dlm309b.exe

OpenCandy Inc.

The application dlm309b.exe by OpenCandy has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
OpenCandy Inc.  (signed and verified)

MD5:
11868a19e2e375a7d41fd0a59a143945

SHA-1:
bbecc610558965d4f4b937291b9d49b0aa4a41ad

SHA-256:
6886232e8237528479604ae767fe35e1e3ee194b914c74b6929d22387a41ddfc

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
12/24/2024 1:53:30 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OpenCandy (M)
17.2.3.22

File size:
299.2 KB (306,392 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\opencandy\72a2b1bd3c13427c92d4d804743b709d\dlm309b.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/28/2014 3:00:00 AM

Valid to:
6/29/2015 2:59:59 AM

Subject:
CN=OpenCandy Inc., O=OpenCandy Inc., L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
79D7802797DB6E08C313832B63BDA95F

File PE Metadata
Compilation timestamp:
8/27/2014 2:31:53 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xBADE0

Entry point:
C4, 95, 17, FE, C3, 94, 17, FE, C2, 94, 17, FE, C2, 94, 17, FE, C1, 94, 1A, FE, D1, B0, 58, FE, E1, D8, C5, FE, DA, D3, C9, FE, DA, D4, CB, FE, DA, D5, CC, FE, DB, D5, CD, FE, DB, D6, CD, FE, DC, D6, CE, FE, DC, D7, CE, FE, DD, D7, CF, FE, DD, D8, CF, FE, DE, D8, D0, FE, DE, D9, D1, FE, DF, DA, D1, FE, DF, DA, D2, FE, DF, DB, D3, FE, E0, DB, D3, FE, E1, DC, D4, FE, E2, DC, D5, FE, EA, E5, E0, FE, F6, F4, F1, FE, F2, EF, EC, FE, ED, E9, E5, FE, E8, E4, DE, FE, DF, DA, D3, FC, 8A, 87, 81, AA, 44, 43, 3E, 12...
 
[+]

Entropy:
7.7885  (probably packed)

Code size:
248 KB (253,952 bytes)

Remove dlm309b.exe - Powered by Reason Core Security