vdownloader_setup.exe

Hipefoci

Criteria Quality (Alpha Criteria Ltd.)

The application vdownloader_setup.exe, “Hipefoci Setup ” by Criteria Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.vaultbytehead.com and multiple other hosts.
Publisher:
Romerot   (signed by Criteria Quality (Alpha Criteria Ltd.))

Product:
Hipefoci

Description:
Hipefoci Setup

Version:
1.5.4.6

MD5:
b7a337deff7bd3bbdf936394c4406c88

SHA-1:
1fffdde7fd15b865e5c8579bffb0c5fd12256b3c

SHA-256:
a3290f8011bd98a271e470276ec87d9fa288be621481e8c54ffd7d8cd02ddc7d

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 12:50:37 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC.Installer (M)
16.6.26.9

File size:
1.3 MB (1,356,536 bytes)

Product version:
4.8

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 7:14:57 PM

Valid to:
8/3/2016 10:13:33 PM

Subject:
CN=Criteria Quality (Alpha Criteria Ltd.), O=Criteria Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216B914C61A8F4896BFAF26489B9954D2A

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:21yqR+OTsS8yxgPhtFidak7+x+ePJx/7+LCoUDq8tIBYbM:2gEs0g5tFP8+FhxKLCnDaBIM

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.3553

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file vdownloader_setup.exe has been seen being distributed by the following 50 URLs.

http://www.vaultbytehead.com/z57L1r 8NxE701zy8t0FR3TtRvhO03X3sPEgesOy_759M_UMu7eaaSR52iK IgYULBICA_2EIaCoLb7hCvJ2y6FGtg9EhkiuU1B2MBGBmS3v5r_tuxMWBQ4nlrCqWEMHeJH1vUZ_7KCC4f1A5ZSNARdACzfITKvU21vccwk2VzzB0CgS7QRyFjaRf_DI A6XU_kSF9pE-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.vaultbytehead.com/ohwNoyrEMzZ9LaUXmeqpZ 5qlXjn6trsqS7C7HG5lX0O8tAZPRQkB17B1F0sagiBlqalP75kY1 Q3zitKaU17CZjl903BIuSztdmCmT9bpY0W7s iTFxfTiARVkSruIw0XdxhQ27aYmimFI_fWykCfr9NnVlSxIYIGTAZ0ps7ftvix4U4g4=-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H-e

http://www.vaultbytehead.com/pZ9jr8DilCfxtKbQX28Wh6Q6vrUJDiFyrzcOLK5GRe zFoe ORNoEr0oAoBYXXymfpvsKGubOD0xDk8y5XP3NdD1npxXVPfNtrhg7M5oMtQNTfCNI1ZL2Q_xJgoT4DxUEDgSi4GGS04qI0O8wYbEUbRY9vn JNniBn5F1_HilhYdZSHJe0o7wHzagmoB2AxFCrpJ2BWR-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.vaultbytehead.com/47Iri3T Pv8lgPfLcws65EGKs3SsI1rd2MrnfLj4_2HOHDXTzFFhJmYR2zJVNIQK8CR wmfY4am19Uxgnm4rg70JjXwPS0cNdB5fxA3auH9Lfgv4LqE5v9 34H3vHR7CtE4WsrTMWeZcUP0PB uqg4CrI1AtLwoXjsxMGx4UM72sf_M6TsGhxpSf1 6YwIhtOmisbdJW-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.vaultbytehead.com/TElriEYVp lHnvhCLseQagMJszuMhqZUV56w67oWx1 vAw6iZcFI9EoEnPAUetTE8QV0PF6WDTlrsuVFCoKpIzKWD1o6Tzoo81GezUCiKPRNf8_fpZUoCwGwtDtcyqnVAr7KLEEMqUHTiql8bRbO0oPpBvCQac9bT2lbrcm8T_fwOuwcRA0RzWXyZajj7bbdN390VOXN-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.vaultbytehead.com/zpYVnRQGhGhkm5w_mUYQHkp1mjxSE8XeT2iPpwNDJf0HXqPmGpstDZyEDth1xI3pkh2K boe7SME 7ihqME846VlkPL9PM8sLor1rBRekkmP uE9a0j8gZNPVZQjxdMplU1Y26h7wZRrIBy4q0FZ ap7ZQz dUBNyAe7HpNsHG1l98wu0jvNZHxeDO rYaTeMzYhJ5SC-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.vaultbytehead.com/P8rGTp0uCZoBtK7XeHDfgl1WsGg6q6SXcex9tg_kKOCBEuLWZ4G5X5GEHFRCcEQCtNlCWz2iHIdpwSbG3sgmVCIYtLjpSFVwmelYsjSSugrtIN07dInNq sRL8b9ZW5HXHJSCWDC2kvud9B1vM5jTE1TP4DWeT2ha7DudOK0jg1VA5dNPvP80cDeOs7_GjWV1GYz5Y8F-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://ec.ccm2.net/it.ccm.net/download/.../VDownloader_Setup-4.2.1970.exe

http://www.vaultbytehead.com/lfQ8dYbS3Q24PNUCnrdg4MFMJZ4s4UN9M6gAU3aW_EQqtPPsPVkmX HLGX9LmYiFzblPVPEOCF7JFnS GxzYOcXaTGHS5pMF72HnpEEk0eG8OzCUFB1OCW11b7C19TPm4fNvXi6edBbuUsn T nKYK0tJ1SeO b3VAUQmsBPFmYSxYphAsskjsgISdCgfnyRfgZdqsDv-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

Latest 30 of 53 download URLs

Remove vdownloader_setup.exe - Powered by Reason Core Security