Threat Database Adware Adware.OpenSUpdater.AO

Adware.OpenSUpdater.AO

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 18,686
Threat Level: 20 % (Normal)
Infected Computers: 88
First Seen: October 25, 2022
Last Seen: September 23, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Adware.OpenSUpdater.AO
Signature status: Root Not Trusted

Known Samples

MD5: 7a26c7c6770a6fb4e370b1bc11cad350
SHA1: e2e48c0e30d8165cffde9f5d4f0b7bac7caa0e3f
SHA256: 94FB6BA8A23AC036169FD13A66A41024666998A9139B87E93C80027F0B56A92E
File Size: 2.27 MB, 2274792 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Unsuitable Vebo Energy.
File Description Unsuitable Vebo Energy
File Version 1.8.7.7
Internal Name unsuitableveboenergygl.exe
Legal Copyright Copyright Unsuitable Vebo Energy. 2022
Original Filename unsuitableveboenergycw.exe
Product Name Unsuitable Vebo Energy
Product Version 1.8.7.7
T E S T I N F O stRING

Digital Signatures

Signer Root Status
FancyNiu FancyNiu Root Not Trusted

File Traits

  • x64

Block Information

Total Blocks: 2,435
Potentially Malicious Blocks: 552
Whitelisted Blocks: 1,692
Unknown Blocks: 191

Visual Map

0 ? ? ? x x 0 0 ? x x ? ? ? ? ? x ? ? ? ? ? ? ? x ? ? ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x ? ? x x x x x x ? x 0 x x 0 ? x x x ? x ? x x x x x x x x ? x x x ? x ? x ? ? x x ? ? x x x x x x x x ? x x ? x ? ? ? x x ? x ? x ? x ? x 0 x x ? x 0 x x ? ? x ? ? x ? ? ? ? ? ? ? ? x 0 ? ? ? ? ? ? ? ? ? ? 0 x x ? ? ? x x 0 x 0 x x 0 ? x x x x ? ? x x x x x x ? x ? x x x ? x ? x x ? x x ? ? ? ? ? x ? x x x x ? ? ? ? x x ? x x ? x ? ? ? ? 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 x 0 x 0 0 1 0 0 0 0 0 x 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 ? ? ? x x 0 0 x x 0 0 0 0 0 0 0 0 ? x x x 0 x 0 0 x 0 0 0 0 0 ? x 0 0 0 x 0 0 x 0 0 ? x x x ? x x x ? x x ? ? ? ? x x x ? 0 0 0 0 ? 0 0 0 ? ? ? 0 ? ? 0 ? 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 x 0 0 ? x x x x 0 0 0 x 0 0 x 0 0 ? 0 0 0 0 ? x 0 0 ? 0 0 0 0 ? 0 ? 0 0 0 x ? 0 0 0 0 x 0 x 0 x 0 0 0 0 x ? 0 0 x 0 0 0 0 1 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x ? 0 0 0 0 x 0 x ? x 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 x 0 0 0 0 0 0 ? 0 0 x x x x 0 0 0 0 x 0 0 x 0 ? x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 x x 0 0 0 0 x x x x x x x x 0 0 0 x 0 0 x 0 0 0 0 1 x 0 0 x x x x 0 0 x 0 x x x x x x 0 0 x 0 0 0 0 x 0 0 x x x x x x 0 x x x 0 x 0 x ? x x x x x x x x x x x x x x x x x x x x x 0 x x 0 0 x x 0 0 0 0 ? x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 ? ? ? x 0 0 x x x x ? 0 ? x 0 ? ? ? 0 0 0 0 ? 0 0 0 x 1 0 x 0 x 0 0 x 0 x 0 0 0 x x 0 0 0 x x x x x 0 x 0 0 0 x 0 0 x 0 x x x 0 x x 0 0 0 x 0 0 0 x ? 0 0 x 0 x 0 x 0 x 0 x 0 0 0 x x x x x x x x x 0 0 x 0 x 0 x 0 0 0 x 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x x x x 0 0 x 0 x x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 x x 0 x x x 0 0 x 0 0 0 ? ? ? ? 0 0 0 0 ? ? ? 0 0 ? 0 0 0 x x x x x x x x x x x x x x x x x x x x x ? 0 0 x 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 x ? x x x 0 0 0 0 0 x x x 0 x 0 0 x 0 0 x x x x ? 0 0 x x ? x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 x 0 x 0 0 x ? x 0 0 x 0 x x 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x x x x 0 x x x x x ? 0 0 ? x 0 ? x x x ? 0 ? 0 x 0 0 x 0 0 0 0 x x 0 x 0 0 ? 0 ? x ? x x x x 0 0 ? 0 x x x x 0 0 0 0 0 0 x x x 0 x x x x x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
Show More
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...