player.exe

tuguu sl

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application player.exe by tuguu sl has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. The file has been seen being downloaded from www.lpcloudbox414.com.
Publisher:
tuguu sl  (signed and verified)

MD5:
e8b743be587d594362518c54740f1207

SHA-1:
898bf8690e82e5f627fc8e869024ef731d52ba6b

SHA-256:
1a45f5d3c53d03caa95d0e7b723b8296bb2d29d1737c6d916e2bb7d0ffa8c200

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/18/2024 2:51:31 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Lollipop
7.1.1

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.151.6

avast!
Win32:Installer-U [PUP]
140516-1

AVG
DomaIQ
2015.0.3466

Bitdefender
Gen:Variant.Application.Graftor.142453
1.0.20.720

ESET NOD32
Win32/DomaIQ.BF potentially unwanted application
7.0.302.0

F-Secure
Gen:Variant.Application.Graftor
11.2014-24-05_7

G Data
Gen:Variant.Application.Graftor.142453
14.5.24

K7 AntiVirus
Unwanted-Program
13.178.12184

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.3826

Malwarebytes
PUP.Optional.DomaIQ
v2014.05.22.07

McAfee
Adware-DomaIQ!E8B743BE587D
5600.7122

MicroWorld eScan
Gen:Variant.Application.Graftor.142453
15.0.0.432

Panda Antivirus
PUP/MultiToolbar.A
14.05.22.07

Reason Heuristics
PUP.tuguusl.G
14.8.7.18

Sophos
DomainIQ pay-per install
4.98

VIPRE Antivirus
Threat.4783235
29418

File size:
393 KB (402,440 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\player.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
6/13/2013 10:06:55 AM

Valid to:
6/13/2014 10:06:55 AM

Subject:
CN=tuguu sl, O=tuguu sl, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B632A0CF95E4D

File PE Metadata
Compilation timestamp:
5/21/2014 5:05:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:4WEdNEx+LBMWohJX127orr1lan4cvV/QT:7QEx+1UdSkr1lI4ct/A

Entry address:
0x4DF4

Entry point:
B8, D8, 33, 4D, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 6E, 6F, 73, 72, 65, 73, 65, 6D, 70, 61, 00, C4, 9E, 79, C5, 85, 7E, 74, F1, 86, F9, 38, B1, A5, 3E, E6, 9A, 26, B0, 63, 14, C4, 68, CA, E2, D6, FC, 02, 2C, 93, 28, 03, 31, 89, 6E, 64, 44, A5, BE, AE, 85, CB, 6C, B6, 15, 9B, EC, A9, E8, F3, AD, BA, 60, B3, 16, D2, 64, 98, 18, B8, EA, 9B, 96, 57, 61, 09, 92, B7, C5, E4, 01, A1, 8C, 7C, 06, 11, 5F, 1D, A5, 39, 90, 46, 1C, 47, 8E, DB, AA, D6, 9A, 25, 5A, 95, A2, 40...
 
[+]

Entropy:
7.9688  (probably packed)

Code size:
109 KB (111,616 bytes)

The file player.exe has been seen being distributed by the following URL.

Remove player.exe - Powered by Reason Core Security