sword_2_20110301_fileplanet.exe

K2 Network, Inc

The application sword_2_20110301_fileplanet.exe by K2 Network, Inc has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
K2 Network, Inc  (signed and verified)

MD5:
ee420289bfdab1d3f8e7eefb381475ed

SHA-1:
fc6d54d49e9073ac4d9a4758988f691695608431

SHA-256:
9ee8d87b9aec0f916fbbacfb3c8c03d46c7f9ede2d586e1d381904689aed2e16

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/23/2024 7:53:23 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/OpenCandy potentially unsafe
9.11293

G Data
Win32.Adware.OpenCandy
15.12.25

Malwarebytes
PUP.Optional.OpenCandy
v2015.12.07.04

Reason Heuristics
PUP.OpenCandy.Installer (L)
15.12.7.4

Trend Micro House Call
HV_ZYX_.D9506787
7.2.341

File size:
21.2 MB (22,254,328 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\sword_2_20110301_fileplanet.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/15/2010 5:00:00 PM

Valid to:
3/16/2011 4:59:59 PM

Subject:
CN="K2 Network, Inc", OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Portal, O="K2 Network, Inc", L=Irvine, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
43C1E097CA2E6CE2190D2FA8A3814069

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:Ia8WcWg5+VdzjW6rsL7LRl/I31v5zCImnQej7ooeh5E+Y4UHyZVKO:zVcXGOoGL031v52IwQhh5QHoJ

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
8.0000

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove sword_2_20110301_fileplanet.exe - Powered by Reason Core Security