spotflux-3.0.0-118.exe

Spotflux, Inc

The application spotflux-3.0.0-118.exe by Spotflux, Inc has been detected as a potentially unwanted program by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from launch.spotflux.com and multiple other hosts.
Publisher:
Spotflux, Inc  (signed and verified)

MD5:
b7c365b926aaa0f4a75fc81c44870abf

SHA-1:
46aa9984dc3eb2f687d4f7a1e9f2ae999e3d24a7

SHA-256:
98d188a257e9ec93c4416ee70aa622918647ecc0610185afe8825af6d9b51055

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/24/2024 6:17:47 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.OpenCandy.4
9.0.1.0193

ESET NOD32
8.10086

Fortinet FortiGate
Riskware/OpenCandy
7/12/2014

G Data
Win32.Adware.Adpeak
14.7.24

Malwarebytes
PUP.Optional.OpenCandy.A
v2014.07.12.03

McAfee
Artemis!B7C365B926AA
5600.7071

NANO AntiVirus
Riskware.Win32.OpenCandy.cxjcyz
0.28.0.60698

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
23.00.65.14710

Trend Micro House Call
Suspicious_GEN.F47V0710
7.2.193

VIPRE Antivirus
Opencandy
31206

File size:
7.6 MB (7,983,632 bytes)

File type:
Executable application (Win64 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\spotflux-3.0.0-118.exe

Digital Signature
Signed by:

Subject:
CN="Spotflux, Inc", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Spotflux, Inc", L=New York, S=New York, C=US

Serial number:
787B156DBE2C603B1C32E7122CF5A030

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
196608:WxpksMaGNP2tN1zStlaeg8bjk7W6wvwc0CZ4lcU:ouHP2tLzorggxwcr4lc

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9966

Packer / compiler:
Nullsoft install system v2.x

The file spotflux-3.0.0-118.exe has been seen being distributed by the following 5 URLs.

http://launch.spotflux.com/.../win

Remove spotflux-3.0.0-118.exe - Powered by Reason Core Security