vdownloader_setup.exe

Dotora

Setup Alpha ((New Media Holdings Ltd)

The application vdownloader_setup.exe, “Dotora Setup ” by Setup Alpha ((New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.vaultbytehead.com and multiple other hosts.
Publisher:
Setup Alpha ((New Media Holdings Ltd)  (signed and verified)

Product:
Dotora

Description:
Dotora Setup

Version:
3.5.4.8

MD5:
77e3e27c15ca4797a2f87629b74807e4

SHA-1:
3eac5c37f9ae399a92fccf663b2511b2fb0466a8

SHA-256:
3cf62748f1300d601a64aca0bd370371358528e9c565f6edb3c1735be3ca1277

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/26/2024 1:06:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.5.8.10

File size:
1.3 MB (1,365,832 bytes)

Product version:
3.1

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vdownloader_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 11:41:44 AM

Valid to:
5/25/2016 8:42:13 AM

Subject:
CN=Setup Alpha ((New Media Holdings Ltd), O=Setup Alpha ((New Media Holdings Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216F55CB04783E0F0E5AC4C45115E1BCCC

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:FRMxD0xjYs64B9fuhlUZbhEM0/3UitYb7Y7/68NUA5W1Hn1:FWKlY8B2lUZbz0Mc5/JNUAI1

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file vdownloader_setup.exe has been seen being distributed by the following 50 URLs.

http://www.vaultbytehead.com/c?x=lKzbeyF6sQcDgqCqsAmKXtAB6CL9YFBvQbSb3xFoavM=&c=kEQfRztIUbzDMO7SI1axHhsj/IaOjOB53KxVoQN MJsN6SejarZiLGpDmu6SkxfrRTy1OdlNNBzcf pjjO5H25imJuASJnBFuE mbO/zUOLNksLOJBzY9x0LRiSzW3Vk5AiTAASsSYdzr8X77l6PBU73xPw6IqHWP5APtBhzpWY=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=3pJokB2wmWlHsAhD9sW8CJ4rikbUsztMSmCRnIJIkdw=&c=tHTaZCvOwJqr3jf77xOdvZN68dFXofqNt n3xHWVpXKstTI3Sah1S2ShmsvWKnLLlD7ui9NTXaHFpOxN4/nAkgOsHmoEVwb8aMGVIEj7 o0TFegNRFc DZol2ZuP1YzvcV9Csn0YX72s3MUP1ZPxyeG2pqlYzngu qtDyTMJZBg=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=iduqsPWUaWJUxduIEc2ZTy2FyrgzzMAYF 7rFZPTVBI=&c=qWkDj70PngWmiqbB0RbhDsCAY0WEH2f4ACEiDN5xaTgkfVA4Zse0KRTkMGO1EfktUNpFS4QwRT1Ez/brbI6hcOs81fKNFp noS7215px1 T a/XBeWMzdNEez92ybvJ0/3G3LK7mvQqNObDBP6Itnstr2Cg1wF98OVRMOFbbpgM=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=nXFxqN8bhomaLPN y1astQhz3DGBBAVuzpp1jruGh6s=&c=NR io 4C4o3iyIXe3lMMl2H2LwZJwwJt05qaTVvrZ7wYfUAWumfs6vT0 TtndwuawIa1x4NS7djdal54zznld6EN9nvK6Aya0ycKi tNBTp8U2ssFIJeTDHN36zPvAkAsDmXUATyeRmFC/YL7nCIiwhDl ei/KQOCCXOoW3Zh4A=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=7rVE8argnJUOsAmjqqgZPSXvY0nK0FkBLapm11b5wKs=&c=PgQREmiOwye1CP1bHghcWErV34NS1qSmOE/x elgFgIfK9sOkwXgiELkgWv1gmkM2Br 2gabeSb93nbTDzXlkwbaIv auIWhZ/VF5 kMdk9PIesyur uNQcjyf5fumrIeU2dGnuDXDOe7dY0vlDgTBsAWq/6ht rb9y24cG/GLM=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=05 K0/XWJvX71MrYrwLA4aPoZxkCsYA0STis3WIfLkQ=&c=5tjuZ6QZsddUh7T543C1y5 j0xT0isSpXofdeIapm4V1RnigPb6T/8hxYbUdzFEtYvbCG8oYmmYT3F2n39wmZsJIB2c2t4RhVcgGaPdQGX/JaeGWEPvKzTJNA3tJyDkIW24MToogBzmLXdI ko6hZSDrK15CVYYq3YUaPk0mEo=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=hUsJYTP3QwLKf3/7R1XK/TPSTDU2nQFEp/jeIMQMTPE=&c=H/dDIM8vyDxIfI4NjIYk595zhkDUQfXf/qNeWzwLlLGKpDspXa6nqF5fj8Iz5DvzTJDY6Pt zSyy20SiDjWXuCMJMB1WL4Eequ9OUAuwsQ6 uv17Un75CnM/TuNI21BRX vQIjr5l 4odblduQ26BzgzCxaxPCObUK/xsU7MuwQ=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=HULwLtiUcsAkekmJe3/CJjn2VBpCo6rxFWVnOAYF5l4=&c=Unl2T3NStJK1EQcLKgOdlRkNiMoEtP3H9oAOMG jvNcfWUcfbfSDrsnGT/2aKXfEUt0dW UMXUz A2/lNUUsmdpXVFJVYkIZQg69McSureIxTxI4dLX79VvLKNeckduVaGl6IvD33ZGauW I9GFf1ocRbpzZpEy9GA6BBBfz8yg=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=MhclyytoP tMDxks7NmxPxy6M0rUEn605LrppWklmis=&c=dR8RNKezZa2yl aUwhLaXUZA 3yCDeunVI76YwPHT4t2H8fROT1iyvT8AqhxzlO/19TrL51bIp/ttL4Q3UCrYrG5Cy7lf3OwbAk/OfIDI8PWe7uqOg5aAshWGpnr172RuSRJFgOX0MfhfdsRQOTUZcrlW1qqkGsMP9FgSEOqSXo=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=rXF6qoJxaUT6UV9bYr4n6nY9eIyhverkZkrd9i MEzE=&c=j0n j2DqOKVtWqBY9AG46HUTBl25wBIwLJk8EBGgvHHWfKWlf0fB6HJOVBXWyl0k4yJhHqE256lY6Ow4KqVklDqhcBu8bMbLoCPO02637w6nnpZuKXriXEcipaWU6Juf8 IcFO71wwytk0UcPE9nqg==&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=VJAEObnVNAqc1Uv9h1ui/c9PXkedTvXIaUle7iWT5X0=&c=n30u550GIgZQXE5fG7 DGJKPM4haOjyKuY23copYiMvIz/k9ksS1lheikE0udyoCVbIPSJgpFc6FOsypjXrTwBuTw0KxKjyAvLaiVu6UDXGhrnsrYDw7AdJRwLwFvYvm7clqt2x3PI7rJBO 6jbbO2B8vqGYcnGByTFEriYAFTw=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=VbhK9OBmKGy7ypSkuQXtayziMc4iK06RkjyJ3b8pnYU=&c=4pbIWb1r9VmKx18wu2ypdRDmzJECe/21pkEGCpxwZbmbMrzKel75YVNo lWUgVX1gV0zrbyTPF361iJmEHhE/K0t1oIjE1PAjnzyphdUV82t2Uz3dHiHXUZTMAJwbezt/vljnVLfTyP wuoSJp2dIQWuZy8fz2EJzTtEI5RaVtQ=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=r0KH6g9IsyfmnY5ol12OJGUuLtZjxgOTJxscLh8Ei8w=&c=OibpzO GcakqnVLLO422dNNVug3q5hM0EXccgvb4es4SB7d4TrOXXYmN3U4LRQeMhLCXzEhBuzzVQhKrdW9Vdo4Cxia8mVIXVFfnFKkiOQuQuySy6hptNHkKnbmKJLGVHiyOYJy9rp/DZ0fsLWEPWOdQ6YhiOAEwmoe62RmrbC4=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=67ytg qFmULALPx0M69BgSiNKvGvqfAP5nGWqFxZ sQ=&c=b2 M8jMrDMefkNnHxvMas0V/tbwIjPMm6QgB9B20T/MG 9fDz9zNP95pA DLGV6vRu 4pEaxIddtBTyps9RlXLcK884E7ByoM3qbbHwbIqJWxB2NEaZxqLQWVh3A28tDrZ2d1CcmPqcZ4vr/uZDFh26K2ZXZ/5NyBE/f6t1lJS4=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=lpoJ/tlU5Rbm YGsqtmjHkC1rrnQr4aUpLR1W6l5CkA=&c=37lqQKeLwASQ20AZCslljt1QguNQ9mBx27HfHnSenkojwpD/h5BiPJ2BpBQumJD0FCjImH5ZQ8RH4jYxci8bQS5FI0 ljDVANZHrobu0LH5JVn5Qa9pRtM11IyXST5rmnqPq5OYz6VuT/YT6u0Dwm 2j4Bw7OSk/aJWi/QJMmpo=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=ByIChcOV9wygOW2hf/qpkNpbOMOcHQKKLJ2HcuxpPcc=&c=B/uldXDR30vEKhTMlCQV0TvhJzAqyezNOUEipANYWWCVM2A7YHCJ/Davc01Ymcs9usWqjfjg7jqxz52VEymx0qlAXszG6Kr4WEZersvU41FMW/P1 oAYegVzccFWk V49Zl3VCjwZkdXWlqNjVpp0482xRBhHogjTW7TkMXKYyA=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.vaultbytehead.com/c?x=DMGhW8HX2Rjnzf68utKBNgMhGxguiGspnbkCzxgtgJo=&c=pRnAcpzswZrmrpYftYkFmGhpCEy9DumLVNmXt6bg7L/S59CTCVJDIV D0dtPTCcC3p48DfGzWOgw 8Jgfu/KAnDgPsxmWOLYyc0xzlS5wH/yW3ayEcBmnhmkg0 Ueze9KuzM6gRWymvRo2mQ/3whhuNcC2GAqQRF plyldg2Lf0=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

Latest 30 of 107 download URLs

Remove vdownloader_setup.exe - Powered by Reason Core Security