installer_driver_lexmark_x1110__x1130__x1140__x1150__x1155__x1160__x1170__x1180__x1185__x1190__x1195

Vittalia Internet S.L.

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file installer_driver_lexmark_x1110__x1130__x1140__x1150__x1155__x1160__x1170__x1180__x1185__x1190__x1195 by Vittalia Internet S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Vittalia DM installer. The file has been seen being downloaded from download.drivers.solodrivers.com.
Publisher:
Vittalia Internet S.L.  (signed and verified)

MD5:
936a3aeb3de2e069a8fdc1fee03a1e2e

SHA-1:
3075b64d6c64ad0304f4cacb1d321119057e7711

SHA-256:
cff716d83dc46a4d0c157a7343830c9f07585140962a611839a43bfeb24cdcf4

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 3:01:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Vittalia (M)
16.7.30.16

File size:
1.2 MB (1,293,328 bytes)

Bundler/Installer:
Vittalia DM

Common path:
C:\users\{user}\downloads\installer_driver_lexmark_x1110__x1130__x1140__x1150__x1155__x1160__x1170__x1180__x1185__x1190__x1195_spanish.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/5/2012 1:00:00 AM

Valid to:
5/9/2013 12:59:59 AM

Subject:
CN=Vittalia Internet S.L., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Vittalia Internet S.L., L=Mostoles, S=Madrid, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7952CFD9EF040B59F3C140BA1DA97A60

File PE Metadata
Compilation timestamp:
12/4/2012 9:27:43 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:w9WC988bu6CootMz82LE8XZK8mLE4lB/6XqSM0su4V6KQY:wB88TCoJz82DXY8mF6XH/y6ZY

Entry address:
0xE39A

Entry point:
E8, 8D, 88, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B8, D1, 42, 00, E8, 50, 57, 00, 00, E8, 32, 29, 00, 00, 0F, B7, F0, 6A, 02, E8, 20, 88, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 5E, 5D, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
139.5 KB (142,848 bytes)

The file installer_driver_lexmark_x1110__x1130__x1140__x1150__x1155__x1160__x1170__x1180__x1185__x1190__x1195 has been seen being distributed by the following URL.