dexclock_12_r32.exe

Dexclock 1.2 Setup

Dexpot GbR

The application dexclock_12_r32.exe, “Installer for Dexclock 1.2” by Dexpot GbR has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from dl.cdn.chip.de and multiple other hosts.
Publisher:
Dexpot GbR  (signed and verified)

Product:
Dexclock 1.2 Setup

Description:
Installer for Dexclock 1.2

Version:
1.2.0

MD5:
017753d57f91890c81d039b57ac9b4db

SHA-1:
c9a5c6b2f570d050f0c35fa4348943801c4aecc1

SHA-256:
2081c0b56343e807435ef17208fc1f54b73910e1c2ccdda332abebd4f264a3d4

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/25/2024 4:06:17 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
7.9142

Fortinet FortiGate
Riskware/OpenCandy
12/26/2013

Malwarebytes
PUP.Optional.OpenCandy
v2013.12.26.03

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
23.00.65.131224

File size:
5.3 MB (5,512,800 bytes)

Copyright:
© 2010-2013 Dexpot GbR

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\dexclock_12_r32.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/5/2013 2:00:00 AM

Valid to:
7/5/2016 1:59:59 AM

Subject:
CN=Dexpot GbR, O=Dexpot GbR, STREET=Bergerfurth 38, L=Wesel, S=NRW, PostalCode=46487, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009101BB3EB4B14E4D5C02CB74F564B839

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:vqc4yd5fxuAIYlpNLibogAxVJHpiiiY/izZc5p2W7P1LmVQtfMpnC4SYy8q7VX:vqc9d5fgAVpBibotsiXato8WRmVQOC4I

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Code size:
23 KB (23,552 bytes)

The file dexclock_12_r32.exe has been seen being distributed by the following 2 URLs.

Remove dexclock_12_r32.exe - Powered by Reason Core Security