installer_password_eliminator__xls_1_0_4_deutsch.exe

Vittalia Internet S.L.

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_password_eliminator__xls_1_0_4_deutsch.exe by Vittalia Internet S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Vittalia DM installer. The file has been seen being downloaded from deutsch.eazel.com. While running, it connects to the Internet address services.upd4ter.com on port 80 using the HTTP protocol.
Publisher:
Vittalia Internet S.L.  (signed and verified)

MD5:
741e8b7ae50d1d1f499df22b1bf67139

SHA-1:
e59197a38c83f67195f263a3f015f03178e5c4fa

SHA-256:
ac9458dd8fd95bc459e57bf7978cb6b3a78e14a91818dc38322ec4002526d791

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 2:39:52 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Vittalia.Bundler (M)
16.6.12.9

File size:
3.6 MB (3,800,736 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Common path:
C:\users\{user}\downloads\installer_password_eliminator__xls_1_0_4_deutsch.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/26/2013 2:00:00 AM

Valid to:
10/2/2015 1:59:59 AM

Subject:
CN=Vittalia Internet S.L., OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Vittalia Internet S.L., L=Mostoles, S=Madrid, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
320EBE59A34A647E4E737AD60CDBAE80

File PE Metadata
Compilation timestamp:
8/27/2013 11:27:23 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:S9+hWYM7W9un6QJar6QTbYUx5Fs+VuibE0SM3Qxexre6N6h4fcXSQPjN1okzNoL7:SOVcOfp6hGqowe

Entry address:
0x24BD9

Entry point:
E8, 12, 99, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 20, 64, 44, 00, E8, 41, 54, 00, 00, E8, B4, 42, 00, 00, 0F, B7, F0, 6A, 02, E8, A5, 98, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 9D, 76, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
233.5 KB (239,104 bytes)

The file installer_password_eliminator__xls_1_0_4_deutsch.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)