vdownloader_setup.exe

Beru

BeamMode (New Media Holdings Ltd.)

The application vdownloader_setup.exe, “Beru Setup ” by BeamMode (New Media Holdings) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.giftgiftlaboratory.com and multiple other hosts.
Publisher:
Tas   (signed by BeamMode (New Media Holdings Ltd.))

Product:
Beru

Description:
Beru Setup

Version:
3.3.3.3

MD5:
d2b6c4e6265a72de319ea635137a1ab2

SHA-1:
9463b4df20e6f503184dada8974e9a3808b970c3

SHA-256:
6155a7b75f9eea9cb5b455f791d0876b95c66c3e70e729a4031b6330b3701750

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/26/2024 1:56:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewMedia.NMH.Bundler (M)
16.3.23.22

File size:
987.1 KB (1,010,760 bytes)

Product version:
4.2

Copyright:
Software Program Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vdownloader_setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 7:58:18 PM

Valid to:
4/22/2016 7:25:03 PM

Subject:
CN=BeamMode (New Media Holdings Ltd.), O=BeamMode (New Media Holdings Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121179CBD5A997BA03A6A5502D9FC4DAAC6

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:8ho0ueXv+Rk+FGEZFguXvdnCHx3/fL0iwBq77htIjCXWn8JXXsfC:8NBv+RiGcN8a7h2WaoAC

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9145

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file vdownloader_setup.exe has been seen being distributed by the following 50 URLs.

http://www.giftgiftlaboratory.com/c?x=9USYM7stcKAjEGdwe6DZ4DyRe6N8waD7LOcL31r46UU=&c=kv sXf3CtbV9R0CXM/ha18osTWeTLQDbkWwJd7Aj8yaVbHdVkgZYUMPaDZEJoqFXloxKuSrRTJsdyQyfRqqKW zK7sIyomTRCVjud 5U3lruopJSwsjY2SfFM27ifusQzKUIy4ut30vhCVg2JaOs18Jaw1ZWh53hTI6pVxTmc18Zs9dfbRYTBz9X6Y7JTEz9&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=AW98BwEitp8/huUclzzreYKpLbmsvVD8rwQwVq60qLY=&c=fB/hXqcRtq3G6jGhgwkQjCTTTuHPjMZo0DwbLY9SgymyA5NLE4wGSr8/S SFdcJ1 GuiAS1njk5WshDIRnfpzf3H6l2kmxitx9lu/l7ee13MFSrG5GEg0wimt6TKOUSXUjmfT30m I xR3XDgOvjUA==&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=4Begkhmqf7C4EWZaomsJgpywcWYk p1RFsgYx37zVeE=&c=KK76sS76o6SpcGgU4jUWNSPsB/0c3sotnkhVwN6Hykk4V1YU6UEkbyXJ9SW5Zm5f8kVgBfBSfrS6/r3RkfugMIUD2SxDyXM305QwAS JlJRUOfuNKZWABkEABekj7ungPMztr1ayEpL9XupqbS4Ojgw8Bnj3QnYepLjPnRxCM4k=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=WI3RMrRGFU1XtXturPvEd58ym3pqiOs7mgO1I1ujWmc=&c=OtIGhQLiZ798cLZ2RoTiIeATwey1qHztDSkpZI6r5DrK7PkeT84krzD3RSIZma4bBRggDdB9kzmC7YsMR73KymGB7Ec9W4BEep562NiCV9iBHITlUDDZGt/zVTkc/ezdewQht4hzYjp/Vht1tE4D40fvxiApynZ5hhdd2JZXZJcOqI6dcLtIcAC7abVYP8P4&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=CZI3XqhARLqgt5wzLr2uABpYRQBlY4f/YDI90QDPQ8E=&c=YMP7MweHRNEJll0fp/7/4w4MLw7oQd1kzeeSCXK2IiF5VEeK08yErj7lWpYr951BVAU0S1rIzL4Ub4zl2iAvXdcKfmhJ7YcWqeOjV uVDSp8Y7ApFaWx7EszW6ECZMGyXTN LX8lA/JghYktDO8yLw DYdp4pXDCULLlg4CTuoGHJBjP/TW0tUDzeDGAHvcJ&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=Zhc16z6EI8f DgDvWVhtyoBMiUabhLtrC8byHK/Aou8=&c=WHIi3sLJbIVvrgfcvkNzA07KtVwozQ1Oza u8S3IPfAmIjO1pKoU2Rmwz5ietjWjdMDlpSwMXmGwAaOJpih8Pnn sJc/TXsJJAsRFAc/9RAurqJvbvutZt bNaHWIfWPagbTUuWWz Wb8bXx PpiWsPWVZ6mBuk/19Xu25Fpcik=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=LEbHanka98p54kBj4XrJ98XJQH7/J9y7BduYv/jKwQo=&c=bn0HoDiJ66Bwt2kDRIwpchmZMSjeKEsF7AhwZUmpBR3hHY93vfJpNY7zll xSYkoakt1ymFxeFDjv2PrlJl4Cp4FYEikfPl1CF ZuYK8S01s6zmcqNaHRx1 drXAFPqUI47Zzg72xzsByHpbBOn/UIYfmyVTJhW XwywlbAnbgxj5jK6OCLH8VG3RDwkQvGp&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=Bo iBnkMCKVmzFPaZ EeCzETxJCQiaoMc0RkwHHpaeI=&c=LRiZpnjvL6a7ny2iUSFTiiC8k4xUZ mf8 fKhGRZpgBMcB ny99pItkVaGzrwRbE2Y6wmhaRIZPMyIsLXg2BHskJpBZ3RA05/DKah9kvgh38BRYS/Xy68RpfrZ8pSJyg3G9aJYD4PHiCvmGZkmDGaJrJaAnrhq585fweRUCm//NCCOrULVrOV/zIKiiqY88o&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=99QQZ/7gz1F0J4Frsugp6AQFgwJt sNW2hsWofBdrMg=&c=uE4ZPBpgcwJOVmJzjQEOQGrUbDpic5cmKQgNH2VoA8dvIMqDPlmwXAS9K6StAl8GsvPcQ3X61o4bZfVWR/33GCajfMsUY6QFB7AfHmK4OxoS0bhvk1bN pJeHvCUfgeO2R8VJgNLFSeTSMFpDTko5WUHyxjP0tNdjwd3w2J9iTw=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=v Uy8fb2BTgC7v RK jEPhornjW09bthyM7By7tRrCg=&c=c2S6wVbiSYAta3dbWYyBIR9FpqFZvUQdQ9t8Gz6/lAUpV8ZJ0hTZRpc4/SMEx0ekHzCRZESv DuIG0g1s9fkd3QHXX5KgTQHT7Lbt7s6kCabK2ml8panIScl Smr56/tfBBCdJtSbegXdw vFOnaA5fqyePXY0rKbn0hK3pp55pTq7eeiWgRufg71V6SZ8cO&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=HWHiPSmhm/Ho clxaeo5j3so8jdgzTDbZWZK 5Jh6ZQ=&c=JijAez4gpYoHfZrZntbHvlsaRA64tAx7EbUZ2oIIaUJsMcFKbmj4E88nDO5HBI6e6jl7x5pmBa AuakK meW1Gj4RmelxhKJZ dYnCFhlB1Vf0q8ckToQ2vdsceKxcKcEJYLgtuBbDXWJVtlWuB5rQ8lS9sz3u3gWvSGQ7QTZ1e bVsqOhbXD2rXADF6H7Tp&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=wnjnH9ZbPVkPLimXFWPBozUFsxKvIYvLksdgpXHjOFs=&c=55G2qU9AyPfo1HHlSOA UjMMg2YTg3YddzQJU7xqUHlPaqd0N2pq/FzzFBxDVcAHSS94k6nm6cVDDDgteL0eOPF4JUa2XhuPoqtlPDzOGyHfPjNSZxMHMhDiz/kUqE5V/usFj0pZzL6kCaxWvDjssw==&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=Xt0RnHwqXS9lcG0oUlifsByodRu5FPVU7F4s0k1HRZI=&c=KEmzTckZlLXlBdfnynXfO1jqTVXuEXKjBj7FKhIPvwglnj59x0GXKahDPKgUXGP2AUqjZC9gW13hR0s3BBMqLXD20GK3vKc0m3TLo7hZ9IBvxMeRJ1oo/bm1nb1X b395syCf23HLhR/8v3ogEPy3g==&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=ZF3EGpDE22qOGGf/1wcg7/vbkopv4f0OlhiTuDU4USs=&c=tVOqqQz9ksMm4qFmzd6IX5PzHD0QH5ffFUO2vkmX7nE3cD7zAFo3NYZ0dWjRcNWJyQ4gvAkWkUo/oHY00Au1QK9lISehroQX/l3Fcm QAyDbYLrva7yg63uHLgCtsxQDnJzB/5xlvmio5G6UKAq7V2HcprCHNocW818fSHaV/Kk=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=4WTqRiApjI6UFtW4eI8S3GtadHucJASr3oy3tAPrlgY=&c=n5nw7LgxMJwNYCRa6kIxXT3d xK YSxwDp7G8qPaHJD9eThKnkzrMcEP3sfqSnojygxkY9oWwpMxBvXcL7JqI2El0Jl1uBQ4plGkWFX4Zwn2nywJkwk Z7MZcFtchmRarc23Tk5XIHTSofecp4Tix7MReVSn4yH9QsgXuxZKXqc=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=yBF8gHTgHkA30VGiGulIolD0DhzB9Fb2AkUVXIkx KQ=&c=uGqrsKWXCwYh8cGHz48gedd2S16nNctaoelP/E1 2cu JuYfXDi5ZvHEQlOn/nv/L8AZj2PDqYD2XfQX4JW1gOJz46hp99PVDnwUrqsIxj0WrLi 4z3kjWNc13lLdYMHAu5fr9xtZ7KWqmsi7wlDCQ==&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=wGMFMc7iWwU407ZdVPhcmBkjJ WxzW3in5/wgMkitHw=&c=ZtbucAaTEuzId8mvOX4hYCNDZbrwsdq5EySFBp8f8fUzd83bEWq TWKASFSX0W1kxji4ZN0oY63hDaNo98l7e6InVLT3lj/SKMjfY6Sz5Rqg qgiSIXgc7x2SdLYk/bBXlRkpo9ayD0mMqqaqUhzQwkmsxhFwFjnARl99Z9pQJbWt963Fa BvebX2JQVm97&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=oIwL5mF7/hNc ob6bn6EgipRlRGul9OsrKCxC5L2HFk=&c=2fKkah9AFnIdaXTiPCbx4DQsRCqvUAqM9QCNRZ4EDaXRsO7/CdDuz9vPial2Kmtlim6mo7CyS/66apTU1IDRBn4OlKZP5kEdUNAg3ssSZgBmfQaC DtW0e6XfE9xf45ZI1KDhMIvzbAoN5KFmVF/KLT/VrPKgNchXPYavjwfiN4=&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=Tf//5T553n//qrGpDLVDd5aE MG88s6L8KLekebbEDA=&c=B yRnlvNucBbKpEeIfQlKHd7fy3waZbRcmJJdnA29c8Z51S8EuoWQd/UW 6c3eUmySxeS30jMxY 3GISk7JMTy2cVokHCGL4vl2BUNt38AKvOsBTpEs6vgRvqRAD6i/YlGBI3lSzIo56j2VRV/HOKrfcs5v31 wC2RQpxcSO 2rzhki0rb2upXv n7dXTbi&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

http://www.giftgiftlaboratory.com/c?x=2hugw37iIRQAZjHKE64/DM3Ux17g1dYwLjRi4VlrTLE=&c=IfFD o/HPL vPWtNsbKLsNNsTKAEvkCEWpV97vFvvQto29I3Mt4JAvHS/R6MWHPqTPmNxKchx84l4Mru rLZfCLkRBJ7K7C/4/L4/NMdjyfmo4G1alOFKH1pI1VAWhm9MSnjkMeu8rrvUy1dPGprgw==&e=0&downloadAs=VDownloader_Setup.exe&fallback_url=http://.../?p=plus

Latest 30 of 191 download URLs

Remove vdownloader_setup.exe - Powered by Reason Core Security