dlm309b.exe

OpenCandy Inc.

The application dlm309b.exe by OpenCandy has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
OpenCandy Inc.  (signed and verified)

MD5:
095864ee22c0fbe98c56befa949e172a

SHA-1:
da4e4f04023e8d2242b32c09188acfb68d8053d9

SHA-256:
1275c308a781a2e1b01381e5c972558e29db49dc2d5344ef759c842e7fb8ae3f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
12/24/2024 2:18:16 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OpenCandy (M)
17.2.3.22

File size:
299.2 KB (306,392 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\opencandy\67ba5fdcab9f47eb918e30f1c1d433b6\dlm309b.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/28/2014 3:00:00 AM

Valid to:
6/29/2015 2:59:59 AM

Subject:
CN=OpenCandy Inc., O=OpenCandy Inc., L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
79D7802797DB6E08C313832B63BDA95F

File PE Metadata
Compilation timestamp:
8/27/2014 2:31:53 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xBADE0

Entry point:
FF, 19, E2, 44, 07, 92, 0B, D7, 68, 84, 80, 5D, 6A, 78, 64, 45, CD, 60, 46, 7E, 54, C1, 13, 7C, C5, 79, F1, C9, C1, 71, 02, 03, 01, 00, 01, A3, 81, FA, 30, 81, F7, 30, 1D, 06, 03, 55, 1D, 0E, 04, 16, 04, 14, 5F, 9A, F5, 6E, 5C, CC, CC, 74, 9A, D4, DD, 7D, EF, 3F, DB, EC, 4C, 80, 2E, DD, 30, 32, 06, 08, 2B, 06, 01, 05, 05, 07, 01, 01, 04, 26, 30, 24, 30, 22, 06, 08, 2B, 06, 01, 05, 05, 07, 30, 01, 86, 16, 68, 74, 74, 70, 3A, 2F, 2F, 6F, 63, 73, 70, 2E, 74, 68, 61, 77, 74, 65, 2E, 63, 6F, 6D, 30, 12, 06, 03...
 
[+]

Entropy:
7.6105

Code size:
248 KB (253,952 bytes)

Remove dlm309b.exe - Powered by Reason Core Security