nana_open_office.exe

The application nana_open_office.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from software.nana10.co.il.
MD5:
f86ab03a7466ebe4c9255cdfc3a1b792

SHA-1:
90d45ab35988363f3567270211eb81ca6ab00b6b

SHA-256:
a346addc5d3561f37efcd578511ee246096a6137ff7cf6bb9f1f10e7fc45e638

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
5/10/2024 2:52:12 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Conduit
4.0.3.16731

Dr.Web
Adware.Conduit.3
9.0.1.0213

ESET NOD32
10.9704

K7 AntiVirus
Trojan
13.176.11833

Malwarebytes
PUP.Optional.Trovi
v2016.07.31.06

McAfee
Artemis!F86AB03A7466
5600.6321

Reason Heuristics
PUP.OpenCandy.Installer (L)
16.7.31.18

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
23.00.65.16729

VIPRE Antivirus
Conduit
28468

File size:
1.1 MB (1,104,964 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\nana_open_office.exe

File PE Metadata
Compilation timestamp:
2/24/2012 9:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:dGOj+BVz+UR3Y0sefZL1H46Wd7qmRjH5Tp4lJDENU:bWz+msebkpsJYU

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Entropy:
7.9539

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file nana_open_office.exe has been seen being distributed by the following URL.

Remove nana_open_office.exe - Powered by Reason Core Security