el consejero 2013 cam bajo castellano by arkonada.exe

Tuguu Israel Ltd

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application el consejero 2013 cam bajo castellano by arkonada.exe by Tuguu Israel has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the TUGUU DomaIQ Setup installer.
Publisher:
Tuguu Israel Ltd  (signed and verified)

MD5:
fe77a53fc1c63c3b30045a51a97a26ff

SHA-1:
4ee196e2bcea40168ac308fb4c9b76f07a2eae36

SHA-256:
65e4b36b89d09f52f46f81e30a24e92e4b0e493eec1836169d6fb886e229004f

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The software bundles potentially unwanted offers during setup including toolbars and adware.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/11/2017 4:42:26 AM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Tuguu (M)
16.7.17.19

File size:
449.6 KB (460,408 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\el consejero 2013 cam bajo castellano by arkonada.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
6/12/2013 2:00:00 AM

Valid to:
8/20/2014 2:00:00 PM

Subject:
CN=Tuguu Israel Ltd, O=Tuguu Israel Ltd, L=RAMAT GAN, C=IL

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06FD356584CBF71B04A7AFE790A2329F

File PE Metadata
Compilation timestamp:
1/12/2014 6:58:46 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:gJ5R/NeaeZ/BeDPwEQTSLw8mbo3F/SmqraOxZQLv2U+:O8ZoDPw7Eko3cdZQLuh

Entry address:
0xCD12

Entry point:
E8, A4, 5E, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 80, 22, 42, 00, E8, C4, 04, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 58, 88, 42, 00, 77, 22, 6A, 04, E8, 8F, 60, 00, 00, 59, 83, 65, FC, 00, 56, E8, 96, 68, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, D0, 04, 00, 00, C3, 6A, 04, E8, 8A, 5F, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 70, D0, 41, 00, 83, 3D, 1C, 85, 42, 00, 00, 75, 18, E8, 4A, 57, 00...
 
[+]

Code size:
111 KB (113,664 bytes)

The file el consejero 2013 cam bajo castellano by arkonada.exe has been seen being distributed by the following URL.