player.exe

Clovermedia SLU

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application player.exe by Clovermedia SLU has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from www.lpcloudbox0120.com.
Publisher:
Clovermedia SLU  (signed and verified)

MD5:
641fd40ab50e3ddec3eabb5a1af45db7

SHA-1:
316baf1c0f6cacaa96effe765f55db8674a5650a

SHA-256:
e3e053cf17bf0af4b24400ba08ca711ad97f48ad2b1c88d2893d55b60541cc31

Scanner detections:
23 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/25/2024 3:46:46 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.DomaIQ.3
998

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
14.05.12

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.149.42

avast!
Win32:DomaIQ-BM [PUP]
2014.9-140512

AVG
DomaIQ.X
2015.0.3476

Bitdefender
Gen:Variant.Application.Bundler.DomaIQ.3
1.0.20.660

Comodo Security
Application.Win32.DomaIQ.PUP
18261

Dr.Web
Adware.Downware.2215
9.0.1.0132

ESET NOD32
Win32/DomaIQ.BB (variant)
8.9790

G Data
Gen:Variant.Application.Bundler.DomaIQ
14.5.24

IKARUS anti.virus
AdWare.DomaIQ
t3scan.1.6.1.0

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.3877

Malwarebytes
PUP.Optional.DomaIQ
v2014.05.12.04

McAfee
PUP-FJP!FFDE0F5AEFA1
5600.7132

MicroWorld eScan
Gen:Variant.Application.Bundler.DomaIQ.3
15.0.0.396

NANO AntiVirus
Riskware.Win32.Downware.cvxwqj
0.28.0.59826

nProtect
Trojan-Clicker/W32.Agent.398344
14.05.12.01

Quick Heal
AdWare.MSIL.r3 (Not a Virus)
5.14.14.00

Reason Heuristics
PUP.ClovermediaSLU.G
14.5.12.14

Rising Antivirus
PE:Malware.DomaIQ!6.1543
23.00.65.14510

VIPRE Antivirus
Trojan.Win32.Generic
29136

Zillya! Antivirus
Adware.DomaIQ.Win32.178
2.0.0.1785

File size:
389 KB (398,344 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\player.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/13/2014 4:00:00 PM

Valid to:
2/14/2015 3:59:59 PM

Subject:
CN=Clovermedia SLU, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Clovermedia SLU, L=Adeje, S=Santa Cruz de tenerife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0524A867F334951775CD16FBB2ED7E9B

File PE Metadata
Compilation timestamp:
3/4/2014 8:53:36 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:fSI5kqTzKcS2iJQoRPXHge7+zssn38HPhd5CnbjUW8pEjY52:3pTzxSFQoRPXgeCsYMf3WuEw2

Entry address:
0x30ED

Entry point:
E8, B2, 3B, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3...
 
[+]

Entropy:
6.2774

Code size:
55 KB (56,320 bytes)

The file player.exe has been seen being distributed by the following URL.

Remove player.exe - Powered by Reason Core Security