parent.txt

Lunacom Interactive Ltd

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file parent.txt by Lunacom Interactive has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. It is also typically executed from the user's temporary directory.
Publisher:
Lunacom Interactive Ltd  (signed and verified)

MD5:
fa34b1f381e495731b29abd066cacb06

SHA-1:
69730d54f522b6327177937b686b4255e193330a

SHA-256:
3db8d567cb24082978045d46ed428fea7bdcf8c5986de1e238a006e07fa541a1

Scanner detections:
10 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/6/2024 11:19:24 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Adware Skodna.Bundle_r.P
2015.0.3345

Clam AntiVirus
Win.Trojan.Domaiq-64
0.98/19406

Dr.Web
Trojan.PayInt.1
9.0.1.0263

Emsisoft Anti-Malware
Dropped:Trojan.Generic.10073764
8.14.09.20.02

ESET NOD32
Win32/DomaIQ.AN potentially unwanted application
8.7.0.302.0

F-Prot
W32/MSIL_Troj.CL2.gen
v6.4.6.5.141

Kaspersky
not-a-virus:AdWare.Win32.DomaIQ
14.0.0.3222

Reason Heuristics
PUP.LunacomInteractive.J
14.9.20.14

VIPRE Antivirus
Threat.4150696
32938

File size:
451 KB (461,848 bytes)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\parent.txt

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/5/2013 8:00:00 PM

Valid to:
12/5/2014 6:59:59 PM

Subject:
CN=Lunacom Interactive Ltd, OU="Raul Valenberg 6, ", OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Lunacom Interactive Ltd, L=Tel Aviv-Jaffa, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
15E496383F5A0396A7AD86D85850D5BB

File PE Metadata
Compilation timestamp:
11/29/2013 11:13:40 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:ZOoM2iSrUT2nTNtY/ccTDtpzQJ953zfjbBagEJdzfIzNJ+xTRUkUkhDYI:smnTNtY/zDA53bGJdD6J+xFUtG

Entry address:
0xD74B

Entry point:
E8, 99, 59, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 90, 35, 42, 00, E8, EB, 22, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 70, A8, 42, 00, 77, 22, 6A, 04, E8, 84, 5B, 00, 00, 59, 83, 65, FC, 00, 56, E8, 8B, 63, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, F7, 22, 00, 00, C3, 6A, 04, E8, 7F, 5A, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, A8, E0, 41, 00, 83, 3D, 1C, 95, 42, 00, 00, 75, 18, E8, 4B, 51, 00...
 
[+]

Entropy:
7.3911

Code size:
114 KB (116,736 bytes)

Remove parent.txt - Powered by Reason Core Security