00000000

Tuguu S.L

This is part of the Tuguu DomaIQ , a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file 00000000 by Tuguu S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Tuguu S.L  (signed and verified)

MD5:
aaf3b377c2ebd886b7eda4ccb97e514d

SHA-1:
ddaf88734088c3286feadc6bc289b773207bb26e

SHA-256:
e57a8f918199acd80fd3ca07fc4ab64f7ec3950113d9fe57b60bde9de8cabad5

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/19/2024 2:57:27 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Tuguu.TuguuSL (M)
16.2.14.18

File size:
312.5 KB (320,000 bytes)

Common path:
C:\users\{user}\appdata\local\google\chrome\user data\default\file system\001\t\00\00000000

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/3/2013 9:13:51 AM

Valid to:
12/4/2014 9:13:51 AM

Subject:
E=victor.camacho@tuguu.com, CN=Tuguu S.L, O=Tuguu S.L, L=Adeje, S=Tenerife, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121111958C6091E136AAD058195A273968F

File PE Metadata
Compilation timestamp:
2/6/2014 6:50:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:MV24jwnTGLyoE2fsAu6i6xgB1A/QXoCPk96zmyYh:MV2mwnTyyoE2fsz6xgBu1CC

Entry address:
0x1573

Entry point:
E8, BF, 26, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, D8, CF, 40, 00, 89, 0D, D4, CF, 40, 00, 89, 15, D0, CF, 40, 00, 89, 1D, CC, CF, 40, 00, 89, 35, C8, CF, 40, 00, 89, 3D, C4, CF, 40, 00, 66, 8C, 15, F0, CF, 40, 00, 66, 8C, 0D, E4, CF, 40, 00, 66, 8C, 1D, C0, CF, 40, 00, 66, 8C, 05, BC, CF, 40, 00, 66, 8C, 25, B8, CF, 40, 00, 66, 8C, 2D, B4, CF, 40, 00, 9C, 8F, 05, E8, CF, 40, 00, 8B, 45, 00, A3, DC, CF, 40, 00, 8B, 45, 04, A3, E0, CF, 40, 00, 8D, 45, 08, A3, EC, CF, 40...
 
[+]

Entropy:
5.8867

Code size:
30.5 KB (31,232 bytes)

Remove 00000000 - Powered by Reason Core Security