vdownloader_setup.exe

Cudel

BeamMode (New Media Holdings Ltd.)

The application vdownloader_setup.exe, “Cudel Setup ” by BeamMode (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.giftgiftlaboratory.com and multiple other hosts.
Publisher:
BeamMode (New Media Holdings Ltd.)  (signed and verified)

Product:
Cudel

Description:
Cudel Setup

Version:
1.6.5.2

MD5:
8628958173e38947ae282db506514f7e

SHA-1:
6a0ce557c72ff159662f37381393cf2f9b7f32a5

SHA-256:
be2319ebc97c6ea197deec983584a66c99c10daafb16c0d11e191bba82aee88a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 2:42:05 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.4.9.18

File size:
1.2 MB (1,241,592 bytes)

Product version:
5.3

Copyright:
Wizard

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vdownloader_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 1:58:18 PM

Valid to:
4/22/2016 12:25:03 PM

Subject:
CN=BeamMode (New Media Holdings Ltd.), O=BeamMode (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121179CBD5A997BA03A6A5502D9FC4DAAC6

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ieSkBFJutwEg4DObWVfl6B/5fT9AeMTvtDTSUf6:iLOOwEg4d6B/5fqtTvtDOo6

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file vdownloader_setup.exe has been seen being distributed by the following 50 URLs.

http://www.giftgiftlaboratory.com/WVl6OTRQVkozT1ZSVWRDVXlRallsTWtKVloyVmhTVU00SlRKQ1VtOW5iRmxPTUc5dUpUSkdWbUZWYWxWNE5GVlJNWEZKZVZsQ2F5VXpSQ1pqUFc5aVRXOGxNa0paWkVWclpXcG9lblU1T0U5UmFuUjViV0ZaWjFOTVdWcFdSMHROVVdKSVVrNDVWMFJxVVRsUVVWcGliVlZzTjBWU1FucHhkR3hYVjJkWWFWbzRKVEpHWkdKMWVHVnFaRXN4YVdGV00zcGhRMGRLUVhCUFRXODVTWFUyZVdoTVVERkpaMDV2VDNoNFQwcHVaM2hSY1Uxb1RsUmFTRFo1VjBGdkpUSkdiamxVSlRKR1VFSnNNbk5PVG5sdVRHUm9XVWhGVFZKaFIxcFJKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFZaRWIzZHViRzloWkdWeVgxTmxkSFZ3TG1WNFpTWm1ZV3hzWW1GamExOTFjbXc5YUhSMGNDVXpRU1V5UmlVeVJtZGxkSFprYjNkdWJHOWhaR1Z5TG1OdmJTVXlSaVV6Um5BbE0wUndiSFZ6

http://www.giftgiftlaboratory.com/c?x=fs/j7jicpTb8jLsRSiaVHDk1Xx3McWHLrkY6CiN4GAk=&c=kjcW28DCaJZ2ovWQvZv3wliubu/OXsCweml/Ih fy281gmvBJsMrwt0 0QBTjR2CObEJ TSsGk4lmtvlZq7igIy4bL2mSVMkVCkehIlvYq78lNP0IYyVxnL13S58SuzWA3VtMFK/Isy Dx/bkofKeiwaJpbXoCsm/TNsSK EZC e RwFFAo3twnDXoqIWH1w&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/WVl6OTRQWGMwWlRCWGFGZDZSa1F4VjFOWGRYSmtNSGd5WjNabFNXcHFjRGgyTXpaV1NGVkRVVVUxVlhwUWJsRWxNMFFtWXoxTFJDVXlSa3RxTmxwYWIxTkpKVEpHVTFSNVNsQlpObnBZWW5kVVRIUTVNa05QTTNNbE1rWnBRa2RaTlVFbE1rSjZKVEpDYjFWblNDVXlSa3hQYkRjMmFXRnRaMGwzUlhsdWIyY3lkRk5DV1NVeVFsbERjVFpISlRKR2N6TndPR2hET0dsM1FrNHlVamRzWldwVlVsQTNRWEF5ZHlVeVFucHFiaVV5UW10S2VYZEhibk41YkhKd1ZqWlJORmhEWlZkeloyNVRTMFphTTNOQk9YQWxNa0pYUWtkeU1YbzVWbk00VlU1QkpUTkVKVE5FSm1VOU1DWmtiM2R1Ykc5aFpFRnpQVlpFYjNkdWJHOWhaR1Z5WDFObGRIVndMbVY0WlNabVlXeHNZbUZqYTE5MWNtdzlhSFIwY0NVelFTVXlSaVV5Um1kbGRIWmtiM2R1Ykc5aFpHVnlMbU52YlNVeVJpVXpSbkFsTTBSd2JIVno=

http://www.giftgiftlaboratory.com/WVl6OTRQWGhsYkdjd1RIZzBjWGRYTTJ0bmFXcHNkV28zVDNaV2RqVnJTemRGY2tKRlJuTTBSMnB4WlVSclNrVWxNMFFtWXoxclJWaEpkWFYyYzJ0dlJXSkVaSE00VkdVbE1rSlRRV1ZrYTBGVmN6Uk1PVTVHVmxCQ1lreGxVMmgwY20xVllVVXpWM0ZaUlVaME1UVldWMjVKUlc1SmIxUnhUVE13Tm01RllrRldhbmxVSlRKR2MxaDNXSFZhVkVwcVkwdzFkbGRxVEdac2RHTjRka2hTUmtsU1VYcGFhako2TW1KbWFVUk1TVE5wTUZKQ1ZrbHRjak5HWkZoMGRrWk9lVWMxYnlVeVJqVmhNbGRDT1RjMVpGRWxNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05VmtSdmQyNXNiMkZrWlhKZlUyVjBkWEF1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR1oyVjBkbVJ2ZDI1c2IyRmtaWEl1WTI5dEpUSkdKVE5HY0NVelJIQnNkWE09

http://www.giftgiftlaboratory.com/c?x=17F9jJOCFh3tQxd3f9cXdgVcjWbglZ/srF3YP7YYvcc=&c=r8zrQUo HSwQKWr/D0iFD3uKyqL51LbQ GhcYlfTboO4KgirC1uQvt6KRmzs1LuPFjlLUprI5 L27Pl1haX5QqRPaZwmTDgD51UGJPd42PruwkRaCzZC4Z17atMb4DLHJSfMItgscqmze4RMH0f1cnw7Ny1MftcGNAIZilmV6Lc=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=w0Z8RY4LDVDj8kebAM5tAZil1viopDHcvIWGuoYq4XE=&c=Tjc6SXeyfz6/G0e8dXbKwzUWRilEvvPEtm0lyJ3QNSr7jEUInbV3WCJf2B2YdbTpI9uHzvqnzT/hmJ Fqv4OoIfcKbW7SQcbbC7iyHJ4xrfsZ5lYrCg4RX9B0GeM0C8NtNkpzjXcCwKFUuzmo1wnArC/EjPQwETDXvQIHktM34RFd7qCScCFPbrEbWYk3glz&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=7JL2XwUNnKsgOjJgFC/dV1vyb8XHq8diywOo2Vi/utI=&c=qhdfUoB7lLa1k5WpPS5zSJSArTWefDdZN78X1cOqkUVJROjGXFN5pTceJygByc4V0sdEDYugvDPw0DkUPzU15En393tgKjwZawqQx/0aQogpamh65XXNZyUU4Py4DQqhn5ebzpC/Pjp5aDQTKe6tEjnzOS0ivFSUrs9BbgoPVm07PTXxcS5ngAGMgGJLjEF &e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=/wVkBXRJJMvpIx5XtE42Q/qlLcAHWbTOOjBoIqn3WBo=&c=X4GzMigFIP1AGLh45heeThMbktvggPi3ZiLOkxenZswC vDEuAtFBpKQFzTbQFzVi5j5PmOGO2Sh iC1Dr8lLr2pwRwQ7F2/fgCbB2cQbFt/NQ19wpdReXPS1oCBVHDe9hBPXpgKCn6e90kKsH88uw==&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=MTP0H35 NsaJIV9l6yh9MXJH2i66jftcoC6TUuQnf50=&c=fkWUOKotFgOPA4605WJvT59rHHiYr HkL9ypvSQTvTvrPxN2lkhv5WweLIijW8dyxX6K4042 ucySq60Ubt8IBUgGLv13VWLv RCWMEqn6iDqCh gdDKbhUTWPezNNqWhu0SRMSEVTUOLiaLzE7hE0rVk/pnXYKLyHVKABavnCwDbtQngB9UG6Qq3supPuBT&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

Latest 30 of 51 download URLs

Remove vdownloader_setup.exe - Powered by Reason Core Security