zipper_v.6132160.exe

TUGUU SL

The Tuguu download and install manager uses the DomalIQ installer to bundle additional adware offers such as toolbars and browser extensions during the setup process. This software distributes modified installers which are not the same as the original distributed by the author. The application zipper_v.6132160.exe by TUGUU SL has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
TUGUU SL  (signed and verified)

MD5:
8c24d76ca013875a1ae6af3f8a7caa89

SHA-1:
107569ae5c86e49b091bbdf3f89907fe55dba2dd

SHA-256:
e3032c23826f74a9cf6c3d40674bc7dba5e7ca721bf1b1034257f9f56e57db45

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Uses the InstallIQ download installer to bundle various adware offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
1/13/2025 2:36:17 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.122.154

avast!
NSIS:DomaIQ-B [PUP]
2014.9-140716

Baidu Antivirus
Adware.Win32.DomaIQ
4.0.3.14716

Comodo Security
UnclassifiedMalware
17513

Dr.Web
Adware.W3i.29
9.0.1.0197

ESET NOD32
Win32/DomaIQ
8.9190

Fortinet FortiGate
Adware/DomaIQ.DT
7/16/2014

G Data
NSIS.Application.DomaIQ
14.7.22

K7 AntiVirus
Unwanted-Program
13.174.10656

McAfee
Artemis!8C24D76CA013
5600.7067

Panda Antivirus
Adware/MultiToolbar
14.07.16.03

Reason Heuristics
PUP.TUGUUSL.P
14.8.7.18

Sophos
DomainIQ pay-per install
4.96

SUPERAntiSpyware
PUP.BundleInstaller
10480

Trend Micro House Call
TROJ_GEN.R03WH0AJU13
7.2.197

VIPRE Antivirus
DomaIQ
24842

File size:
230.2 KB (235,688 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\zipper_v.6132160.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
5/3/2012 5:02:02 PM

Valid to:
5/3/2013 5:02:02 PM

Subject:
CN=TUGUU SL, O=TUGUU SL, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
079402776DB199

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:Ss6FtDC8uZofbVKaEHnKUpMC+qcBDh6+P9E6u15E:UFJC8umfbzEHKUpDJcj9E60u

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file zipper_v.6132160.exe has been seen being distributed by the following URL.

Remove zipper_v.6132160.exe - Powered by Reason Core Security