flashplayer_v.73196827c.exe

Awimba LLC

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application flashplayer_v.73196827c.exe by Awimba has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. The installer is marketed through download protals and search ads as the free Adobe Flash Player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Awimba LLC  (signed and verified)

MD5:
df5d68bf1f9dc530e8113b26722841c4

SHA-1:
26f29baf0742e84b0cdabed86e4b66a201d8b60e

SHA-256:
ff015af9e0574899e8cd0828a4bac9cf0887db8703218bb5c68b55289a77fd2f

Scanner detections:
21 / 68

Status:
Adware

Explanation:
Uses the InstallIQ download installer to bundle various adware offers.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/25/2024 3:22:30 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.121.36

avast!
Win32:DomaIQ-AI [PUP]
2014.9-140204

AVG
MalSign.Skodna
2015.0.3574

Comodo Security
UnclassifiedMalware
17478

Dr.Web
Adware.W3i.29
9.0.1.035

ESET NOD32
Win32/DomaIQ
8.9190

Fortinet FortiGate
W32/DomaIQ.C
2/4/2014

F-Prot
W32/DomaIQ.A
v6.4.7.1.166

G Data
NSIS.Application.DomaIQ
14.2.22

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

K7 AntiVirus
Trojan
13.174.10588

Malwarebytes
Adware.DomaIQ
v2014.02.04.07

McAfee
Artemis!DF5D68BF1F9D
5600.7230

NANO AntiVirus
Trojan.Win32.W3i.cjeffs
0.28.0.57029

Norman
Obfuscated.gen!r
11.20140204

Reason Heuristics
PUP.Awimba.W
14.8.7.18

Rising Antivirus
PE:Trojan.Win32.Generic.1582BDDE!360889822
23.00.65.14202

Sophos
DomainIQ pay-per install
4.96

Trend Micro House Call
TROJ_GEN.R0CBC0PIP13
7.2.35

Trend Micro
TROJ_GEN.R0CBC0PIP13
10.465.04

VIPRE Antivirus
DomaIQ
24590

File size:
832.1 KB (852,048 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\flashplayer_v.73196827c.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
12/18/2012 5:12:06 PM

Valid to:
12/18/2013 5:12:06 PM

Subject:
CN=Awimba LLC, O=Awimba LLC, L=wilmington, S=DE, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
0423F035F20DC9

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:DF8DGD/L5fUJ/nn3bOKSk+gU/FO1GxISS5cWltdzuRh:p3RUNuzgU01SqXfzuRh

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file flashplayer_v.73196827c.exe has been seen being distributed by the following 50 URLs.

http://yads.zedo.com/ads2/c?a=1513424;x=2317;g=55;c=1856000418,1856000418;i=0;n=1856;s=135;1=8;2=3;tg=1365858007;vr=3;m=18;w=18;p=6;h=1714596;f=1750880;b=10;u=cZWSjwoAADYAAHyvMmkAAABD~013013;z=0.37819108808650714;ainfo=;k=http://xads.zedo.com/ads2/c?a=1530327;x=2304;g=55;c=2019000150,2019000150;i=1;n=2019;tg=1365856016;v=1000002;i=1;u=cZWSjwoAADYAAHyvMmkAAABD~013013;1=8;2=3;e=i;s=122;g=55;w=18;m=18;q=0;z=0.5742394004482776;k=http://tc.nicdls.com/tracking/a/.../ClickID=%z&PubID=40

http://yads.zedo.com/ads2/c?a=1492309;x=2317;g=49;c=1856000355,1856000355;i=1;n=1856;s=123;1=8;2=4;tg=1365895393;vr=3;m=10;w=48;p=6;h=1714596;f=1722550;b=10;u=Cdgdrg3rSKGO0MwrDgpkEQ**~041313;z=0.5126538841970216;ainfo=;k=http://tc.nicdls.com/tracking/a/.../ClickID=%z&PubID=11

http://yads.zedo.com/ads2/c?a=1513424;x=2317;g=55;c=1856000407,1856000407;i=0;n=1856;s=135;1=8;2=3;tg=1365973120;vr=3;m=9;w=4;p=6;h=1714596;f=1750880;b=10;u=8TAPpwoBAIoAABiEJqoAAABT~040413;z=0.5033028308169373;ainfo=;k=http://xads.zedo.com/ads2/c?a=1517613;x=2304;g=55;c=2019000232,2019000232;i=0;n=2019;tg=1365971784;v=1000002;i=0;u=8TAPpwoBAIoAABiEJqoAAABT~040413;1=8;2=3;e=i;s=192;g=55;w=4;m=9;q=0;z=0.27490437938831747;k=[INSERT_CLICK_TRACKER_MACRO]http://tc.nicdls.com/tracking/a/.../ClickID=%z&PubID=40

http://yads.zedo.com/ads2/c?a=1488443;x=2317;g=41;c=1856000382,1856000382;i=0;n=1856;s=129;1=8;2=2;tg=1365957490;vr=2;m=1;w=7;p=6;h=1714596;f=1719164;b=10;u=h6uwhAoBAIoAAGnEZLoAAABG~041313;z=0.9409476738475209;ainfo=;k=http://tc.nicdls.com/tracking/a/.../ClickID=%z&PubID=1

http://dls.nicdls.com/p/151/FlashPlayer/321/.../V.68410681c

http://yads.zedo.com/ads2/c?a=1513438;x=2317;g=171;c=1856000406,1856000406;i=0;n=1856;s=135;1=8;2=1;tg=1365873111;vr=3;m=425;w=1;p=6;h=1714596;f=1750886;b=10;u=59iXT89a2LnTTrFAM11UfgdR~042512;z=0.6699929642720217;ainfo=;k=http://xads.zedo.com/ads2/c?a=1517603;x=2304;g=171;c=2019000080,2019000080;i=0;n=2019;tg=1365871354;v=1000002;i=0;u=59iXT89a2LnTTrFAM11UfgdR~042512;1=8;2=1;e=i;s=61;g=171;w=1;m=425;q=0;z=0.616656088270247;k=http://tc.nicdls.com/tracking/a/.../ClickID=%z&PubID=40

Latest 30 of 55 download URLs

Remove flashplayer_v.73196827c.exe - Powered by Reason Core Security