tuto_openoffice_01.exe

PCTuto

Tuto4PC.com

This is the Eorezo installer which may include software offers for unwanted programs including toolbars. The application tuto_openoffice_01.exe, “PCTuto Setup ” by Tuto4PC.com has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Eorezo Downloader installer. With this installer, users are expecting to download the free Apache OpenOffice but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Agence-Exclusive   (signed by Tuto4PC.com)

Product:
PCTuto

Description:
PCTuto Setup

MD5:
f2b81d3d3fd22ad7f5ff48cab7a6a017

SHA-1:
6c54c7b4e99540d8dcb88976d0bef559c11e964c

SHA-256:
b9c9ace3d38ee775628bc604bc5816b53ea7ba2e0bec4c42223efe1bd1dc7ed1

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 10:25:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Eorezo.Tuto4PC.Bundler (M)
16.2.14.13

File size:
724.1 KB (741,496 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Eorezo Downloader (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\tuto_openoffice_01.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
10/27/2011 5:26:43 PM

Valid to:
10/27/2013 4:26:43 PM

Subject:
CN=Tuto4PC.com, O=Tuto4PC.com, L=Paris, S=Ile-de-france, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11217A044D9875AB5200314888C39C5486EF

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:Pna9tZ1NWzsIpudPKZEywlcyglMgPE49Wtz64L84GF4O2DnM2xk/O2+:PnaD3Ny1odPK2/l6ll84aewGQJxkT+

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file tuto_openoffice_01.exe has been seen being distributed by the following URL.

Remove tuto_openoffice_01.exe - Powered by Reason Core Security