doubletwistsetup.exe

doubleTwist Corporation

The application doubletwistsetup.exe by doubleTwist has been detected as a potentially unwanted program by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from www.techtudo.com.br and multiple other hosts.
Publisher:
doubleTwist Corporation  (signed and verified)

MD5:
b00e55596c022249488ffabf5911eece

SHA-1:
d6b33284491f3d08b1d4baeb13d20d6e23e2b4d4

SHA-256:
739cae5eb1b06edb07b5909540ff05b5fdefed7e81c9b6d9084e35b9f61f7757

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
11/14/2024 2:18:30 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OpenCandy
7.1.1

AVG
OpenCandy
2016.0.3212

Baidu Antivirus
Trojan.Win32.OpenCandy
4.0.3.15131

ESET NOD32
9.11088

Fortinet FortiGate
Adware/OpenCandy
1/31/2015

G Data
Win32.Adware.OpenCandy
15.1.25

K7 AntiVirus
Trojan
13.193.14789

Malwarebytes
PUP.Optional.OpenCandy
v2015.01.31.04

NANO AntiVirus
Riskware.Win32.OpenCandy.czxtqp
0.30.0.65070

Quick Heal
AdWare.OpenCandy.g5 (Not a Virus)
1.15.14.00

Reason Heuristics
PUP.Installer.doubleTwistCorporation
15.1.31.16

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
23.00.65.15129

Vba32 AntiVirus
AdWare.OpenCandy
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
37052

File size:
1.2 MB (1,307,056 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\programs\doubletwistsetup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
4/27/2012 1:00:00 AM

Valid to:
4/28/2013 12:59:59 AM

Subject:
CN=doubleTwist Corporation, O=doubleTwist Corporation, L=San Francisco, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
76841B75BB05730DAF509BC51CB852FC

File PE Metadata
Compilation timestamp:
7/6/2011 3:31:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:TmJk0O671jAxg6Kwl6lMqjcWKkQAlGVFyitu/fa6ClaKTPqlkUB1QEIM6:TEf8i6KwEMqjcWfsyou/y6CoKb/UBaEM

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.3374

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file doubletwistsetup.exe has been seen being distributed by the following 2 URLs.

Remove doubletwistsetup.exe - Powered by Reason Core Security