dlm309b.exe

OpenCandy Inc.

The application dlm309b.exe by OpenCandy has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
OpenCandy Inc.  (signed and verified)

MD5:
1c639422f6d333c8dd7af19b80fc94df

SHA-1:
87a89099cc31111df232aee18cd8d0903a3cc729

SHA-256:
d8d4b346e5cf3122c766a9cf8f29208469f396c1f9a8285e27487e1e9b450c51

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
12/24/2024 2:02:22 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OpenCandy (M)
17.2.3.22

File size:
299.2 KB (306,392 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\opencandy\e99afc4d3c4d45ff815443d76543e8a6\dlm309b.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/28/2014 3:00:00 AM

Valid to:
6/29/2015 2:59:59 AM

Subject:
CN=OpenCandy Inc., O=OpenCandy Inc., L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
79D7802797DB6E08C313832B63BDA95F

File PE Metadata
Compilation timestamp:
8/27/2014 2:31:53 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xBADE0

Entry point:
63, 41, 64, 64, 72, 65, 73, 73, 00, 00, 56, 69, 72, 74, 75, 61, 6C, 50, 72, 6F, 74, 65, 63, 74, 00, 00, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 00, 56, 69, 72, 74, 75, 61, 6C, 46, 72, 65, 65, 00, 00, 00, 45, 78, 69, 74, 50, 72, 6F, 63, 65, 73, 73, 00, 00, 00, 52, 65, 67, 45, 6E, 75, 6D, 4B, 65, 79, 57, 00, 00, 00, 47, 65, 74, 4F, 62, 6A, 65, 63, 74, 57, 00, 00, 43, 6F, 49, 6E, 69, 74, 69, 61, 6C, 69, 7A, 65, 00, 00, 45, 6E, 75, 6D, 50, 72, 6F, 63, 65, 73, 73, 65, 73, 00, 00, 00, 53, 68, 65, 6C...
 
[+]

Entropy:
7.7200  (probably packed)

Code size:
248 KB (253,952 bytes)

Remove dlm309b.exe - Powered by Reason Core Security