download video player.exe

Tuguu Israel Ltd

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application download video player.exe by Tuguu Israel has been detected as adware by 30 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
Tuguu Israel Ltd  (signed and verified)

MD5:
3f5a36bffc5d857b6d548c9ed4d6bbb3

SHA-1:
f54fd0d5571b084263ecb4d553d4c122973439db

SHA-256:
080d3c11e104e9765d95699a8bf361f5a5c1d9ac4cf36f0c51c03da17c9693a8

Scanner detections:
30 / 68

Status:
Adware

Explanation:
The software bundles potentially unwanted offers during setup including toolbars and adware.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/25/2024 9:54:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11001474
909

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.08.10

Avira AntiVirus
APPL/DomaIQ.AV
7.11.125.192

avast!
Win32:PUP-gen [PUP]
2014.9-140809

AVG
Skodna.Generic_r
2015.0.3387

Bitdefender
Trojan.Generic.11001474
1.0.20.1105

Clam AntiVirus
Win.Adware.Domaiq-18
0.98/19265

Comodo Security
Application.Win32.DomaIQ.D
17640

Dr.Web
Trojan.PayInt.27
9.0.1.0221

Emsisoft Anti-Malware
Trojan.Generic.11001474
8.14.08.09.09

ESET NOD32
Win32/DomaIQ.AV (variant)
8.9310

F-Prot
W32/Backdoor2.HTIW
v6.4.7.1.166

G Data
Trojan.Generic.11001474
14.8.24

herdProtect (fuzzy)
2014.10.11.8

IKARUS anti.virus
PUA.Tuguu
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.183.12998

Kaspersky
not-a-virus:AdWare.Win32.DomaIQ
14.0.0.3431

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.08.09.09

McAfee
RDN/Generic.bfr!fq
5600.7043

MicroWorld eScan
Trojan.Generic.11001474
15.0.0.663

NANO AntiVirus
Riskware.Win32.DomaIQ.csmcgi
0.28.0.57029

nProtect
Trojan.Generic.11001474
14.08.08.01

Panda Antivirus
PUP/MultiToolbar.A
14.08.09.09

Quick Heal
Adware.Domal.A5
8.14.14.00

Reason Heuristics
PUP.TuguuIsrael.V
14.8.9.21

Rising Antivirus
PE:PUF.DomaIQ!1.9DE0
23.00.65.141009

Sophos
DomainIQ pay-per install
4.96

Vba32 AntiVirus
BScope.Downware.DomaIQ
3.12.24.3

VIPRE Antivirus
Win32.Malware!Drop
25584

File size:
449.1 KB (459,880 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\download video player.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
6/11/2013 5:00:00 PM

Valid to:
8/20/2014 5:00:00 AM

Subject:
CN=Tuguu Israel Ltd, O=Tuguu Israel Ltd, L=RAMAT GAN, C=IL

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
06FD356584CBF71B04A7AFE790A2329F

File PE Metadata
Compilation timestamp:
1/9/2014 8:46:35 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:+OeTIfnjAEkxJPNeaL9uRqQb3fgnFwFGLgJ2k0SyCKF1pYax6uYj+LkYU:dAEOJPNeapQrgjLgJoSyCuDYax6hjn

Entry address:
0xCCE2

Entry point:
E8, 94, 5E, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 88, 22, 42, 00, E8, C4, 04, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 58, 88, 42, 00, 77, 22, 6A, 04, E8, 7F, 60, 00, 00, 59, 83, 65, FC, 00, 56, E8, 86, 68, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, D0, 04, 00, 00, C3, 6A, 04, E8, 7A, 5F, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, FE, E0, 0F, 87, A1, 00, 00, 00, 53, 57, 8B, 3D, 70, D0, 41, 00, 83, 3D, 1C, 85, 42, 00, 00, 75, 18, E8, 3A, 57, 00...
 
[+]

Entropy:
7.3919

Code size:
110.5 KB (113,152 bytes)

The file download video player.exe has been seen being distributed by the following 2 URLs.

Remove download video player.exe - Powered by Reason Core Security