vdownloader_setup.exe

Pogadalo

Criteria Quality (Alpha Criteria Ltd.)

The application vdownloader_setup.exe, “Pogadalo Setup ” by Criteria Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.capitalsharetours.com and multiple other hosts.
Publisher:

Product:
Pogadalo

Description:
Pogadalo Setup

MD5:
8d32aee73a91d3d56d94a7eca21d5525

SHA-1:
37f67f167f7ae6e4cd8d4a1986d34a80d8731086

SHA-256:
6685630869d469652adf7d7c63d846b2c311987b30c2048420baf9b24a975d7b

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/24/2024 1:53:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC.Installer (M)
16.7.10.9

File size:
1.2 MB (1,253,176 bytes)

Product version:
5.3.9

Copyright:
Fast Web

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vdownloader_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 6:14:57 PM

Valid to:
8/3/2016 9:13:33 PM

Subject:
CN=Criteria Quality (Alpha Criteria Ltd.), O=Criteria Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216B914C61A8F4896BFAF26489B9954D2A

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ooFlU3xbMwPX+YEMKqyn5PfsmU8tnFtittZC5kSDa7yl7u:XAxbMwPXnEn75w8PtW/1SO7y

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.2883

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file vdownloader_setup.exe has been seen being distributed by the following 29 URLs.

http://www.capitalsharetours.com/T7qt0n0z4D5AgMJ7y138oA74htgT4UMlvCQ8nOrVjTpWBfa0Dxgn2GdaCl2jScu Dwsh mJSBamHvyj4mFOtipQs0iPbhRLPtHpCSw vJ9HguJUcVJ32pVg7pMNE4ji5PNeXs9vaRZFtFSXem0r2F DvYch94J_ 1IlGmfACNBJ7lznhj4k=-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H-e

http://www.capitalsharetours.com/zIRIBj7S3t3Fltno4PUMEykht1o3QhWZRg_kfoL 2jLrY0tQLwUHvmkb86sYChjWXrdwhOQxUx1HDsrgu3yuEl9WmR2Q9v4V3kuQgJGEELnHxHVqsjqdXmNhI7tA8vRXp _CceI6ycgfipjXGWrZMXl8nuhIHjepj8xohkBT_7mCbIeOdmcuK8xLsaO9 UB0aiMYy0nu-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.capitalsharetours.com/jN1LJ5pi1SaoF6t87RU2lGw7N9lid1uKQobZeNK2E71RovHsKlwRxaNAoBzKtope2JmbAQPcv_VRjbPKobKg9yUSHMt9LyU9HJjEfumAhXHjjUtqrXMcQYrbATzkrkdk3mCXivSGkZtWHJttndQa0D56gs_yRSGKC03cJIhunJKq trtnWIi2KA0lkOhcwK0hVseQASy-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.capitalsharetours.com/kh2hiF6VgWndzJxoOEeLHX_s1058cDVDZhc3pmdbexnNPHRWnf9WiOlVwm3mWUzqfy9_H_DYby c f9po1nJOIK3f7Y2_WZX9ZgLdgmNfKPDV7wn9HoiqixEwCwYS8vgPhy ztU4 5unwmw0B94gfFPb_dD49TGNKyry22JDaC IZ2w170I=-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H-e

http://www.capitalsharetours.com/L0FqsbG5YV1Sqt 9G1K7LXyO2dJ5bLBwI8CY3FENht1VH4JPkf3riB0ZN1LiPcaf3ON9AzPCsx8dQ19v7iMEaHbd7YV5QCL6Jhwldeze4w WwbaiTGroln4VUzyAiqmRb8BYibLRWLjrqSldYUevPP19PvlSYOwP7sS95EntlwSu7XqQ3c28Maksa_fNBTd5ED5O7whD-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.capitalsharetours.com/7s029GSyZKsOls6XCsxQTYZIHq4n UDNBlh1HGCS0xtvIZv9rP5F_2CqW9_9F27 wSiHWA1QTqm6wkOC QwYI7 NE dOby0qTq79p8kW7SBGD01HklxjXmbYFVOq6p1JZdzN7KuTHooB8XtM3Yuap3iOHfqnMYsglurMidSTNaK7x74YKow=-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H-e

http://www.capitalsharetours.com/QHit30nrN5LZeMLJcVApNHeCx KBohQkyOGfcqm odl BTSOrrPMCiAwn8hPhEf7LoXbW3Mts7hSooi40QwKiGc5MvibLHIuxcJj0RT 0sUMNjp07VzSWS22LiFrVvDwfChPivJzKvA JG12iVhd3j9grv_tfaloGEd0iUGPbRl2kjMtZ6k=-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H-e

http://www.capitalsharetours.com/b65klFaiWL4ZW kSBNQjQSnCKgzSXY 2SFk1ZABgvB9QttYI8A8vjzlafGsJ2PfN zdICK6b2_tqarXodQz9 HZZvLYL8gVOw yLGBfejxpgkze_SakZpYo7cpc4Yx9gsigu9N_LXdwo 3rENaVnPmlN_mXMM1a03gPIJpE771OIw4qaVEtT6ZOvQL2G5Fn3Af6YcKyy-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

Remove vdownloader_setup.exe - Powered by Reason Core Security