parent.txt

Tuguu S.L.

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The file parent.txt by Tuguu S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the TUGUU DomaIQ Setup installer. It is also typically executed from the user's temporary directory.
Publisher:
Tuguu S.L.  (signed and verified)

MD5:
367eb75b4c8bec65fa4e7bfedcf0657f

SHA-1:
6b01d447ec686c1355641ed5709399c9db7e08b7

SHA-256:
c7c156ea01c3e4e74686c60966d34a1e9a0bd0122f0724d1ccdd33b558ce9e7f

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles third-party components such as adware in the installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/23/2024 9:30:11 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Tuguu.Bundler (M)
16.2.14.6

File size:
480.5 KB (492,040 bytes)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\appdata\local\temp\parent.txt

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
5/13/2013 8:00:00 PM

Valid to:
7/18/2014 8:00:00 AM

Subject:
CN=Tuguu S.L., OU=U B76539535, O=Tuguu S.L., L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
08EC69B75B2FE31EC2C53E0E441AC0E1

File PE Metadata
Compilation timestamp:
12/30/2013 9:12:03 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:0QR17ZoiA6aq0/9FzC+jnDWF0UBLcRRWv+:5ZoizMlI+jnCFj4am

Entry address:
0xD162

Entry point:
E8, C5, 63, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 18, 43, 42, 00, E8, C4, 04, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 58, A8, 42, 00, 77, 22, 6A, 04, E8, B0, 65, 00, 00, 59, 83, 65, FC, 00, 56, E8, B7, 6D, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, D0, 04, 00, 00, C3, 6A, 04, E8, AB, 64, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 70, F0, 41, 00, 83, 3D, 1C, A5, 42, 00, 00, 75, 18, E8, 6A, 5C, 00...
 
[+]

Entropy:
7.4496

Code size:
119.5 KB (122,368 bytes)

Remove parent.txt - Powered by Reason Core Security