installer_asrock_alivenf6g-vsta_chipset_+_t__de_red_deutsch.exe

Vittalia Internet S.L.

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_asrock_alivenf6g-vsta_chipset_+_t__de_red_deutsch.exe by Vittalia Internet S.L has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. The file has been seen being downloaded from deutsch.eazel.com. While running, it connects to the Internet address services.upd4ter.com on port 80 using the HTTP protocol.
Publisher:
Vittalia Internet S.L.  (signed and verified)

MD5:
833580e464b3ca7b13567f37ff3752d5

SHA-1:
00ca5f193625ac886399b5754db109036b3a9391

SHA-256:
100d0fd4fb67045c14ccf8dfd9f707c111be2c4df5861002b5d6dfdfef4eba17

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/26/2024 2:13:18 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.150.22

AVG
Adware AdInstaller.Vitalia
2014.0.3950

Comodo Security
Application.Win32.Vittalia.AB
18286

Dr.Web
Trojan.DownLoader10.36044
9.0.1.0136

ESET NOD32
Win32/Vittalia
8.9810

Fortinet FortiGate
Riskware/Vittalia
5/16/2014

Malwarebytes
PUP.Optional.VIT
v2014.05.16.07

NANO AntiVirus
Trojan.Win32.Generic.cspepc
0.28.0.59911

Qihoo 360 Security
Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.VittaliaInternetSL.FF
14.8.7.21

SUPERAntiSpyware
Adware.Lollipop/Variant
10601

Vba32 AntiVirus
Downware.Vittalia
3.12.26.0

VIPRE Antivirus
Vittalia Installer
29280

File size:
2.4 MB (2,527,784 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Common path:
C:\documents and settings\melanie\eigene dateien\downloads\installer_asrock_alivenf6g-vsta_chipset_+_t__de_red_deutsch.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/1/2012 2:00:00 AM

Valid to:
10/2/2015 1:59:59 AM

Subject:
CN=Vittalia Internet S.L., OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Vittalia Internet S.L., L=Mostoles, S=Madrid, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
00B5B17F6085B2B530BA3A0FF637EE1A

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:91A5Xwem6TG2hhr+sAIuJHbXpzh0g4Je6gmcrBT98Q:9W5bGecJJjZnZTT

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_asrock_alivenf6g-vsta_chipset_+_t__de_red_deutsch.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)