installer_youtube_downloader_3_4_chinese.exe

Vittalia Internet S.L.

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_youtube_downloader_3_4_chinese.exe by Vittalia Internet S.L has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. This setup program installs potentially unwanted software on the user's PC at the same time as the expected/marketing software, without adequate consent. The program is typically installed via a form of malvertising
Publisher:
Vittalia Internet S.L.  (signed and verified)

MD5:
b7c75871008b268b7226b3beb2bd7ff1

SHA-1:
8690c011c8890a86fbac5410e9d13a66966dd090

SHA-256:
7add83e24307468bf4512931695a2005775f0dbaf1228c0a9a25109bcee1be38

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/4/2024 5:11:42 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/Vittalia.onema
7.11.184.156

AVG
Skodna.Bundle
2015.0.3293

Comodo Security
Application.Win32.Vittalia.L
20059

Dr.Web
Adware.Downware.178
9.0.1.05190

ESET NOD32
Win32/Vittalia.H potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/Vittalia
11/11/2014

IKARUS anti.virus
Trojan.Win32.StartPage
t3scan.1.8.3.0

Malwarebytes
PUP.Optional.VIT
v2014.11.11.11

NANO AntiVirus
Trojan.Win32.Downware.crdprr
0.28.6.62995

Qihoo 360 Security
Malware.QVM10.Gen
1.0.0.1015

Reason Heuristics
PUP.VittaliaInternetSL.i
14.11.11.23

Sophos
Lolliport SoftwareBundler
4.98

SUPERAntiSpyware
Adware.Downware/Variant
10243

VIPRE Antivirus
Threat.4782551
34232

File size:
3.8 MB (3,992,480 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Common path:
C:\users\{user}\downloads\installer_youtube_downloader_3_4_chinese.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/26/2013 8:00:00 AM

Valid to:
10/2/2015 7:59:59 AM

Subject:
CN=Vittalia Internet S.L., OU=IT, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Vittalia Internet S.L., L=Mostoles, S=Madrid, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
320EBE59A34A647E4E737AD60CDBAE80

File PE Metadata
Compilation timestamp:
8/27/2013 5:27:23 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:G9+hWYH0pR0sGwas+jr2QTIYAnrUTSV2UxSQV1+3JMQdbH2h6aB79Oj:GO6ur6xu22

Entry address:
0x24BD9

Entry point:
E8, 12, 99, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 20, 64, 44, 00, E8, 41, 54, 00, 00, E8, B4, 42, 00, 00, 0F, B7, F0, 6A, 02, E8, A5, 98, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 9D, 76, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4742

Code size:
233.5 KB (239,104 bytes)

The file installer_youtube_downloader_3_4_chinese.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.uplstatsone.com  (93.189.33.84:80)

TCP (HTTP):
Connects to services.upd4ter.com  (93.189.33.101:80)

TCP (HTTP):
Connects to media.vitavita.com.es  (109.70.128.135:80)

TCP (HTTP):
Connects to download.upd4ter.com  (93.189.33.101:80)

 
http://download.upd4ter.com/installers/down.php

Remove installer_youtube_downloader_3_4_chinese.exe - Powered by Reason Core Security