dlm309b.exe

OpenCandy Inc.

The application dlm309b.exe by OpenCandy has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
OpenCandy Inc.  (signed and verified)

MD5:
99c3af5df5b111600d42c55542f7a615

SHA-1:
4303584b5d0b7e5ca949798bb88094acd6a63659

SHA-256:
6b6580d4fc97c7865327ed3f1809f3f9817928a1b9f55e59428bc55cba5bc529

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
12/24/2024 2:12:11 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OpenCandy (M)
17.2.3.22

File size:
299.2 KB (306,392 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\opencandy\7a870bbbe5d447879c391e48a4c7630c\dlm309b.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/28/2014 3:00:00 AM

Valid to:
6/29/2015 2:59:59 AM

Subject:
CN=OpenCandy Inc., O=OpenCandy Inc., L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
79D7802797DB6E08C313832B63BDA95F

File PE Metadata
Compilation timestamp:
8/27/2014 2:31:53 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xBADE0

Entry point:
00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 57, 57, 55, 04, 45, 45, 42, 1D, 83, 83, 80, 87, 9C, 9C, 99, A4, 84, 83, 81, 93, 79, 78, 76, 81, 69, 68, 65, 6F, 62, 62, 5F, 5C, 51, 50, 4D, 49, 4C, 4B, 48, 39, 49, 48, 45, 29, 42, 41, 3E, 1C, 49, 48, 44, 16, 49, 48, 44, 11, 54, 53, 4F, 0C, 4F, 4D, 49, 09, 57, 56, 52, 07, 54, 52, 4E, 05, 50, 4E, 4A, 04, 4E, 4C, 48, 02, 46, 45, 41, 02, 3C, 3B, 36, 01, 34, 33, 2E, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6878

Code size:
248 KB (253,952 bytes)

Remove dlm309b.exe - Powered by Reason Core Security