limewire_ver_5_6_2.exe

Tuguu S.L.

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application limewire_ver_5_6_2.exe by Tuguu S.L has been detected as adware by 18 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
Tuguu S.L.  (signed and verified)

MD5:
d059e2c768a8ccc8a4b7e16f3f9382bb

SHA-1:
43ecaa50bccd7d53e6357a8c61e30f4392125da9

SHA-256:
6a9c272140e32711102bbda99fc45b1a3f70f5a2b64d21f92d14d45f6f4bbbab

Scanner detections:
18 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 4:54:07 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.03.09

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.135.186

AVG
Skodna.Bundle_r.U
2015.0.3576

Dr.Web
Trojan.DownLoader9.15042
9.0.1.033

Emsisoft Anti-Malware
Worm.Generic.21506
8.14.04.05.02

ESET NOD32
Win32/DomaIQ.AZ (variant)
8.9518

G Data
Win32.Application.DomalQ
14.4.24

herdProtect (fuzzy)
2014.4.5.14

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.4373

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.02.02.10

McAfee
Adware-DomaIQ!4019C3F4733F
5600.7232

NANO AntiVirus
Trojan.Win32.DomaIQ.csuxpi
0.28.0.58101

Panda Antivirus
Adware/MultiToolbar
14.02.02.10

Reason Heuristics
PUP.TuguuSL.S
14.8.7.18

Sophos
Generic PUA OF
4.98

Vba32 AntiVirus
BScope.Downware.DomaIQ
3.12.24.3

VIPRE Antivirus
DomaIQ
27206

File size:
312.7 KB (320,192 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\limewire_ver_5_6_2.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
5/14/2013 1:00:00 AM

Valid to:
7/18/2014 1:00:00 PM

Subject:
CN=Tuguu S.L., OU=U B76539535, O=Tuguu S.L., L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
08EC69B75B2FE31EC2C53E0E441AC0E1

File PE Metadata
Compilation timestamp:
2/4/2014 11:28:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:Gk6y38qiVy3aWuwpeTgYuAXHs+3xr9hvqBuMnwqCYf6I3HutHKc0Sps96pMFVzDN:Gxg8qdPnsXM+3x9CwqCYfDO/W9bpdYZc

Entry address:
0x1576

Entry point:
E8, BC, 26, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, D8, CF, 40, 00, 89, 0D, D4, CF, 40, 00, 89, 15, D0, CF, 40, 00, 89, 1D, CC, CF, 40, 00, 89, 35, C8, CF, 40, 00, 89, 3D, C4, CF, 40, 00, 66, 8C, 15, F0, CF, 40, 00, 66, 8C, 0D, E4, CF, 40, 00, 66, 8C, 1D, C0, CF, 40, 00, 66, 8C, 05, BC, CF, 40, 00, 66, 8C, 25, B8, CF, 40, 00, 66, 8C, 2D, B4, CF, 40, 00, 9C, 8F, 05, E8, CF, 40, 00, 8B, 45, 00, A3, DC, CF, 40, 00, 8B, 45, 04, A3, E0, CF, 40, 00, 8D, 45, 08, A3, EC, CF, 40...
 
[+]

Entropy:
5.8913

Code size:
30.5 KB (31,232 bytes)

The file limewire_ver_5_6_2.exe has been seen being distributed by the following URL.

Remove limewire_ver_5_6_2.exe - Powered by Reason Core Security