vdownloader_setup.exe

Faranogin

Criteria Quality (Alpha Criteria Ltd.)

The application vdownloader_setup.exe, “Faranogin Setup ” by Criteria Quality (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.capitalsharetours.com and multiple other hosts.
Publisher:

Product:
Faranogin

Description:
Faranogin Setup

MD5:
015ecbcdaadfdda6e1042b7f241536e8

SHA-1:
5701798c4aa3d273400b4d5204364f4ce7bc7898

SHA-256:
56de5447442c408049c5e7791f0636f3e2729dd9255d078ec6ed34b941c0c247

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/24/2024 2:13:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC.Installer (M)
16.6.28.8

File size:
1.3 MB (1,357,816 bytes)

Product version:
4.6

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vdownloader_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/31/2015 5:14:57 PM

Valid to:
8/3/2016 8:13:33 PM

Subject:
CN=Criteria Quality (Alpha Criteria Ltd.), O=Criteria Quality (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216B914C61A8F4896BFAF26489B9954D2A

File PE Metadata
Compilation timestamp:
6/20/1992 4:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:qhlrohTyWYNo9MTpxTAjV1ImgWYX7x9kD7PwL9RoMUYQy/:qrMFVolAjImMXTw7PA9937/

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.3506

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file vdownloader_setup.exe has been seen being distributed by the following 50 URLs.

http://www.capitalsharetours.com/8TQWsbvIgw3hh8 CACcL5zpiX7YzP_hO6Hgjk0AjiURfzYccgATDRtbTR2eC0UCv_PR3CfgCYP nehje3VNsN1OaGftDuxEnljLZ8Vd8Mr698eVjMNLssfJrhu5VFTV9nyEhfJNWE3GHRQMvt05TZ9Hblow5J 5djUpGQIFoSyBekKwiQxf9cocmAqkGzL5iUM4kZlf3-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.capitalsharetours.com/mS2L4Aa ZJUSKRRGFWezZj7hk0NB4rqCzSdgPLtvajUzMtANCunoIOIdXw7aaQJxktR9 2glo0VdzEfiLm0lkXKQpa ICSbU7FZNQBXdHr2FlLbW2LgdAt7Ypx8HyHpiwbjBU7L35Nn13LogATpL1iJlqGpY3xr9n20rExEysucTpwffDcKWpGYnOmpz9hLMsP6pgXp6-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.capitalsharetours.com/pmg3lIHKgt3O3KILXQBI1_qVvcLOZhPOfVyVoFekI8y1SjgQfPqy01pF9mXxtbssiqKOTyXf9oQ50NwBxnC46vko9Msk3LNTHlDeVDU9dYLKSWAFXiBM FNIl1KabnCsB2DRN5nC2tiXzUa8PxVaNC2HxsV6VynLs1CdobXJiAsbAIdCRtCcV SDhTz ieFGhyrf_H6-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.capitalsharetours.com/Cu4IaDkFffeD44l4Tz2aiFndVuOx _GLImGEGc377QV15 Z3Y20GwtrGwkeoVTsyh5AB5tFctNqist_3WO1bqKUBisQ7l9NrU3LIJtZ_MQV6dwxWDp9ziQDQDnq8lFCeYLfuEXeZuzO hFK76mbhEEYPFzbxmHuE_bTvwXZhZysaVDIpA20=-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H-e

http://www.capitalsharetours.com/Net8Lvg06lXHFWXa3U4S1Zk3fUSyyMD7ZwhHjvHStMDGLomU909kl7p69LGRHJ7dJDQyncP_6qsam xITiOa74h6Imq6P2_pEZU_ 7sVnUBwEFKeb69neJnVDiMWJi5kDKsCTAB8Gwzn8hBPz H eWj67Y9ZuhI_pUgwdHHF2m13HG7kIQ0=-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H-e

http://www.capitalsharetours.com/9J926A4RRi4i7UZ9gDQTu12_ktWKjsfSObQk9UlSe70EhE6CBCqOz_jK7kddrFhzQwIICsyz85gEfv7qAvRF8qkLznGc7mU_vWSsR19BvFh3sIUi7G6ZZw5o2hfg8EJEJIsR5TXYurDmAjgjI98jHU0u0neTEu4fNkhuR0AOzz2I3UrshpSYnCrg Lwhs7M6tOYlrpUW-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H

http://www.capitalsharetours.com/hKrckyeS3AMedN8EUZCi4qd6Muy7fA4NWmoXhEfwk8OOdwQhckWThgkkDk2PHracZVLEYyRBN07MfpvptoYbyk0K3d7oOoesPdGelg ipi5qSLrTeYpXvviD AbcdJyIj_CK4jIAyiWNpCjbn9CvQ7ro4qC ZYOZhdOwPFe3xb9bo4zZB2Q=-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H-e

http://www.capitalsharetours.com/6sGNhDkQ_S6vKCPGLjSNiiDThqIMJ2w9Xglr4kG7QL726FzfwC71tcErAvD TZNARwTNmELiGBG6IZG99m RwzIMHuf5q5drwS4PZWbSWZc2hAk5SbuDFQlk248PH0iUxOUh2jzWhgYqNpi8o58WAGi5nXJkryB2M6gkO Hqgow OBWG94I=-Gy0AAATqZLEpSWg2od1Us2dgAw6cAgoCW AesA3EjVfoZDJFpfOBto0H-e

Latest 30 of 61 download URLs

Remove vdownloader_setup.exe - Powered by Reason Core Security