avg-anti-virus-free-edition-2014.exe

Lunacom Interactive Ltd

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application avg-anti-virus-free-edition-2014.exe by Lunacom Interactive has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. The file has been seen being downloaded from ttb.gufiledownload.com.
Publisher:
Lunacom Interactive Ltd  (signed and verified)

MD5:
7f2addabbac1d7e6a49a968c55757b23

SHA-1:
b375ee50957a6c6056f33b7d98bae4b76163d41a

SHA-256:
fc7ac08845912e55c722663f8005c9e73a1029ff464a243cd4f5921d2c93d225

Scanner detections:
10 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 10:00:23 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Adware Skodna.Bundle_r.P
2015.0.3345

Clam AntiVirus
Win.Trojan.Domaiq-64
0.98/19406

Dr.Web
Trojan.PayInt.1
9.0.1.0263

Emsisoft Anti-Malware
Dropped:Trojan.Generic.10073764
8.14.09.20.02

ESET NOD32
Win32/DomaIQ.AN potentially unwanted application
8.7.0.302.0

F-Prot
W32/MSIL_Troj.CL2.gen
v6.4.6.5.141

herdProtect (fuzzy)
2014.12.3.5

Kaspersky
not-a-virus:AdWare.Win32.DomaIQ
14.0.0.3222

Reason Heuristics
PUP.LunacomInteractive.a
14.9.20.14

VIPRE Antivirus
Threat.4150696
32938

File size:
451 KB (461,848 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\avg-anti-virus-free-edition-2014.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/5/2013 8:00:00 PM

Valid to:
12/5/2014 6:59:59 PM

Subject:
CN=Lunacom Interactive Ltd, OU="Raul Valenberg 6, ", OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lunacom Interactive Ltd, L=Tel Aviv-Jaffa, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
15E496383F5A0396A7AD86D85850D5BB

File PE Metadata
Compilation timestamp:
11/29/2013 11:13:40 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:ZOoM2iSrUT2nTNtY/ccTDtpzQJ953zfjbBagEJdzfIzNJ+xTRUkUkhDYq:smnTNtY/zDA53bGJdD6J+xFUtE

Entry address:
0xD74B

Entry point:
E8, 99, 59, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 90, 35, 42, 00, E8, EB, 22, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 70, A8, 42, 00, 77, 22, 6A, 04, E8, 84, 5B, 00, 00, 59, 83, 65, FC, 00, 56, E8, 8B, 63, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, F7, 22, 00, 00, C3, 6A, 04, E8, 7F, 5A, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, A8, E0, 41, 00, 83, 3D, 1C, 95, 42, 00, 00, 75, 18, E8, 4B, 51, 00...
 
[+]

Entropy:
7.3911

Code size:
114 KB (116,736 bytes)

The file avg-anti-virus-free-edition-2014.exe has been seen being distributed by the following URL.

Remove avg-anti-virus-free-edition-2014.exe - Powered by Reason Core Security