setup.exe

Tuguu S.L

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application setup.exe by Tuguu S.L has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. The file has been seen being downloaded from ttb.lpcloudsvr403.com.
Publisher:
Tuguu S.L  (signed and verified)

MD5:
44765ff867a1faa115c927e9e7663d48

SHA-1:
01b3e68fed865b199b3320758919a44b468d7b1b

SHA-256:
261ae54783ba930629ea8c791f6422c9e3d24163a2bee709203863f7fe25388d

Scanner detections:
21 / 68

Status:
Adware

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 1:16:16 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.331796
1030

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
14.04.11

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.138.26

AVG
Skodna.Bundle_r.U
2015.0.3508

Dr.Web
Trojan.DownLoader9.15042
9.0.1.0101

ESET NOD32
Win32/DomaIQ.AZ (variant)
8.9567

F-Secure
Gen:Variant.Kazy.331796
11.2014-11-04_6

G Data
Win32.Application.DomalQ
14.4.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.4033

Malwarebytes
PUP.Optional.Domalq
v2014.04.11.08

McAfee
Adware-DomaIQ!7727D06EC3A7
5600.7164

MicroWorld eScan
Gen:Variant.Kazy.331796
15.0.0.303

NANO AntiVirus
Trojan.Win32.DomaIQ.cswtvq
0.28.0.58491

Panda Antivirus
PUP/MultiToolbar.A
14.04.11.08

Reason Heuristics
PUP.Installer.TuguuSL.F
14.3.31.14

Sophos
DomainIQ pay-per install
4.98

Vba32 AntiVirus
BScope.Downware.DomaIQ
3.12.24.3

VIPRE Antivirus
DomaIQ
27574

File size:
313.6 KB (321,112 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/27/2013 1:00:00 AM

Valid to:
11/28/2014 12:59:59 AM

Subject:
CN=Tuguu S.L, O=Tuguu S.L, STREET=AVENIDA BARRANCO DE LAS TORRES 10, L=Adeje, S=Santa Cruz de Tenerife, PostalCode=38670, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BD6B6D8F58D08D8E89D1700D774E2094

File PE Metadata
Compilation timestamp:
1/29/2014 2:47:03 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:fk6y336SLWmpqVWNwXLXuvfxMmJGUFpTqRau6AKnOA2ys+9e+3c5kzdCMFFV0Dlj:fxg36PWNw7XuBWmkeVd9wxT0Y1

Entry address:
0x1576

Entry point:
E8, BC, 26, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, D8, CF, 40, 00, 89, 0D, D4, CF, 40, 00, 89, 15, D0, CF, 40, 00, 89, 1D, CC, CF, 40, 00, 89, 35, C8, CF, 40, 00, 89, 3D, C4, CF, 40, 00, 66, 8C, 15, F0, CF, 40, 00, 66, 8C, 0D, E4, CF, 40, 00, 66, 8C, 1D, C0, CF, 40, 00, 66, 8C, 05, BC, CF, 40, 00, 66, 8C, 25, B8, CF, 40, 00, 66, 8C, 2D, B4, CF, 40, 00, 9C, 8F, 05, E8, CF, 40, 00, 8B, 45, 00, A3, DC, CF, 40, 00, 8B, 45, 04, A3, E0, CF, 40, 00, 8D, 45, 08, A3, EC, CF, 40...
 
[+]

Code size:
30.5 KB (31,232 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security