crystaldiskmark3_0_4-en.exe

CrystalDiskMark 3.0.4

Noriyuki MIYAZAKI

The application crystaldiskmark3_0_4-en.exe, “CrystalDiskMark Setup ” by Noriyuki MIYAZAKI has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from osdn.jp and multiple other hosts.
Publisher:
Crystal Dew World   (signed by Noriyuki MIYAZAKI)

Product:
CrystalDiskMark 3.0.4

Description:
CrystalDiskMark Setup

Version:
3.0.4

MD5:
86cf66164c3c3be94aec88549d2cf613

SHA-1:
21900d4f8a030187ca8171ef0900ff1aa2fc5955

SHA-256:
9cc5e7e0c94219ab23c989425d0acd6fbd8789cf4e91348061e93249719bf004

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
12/25/2024 12:14:11 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
OpenCandy
2016.0.3137

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
Win32/OpenCandy potentially unsafe application
7.0.302.0

Fortinet FortiGate
Adware/OpenCandy
4/16/2015

F-Prot
W32/OpenCandy.B
v6.4.7.1.166

G Data
Win32.Application.Agent.LX6E89
15.4.25

IKARUS anti.virus
not-a-virus:AdWare.OpenCandy
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.202.15623

McAfee
Trojan.Artemis!86CF66164C3C
16.8.708.2

Sophos
PUA 'OpenCandy'
5.12

Trend Micro House Call
Suspicious_GEN.F47V0401
7.2.106

File size:
1.6 MB (1,658,864 bytes)

Product version:
3.0.4

Copyright:
Crystal Dew World

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\crystaldiskmark3_0_4-en.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/5/2013 8:53:40 AM

Valid to:
2/6/2016 8:53:40 AM

Subject:
CN=Noriyuki MIYAZAKI, C=JP

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121D6683A851E981F3776DC28605DC830EF

File PE Metadata
Compilation timestamp:
10/13/2013 4:19:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:UxGYqyinKvzIk3BMelKdMuqajaXP7Ovl6H2CesGpROpy3zdDKcLpIJkXta+M9cCq:ZQrMdTXOTOvlBJRIyRDKS3Xta+Cwj4e

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9443

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file crystaldiskmark3_0_4-en.exe has been seen being distributed by the following 3 URLs.

Remove crystaldiskmark3_0_4-en.exe - Powered by Reason Core Security