Trojan

TrojanDownloader:Win32/Tugspay.A malicious file

Malware Removal

The TrojanDownloader:Win32/Tugspay.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Tugspay.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Tugspay.A?


File Info:

name: AC5EF762F0A7B14C41F1.mlw
path: /opt/CAPEv2/storage/binaries/7e9ccc68449783314ac4899f92a359a4842f9dfbde212e2c22924187db61eb19
crc32: 67F3DCAE
md5: ac5ef762f0a7b14c41f14e74533786b0
sha1: 75317957f03354471f374bf8b3226e4b8d79d304
sha256: 7e9ccc68449783314ac4899f92a359a4842f9dfbde212e2c22924187db61eb19
sha512: 32331bfc72b01449456f05b0c0b6267b619fcd2aa546efbf920c0aeb9eae8b89ba8fb912fdf5d085d62f3f941d59d2768f3fe63a6ee842bb4ee186af809f7ad1
ssdeep: 12288:zSP2Vu2On5XQlE983JNsUDvlkd73hS3n8H5PGFAyG/Q7wvq:u/2On5XakphS305P4An/9y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T158056B1977AFDD56D82E1AB7C861C56412B6F9078F82E77B7DC92BCE0C713894602283
sha3_384: 0cf7db26cedbbdf9e75aa6bb71653c1c95deeffa66aa0f74b2e3b932b5050529953a49e28b8b27efded376b69566fcf8
ep_bytes: e82f340000e939feffff558bec837d08
timestamp: 2014-05-22 08:14:35

Version Info:

0: [No Data]

TrojanDownloader:Win32/Tugspay.A also known as:

BkavW32.AIDetectMalware
LionicAdware.MSIL.DomaIQ.lY9v
MicroWorld-eScanTrojan.GenericKDZ.94149
FireEyeGeneric.mg.ac5ef762f0a7b14c
CAT-QuickHealAdware.DomaIQ.BT5
SkyhighBehavesLike.Win32.Generic.bh
ALYacTrojan.GenericKDZ.94149
Cylanceunsafe
ZillyaAdware.DomaIQ.Win32.300
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaAdWare:Win32/DomaIQ.aba44aa6
K7GWRiskware ( 0040eff71 )
VirITTrojan.Win32.Packed.BNRN
SymantecPUA.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/DomaIQ.BB potentially unwanted
APEXMalicious
ClamAVWin.Adware.Domaiq-1
Kasperskynot-a-virus:AdWare.MSIL.DomaIQ.ccbi
BitDefenderTrojan.GenericKDZ.94149
NANO-AntivirusRiskware.Win32.Lollipop.dvstgo
SUPERAntiSpywarePUP.DomaIQ/Variant
AvastWin32:DomaIQ-CC [PUP]
TencentMalware.Win32.Gencirc.10be3e83
SophosDomaIQ pay-per install (PUA)
F-SecurePotentialRisk.PUA/DomaIQ.Gen
DrWebTrojan.Packed.26819
VIPRETrojan.GenericKDZ.94149
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.94149 (B)
IkarusAdWare.DomaIQ
GDataWin32.Trojan.PSE.141FS7S
JiangminAdWare/MSIL.rs
GoogleDetected
AviraPUA/DomaIQ.Gen
VaristW32/A-9e1fd62c!Eldorado
Antiy-AVLGrayWare/Win32.DomaIQ.bb
KingsoftMSIL.AdWare.DomaIQ.heur
XcitiumApplication.Win32.DomaIQ.EAH@5hwroa
ArcabitTrojan.Generic.D16FC5
ZoneAlarmnot-a-virus:AdWare.MSIL.DomaIQ.ccbi
MicrosoftTrojanDownloader:Win32/Tugspay.A
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DomaIQ.R108419
Acronissuspicious
McAfeeCryptDomaIQ
MAXmalware (ai score=100)
VBA32BScope.Adware.MSIL.DomaIQ
MalwarebytesPUP.Optional.DomaIQ.DDS
PandaTrj/Genetic.gen
RisingDownloader.Tugspay!1.A14B (CLASSIC)
YandexPUA.DomaIQ!88I1iFGeB+0
SentinelOneStatic AI – Malicious PE
MaxSecureDownloader.Agent.bwcr
FortinetRiskware/DomaIQ.BB
AVGWin32:DomaIQ-CC [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove TrojanDownloader:Win32/Tugspay.A?

TrojanDownloader:Win32/Tugspay.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment