installer_adobe_flash_player_tailandés.exe

One Installer LLC

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_adobe_flash_player_tailandés.exe by One Installer has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Vittalia DM installer. The file has been seen being downloaded from pizi74663yilolu.becokrefulew.net.
Publisher:
One Installer LLC  (signed and verified)

MD5:
ab32f8a9eee171712a4f147932073dfd

SHA-1:
43b60f2569c5c919cf1250deb08e2f45a2157a1e

SHA-256:
32c9dc151f930b4153aa6a3c190f06962554d7e833b8a6f3ee5c25d25dd1b62d

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/27/2024 8:25:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Vittalia.OneInsta.Bundler (M)
16.3.23.6

File size:
1.1 MB (1,121,088 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
11/6/2013 10:20:03 PM

Valid to:
6/24/2016 11:26:08 PM

Subject:
CN=One Installer LLC, O=One Installer LLC, L=Wilmington, S=Delaware, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
280F69FCB8F054

File PE Metadata
Compilation timestamp:
12/6/2009 5:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:+d5jEFpe/pbXY+4Fv65DcSOKYWkxQhU1UOpz7R/:Ij4peRT4FgPwXx7V3V

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
6.6996

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_adobe_flash_player_tailandés.exe has been seen being distributed by the following URL.

Remove installer_adobe_flash_player_tailandés.exe - Powered by Reason Core Security