fvd2015setup.exe

Hiduluh

InstallSpeedy (New Media Holdings Ltd.)

The application fvd2015setup.exe, “Hiduluh Setup ” by InstallSpeedy (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.vaulttowerssign.com and multiple other hosts.
Publisher:
Sekafaha   (signed by InstallSpeedy (New Media Holdings Ltd.))

Product:
Hiduluh

Description:
Hiduluh Setup

Version:
2.7.5.7

MD5:
54dcfb41762caafb0120d20599ae1cd1

SHA-1:
510c7c83744f43531f4a416003ad52cfed91c744

SHA-256:
cf75af705dde74c91d5e7ddf2ae349243dee106b08a35171a019e4d44dffced4

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/15/2024 7:22:08 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.6.10.4

File size:
1 MB (1,056,072 bytes)

Product version:
2.7.9

Copyright:
Installer File

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\fvd2015setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/15/2016 11:40:35 PM

Valid to:
7/11/2017 9:28:33 PM

Subject:
CN=InstallSpeedy (New Media Holdings Ltd.), O=InstallSpeedy (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F59EA8A6B04CAE5E738F6CB09D295BDB

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:9C6tzjeUdH0pvUkGvpKsQXX61x6y5MyVMqCNDXG:9L1je2kyfx6iMsob

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file fvd2015setup.exe has been seen being distributed by the following 30 URLs.

http://www.vaulttowerssign.com/c?x=q0Uzz3uq3hOFaski/l85h4FCR/dYRfjjO5cib6MPxAY=&c=98vhvKyGOE4ElCWiSLe7nauWFNfzCwM8WRBd5myEw3yAClUJKq1lY0PVUbT2NCneYfalaQFy9Zf 0 iD 4xrKzPXqNXkY5dqv3ImGjGqCDWYQy2Eus8ZFayW7rH5q2zrOU6/yfb6T OVHSGryqmicdisouOyGkTMTCBrEwEiIy4=&e=0&downloadAs=FVD2015Setup.exe&fallback_url=http://www.finalvideodownloader.com/.../newest.exe

http://www.downloadspresentguard.com/WVl6OTRQV1IzYUZNMmRYQk5SVmh2WWt3elNXMTZObk5YUlVRNFJuaDFjRXRGSlRKR1NEbEpUbEpuSlRKR2MzaHpKVEpDU2swbE0wUW1ZejFSUlc5SlpXcElURkpVZVVWVFZDVXlRbEI1TkRKMWVHUlJUM2tsTWtKalptbDRiMXBuZFhWeWRVZHdWalowYlhSdFVIbFlRWEZvVms5alRrNWxOMDVYTVZCMk9VRlBSVzVVYmtWaGVtRndaMVF5UVROdVRucGlWblphY1V0TWNUbGxRakJaT1ZkUFoySnVlVmhXWnpWaU1tNVRKVEpDTWpKUGNEWkZWV0pJVmpRNGJYTTVWREV5V2xWR0pUSkNUM1JMY25aeVNqQkZabGRPVTNkblFTVXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFHVmtReU1ERTFVMlYwZFhBdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdkM2QzTG1acGJtRnNkbWxrWlc5a2IzZHViRzloWkdWeUxtTnZiU1V5Um1SdmQyNXNiMkZrY3lVeVJtNWxkMlZ6ZEM1bGVHVT0=

http://www.updatetodaystock.com/c?x=zuvdjd4OwK6LuphZENOwN9f1Mk6ZS5QJTHQACVxLV4Y=&e=0&c=E49uAW4ZBfUfLzxMmu5p1he/u1FE4Ah6I6N8rGN/A KckKoGkJUL//FskWq3KkbSmZMnoUI/txKC1IPRzFHsC2xJdGWCDpTKfeACfzfpFOSj6aveIptjxp1NndJ7wukkphc12cudWJsHOB3Q4VNP5qkl7iyeFkGkF1xCAve OYs=&downloadAs=FVD2015Setup.exe&fallback_url=http://www.finalvideodownloader.com/.../newest.exe

http://www.currentbinariesuniverse.com/c?x=MPO07OWz gpeKfuY8A7xubAKZ54pg/4GO2xRD2z6eR0=&e=0&c=vS6W5K6v4EXIinmRe9IEVxY2mb7VTrLijQOPbtYa ozryfugLhzESK/OZWh zd1XIv9awpqMDGbC4mkPsBtxsh8uF K6k/6/8/rBefFQCOwj2za1z4nZbbc Ay1jMv/7RFQ5wfrTryhgsKJw2xfAIgvLg4agGlpawr4VfCkw0Sk=&downloadAs=FVD2015Setup.exe&fallback_url=http://www.finalvideodownloader.com/.../newest.exe

http://www.bestcycleupdate.com/c?x=bs3jGjX4QaD4kj9YlG7PfL6TDL53f1jLxZW7HQVy VQ=&e=0&c=IinrI2mnyq lFrs4t2neB/BqASho7bpBzJeaDbGqE0A0CG/qtLrLU/s0cWHz2L0qwCICL53EViKJkon1U4jWjCedQw7ntwZRmWH5smiF9Tijkrfg6yc821i0v bGBoIjmSd9Okk6BZFkpSpnFcxqaGspmqKRZleCX5L3DUR9V0k=&downloadAs=FVD2015Setup.exe&fallback_url=http://www.finalvideodownloader.com/.../newest.exe

http://www.farmtowerscapital.com/WVl6OTRQVWxDT0hwU2RteEpRV1l4TlUxMVRVWmtVRzFKVFVWV2RreE1XbVJMV0ZkT1dHbENRWEpSUTIwNUpUSkdNQ1V6UkNaalBUSlpPWFl3Y1hGYVJqUTVSbXg0VFVwcWQwMWtkR2xZY0RJM1lqQTBhR2hOWmsxWlVHcGhValZDTjFkbGVYRTRlWGc0ZVhWeU0wVjNhU1V5UmxGT05rTWxNa0pTU1hkSGJHRnJabVY0TUV0UmJteG5VR1JtV2pWTk1ubHJSVTFhZEdaU1pGWWxNa1pIU0hsck9VcHBTMmxOVVRrbE1rWXdNemhqUkROak1WSjRKVEpHVTJ3NFNGSkZOMFlsTWtZbE1rSkpWV2R3TkVjNEpUSkNVMjlCTXpocE5XUldhbEVsTTBRbE0wUW1aVDB3Sm1SdmQyNXNiMkZrUVhNOVJsWkVNakF4TlZObGRIVndMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um5kM2R5NW1hVzVoYkhacFpHVnZaRzkzYm14dllXUmxjaTVqYjIwbE1rWmtiM2R1Ykc5aFpITWxNa1p1WlhkbGMzUXVaWGhs

http://www.tourbitscapital.com/WVl6OTRQVEZhUVdVNGVTVXlSakZKVmxWcVRFNUhaR05LVURWYVZHNVJlRXhUVjAxbWIyVkdRVmxHTkROTkpUSkNWRk5KSlRORUptTTlPVmhNYlRWVFdrSkVPVGhCZGtwTFZVRkRkVE0zZGsxRFoxZDNNV3czVEZaS2RWbHFSa3hCYUdGUVowWXpPVGRySlRKR1IyOTZURmhRWm5CUFRUTktUazB3UWxaeFVXNU5kR1JuTkZoTlF6UnJOR1JvT1dsWlJqY3hORTFpYjAxbFJ6SjVlRXcyYXpGT1ZXOUxjVFExYzIxcFZXVXpKVEpDU0Zoa1RGUWxNa0p5Vm5wUWJ6bG1lVVYySlRKQ1YwUkdVMUJaVDBKYWIzRmpiVVpvT1VFbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlSbFpFTWpBeE5WTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTVtYVc1aGJIWnBaR1Z2Wkc5M2JteHZZV1JsY2k1amIyMGxNa1prYjNkdWJHOWhaSE1sTWtadVpYZGxjM1F1WlhobA==

http://www.bestcycleupdate.com/c?x=ETS67gNS6jzMJ3nMD7xb1eIK2V9XaVS1raHzY5wyYpI=&e=0&c=Ki3LoxK7a1WMgsNDCrqucIxd bGlFtFTFEhEbkbVxBwOsxQdmXKAn/xIZVVyN/LB0Dwir/By5SbbtEyeERwZNJxJHWOUPfyHkbo1vg8wVaacjS4EsN9iGrBztCb5SpaSF7rbXlgz/LBJewPOz55zcrZQxp/xrgCO5Pl0KjPSdFI=&downloadAs=FVD2015Setup.exe&fallback_url=http://www.finalvideodownloader.com/.../newest.exe

http://www.chucklesignstower.com/WVl6OTRQVzU0YkRCR09YbGhlVU15TjFoeVJFSTJURTVTWkdoQ1ZXOWxTbmQyU3psR1UwaG9TemRaZUZaRVdFVWxNMFFtWXoxcVNtNUtZVGRhZFhoblNUWmFSekZEYVhVbE1rWklWVlJuZW14dmMyUnpNMUJZTVdvNFVFUllhVU4wYTNaSFlUTkRhMFJoVkhGbmNFcDZTVFowSlRKR1NFVnVTRlpXT1dkbFlscGhRa2R4ZGpKelNHbDBiaVV5UmxCMVdYUjNiVWg2VlVzMmMwMTVPR0pxWlhaVFpVTndUSEpYYVZocFlVTmFhMFk0UVU4MllXZGFVVmxCVjNsc0pUSkNlRmQyYjBsSlMxUmxNMUphTnpkUFNFZFlVU1V6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxR1ZrUXlNREUxVTJWMGRYQXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROQkpUSkdKVEpHZDNkM0xtWnBibUZzZG1sa1pXOWtiM2R1Ykc5aFpHVnlMbU52YlNVeVJtUnZkMjVzYjJGa2N5VXlSbTVsZDJWemRDNWxlR1U9

http://www.nowrepositorylaboratory.com/WVl6OTRQU1V5UWpVeFJqVTROVmg0VmpGTWMweHdWRW8wTW1sWWMwcDBkM0Z5WmpaTlZXZGhXbE5zTkVsRllYTmlWU1V6UkNabFBUQW1ZejFVYzJWNFRHeHBhMDFSYUZweFQyeHpiR3hQVEd4dlZrNVpSekZzSlRKR2JGSmhPWFZ1WXpGVWRtTlNiMjluYm10dWNFZHJjMHB0TTB4UVJYSkJlR1ZVY2sxM05UTk1aWGhUTjBaNE0yWjNPRE5CUm5GQ2RERnBTRkZMYkhoU1RtdGhiMHRGTlVzM2VsUkpZMFJ1Um1oc2VUbHVSa3RGY21oM2FUVlJWbWxYZDFRbE1rWk1KVEpHY1RVM05TVXlSbkZTTjJ0eU9XSk1ZMFZWSlRKR2NqUjNKVE5FSlRORUptUnZkMjVzYjJGa1FYTTlSbFpFTWpBeE5WTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJuZDNkeTVtYVc1aGJIWnBaR1Z2Wkc5M2JteHZZV1JsY2k1amIyMGxNa1prYjNkdWJHOWhaSE1sTWtadVpYZGxjM1F1WlhobA==

http://www.updatetodaystock.com/c?x=wfIRsISoQJTIAnI1SUHMDjXF9Asc1GAXFSiXhB76wn0=&e=0&c=OU6iFhliAks5tQC7uoNTh4R S4w72cfVH05ZzFn0jRRGv0h2ns2mbyy0C35M/1uOXa8ynFcRK9aPcUmaqqugQ9f/1VwegacQg7lpOJcG65r73hz2po neX8t45quNFQxPIt 9golZgmgX9Bd9ZRvZJZZ0eYSTJjfnswGURvNtvo=&downloadAs=FVD2015Setup.exe&fallback_url=http://www.finalvideodownloader.com/.../newest.exe

http://www.appscontentsoftware.com/c?x=3 i0IhasyeW U Se8QNgQolYfmKikkmkMLFHLV/Ae2E=&e=0&c=1/8HWsiuImuMo67EWNL9 HPdzEvggXhxT4D7 50g8sgx piAvITU2VSnoHdij5aoTf3cX3h KeUFl4iJ0SIrhzNzsQpJpOQt2/n3719AI9Q1Huo/4JLjt SEmIxyN b/4qs3A3P9lQdfRO0TVO8KAgMZNtj5NEsc02ccLZyHOQA=&downloadAs=FVD2015Setup.exe&fallback_url=http://www.finalvideodownloader.com/.../newest.exe

Latest 30 of 30 download URLs

Remove fvd2015setup.exe - Powered by Reason Core Security