google-earth.exe

Awimba LLC

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application google-earth.exe by Awimba has been detected as adware by 32 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from dls.nicdls.com.
Publisher:
Awimba LLC  (signed and verified)

MD5:
e976eb9ad98076b6bd72c9b5956faec9

SHA-1:
fd8029b01a7b3442a96f5ebc82c1bfcc8fb0ba1e

SHA-256:
7ea5ad2d004330834971addb72f00c752c4ad34ca34879c964b36a1b81639826

Scanner detections:
32 / 68

Status:
Adware

Explanation:
Uses the InstallIQ download installer to bundle various adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 10:49:25 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.DomaIQ.F
562

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
Win-PUP/DomaIQ.Gen
2015.04.12

Avira AntiVirus
PUA/DomaIQ.Gen
3.6.1.96

avast!
Win32:DomaIQ-AI [PUP]
2014.9-150722

AVG
DomaIQ
2016.0.3040

Bitdefender
Application.Bundler.DomaIQ.F
1.0.20.1015

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.Downloader.Agent.WA
21735

Dr.Web
Adware.W3i.29
9.0.1.0203

ESET NOD32
Win32/DomaIQ.C potentially unwanted
9.11460

Fortinet FortiGate
Riskware/DomaIQ.C!tr
7/22/2015

F-Prot
W32/A-7e3b8ba8
v6.4.7.1.166

F-Secure
Application.Bundler.DomaIQ
11.2015-22-07_4

G Data
Application.Bundler.DomaIQ
15.7.25

herdProtect (fuzzy)
2015.8.22.20

IKARUS anti.virus
AdWare.Agent
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.177.12041

Kaspersky
not-a-virus:AdWare.Win32.DomaIQ
14.0.0.1697

Malwarebytes
Adware.DomaIQ
v2015.07.22.01

McAfee
Artemis!961780AC0032
5600.6696

MicroWorld eScan
Application.Bundler.DomaIQ.F
16.0.0.609

NANO AntiVirus
Riskware.Base64.DomaIQ.cwpnap
0.28.0.59826

nProtect
Adware.Agent.NPO
14.05.11.01

Panda Antivirus
Trj/CI.A
15.07.22.01

Quick Heal
AdWare.MSIL.r3 (Not a Virus)
7.15.14.00

Reason Heuristics
PUP.Awimba.Bundler (M)
15.7.22.13

Sophos
DomainIQ pay-per install
4.98

Trend Micro House Call
TROJ_GE.43A281A2
7.2.203

Trend Micro
ADW_DOMA
10.465.22

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.26.3

VIPRE Antivirus
DomaIQ
29128

File size:
1.1 MB (1,135,664 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\google-earth.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
12/18/2012 11:12:06 AM

Valid to:
12/18/2013 11:12:06 AM

Subject:
CN=Awimba LLC, O=Awimba LLC, L=wilmington, S=DE, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0423F035F20DC9

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:29 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:DFOhYnnxyo195tnarEcQ07/sNGV4Xo4L3D0qswo3yHpzZ:6Yr7gEC7kAeXo+xsMhZ

Entry address:
0x30DE

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 27, 7A, 00, E8, F1, 2B, 00, 00, A3, A4, 26, 7A, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 68, DC, 79, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, A0, 1E, 7A, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 80, 7A, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9855

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file google-earth.exe has been seen being distributed by the following URL.

Remove google-earth.exe - Powered by Reason Core Security