Threat Database Adware Adware.MSIL.OpenSUpdater.A

Adware.MSIL.OpenSUpdater.A

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 1,963
Threat Level: 20 % (Normal)
Infected Computers: 10,142
First Seen: January 3, 2013
Last Seen: November 10, 2025
OS(es) Affected: Windows

SpyHunter Detects & Remove Adware.MSIL.OpenSUpdater.A

Directories

Adware.MSIL.OpenSUpdater.A may create the following directory or directories:

%programfiles%\AlructisitApplication

Analysis Report

General information

Family Name: Adware.MSIL.OpenSUpdater.A
Signature status: Root Not Trusted

Known Samples

MD5: a585a4d69b4fd51c60cae0594a6d19cb
SHA1: c01f21fc1b67efa1d13d1c0e98566b6eda8c7862
SHA256: EB5F928D32D817352C99AC5B0310E6592352C4056BDDB0AF25AFB129D9EDA6F2
File Size: 8.13 MB, 8128696 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.1
Company Name Thundersea Soln
File Description Thundersea
File Version 1.0.0.1
Internal Name OneUpdater.exe
Legal Copyright Thundersea Soln 2021 ©
Original Filename OneUpdater.exe
Product Name Thundersea
Product Version 1.0.0.1

Digital Signatures

Signer Root Status
ThunderseaSoln ThunderseaSoln Root Not Trusted

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 211
Potentially Malicious Blocks: 69
Whitelisted Blocks: 119
Unknown Blocks: 23

Visual Map

0 0 0 0 0 x x 0 x x ? ? 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x ? ? ? ? x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 x x x x x x 0 0 0 ? 0 0 ? x 0 x 0 x 0 0 0 ? x x x x x x x 0 x 0 0 0 0 x ? ? ? x ? ? 0 0 0 0 0 0 ? ? x ? ? ? 0 0 0 0 0 0 0 x x x 0 x x x x x x x x x x x ? x 0 x 0 0 x x x x 0 x 0 0 0 x x 0 x 0 x 0 ? ? x x x 0 0 0 0 0 x x 0 0 0 0 0 x x 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.OpenSUpdater.A

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext

Related Posts

Trending

Most Viewed

Loading...