vdownloader_setup.exe

Catuhacun

Setup Alpha ((New Media Holdings Ltd)

The application vdownloader_setup.exe, “Catuhacun Setup ” by Setup Alpha ((New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.vaultbytehead.com and multiple other hosts.
Publisher:
Setup Alpha ((New Media Holdings Ltd)  (signed and verified)

Product:
Catuhacun

Description:
Catuhacun Setup

Version:
4.7.1.5

MD5:
9dcd79166aa4a3185349f6415abfaf53

SHA-1:
95d04e0abe237cccfc5b6f2b2b8f5158a5672324

SHA-256:
1dda1e2378e19c0391dc8f2822115ecd1b1f358e64bd459f2b1ff448bea36ab8

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/20/2024 11:20:49 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.5.22.14

File size:
1.3 MB (1,344,856 bytes)

Product version:
3.6

Copyright:
Wizard Lite Stub

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vdownloader_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 10:41:44 PM

Valid to:
5/25/2016 8:42:13 PM

Subject:
CN=Setup Alpha ((New Media Holdings Ltd), O=Setup Alpha ((New Media Holdings Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216F55CB04783E0F0E5AC4C45115E1BCCC

File PE Metadata
Compilation timestamp:
6/20/1992 7:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:qd0glPmINSKRkXb/2JKqTnWb875uqzslsBc2qPx0hOtNj0Rpv:qqcRkXFqTWbmuq5BclHN6pv

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file vdownloader_setup.exe has been seen being distributed by the following 50 URLs.

http://www.vaultbytehead.com/c?x=m2FmHu1jbKwhtffQXqqG7twzzHf00RSGVJMxqegZ6RM=&c=UBR2/dqtwJ2XirIXIYiLeam38y1v38Eel8/NKLo4KlY/yuW8qsj6APNve19ZA7LeSx5VA8EmFmsP8ZBnTlzqBW0UtGYJT6ZLS/TeowRwl4jyxcb/H8ehgz8/DObrDeEmzl2f46D7K62v6Spj1WwIHCfqDOQyzwHVjOxcz4j xw4=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=6FTsioCufhnTutnEJ/a0Rg94zDMwpUFBOKq4CeY2lXo=&c=HNYVMguRn2UxO36T827yYR9Huv3m4475Lv/TFcq/ypj8Xh8fK2bgvQSXdQq9NIYEVb9jTAnGgpRg392A7PgP8nw98Zic1LBXiT9LvKXNJGFfbWsFmeUsp9V1P4Qh1i1jdvw/oN/mRfy9JKDDivR39/3hRCTzPErrxuaAwYm0rDo=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=Aa6HBD8cqzsSuVCdLVLbrTHcITqTET3MCDsOMon3opw=&c=tfIeCC5frzgCsLWwnG1c7R/Yq0ebCEjWGqIK4mzd95a rkNCi0mD Ps1G7hrNu9gdUdaolzCVOV7vC6jyEGGkHR8WSoB282GxkMR6kaQPVbqve2UMeNHEp2EGbjlZeA4yuswWeM2keJItcGZbhKQymwNact2l20S7yx3SsVCZ6E=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=/jUPAPAAZRPiZ9N SvM5 7Agjqrd0QTbNvtvmL7Iss4=&c=DXhP5UaspjY0JdT7qKT7fW1EQb2oDAqdTYmIUI6K5vJoFZM1YMZINDjMWahebFyiFo VnZ6c48l4iO0ULojdonFrCZMrp83ItSduICldRhIlFmVFHsKD5on75ib3fd6DsREqJ/u5DAak7quKJ2PI0KWMxRCIyoP7D3qSFH9ByZQ=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=giVbBaAwLPq6CJ37BNsI9Zt1/xMwXZBR2LnfvXpi0zI=&c=W/XT54qEja1MpX0kPccWmqVRWLtmHanNP9piLV3Ftvs1CBNAiiPNL8p1ZNIQFxYPK/ZrUird6qXVdZPXoH3IFkk3FuiSqH4TgRihvlFUNjjE41uxI77CnRIBYSsnL1TAVs91fZPqtcQ3A/5igC0rhVX4LhqHboqxRkQ1yo ft c=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=RqChjRkJ6DtlbgqidMRsQqMna U80vzqbC2pzcFAhu0=&c=mf171CKS/D11OP5NyFlvH3QKQEE0D6p6JatHnLdi1697gnMswSii6Sz/Ver99kzzxLmJMLX5P7C1UA50Pj2PORc1o kJTSUiOwOaNIR987Zz0wZWqgI3VL4EmJDcg3a2kwr23nv2yaLMoHcjD9CdefUCpn4Z/vdicuNbbA1ywuM=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

Latest 30 of 61 download URLs

Remove vdownloader_setup.exe - Powered by Reason Core Security