player.exe

Payments Interactive SL

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application player.exe by Payments Interactive SL has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The file has been seen being downloaded from www.lpcloudbox0121.com.
Publisher:
Payments Interactive SL  (signed and verified)

MD5:
d8d1f343520047b8a3c75498d4dc4314

SHA-1:
d19820483cdce6d6612b8e3a68b61c5689c2cac2

SHA-256:
2bc16a4be3411730cb2952d770aa004be6b985b83c2ac0f3332dbc245bd72a3f

Scanner detections:
20 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 10:20:06 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.DomaIQ
7.1.1

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.142.186

avast!
Win32:Rootkit-gen [Rtk]
2014.9-140418

AVG
DomaIQ_r.H
2015.0.3500

Comodo Security
Application.Win32.DomaIQ.PUP
18084

Dr.Web
Trojan.Packed.26446
9.0.1.0108

ESET NOD32
MSIL/DomaIQ (variant)
8.9665

F-Secure
Dropped:Rootkit.13610
11.2014-18-04_6

G Data
Win32.Trojan-Downloader.Lisp
14.4.24

K7 AntiVirus
Unwanted-Program
13.176.11721

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.3997

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.04.18.02

McAfee
Artemis!564F55A8164A
5600.7156

nProtect
Dropped:Rootkit.13610
14.04.18.01

Panda Antivirus
PUP/MultiToolbar.A
14.04.18.02

Reason Heuristics
PUP.PaymentsInteractiveSL.G
14.8.7.23

Sophos
Generic PUA IP
4.98

Vba32 AntiVirus
AdWare.MSIL.DomaIQ
3.12.26.0

VIPRE Antivirus
DomaIQ
28194

File size:
432.7 KB (443,056 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\player.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/28/2013 1:00:00 AM

Valid to:
11/29/2014 12:59:59 AM

Subject:
CN=Payments Interactive SL, O=Payments Interactive SL, STREET=Camino las fayeras 1, L=Puntagorda, S=Santa cruz de Tenerife, PostalCode=38789, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D9CDF60C136552E24EDA78215D3EE028

File PE Metadata
Compilation timestamp:
4/9/2014 6:31:45 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:1LkL+jocfjGNouUGCDPJolfCf/EO0ksQyXYf4+UYPskubZmYaQzY50:1wL+ccfjTuUGCDholyb0YHUnM0

Entry address:
0x2315

Entry point:
E8, 53, 24, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, DD, 09, 00, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, 51, E8, 3B, 25, 00, 00, 59, 59, 5D, C2, 04, 00, 8B, FF, 51, C7, 01, E8, C9, 41, 00, E8, B7, 24, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, F1, E8, E3, FF, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, B8, FF, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, FF, 75, 08, 51, E8, 1E, 26, 00, 00, 59, 59, 5D, C2, 04, 00, 8B, FF, 51, E8, 78, 24, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08...
 
[+]

Code size:
108 KB (110,592 bytes)

The file player.exe has been seen being distributed by the following URL.

Remove player.exe - Powered by Reason Core Security