the_elder_scrolls_v_skyrim_-_crack_.exe

OOO

The application the_elder_scrolls_v_skyrim_-_crack_.exe by OOO has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from downlite.net and multiple other hosts.
Publisher:
OOO   (signed and verified)

MD5:
5c62fc04727e16ecbdc8f8614f4fd0f8

SHA-1:
9e6f58bd53d910ba0cbb63b3d5205e8cc085d464

SHA-256:
37788863636bdec9c8cc69b63e5b853dc71ea134448d6470c676a0a5299e764b

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/26/2024 8:39:05 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:PUP-gen [PUP]
2014.9-140115

Comodo Security
Heur.Suspicious
17137

Dr.Web
Adware.Downware.1329
9.0.1.015

ESET NOD32
8.8944

Fortinet FortiGate
W32/OpenCandy
1/15/2014

F-Prot
W32/OpenCandy.A
v6.4.7.1.166

K7 AntiVirus
Riskware
13.173.9916

Malwarebytes
PUP.Optional.OpenCandy
v2014.01.15.09

McAfee
Artemis!5C62FC04727E
5600.7250

Norman
Suspicious_Gen4.EMXWK
11.20140115

Reason Heuristics
PUP.OOO.d
14.2.21.20

Sophos
OpenCandy
4.93

Vba32 AntiVirus
AdWare.Lyckriks
3.12.24.3

VIPRE Antivirus
Adware.Privitize
22592

File size:
7.6 MB (7,976,464 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\the_elder_scrolls_v_skyrim_-_crack_.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/2/2012 9:00:00 AM

Valid to:
8/3/2015 8:59:59 AM

Subject:
CN="OOO ""Industry""", O="OOO ""Industry""", STREET="Vsevolzhsky 2, bld. 2", L=Moscow, S=Moscow, PostalCode=119034, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D139BDA20096871840DCE08E6A80B6F0

File PE Metadata
Compilation timestamp:
12/6/2009 7:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:cHw+YXn7SRhOEKsniMn92Xitpx6DzYMSCvbNha:Qw+9RhOTsiM92QkXYRCvJha

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9852

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file the_elder_scrolls_v_skyrim_-_crack_.exe has been seen being distributed by the following 22 URLs.

http://downlite.net/download.php?c=occr&n=Uncle.Boonmee.Who.Can.Recall.His.Past.Lives.DVDRip.HORiZON-ArtSu&b=occr

http://downlite.net/download.php?c=occr&n=Adobe_Photoshop_CS6_Extended_Edition_Installer&b=occr

http://downlite.net/download.php?c=occr&n=Full_Mcpixel&b=occr

http://downlite.net/download.php?c=occr&n=Utopia_by_Dani_Daortiz&b=occr

http://downlite.net/download.php?c=occr&n=iOS_7_Beta_1_iPhone_5_Model_A1429&b=occr

Remove the_elder_scrolls_v_skyrim_-_crack_.exe - Powered by Reason Core Security