installer_adobe_flash_professional_cs5_5_5_spanish.exe

Formula EFT Europa S.L.

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_adobe_flash_professional_cs5_5_5_spanish.exe by Formula EFT Europa S.L has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. The file has been seen being downloaded from b499f2b4.cdn.programdlds.com. While running, it connects to the Internet address services.upd4ter.com on port 80 using the HTTP protocol.
Publisher:
Formula EFT Europa S.L.  (signed and verified)

MD5:
4628d6986a3728ab235568846f31d337

SHA-1:
1e349f58585f609668969a26b94b509b5056aa22

SHA-256:
a8cfa9d5306492358137f170834cc2bec4019b871d1d523db59288a1e7d4736b

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Includes bundled offers in the install and download manager that include adware programs.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/24/2024 10:08:37 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AVG
Skodna.Bundle
2015.0.3488

Dr.Web
Adware.Downware.1556
9.0.1.0120

ESET NOD32
Win32/Vittalia (variant)
8.9744

Fortinet FortiGate
Riskware/Vittalia
4/30/2014

Malwarebytes
PUP.Optional.Vittalia
v2014.04.30.09

NANO AntiVirus
Trojan.Win32.Downware.cqixaf
0.28.0.59608

Reason Heuristics
PUP.FormulaEFTEuropaSL.s
14.4.30.19

Sophos
Vittalia
4.98

VIPRE Antivirus
Vittalia Installer
28732

File size:
4.5 MB (4,731,984 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Common path:
C:\users\{user}\downloads\installer_adobe_flash_professional_cs5_5_5_spanish.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/18/2013 4:00:00 PM

Valid to:
11/26/2014 4:00:00 AM

Subject:
CN=Formula EFT Europa S.L., O=Formula EFT Europa S.L., L=Madrid, S=Madrid, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0DB4DBB604EF737F46C4680160CC360F

File PE Metadata
Compilation timestamp:
10/16/2013 2:22:35 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:+OJP+tXRHbximOeQeVaL7dqCcgVBR//xdnpo2BFD1OSQV15Z+24D2C5WxjWwfD42:aGb3dbDOrCNKRAXu

Entry address:
0x111B1

Entry point:
E8, 6A, 98, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 78, 0D, 43, 00, E8, D9, 54, 00, 00, E8, 49, 43, 00, 00, 0F, B7, F0, 6A, 02, E8, FD, 97, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 35, 77, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.3718

Code size:
148.5 KB (152,064 bytes)

The file installer_adobe_flash_professional_cs5_5_5_spanish.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)