setup.exe

Awimba LLC

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Awimba has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
Awimba LLC  (signed and verified)

MD5:
ae6f08f8a88ff409a96309a743207aef

SHA-1:
37b4747b7c64e4467fd577ecf7c9e05420fb522e

SHA-256:
4e79ce3f647ee01159dcdc0dca52ff80e6790d2d463972aa698e9602aaab96f5

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Uses the InstallIQ download installer to bundle various adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 2:49:20 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Agent
7.1.1

Avira AntiVirus
APPL/DomaIQ.Gen7
7.11.145.6

AVG
MalSign.Generic
2015.0.3495

Dr.Web
Adware.W3i.37
9.0.1.0113

ESET NOD32
Win32/DomaIQ
8.9713

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.04.23.06

Norman
DomaIQ.YRV
11.20140423

Reason Heuristics
PUP.Installer.Awimba.I
14.8.7.18

Sophos
DomainIQ pay-per install
4.98

VIPRE Antivirus
DomaIQ
28548

File size:
416.8 KB (426,760 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
5/10/2013 2:00:00 AM

Valid to:
5/15/2014 2:00:00 PM

Subject:
CN=Awimba LLC, O=Awimba LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
09A928EF40E9E87418147E2639362A6E

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:1PB6EuoOBCsM+tq8OnhFVYGcL/17pzASRcnJ6LVHDl/MiGu/K1MfSihx4wNInUQs:p/uo/+tsnzCTASSMLVHDFMZuQwNNr

Entry address:
0x325E

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, EC, 42, 00, E8, 09, 2C, 00, 00, A3, A4, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, C0, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, E3, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove setup.exe - Powered by Reason Core Security