vdownloader_setup.exe

Dotalipi

Setup Alpha ((New Media Holdings Ltd)

The application vdownloader_setup.exe, “Dotalipi Setup ” by Setup Alpha ((New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.vaultbytehead.com and multiple other hosts.
Publisher:
Hesibacef   (signed by Setup Alpha ((New Media Holdings Ltd))

Product:
Dotalipi

Description:
Dotalipi Setup

Version:
4.0.1.1

MD5:
1bf405ee74c07b854c8c9706a28ad777

SHA-1:
34ec0d22b80dfbad845fe7adafe2ad09a09b46eb

SHA-256:
a9ae8b61da2d5dc46c1b261d5652e0cbc052325539bd5a27ccec561b0e6af9b1

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 12:53:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.5.5.11

File size:
1.2 MB (1,255,456 bytes)

Product version:
5.3

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vdownloader_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 5:41:44 AM

Valid to:
5/25/2016 4:42:13 AM

Subject:
CN=Setup Alpha ((New Media Holdings Ltd), O=Setup Alpha ((New Media Holdings Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216F55CB04783E0F0E5AC4C45115E1BCCC

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:iO1wQfAffhvpcAgAtkWsfbjTjf0M8axuQPNtSq5HgQox8/gMwfmg:iUifhvCnWLW3fpLxxtd5HgRxeg

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.2963

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file vdownloader_setup.exe has been seen being distributed by the following 50 URLs.

http://www.vaultbytehead.com/c?x=z1eWoqnfphdMA6FXEbrigHy/0vbS2brdis4MiLNw2UU=&c=7NsJq3ftOvWCAcYQrh5ln5oWLV2vcARkts8h2UuaEsF8yKy jiEqac3TeZ21pFZIqeySNA7mtJd0y66cJRS3RFavQ0S7lrP8bzGDMTjJ1IegjITtAqJ465FuDGHStMwaHToVLi1za/0PXDnZoKQ8MFDc66I/ebTEOiB1fnI2VDU=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=qhHVB2NiwDHHuDbmFfrCTjVMfmnq2RG/QrY8mSv0PjE=&c=Tt91tDnrXfP47Z8YV4PRP35bNMyLFBhUtAdcttMTE9U/suH6sELsDsIKJpV/BcHXs/ClgOnTmwT2bf1fNWAohGTEq9m2Daymz2Zi6tZlgI73mZeyUjEhQrOUrgP/Tydv2TuiJNA8GexMx3Aq72CPD9zxYLVPCF iFBhKku/wvEU=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=C89Ku3t1jXtmVLolGJR1x5uI8A1bNRHlYB6qHKRvXTQ=&c=lA0A0j93fe6EmxtyoTJdvWJJmk Y1h4pLLswPOnF78Bat1iBZXqClbsleqvrGSAIhGZwB3ks5Yv3mMlBe6d1ZKsHhw9kOp2iQU7TueoS1QkGCpy6UIfc6GolxgNS5hUpPJaCjxKcoidRGv0RYiBeaoXv1FWqXILsBPJprHlUC9Y=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=1GuzDbgKLsNu38EF1uoHSYHWEMn8jwWtzBqdYu5SqIk=&c=MrYOd/FZSKRYUfEDkLEdl8tpMyhmZPmXf5Bmmh8NuJdus5wC/q8aV6vspS/1RIbkCU9uIVu7WhLulEOUO8nmwUmnL5JPJNFHkphUY3tD0DS6Vsj74vPa4InYbPVkSCYM/NDcVk22MX0Hxf97OVgEWiroEuLi4cAxTVMXD4X8oxo=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=541FFObUOExkxQAfs46voW6qqLtTsBdtXSR05vOcDhk=&c=R8AgsnF7/54ppeGU Nld7QUG83dUtOKPQGKCGEScdCaF2DXKESeLA3NZfl84tYyjI h50fA00yt5VBxTdGw/FAAvDMZWUCLTtV1D44q//wrueMC6mhcWSDoHi2vitqZDWWCZYrlEuaEdX/ ob9Ps98Lyy46rQiE0192w7l7qkcI=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=GmcUbcudrstBMNfBjjvOmWMbdDw/Btpo1bKv JHOuUQ=&c=nqRoGcvthvCXSOQq61RtBFfImVyQA5KXIl5dIiU23eewrWbODbSTpywFi0sJsRErFSdEq/IfSr8YS7fP44U1e74ys0JY9kBVHK/1lQeu2Pii d3VCSOEmhFGnGWtOfUHhuOuUfGtauIxayV LuNKhaHcwgRF8Krag3oXVQ9iuFjA7smjhyszjxdItqDio9PP&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=DhTCr 43d6tngPS0D B0lavWwoFDQXv/6/xbz6/DDrI=&c=4pfuG4VkWgGMn/2/TTzcrQ7mi/XLepyI/ EhQPCYZ293thfzRd777W5Sy4zCqBN5xhUwpyQcFF u8j94nSLxIwvd3BazrLLt5mKGWpZW8hmHwygmlZLsfbABliSEGgccbI8gWkcUm3Ffn4uGsw4q0vgDhfbkzgAlM1ewI0ajySc=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=fkFasI4coYCAck8EXqb5V/WCTTfZ KsPGHa6Z5L48G0=&c=yIIbnBcxxxmSpPZTi5knS4oYVJ5M0Xrv4ZT51 JTZrauDTcblynh69Yp1cZfZbTka 8DxkjEHPO1tH7m/Nc5HC6Di05tvn4DoHF0hs7rovnmAAaj1KvKuvAVbddW2fSesh9rvh1NC5S1sJuVfkzaOrswa6Pk6XKwBPx1yd31bo=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=GBClw9ebMFfmJoM2fV/2Xf4U3t6RRLdEah8yi0jptZ8=&c=eZWPL5k//WiEjTz7qzt6MuzUrzuo/9bQODmTp8DjNGImqLk0ahhzaqIYBHAXibQ25gQ40orjVJkWr/oFX2VvOzhd3e/xsGa94aLmX DxfYeuactPIXWeZdD2RXUSL7gPaxK4QgvUBPKbOb6V2HXcqD3pb7UDZsCGbxaD/MLDQYYEvk2/wVUHc/v6uSAr8gUq&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=u82g53qqvxXkjirMMwJoa/lPJUKfKkHZqScb1dGPdo4=&c=tDRWVqY5g4CfjJpiBSMuvMVHQpp5OfEgxS/jBJfDoGTKL4lqcn3DH87jCaR8/pJ0xOOUPFK3DD/dB 6HOJUsxZMj8CcWRCOgutJETMwRi6W9nvY AI5WMRzBlLLprelPfS/VVC95x/9fdRADzjkUTA==&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=1sy/TuLkR3kTZ3/ QT8T6KBMCtq7CY7 L54S8YZiGDE=&c=Qby/agaxVGrAs/O6Pzp9HEZ yRgRdAsHLWGCG6ke/Y8mXMT2RodSLDrI4sjk5PzI2H10lFWuzu8n7UmtNUYLFFnfDi7X1iZ6AbcOQLbYo7b4YTgMVpmO2/lfTdZ9mBJ5iNI60WfOl3rmIgsxQaIbpBlgdpAE/QwYa Uk fpEYNijFGvv5IXYRrkshoRpnbsd&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x= SxuLgYfSoyeUzSHvhohgGRnNSa hNlZzmUSg IwZKQ=&c=60ALSczDyQEVi5oFnY7ydPklPc9M1aEQaBqz6HD/oRT0pwXxnGR1VB0xymlkh04fH2wohAoR7yBYTtCmCl5s12F7i8Ia2QvytoHQh28w36jnROyjfDsILmaokJnhrDMMeWg0bkF2g/cMF8gZ/Mg9XiT6jQyOQuXplGUHeOKo68g=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=MwqJIS3MJvBGZYxnWSWiaMN9Me7y6qZ0bxeMGePaX00=&c=SsxGoZspNHmNZprsrgS7S2Ri/mrcEw3NPcVlbvtDSLuIBk9afcHPAxNRctuPBlTLh32ruiVx5FrdUcrGOfHps6FfuSTSyd7M1SRNX4RL1XjzlhZsg23MZahxqbZSnOoDA4RKlJ2RU0giVEz7mWcEYOtIKp3iaZFzZngMY7Bq/tSTO/fpJYq5hHJjhbFVARyd&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=NvD1EqUsFbr6snsHJ1gTTSIpenlI/P5zCSt44yW47to=&c=uApbgyFvul285IuJfQdtZ93XNYgfwITmdtjRow0lXeGb7dfQ 0MZvhykUPAZgN0tbOcsLEh1o3QnhPmNw9FiH2LDYtaaxubc7GSwa7DPy6on x4ZhmOLLskrYK8lU1y5V1vC74EQFt/YlmImJ2mmxhtZNeuayugLT7ekfEL1Bgk=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=exe2kBGvJj WKiTXY3SJEvE89gjYTlk57AEj W116VU=&c=rQWJZgVSe0qui3aivr90MCC1ozOhi4BubTg1wCjOBAkaYzhimaoWLEFQMRgcFdJgbgg5CZFoAcqDOrozqduimiXkal2T49 xegH5WOOEZWdzHwPtuh4AWcHGvdbFakhJL4T1mv/gbtbd32XrnyDpq9j1t fExqM3na1dcr81cqvICJUPS0vsq0cJ6Ur4xwDX&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=4Dd1SPxKad/b9NpgQxl83HlIHWFxtTGUKIGX6QxoMeY=&c=A 1JGudk9pfmAyYQ1KME/nlEtyaCBPfIUOMddqZ/jzx3eSpDGXC6FRHJPp9TIMB39oNH5hn jUWls LPu2sYgxy5z5badALczskvq3PqeUArScDmnzikO/5/k7dLvo4fqrDTiz86ilLKYFQkNtV8jyC/FJpP1Fo8RpKrKTD9pMuKgKsZZc2ByfoWnsZCFrwm&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=z1iC6zPcbPk9dC6ztPE8N2sES0YWEpqtjKdKvJdR2FE=&c=6uUsy51iURIm8IcCkXRutFCQSfMxs4CxFZlBoybxMa0nS9QfwfeceQ4nakg5hjy3KVSZAu5Dm1ZD zvtXmMkVGSo8vkKhl4A/cNR03J/lPd FYe e pH6fhgpl4nJUydYKcGS3CGEdnPQGQBsDwu7MLFugZnEHW/1ys55i6wfRPpbkpJCswXQwjMpv4BkUwB&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=EMLUczpLLDwDAgiTA4i53R62E9xVI84t0Q8LsFn18HY=&c=tMBH2yA0roEkxOQFt5w LuEXa6gDr6eBAqpqtRrctWKXIederW56BWDlNnYd/A/IkBHEvY/RZZLTUParjhmwcSHflFelNThHN5AeinfjUEHJL9qX7O53aAd1sLHfkITzrXUHHhdDQoSeOSBaVZwoaqpe7RSPocY4IFxoNUXSEBTA5loFgDQOQjqkm6r6pLkW&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=6DPGCagYXS5p/O6i Lfq4ZYUslSYzfubkO6Qf5dYCrU=&c=OwQQgJEzA RVH7fKm2gSN3cFhpAD5kf6pG AkvMhQvzrUSE1DcG4dOP9qNsYP8/yKz8griURApRvGyXWMcTt7o14f4n OWhRJrrk0C18UE5GxgiGa1hNcul3Bhq9i4JRESy2SVwgnzHY S1cs02D/sZJzrGQxnfdHVcUrQnX1k7beVa3oDyb2n6Y7xtYr8Il&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=d5ww5GJkb42PVBlQ3JQQhQCOc5sgH48QHnjQFPGfRKM=&c=vHaSfjij9PkSssLN8LJOHF77A0QhLRxRMJW5Ot24JhDsV1wZ6lvPJXROY4H27SwZk8IfJ3qMY8Yj/lhs2TWd20yLG yJrYPjusY bPJPQ3xBcz8Vv4hoS8oWGZ7w5sunPYeVmKxdVZGyr3eC1BIgkiCApzlgeLTRJlL18NbQkUE=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=9TvGKYGTfhmmkgg8p2F dqEKe4O2Tp03vdvBiZmjDE0=&c= 43iQCE8/e eOTz4sjuXJAN3qkGun0U9x5ogcQveM/IalT60CpSsSXdb8EAHopucXwy2UThAmubKBOcT1w5v/rJqxZSsm0 sjFGQQdQI8NZ7rd18zjbFNUFu1dDaR7S5s/K65JG2/YMTCYM 8kRIWKE FQ6SoLtNVAIOLEEvv4=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=LzLUPVRwSpdppmjUiCVZWlBaf2ZFTawsC4qgOycR ac=&c=sajh9ime3kaciKcLH4agdTsqQLhsf9sgfIs YUW268WC6vVt5QGjXjhemKUn4C21PRRp3nRTnWgtJpOeijOjvA/f6lWa6VfFM0FZgUCq/3C8EeR Jxv1/lRxjsrMZjxkZw0cmaR6mDTdUTFveWSmDTmUOG47CvlCyB7xfOI692GpcmJtI363NhwTjrYxitfW&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=vGtw4et3Q5JWAzhS7XHEa Eternohfi8c3vQc M5I9U=&c=WnuRaLzJSqk6kdut4e36MwG9OmkUJwXSHdqbDCVF9wry2ZVO0m2/qAvwrd7u/7ILnJpwQCyD08E Pie3397X407EW/e5jj426Zp1hYnl8Rja lm6HXkR3VEIZl H VKEPMt1QfQ/OuSK1WJNFW LlFreVCmuSaasBk8Ix8n8V8Wo5gHdrRl63 tPe8B/1Gqe&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=0m28ZxZ29dDKqCtlfvZ2KAD49 4ZDkDY1UrlkL2TgCc=&c=r64YEtuN a5jGIE2nn2xIvOB4lanTLb2sbB/ioFN2VV7lcUqcK3TQG8HL4Nx69upUj8hA1O5Jrg2UBeLjxg/0 4r8LxOktuJx/phJ8UDdq4M0AvVHgTDGCmkZ08Mqk/1HJGfVVhq0zVSZAM4ByKXKOTxUaEv3K3AggnN4SxCFz7N59MPOgYheiCJM Y4nwmt&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=qQVYV6hMDOxyWmYa51RfqVdyi7wyvJ/wTRIooO6ukEw=&c=nI5oDs3nJNw8fJ D/IeRObugaIdN8CxbhC7lC Hjcox1qngGbXjlCYPNxwkBRinTW5ioqm/TqmTgp9RmnY322PcosmXmddoQjmFBEMWJ3KinM3utfWe0tsacEkxAW0U8mmFpoVLS/u4lhEjxsy5hfqCvgwsOhiRnCpj7Cv2aitJb4Gaj0TsV0lOcrFknfWx&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=8zX8mYd 5ZLVTd87SANBXGXknGHsNdfTxFGzOkEoxbQ=&c=vy52/CgzjRzjfRMce6tmNmKh5vTXWIiu0EWzZk0xt0HqpZ p385GW8z//mDVak0X5P3 77lJ1Ab8jlIZn5Gh/1Jx7FLcQH40Ek3HyzGvLN1Qd3k0TUuhgIEWLJxqghEdh7ktUGsz6fHqas8pfPNlqaWHa6vp7DvyZRA7QE1oEFjegaqbzY4Jgp8aUO8cYtNM&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=tE0mH0dss4cZ/D8rf5g2 ICPK7cXdA1ObJRqbMcSdaw=&c=KoIr/LIIZiOhIspkrgNZsiQG9n/efPnmI2sNWJhhHnX/jzgHdEFlwbK87RvTDm45qeCtokITa5dPIEwDPlWeq/LZSvIyiUir5dENgjcvnSBTqN509rm4/Aric0O9fRXVX EeuzpF68NTS/r9q6XZylO8PrTuOi3wwDFUg jaukON127/4boLeQePwdTAMQg&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=eyEAIGF05oa7z ihCflXtIWkPxh/VRvyD2VQK tjuOk=&c=8AHifDbzrq2NTwuBxz2zVC9aDoV32PRvRbjnzZJ1kwPfWyvEIiVqPyg2ziDc4xnqm3qQVlLzLG7XFuuFh295kiE9SW3 hI4ViYiTGFNodv3thHHbSaiHBFB9CGe4e60cA4t8rgNvpUlo81zPisz/1WHw5vK8SicU5ElpinVS/aU=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=3oPKGAY4uIqg4r/MyXD39THX7XzrXs90q5QYEv4R5b8=&c=Z4YF1lB6ENmQ3R5MfTLdqJBWK6oKE6eYPRKo3x9HODpZO5L3h jXKfXC72UhOxmX9ceI7Mqcbb5/4hpHqny3Dsw1i4wa2PlcNKLyx0nW74vvB/1wtB8ituPr8CxYwedQSZqxMXEjkwo 64KWMKPlIvS3smEssppvvM2nT6q47 S8GJ0IEj0uD6b6Pfar0Ubv&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/WVl6OTRQVk16VFdGV1NWSmpOVEJyYUZwdmNYRjNNRmhoUTJOTmMwUkNReVV5UWtsMlNFaEtSa0U0UzNkb05tWjZWU1V6UkNaalBVNVRibFl5U0ZSMVNYTkpXbFZ5UVVwd1VFOUZNMXAxUmtFd1YzRmhiWFp4SlRKR2RrOWxTV0pNU1dsWFNtSk1NRWRFVFUxek0xUllNbW8zVkZOUWQwbHRPRmxCYVd4cFYydHVKVEpDV21oUmVWRm1TMDB6VFZWMFRIbGlTMUJqY2xwSVZWWjVlRlpuYkRWbFZITnljRkpXU2toMVpVaDVTVWxYWW1wSWVDVXlSbEpQTnpGeFZtTjJSMjEyYkdreWVrZzVjR3BZUnpOd1QxcHVVU1V6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxV1JHOTNibXh2WVdSbGNsOVRaWFIxY0M1bGVHVW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMEVsTWtZbE1rWm5aWFIyWkc5M2JteHZZV1JsY2k1amIyMGxNa1lsTTBad0pUTkVjR3gxY3c9PQ==

Latest 30 of 122 download URLs

Remove vdownloader_setup.exe - Powered by Reason Core Security