{"id":1268,"date":"2014-08-05T07:30:22","date_gmt":"2014-08-05T07:30:22","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=1268"},"modified":"2018-05-29T12:02:48","modified_gmt":"2018-05-29T12:02:48","slug":"wilmaonline-ltd","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/wilmaonline-ltd\/","title":{"rendered":"Wilmaonline LTD &#8211; VirusTotal and Bundling Report"},"content":{"rendered":"<p>Found a file this morning, claiming to be a <a href=\"http:\/\/www.freefixer.com\/library\/file\/FlashPlayersetup__2570_i1126403949_il3928.exe-136255\/\">Flash Player setup file<\/a>. However, the file was not digitally signed by Adobe, which is the publisher of the Flash Player. Instead it was signed by a company called\u00a0<strong>Wilmaonline LTD.\u00a0<\/strong>which made it look suspicious.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-publisher.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-1271\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-publisher.png\" alt=\"Wilmaonline LTD. publisher\" width=\"475\" height=\"271\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-publisher.png 475w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-publisher-300x171.png 300w\" sizes=\"(max-width: 475px) 100vw, 475px\" \/><\/a><\/p>\n<p>According to the certificate that is embedded in the file, Wilmaonline is a company located in Israel.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-certificate.png\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-1270\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-certificate.png\" alt=\"Wilmaonline LTD. certificate\" width=\"573\" height=\"581\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-certificate.png 573w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-certificate-295x300.png 295w\" sizes=\"(max-width: 573px) 100vw, 573px\" \/><\/a><\/p>\n<p>So, what does the anti-virus programs say about the <strong>Wilmaonline<\/strong> file? No problem, I just uploaded the file to VirusTotal and it turned out that many of the anti-virus programs detects the <strong>Wilmaonline<\/strong> file, with names such as <strong>Adware.Downware<\/strong>\u00a0and\u00a0<strong>PUP.Optional.Amonetize.<\/strong><\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD-Virus-Total-Report.png\"><img loading=\"lazy\" class=\"alignnone wp-image-1273 size-full\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD-Virus-Total-Report.png\" alt=\"Wilmaonline LTD  Virus Total Report - PUP.Optional.Amonetize, Adware.Downware\" width=\"759\" height=\"417\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD-Virus-Total-Report.png 759w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD-Virus-Total-Report-300x164.png 300w\" sizes=\"(max-width: 759px) 100vw, 759px\" \/><\/a><\/p>\n<p>To see more in details what changes the <strong>Wilmaonline<\/strong> file would do on a user&#8217;s computer I decided to run the file on my lab machine. The following <strong>InstallPath<\/strong> installer appeared, where &#8220;Flash Player&#8221;, <strong>Dolphin Deals<\/strong>, <strong>Flow Surf<\/strong>, <strong>Webssearches<\/strong> and <strong>OffersWizard<\/strong>\u00a0selected for installation by default. This is probably the reason why the anti-virus programs detects the <strong>Wilmaonline<\/strong> file, in addition to using Adobe&#8217;s Flash trademark.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-installer.png\"><img loading=\"lazy\" class=\"alignnone wp-image-1269 size-full\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-installer.png\" alt=\"Wilmaonline LTD. - installer for Flash Player, Dolphin Deals, Flow Surf, Webssearches, OffersWizard\" width=\"673\" height=\"465\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-installer.png 673w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2014\/08\/Wilmaonline-LTD.-installer-300x207.png 300w\" sizes=\"(max-width: 673px) 100vw, 673px\" \/><\/a><\/p>\n<p>Did you also find a file digitally signed by <strong>Wilma Online<\/strong>? What kind of download was it and where did you find it?<\/p>\n<p><strong>Update 13 Sep 2014<\/strong>: Thought I should follow up on this one. The <strong>Wilmaonline<\/strong> signed files are still being distributed. They are promoted as Flash Players, chess games, Ask.FM trackers, keygens, cracks, etc. The installer file includes lots of bundled programs, but for unknown reasons, nothing is installed when I click through the installer. Did you also see this behaviour, or did it install the bundled programs on your machine? The anti-virus programs have improved their detection rates somewhat for the WilmaOnline files:<\/p>\n<ul>\n<li><span style=\"color: #ff0000;\">18<\/span>\/54 &#8211; FlashPlayersetup__2570_i1300328638_il1783.exe<\/li>\n<li><span style=\"color: #ff0000;\">15<\/span>\/52 &#8211; Chess Titans setup__6670_il4710.exe<\/li>\n<li><span style=\"color: #ff0000;\">15<\/span>\/55 &#8211; Ask Fm Tracker 2014 Downloader__3687_i1301881522_il2700510.exe<\/li>\n<li><span style=\"color: #ff0000;\">14<\/span>\/55 &#8211; Keygen Installer__9167_il260.exe<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Found a file this morning, claiming to be a Flash Player setup file. However, the file was not digitally signed by Adobe, which is the publisher of the Flash Player. Instead it was signed by a company called\u00a0Wilmaonline LTD.\u00a0which made it look suspicious. According to the certificate that is embedded in the file, Wilmaonline is &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/wilmaonline-ltd\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Wilmaonline LTD &#8211; VirusTotal and Bundling Report<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[94,136,137,134,139,135,138],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/1268"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=1268"}],"version-history":[{"count":9,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/1268\/revisions"}],"predecessor-version":[{"id":1759,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/1268\/revisions\/1759"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=1268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=1268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=1268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}