vdownloader_setup.exe

Lem

Criteria Quality (Alpha Criteria Ltd.)

The application vdownloader_setup.exe, “Lem Setup ” by Criteria Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.vaultbytehead.com and multiple other hosts.
Publisher:

Product:
Lem

Description:
Lem Setup

MD5:
359b465d21444143b7fca88ee909f2a4

SHA-1:
319d0dc497ff75cfece5cd0f41bb2f111f1c854b

SHA-256:
b5d000a25145be80240bda21a99e5b9d581e704e0017fe04f7caddab81ae7436

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 1:00:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC.Installer (M)
16.6.26.9

File size:
1.2 MB (1,252,368 bytes)

Product version:
1.1.8

Copyright:
Web fast

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vdownloader_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 3:14:57 AM

Valid to:
8/3/2016 7:13:33 AM

Subject:
CN=Criteria Quality (Alpha Criteria Ltd.), O=Criteria Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216B914C61A8F4896BFAF26489B9954D2A

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ZjPZscnzorxjLrAN/nhqoSVxf4hqcG9glG+qnj:ZbIFjLr6MlAq59gIl

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.2916

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file vdownloader_setup.exe has been seen being distributed by the following 37 URLs.

http://www.vaultbytehead.com/vkQNZoZ Xl1y0mO4R 4Ro6dZ2EusImscZ8m6zmTN9WJNhChtWxEwGQbGPcTJiFtttfRdqnNy3Xqp4QDG0GItOp_fJQ1UBPhpMfYomcaFVBsnp3dY0wSABA5QVfE3qEjBMX8e6eQZqIUihGYBTo6j20B2mr18Dbs1DeYvPNfUM03z7itXoZdfhGOInr UJcORHo22adH5-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.vaultbytehead.com/Fnm1BJf9S4Hd1AUwtzv8m9cLxeo55M8cTptXZYn2f1aK629AWz IBl5aJQMmJ eIbsOXMBGy3wAZ0udjOvOtsflkH3tOjJsBH2aGTN0KAKiB7KnfsWaq9F9UZTobPD37xjSr2vnFLhmiNoPTb0tBkXGr6q5g5146jTrtXRDsmk_CyM0thneHiuv8XVhLiL8 v7TlqnnD-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.vaultbytehead.com/0qnA9NpDQQYX6hHhHZl6pq2NHGjKmo3qfVK_mP2t4OqT3_MlGka5mWDSm4XQCG Cyx5c37dnyIVb1uaft1vpMzKGMp w3Yt2wAzvm8t51YiPQw9p_qusjenIEht3CFlGDFr29oERLF9XTpz5ZkJKJr8PulKorzo mnc6ih4JeAZX6pxCiEGV0QW1rBREkeIu1k9MijS6-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.vaultbytehead.com/weoxtqZgQLxIgE13Pet01OE5V8qeX_n3RM1mJoRyTdYfcQ5EJHn_rzrccpCg1PB ip8rZZX9jmBdevdCRMP3dKMdLfcJzul kAQSt9RIi5NDKdlOPwnTC_vbA 0ueHcGO_89R1bf0S3RLL35peLxehrO2E2QmbWMnLlh0 beCDHSRKifIvtPnSefsltScXJI8Gi5w_x8-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.vaultbytehead.com/Yqqo23lXvRNqrLrVB0T2jgGaiPaNjkE96IOMR 0Mec3ziAhGrO6mFJtjsfhgy8 W_c8kXg7SVK5QB1iEOwwblfLWFa5LaoC48meswvXo aHZtzZVd9yEXVzXy5uP5o6sB3DEC4DTnpnOR72TbibuSkJyr1HarWkgV8pYoqJyeW0AqgUOK8PhZx7_MBnejGA60BjiS54N-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

C:\Users\Administrator\Downloads\VDownloader_Setup.exe

Latest 30 of 37 download URLs

Remove vdownloader_setup.exe - Powered by Reason Core Security