java.exe

Clovermedia SL

This is part of the Tuguu DomaIQ , a download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application java.exe by Clovermedia SL has been detected as adware by 21 anti-malware scanners. The file has been seen being downloaded from www.downsain.com.
Publisher:
Clovermedia SL  (signed and verified)

MD5:
d24ad05b38e43226725cf3ace048477a

SHA-1:
f8bfced9aee47499fd25f7e4280e551eeeb0d37a

SHA-256:
7b878c2a32ad1336be9f0a5a98fe2111a1c46b0c2a655361921f54389da921ae

Scanner detections:
21 / 68

Status:
Adware

Analysis date:
4/25/2024 12:48:14 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11268939
993

Agnitum Outpost
PUA.Lollipop
7.1.1

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.150.60

avast!
Win32:DomaIQ-CK [PUP]
2014.9-140517

AVG
Adware DomaIQ.CT
2014.0.3950

Bitdefender
Trojan.Generic.11268939
1.0.20.685

Dr.Web
Trojan.Packed.26636
9.0.1.0137

Emsisoft Anti-Malware
Trojan.Generic.11268939
8.14.05.17.01

ESET NOD32
Win32/DomaIQ.BB (variant)
8.9813

F-Secure
Trojan.Generic.11268939
11.2014-17-05_7

G Data
Trojan.Generic.11268939
14.5.24

IKARUS anti.virus
AdWare.SuspectCRC
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.DomaIQ
v2014.05.17.01

McAfee
PUP-FJV!D24AD05B38E4
5600.7127

MicroWorld eScan
Trojan.Generic.11268939
15.0.0.411

nProtect
Trojan.Generic.11268939
14.05.16.01

Panda Antivirus
Trj/Genetic.gen
14.05.17.01

Qihoo 360 Security
Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.ClovermediaSL.E
14.5.15.16

Sophos
Generic PUA FA
4.98

VIPRE Antivirus
Trojan.Win32.Generic
29306

File size:
800.5 KB (819,696 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\java.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
4/29/2014 10:14:21 PM

Valid to:
4/30/2015 10:14:21 PM

Subject:
E=media@clovermediainter.com, CN=Clovermedia SL, O=Clovermedia SL, S=Tenerife, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121FAB97DC7FB0477755E47A50ECFDC36A0

File PE Metadata
Compilation timestamp:
5/5/2014 8:51:47 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:O8pVRWw6fX9+wfupc32/zBj5dy7H5cmaduICyIOspJI5qt3t9I:OOVcftjfqrNn2W8I/IOMzt3t+

Entry address:
0x3D77

Entry point:
E8, 61, 2D, 00, 00, E9, 39, FE, FF, FF, E9, 8E, 13, 00, 00, 3B, 0D, 20, 82, 42, 00, 75, 02, F3, C3, E9, 8D, 36, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, 4C, CF, 42, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 28, 82, 42, 00, 01, 0F, 82, DA, 04, 00, 00, 0F...
 
[+]

Entropy:
5.9721

Code size:
110 KB (112,640 bytes)

The file java.exe has been seen being distributed by the following URL.

Remove java.exe - Powered by Reason Core Security