player setup.exe

Payments Interactive SL

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application player setup.exe by Payments Interactive SL has been detected as adware by 30 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The file has been seen being downloaded from cldlr.com.
Publisher:
Payments Interactive SL  (signed and verified)

MD5:
d9e39497eaffead844dfd4b8eeafc10e

SHA-1:
0709fcde62dcde4b56e2a4a24b9d090cbc81d023

SHA-256:
4ad824799f1e1145ab7c695b12cb3f9c5ed106d5d04fc215c1fccf4a96487b72

Scanner detections:
30 / 68

Status:
Adware

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 6:24:38 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Application.Bundler.DomaIQ.Q
878

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.BundleInstaller
2014.09.10

Avira AntiVirus
APPL/DomaIQ.Gen2
7.11.171.120

avast!
Win32:DomaIQ-CM [PUP]
140908-2

AVG
Adware Skodna.Generic_r.IA
2014.0.4015

Bitdefender
Dropped:Application.Bundler.DomaIQ.Q
1.0.20.1260

Clam AntiVirus
Win.Trojan.Domaiq-29
0.98/19348

Comodo Security
Application.Win32.DomaIQ.D
19470

Dr.Web
Trojan.PayInt.14
9.0.1.05190

Emsisoft Anti-Malware
Dropped:Application.Bundler.DomaIQ.Q
14.09.09

ESET NOD32
Win32/DomaIQ.AU potentially unwanted application
7.0.302.0

F-Prot
W32/DomaIQ.B.gen
v6.4.7.1.166

F-Secure
Adware:W32/DomaIQ
11.2014-09-09_3

G Data
Dropped:Application.Bundler.DomaIQ
14.9.24

IKARUS anti.virus
AdWare.DomaIQ
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.183.13319

Kaspersky
not-a-virus:AdWare.Win32.DomaIQ
15.0.0.494

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.09.09.11

McAfee
CryptDomaIQ
5600.7012

MicroWorld eScan
Dropped:Application.Bundler.DomaIQ.Q
15.0.0.756

NANO AntiVirus
Trojan.Win32.PayInt.csficn
0.28.2.61942

Panda Antivirus
PUP/MultiToolbar.A
14.09.09.11

Quick Heal
Adware.Domal.A5
9.14.14.00

Reason Heuristics
PUP.Installer.PaymentsInteractiveSL.M
14.9.9.22

Rising Antivirus
PE:PUF.DomaIQ!1.9EEB
23.00.65.14907

Sophos
PUA.DomainIQ pay-per install
5.05

Vba32 AntiVirus
BScope.Downware.DomaIQ
3.12.26.3

VIPRE Antivirus
Threat.4783262
32938

Zillya! Antivirus
Adware.DomaIQ.Win32.42
2.0.0.1917

File size:
470.1 KB (481,392 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\player setup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/20/2013 5:00:00 PM

Valid to:
11/26/2014 5:00:00 AM

Subject:
CN=Payments Interactive SL, O=Payments Interactive SL, L=Puntagorda, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0C53B3385E2DD3F89A0D1CFE9C0E443C

File PE Metadata
Compilation timestamp:
1/5/2014 1:10:21 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:bYeUJAy8nnHpMWI1W2o1ZgeH1JMnljQB2in05:IJAyinH2rW2odVAuK

Entry address:
0xD162

Entry point:
E8, C5, 63, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 08, 43, 42, 00, E8, C4, 04, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 58, A8, 42, 00, 77, 22, 6A, 04, E8, B0, 65, 00, 00, 59, 83, 65, FC, 00, 56, E8, B7, 6D, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, D0, 04, 00, 00, C3, 6A, 04, E8, AB, 64, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 70, F0, 41, 00, 83, 3D, 1C, A5, 42, 00, 00, 75, 18, E8, 6A, 5C, 00...
 
[+]

Entropy:
7.4365

Code size:
119.5 KB (122,368 bytes)

The file player setup.exe has been seen being distributed by the following URL.

Remove player setup.exe - Powered by Reason Core Security