PUP.OpenCandy.B

Analysis Report

General information

Family Name: PUP.OpenCandy.B
Signature status: No Signature

Known Samples

MD5: d51d1f3c48dccad28206fd7b4e57ede2
SHA1: e2c7dff59e2b501bd0b815c8bf5f14eed66e5d8f
SHA256: 9AF763C59B38100872775D114CD80BA2C74152DC293419CD860ED9D99C6FE87A
File Size: 3.46 MB, 3464063 bytes
MD5: cd0ae887d7b70528d090aa4e60931e0c
SHA1: 6aa59e4ee0918aae657807ce7e6c52d9776f143d
SHA256: AC455FED0B4618EC476829AEBF8949FFEB9B27CD5A737F98DFB82E597C13E268
File Size: 373.50 KB, 373499 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments GOM Player Setup File (2013-04-03 15:58:14)
Company Name
  • Gretech Corporation
  • LIGHTNING UK!
File Description
  • GOM Player Setup File
  • ImgBurn Installer
File Version
  • 2.5.8.0
  • 2.1
Legal Copyright
  • Copyright(C) 2003-2013
  • Copyright© 2005 - 2013
Legal Trademarks LIGHTNING UK!
Product Name
  • GOM Player
  • ImgBurn
Product Version
  • 2.5.8.0
  • 2.1.50.5145

File Traits

  • dll
  • HighEntropy
  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • ReadProcessMemory
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...