nexonlaunchersetup.exe

Nexon America

The application nexonlaunchersetup.exe by Nexon America has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from download2.nexon.net.
Publisher:
Nexon America  (signed and verified)

MD5:
634c633dac5698f7b513df73e8f5ba06

SHA-1:
6f9484b7646473317e0118b189356b3e37f24787

SHA-256:
306208dacfd312fbdfdf94420a7cc4ed8f5b80b4264945785d31971c43d68c39

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
5/2/2024 3:57:22 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OpenCandy
17.2.20.17

File size:
10.5 MB (11,014,960 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\nexonlaunchersetup.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
5/27/2015 3:00:00 AM

Valid to:
7/26/2018 2:59:59 AM

Subject:
CN=Nexon America, O=Nexon America, L=El Segundo, S=California, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
04EAD2DBE06A257FF5202EA26AE5C868

File PE Metadata
Compilation timestamp:
4/3/2016 11:19:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x32A0

Entry point:
81, EC, D4, 02, 00, 00, 53, 56, 57, 6A, 20, 5F, 33, DB, 68, 01, 80, 00, 00, 89, 5C, 24, 14, C7, 44, 24, 10, E0, A2, 40, 00, 89, 5C, 24, 1C, FF, 15, B0, 80, 40, 00, FF, 15, AC, 80, 40, 00, 66, 3D, 06, 00, 74, 11, 53, E8, 4F, 31, 00, 00, 3B, C3, 74, 07, 68, 00, 0C, 00, 00, FF, D0, BE, B8, 82, 40, 00, 56, E8, C9, 30, 00, 00, 56, FF, 15, 5C, 81, 40, 00, 8D, 74, 06, 01, 80, 3E, 00, 75, EA, 55, 6A, 09, E8, 21, 31, 00, 00, 6A, 07, E8, 1A, 31, 00, 00, A3, E4, 4E, 43, 00, FF, 15, 3C, 80, 40, 00, 53, FF, 15, A4, 82...
 
[+]

Code size:
25 KB (25,600 bytes)

The file nexonlaunchersetup.exe has been seen being distributed by the following URL.

http://download2.nexon.net/Game/.../NexonLauncherSetup.exe

Remove nexonlaunchersetup.exe - Powered by Reason Core Security