setup_v.c3unosrac.exe

Tuguu S.L.

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application setup_v.c3unosrac.exe by Tuguu S.L has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the TUGUU DomaIQ Setup installer.
Publisher:
Tuguu S.L.  (signed and verified)

MD5:
223cf0a9dfe644cb7bea7832fb31e8ad

SHA-1:
4835ec3595a33a78ea7e91f24c86ff79fd64a4bb

SHA-256:
e55f097f0e075b83f783586b1d5f04516f4614e2b422a22dd8d6fda24dcfa656

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles third-party components such as adware in the installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/26/2024 12:43:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.TuguuSL.Q
14.8.7.18

File size:
400.1 KB (409,728 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\setup_v.c3unosrac.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
5/13/2013 7:00:00 PM

Valid to:
7/18/2014 7:00:00 AM

Subject:
CN=Tuguu S.L., OU=U B76539535, O=Tuguu S.L., L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
08EC69B75B2FE31EC2C53E0E441AC0E1

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:XseuAP1bDEHR87DH56GT1gwzF/7zabNsnz0FGgesCkltgIgLnldT6ogX47A:luAP18HR8PZfBgAFWUz0FUklKdTc47A

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9326

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file setup_v.c3unosrac.exe has been seen being distributed by the following 12 URLs.

http://ttb.updatevideos.com/download/request/.../fp6iWTNV?ClickID=AAAAAMKlQQC3MkIBAAAAAG-XUgAAAAAAAgAAAAAAAAAAAP8AAAADEAcHagAAAAAAlsxpAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAApwhcAAAAAAAIBAgAAgD8AuxIwET8BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=&PubID=0

http://ttb.updatevideos.com/download/request/.../fp6iWTNV?ClickID=dK4SAOO3QgC3MkIBAAAAAG-XUgAAAAAAAgAEAAAAAAAAAP8AAAADDwcHagAAAAAAlsxpAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF7BcAAAAAAAIBAgAAgD8A7RSCED8BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=&PubID=1224308

http://ttb.updatevideos.com/download/request/.../fp6iWTNV?ClickID=DESwCeO3QgC7MkIBAAAAAG-XUgAAAAAAAgAQAAAAAAAAAP8AAAADEgcHagAAAAAAlsxpAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF7BcAAAAAAAICAgAAgD8Ac.VEET8BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=&PubID=162546700

http://ttb.updatevideos.com/download/request/.../fp6iWTNV?ClickID=bSClCeO3QgC5MkIBAAAAAG-XUgAAAAAAAgAAAAAAAAAAAP8AAAADFwcHagAAAAAAlsxpAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF7BcAAAAAAAICAgAAgD8Aw98rEj8BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=&PubID=161816685

http://ttb.updatevideos.com/download/request/.../fp6iWTNV?ClickID=oOkWAEHfPQC7MkIBAAAAAG-XUgAAAAAAAAAIAAAAAAAAAAoAAgADEAcHagAAAAAAlsxpAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYNBcAAAAAAAICAgAAgD8AHZE7ET8BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=&PubID=1501600

http://ttb.updatevideos.com/download/request/.../fp6iWTNV?ClickID=EUClC-O3QgC7MkIBAAAAAG-XUgAAAAAAAgAAAAAAAAAAAP8AAAADEQcHagAAAAAAlsxpAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF7BcAAAAAAAICAgAAgD8AnND.ED8BAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=&PubID=195379217

Remove setup_v.c3unosrac.exe - Powered by Reason Core Security