setup.exe

TUGUU SL

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application setup.exe by TUGUU SL has been detected as adware by 25 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. The file has been seen being downloaded from dlp.cloudsvr35.com and multiple other hosts.
Publisher:
TUGUU SL  (signed and verified)

MD5:
149c1cd491cffee08e5f0917ff2caca3

SHA-1:
391b4b5e04b6f1a4ac80ba86f74163f0ea874023

SHA-256:
4503e7c961f7e94da60c0d5b383bccb6afd718f591520dddcc0ee573f9ad9131

Scanner detections:
25 / 68

Status:
Adware

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/25/2024 8:47:27 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.DomaIQ.AN
1015

Agnitum Outpost
PUA.Lollipop
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
14.04.26

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.145.80

avast!
Win32:DomaIQ-T [PUP]
2014.9-140426

AVG
DomaIQ_r.J
2015.0.3493

Bitdefender
Adware.DomaIQ.AN
1.0.20.580

Comodo Security
Application.Win32.DomaIQ.PUR
18167

Dr.Web
Adware.Downware.2759
9.0.1.0116

Emsisoft Anti-Malware
Adware.DomaIQ.AN
8.14.04.26.03

ESET NOD32
Win32/DomaIQ.BB (variant)
8.9725

F-Secure
Adware.DomaIQ.AN
11.2014-26-04_7

G Data
Adware.DomaIQ.AN
14.4.24

IKARUS anti.virus
AdWare.DomaIQ
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.176.11888

Kaspersky
not-a-virus:AdWare.Win32.Lollipop
14.0.0.3959

Malwarebytes
PUP.Optional.DomalQ
v2014.04.26.03

McAfee
RDN/Generic PUP.x!c2r
5600.7149

MicroWorld eScan
Adware.DomaIQ.AN
15.0.0.348

nProtect
Adware.DomaIQ.AN
14.04.25.01

Panda Antivirus
PUP/MultiToolbar.A
14.04.26.03

Reason Heuristics
PUP.Installer.TUGUUSL.F
14.8.7.18

Sophos
DomainIQ pay-per install
4.98

Vba32 AntiVirus
Downware.DomaIQ
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28606

File size:
438.4 KB (448,952 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
5/4/2013 1:24:02 AM

Valid to:
5/4/2014 1:24:02 AM

Subject:
CN=TUGUU SL, O=TUGUU SL, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2776B257979F9A

File PE Metadata
Compilation timestamp:
4/16/2014 5:37:10 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:OXmiLuncbmmkHCUwDgt/ZSwLM2f3a6xAEg8ovT9ploCe1O6pRbYxvfTEYqx:WmiGmkHC3s3SwLMAvxAQwjJe7Srqx

Entry address:
0x271A

Entry point:
E8, 27, 2E, 00, 00, E9, 79, FE, FF, FF, 6A, 0C, 68, 20, FA, 41, 00, E8, 0C, 01, 00, 00, 8B, 75, 08, 85, F6, 74, 75, 83, 3D, D8, 57, 42, 00, 03, 75, 43, 6A, 04, E8, 29, 30, 00, 00, 59, 83, 65, FC, 00, 56, E8, 4C, 31, 00, 00, 59, 89, 45, E4, 85, C0, 74, 09, 56, 50, E8, 6D, 31, 00, 00, 59, 59, C7, 45, FC, FE, FF, FF, FF, E8, 0B, 00, 00, 00, 83, 7D, E4, 00, 75, 37, FF, 75, 08, EB, 0A, 6A, 04, E8, FD, 2E, 00, 00, 59, C3, 56, 6A, 00, FF, 35, 4C, 52, 42, 00, FF, 15, 64, C0, 41, 00, 85, C0, 75, 16, E8, E3, 0A, 00...
 
[+]

Entropy:
6.7360

Code size:
108 KB (110,592 bytes)

The file setup.exe has been seen being distributed by the following 2 URLs.

Remove setup.exe - Powered by Reason Core Security