installer_adobe_flash_player_english.exe

Vittalia Internet S.L

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_adobe_flash_player_english.exe by Vittalia Internet S.L has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from download.filewin.net. While running, it connects to the Internet address services.upd4ter.com on port 80 using the HTTP protocol.
Publisher:
Vittalia Internet S.L  (signed and verified)

MD5:
cd9983cabb24dc4bcbbd33fa66b8166a

SHA-1:
a04581322e8fd4d91f00febee5fd907a27231e7c

SHA-256:
032f17e44b6598c2c68364fbf5b3f449785779af2fd81aabfb888b68434c324b

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 4:29:28 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen
7.11.107.74

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.15411

Dr.Web
Adware.Downware.178
9.0.1.0101

ESET NOD32
Win32/Toolbar.Babylon
9.8908

Fortinet FortiGate
W32/Toolbar.BABYLON
4/11/2015

Reason Heuristics
PUP.Bundler.Vittalia
15.4.11.13

SUPERAntiSpyware
Heur.Agent/Gen-WhiteBox
9942

VIPRE Antivirus
Trojan.Win32.Generic
22306

File size:
185.9 KB (190,400 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/14/2011 7:29:05 AM

Valid to:
6/8/2012 2:13:35 AM

Subject:
CN=Vittalia Internet S.L, O=Vittalia Internet S.L, C=ES

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001308E97D50D

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:fgXdZt9P6D3XJQ4BVXdOZRR2dewzB0VIpbvLGpx/FPEWcs2ENLfr+FQR85DYY:fe34vtU9uW6qQWcs28liiY

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.5723

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_adobe_flash_player_english.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)

TCP (HTTP):
Connects to download.upd4ter.com  (93.189.33.101:80)

 
http://download.upd4ter.com/installers/down.php

Remove installer_adobe_flash_player_english.exe - Powered by Reason Core Security