setup.exe

Cash Buyer Media

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Cash Buyer Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Vittalia DM installer.
Publisher:
Cash Buyer Media  (signed and verified)

Product:
Cash Buyer Media

Version:
61.6.7.6620

MD5:
0dc0a7884e836d4137ca8349cd2ee49a

SHA-1:
dd5e034bd5bbddd8bcd3cae5d67026acde030837

SHA-256:
555156578acb9a84cc9194995400f79ceed3a53169e2b88d813a19c7aca6f7d0

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/27/2024 3:47:55 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Vittalia (M)
17.2.22.15

File size:
870.6 KB (891,496 bytes)

Product version:
61.6.7.6620

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Language:
English (United States)

Common path:
C:\users\{user}\downloads\old\new folder\setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
11/11/2015 2:36:38 AM

Valid to:
9/6/2016 10:41:42 PM

Subject:
CN=Cash Buyer Media, O=Cash Buyer Media, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00D944FE65740A914F

File PE Metadata
Compilation timestamp:
11/29/2014 5:26:06 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x22C6

Entry point:
E8, 45, B6, 00, 00, E9, 49, AF, 00, 00, 81, EC, 18, 02, 00, 00, 53, 8B, 9C, 24, 20, 02, 00, 00, 55, 56, 57, 8D, 44, 24, 10, 50, 33, FF, 57, 6A, 01, 53, 89, 7C, 24, 20, E8, 2B, 2C, 00, 00, 8B, 4C, 24, 20, 8B, F0, 83, C4, 10, 8D, 2C, 0E, 85, F6, 75, 1D, 53, E8, 55, 2A, 00, 00, 53, E8, 4F, 2A, 00, 00, 83, C4, 08, 8D, 47, 02, 5F, 5E, 5D, 5B, 81, C4, 18, 02, 00, 00, C3, 6A, 02, 53, E8, E6, 2A, 00, 00, 8D, 54, 24, 24, 52, 53, E8, 6B, 2C, 00, 00, 83, C4, 10, 3B, F5, 73, 20, 8D, 64, 24, 00, 8A, 16, 8D, 44, 24, 1C...
 
[+]

Entropy:
7.9692  (probably packed)

Code size:
52.5 KB (53,760 bytes)

Remove setup.exe - Powered by Reason Core Security