gothic.exe

The Scone Company, LLC

The application gothic.exe by The Scone Company has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from californiafonts.com.
Publisher:
The Scone Company, LLC  (signed and verified)

MD5:
2c5a7daf88e1ed852c578e8f91690bd6

SHA-1:
a67e74a18ccdf3a32c4c3f199ad57a9df1552c66

SHA-256:
11bdecfd66510c038aa21eb3411851ae608c76a292d707f65ece13cae850479b

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/26/2024 2:22:42 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
8.9895

Malwarebytes
PUP.Optional.OpenCandy
v2014.06.09.05

Trend Micro House Call
HV_ZYX_CI1948A5.RDXN
7.2.160

File size:
3.8 MB (3,995,032 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\gothic.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
3/22/2011 12:00:00 AM

Valid to:
3/21/2012 11:59:59 PM

Subject:
CN="The Scone Company, LLC", O="The Scone Company, LLC", STREET=12902 Dorathea Terrace, L=Poway, S=CA, PostalCode=92064, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
0381CFF79BD7453D57D75E665554AC94

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:Q0RBYA2qVn7wlaXuXRLE54xLHZ7MxYUMkupFdr1S0bndPFyqk6w:9BYxY7SaWq4VwYUMtpLr1SInlFyaw

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9810

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file gothic.exe has been seen being distributed by the following URL.

Remove gothic.exe - Powered by Reason Core Security