00000000

Clovermedia SL

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file 00000000 by Clovermedia SL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the TUGUU DomaIQ Setup installer.
Publisher:
Clovermedia SL  (signed and verified)

MD5:
e8ca880284bd3e29f044095bee07aafc

SHA-1:
9c2ecdd233c2f183e8b4b03937c802f5b7931f3c

SHA-256:
71dff9d77b7daceff80d046f552cba9bf12d995334e7c9595015dc9be6373793

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/27/2024 4:16:28 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Tuguu.Clovermedia.Bundler (M)
16.2.13.9

File size:
264.4 KB (270,712 bytes)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\appdata\local\google\chrome\user data\default\file system\006\t\00\00000000

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
2/13/2014 12:22:48 PM

Valid to:
2/13/2015 12:22:48 PM

Subject:
CN=Clovermedia SL, O=Clovermedia SL, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
281161B1143F2B

File PE Metadata
Compilation timestamp:
5/27/2014 10:30:39 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:8BqbCxZI15H6i50U4gzvYLXwj4yDXL9Bz3GUrY22:8t3aygzvIXK4kL9Bz3LF2

Entry address:
0x5524

Entry point:
B8, 50, EA, 48, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 70, 61, 63, 65, 70, 61, 63, 65, 74, 65, 00, EC, B3, C4, 5B, B9, C4, C4, 0C, D4, 59, 62, F9, 71, 69, EE, 4D, 94, 5F, 44, 6A, 69, A6, 8E, 54, 9C, 7F, C9, 4E, 1C, F2, 50, 74, 56, 3D, 25, B8, 2F, F3, CD, 43, 9E, 7E, 87, 0E, 07, 96, FE, 48, 5B, 6C, 90, B0, FE, F2, E1, E8, 6A, 1E, F7, 71, 01, B0, E4, 97, ED, DE, 08, 32, 10, 51, 14, 03, F4, 33, BB, D3, 78, A4, 64, EF, 80, AD, 42, 10, 9F, 79, 46, B4, B3, 75, 53, 9C, A5...
 
[+]

Code size:
111 KB (113,664 bytes)

Remove 00000000 - Powered by Reason Core Security