player_setup.exe

Awimba LLC

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application player_setup.exe by Awimba has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from ttb.ooopsvideo.com and multiple other hosts.
Publisher:
Awimba LLC  (signed and verified)

MD5:
bc6630b9751f5e6540b81875db49ef1a

SHA-1:
29b2a816870d93e04b242259dc0c73e88aa3c348

SHA-256:
e2d4505e50285a2d2ee546f15cd65c5f2f113073d0b1bffa96b73116b322f202

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Uses the InstallIQ download installer to bundle various adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 6:22:28 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.DomaIQ.Q
896

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
APPL/DomaIQ.Gen7
7.11.168.222

avast!
DomaIQ-BS [PUP]
140813-1

AVG
Generic
2015.0.3374

Bitdefender
Application.Bundler.DomaIQ.Q
1.0.20.1170

Dr.Web
Adware.W3i.37
9.0.1.05190

ESET NOD32
Win32/DomaIQ.R potentially unwanted application
7.0.302.0

F-Secure
Application.Bundler.DomaIQ
11.2014-22-08_6

G Data
Application.Bundler.DomaIQ
14.8.24

K7 AntiVirus
Unwanted-Program
13.183.13139

Malwarebytes
PUP.MSIL.Launcher
v2014.08.22.01

MicroWorld eScan
Application.Bundler.DomaIQ.Q
15.0.0.702

Qihoo 360 Security
Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.Awimba.M
14.8.22.11

Sophos
DomainIQ pay-per install
4.98

VIPRE Antivirus
Threat.4783235
32210

File size:
436.8 KB (447,248 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\player_setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
5/10/2013 1:00:00 AM

Valid to:
5/15/2014 1:00:00 PM

Subject:
CN=Awimba LLC, O=Awimba LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
09A928EF40E9E87418147E2639362A6E

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:zPB6EuoPpn2gCA7+lJkHNLUtcY4L+Xef3gHLaGMxXClv/AsvlNBKFIotak+x4nYY:j/uoPsgCAbNLhY4L+iQGCBfNyCxe

Entry address:
0x325E

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, EC, 42, 00, E8, 09, 2C, 00, 00, A3, A4, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, C0, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, E3, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9399

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file player_setup.exe has been seen being distributed by the following 2 URLs.

Remove player_setup.exe - Powered by Reason Core Security