CcHu2g4wt10RW7clgDB1+/WNJTvr:9MI+V0zwdO2gV7sgVgkVr

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_utorrent_portuguese.exe has been seen being distributed by the following URL.

Remove installer_utorrent_portuguese.exe - Powered by Reason Core Security