minecraft_v.8032463c.exe

Tuguu SLU

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application minecraft_v.8032463c.exe by Tuguu SLU has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. With this installer, users are expecting to download Minecraft but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Tuguu SLU  (signed and verified)

MD5:
b271529e46573d10cf90b81b892638ee

SHA-1:
9615b4f58dde12bbad4ecd0cb912d15e73f61519

SHA-256:
22c507b3d1b90894344cd3e6c25627a0277feecba5139eb1653da4946bf38781

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/16/2024 12:51:30 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.106.64

avast!
NSIS:DomaIQ-B [PUP]
2014.9-131204

AVG
AdInstaller.DomaIQ
2014.0.3635

Comodo Security
UnclassifiedMalware
17071

Dr.Web
Adware.Downware.923
9.0.1.0338

ESET NOD32
Win32/DomaIQ
7.8888

Fortinet FortiGate
W32/DomaIQ.A
12/4/2013

G Data
Win32.Application.DomaIQ
13.12.22

IKARUS anti.virus
Win32.DomaIQ
t3scan.2.0.127

K7 AntiVirus
Riskware
13.173.9807

Malwarebytes
PUP.DomaIQ
v2013.12.04.02

McAfee
Artemis!B271529E4657
5600.7279

Reason Heuristics
PUP.TuguuSLU.T
14.8.7.21

Sophos
DomainIQ pay-per install
4.93

VIPRE Antivirus
DomaIQ
22190

File size:
412.1 KB (421,960 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\minecraft_v.8032463c.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/7/2013 7:00:00 PM

Valid to:
2/8/2014 6:59:59 PM

Subject:
CN=Tuguu SLU, OU=N/A, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Tuguu SLU, L=Adeje, S=Santa Cruz de Tenrife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
552127982028C352ADDA5CA8F6C0BAE7

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:vFmIaxTmlQkoBtWtk/vv5lyM0Ok+Ruoxb:vFmhaQf3/m29

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9359

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file minecraft_v.8032463c.exe has been seen being distributed by the following 2 URLs.

http://dls.gamerdls.com/d/166/Minecraft/24/.../V.7850495c

Remove minecraft_v.8032463c.exe - Powered by Reason Core Security