OpenUrl.dll

Openurl

Zhenjiang ChangYou Network Technology Co., Ltd.

The library OpenUrl.dll has been detected as malware by 5 anti-virus scanners.
Publisher:
Microsoft  (signed by Zhenjiang ChangYou Network Technology Co., Ltd.)

Product:
Openurl

Version:
1.00

MD5:
5bac056aafba9fdf307a4f1ca1365c59

SHA-1:
41f1f1c1efbcd145e54436153a4b1fa8bf35981e

SHA-256:
aae3e5de6a7d1450193f9e56a031d031e65bc8c57bcdbb6f7bb9933f3dce7f93

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
4/19/2024 1:35:28 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.Gen
7.11.198.114

AVG
Generic
2016.0.3179

IKARUS anti.virus
Trojan.Dropper
t3scan.1.8.5.0

McAfee
Artemis!5BAC056AAFBA
5600.6835

Trend Micro House Call
Suspicious_GEN.F47V1202
7.2.64

File size:
34.4 KB (35,192 bytes)

Product version:
1.00

Original file name:
OpenUrl.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\temp\openurl.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/7/2014 8:00:00 AM

Valid to:
3/8/2015 7:59:59 AM

Subject:
CN="Zhenjiang ChangYou Network Technology Co., Ltd.", OU=技术部, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Zhenjiang ChangYou Network Technology Co., Ltd.", L=Zhenjiang, S=Jiangsu, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5E647F3525E873BEEE27CE28AD420537

File PE Metadata
Compilation timestamp:
3/28/2014 1:04:02 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
384:6PGTcH68gI4n48TNsF7DAQ+SWSo2VnYPLDmreMKv:dcHBrM4qNsFnAGooXav

Entry address:
0x2A20

Entry point:
55, 8B, EC, 83, EC, 08, 68, 76, 11, 00, 11, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 81, EC, B0, 00, 00, 00, 53, 56, 57, 89, 65, F8, C7, 45, FC, 38, 11, 00, 11, B9, 13, 00, 00, 00, 33, C0, 8D, 7D, 80, 33, D2, F3, AB, 89, 85, 70, FF, FF, FF, 89, 55, E8, 89, 85, 74, FF, FF, FF, 89, 55, D8, 89, 85, 78, FF, FF, FF, 89, 55, D0, 89, 85, 7C, FF, FF, FF, 8B, 45, 0C, 2B, C2, 89, 55, CC, 89, 95, 6C, FF, FF, FF, 89, 95, 68, FF, FF, FF, 89, 95, 64, FF, FF, FF, 89, 95, 60, FF, FF, FF, 89, 95, 5C, FF, FF...
 
[+]

Entropy:
4.5830

Developed / compiled with:
Microsoft Visual C++

Code size:
12 KB (12,288 bytes)

Remove OpenUrl.dll - Powered by Reason Core Security