00000000

Tuguu S.L.

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The file 00000000 by Tuguu S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the TUGUU DomaIQ Setup installer.
Publisher:
Tuguu S.L.  (signed and verified)

MD5:
5363b8eabf2a1c68a22d84516fc0776c

SHA-1:
8835de6dcca4035cd3828538c987b3c91791ceaf

SHA-256:
6ae614c9be529345795c42e614990d632f847a09bdc68523461290b897a21bb7

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles third-party components such as adware in the installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 3:20:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Tuguu.Bundler (M)
16.2.25.5

File size:
283.5 KB (290,328 bytes)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\appdata\local\google\chrome\user data\default\file system\001\t\00\00000000

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
6/18/2014 2:52:55 PM

Valid to:
6/18/2015 2:52:55 PM

Subject:
CN=Tuguu S.L., O=Tuguu S.L., L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4AFA4A3660EFF4

File PE Metadata
Compilation timestamp:
6/17/2014 11:17:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:OwR5za+HqlckLlSNb8uBaKxW6cG+GF6nTgsY1:VR5zaoMckLMNGKxW6L+GFwTgd

Entry address:
0x609F

Entry point:
B8, 6C, EE, 4C, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 65, 73, 6F, 6E, 6F, 73, 65, 6C, 6F, 63, 00, C2, 57, 8B, F3, 00, DE, 5C, 15, 60, 5E, 16, BC, C1, D7, 51, 99, 02, DC, C9, FD, 80, B5, BB, A0, 31, 5E, 9C, B6, 03, 10, C2, A4, 38, D3, 1A, E9, 04, 36, 7D, 4F, A9, 99, B3, 7C, 7B, 2D, 2C, 1C, 69, 40, C9, AE, A7, 85, FD, 1A, FB, 0F, A2, E8, 59, 7E, C5, 23, 49, EB, 74, 3B, A3, C5, 20, 2C, E0, CD, 4C, E7, 5B, 7F, AD, A3, 13, B3, BB, FF, 3E, 54, CD, E5, AD, 20, 38, B8, 72...
 
[+]

Entropy:
7.7999  (probably packed)

Code size:
111 KB (113,664 bytes)

Remove 00000000 - Powered by Reason Core Security