Threat Database Adware Adware.OpenSUpdater.J

Adware.OpenSUpdater.J

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 9,105
Threat Level: 20 % (Normal)
Infected Computers: 10,168
First Seen: January 7, 2013
Last Seen: February 12, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Adware.OpenSUpdater.J
Signature status: Root Not Trusted

Known Samples

MD5: ff4e49349a874836d6fd32a6cf63b743
SHA1: 0096bb6a6f688416560a17845463a40f69f77d31
SHA256: E53D2B621CB4358BCB3128784DCDFDE437D89C8D5673219E730DB1D30B3EE007
File Size: 3.59 MB, 3590152 bytes
MD5: 29e81edfd1c1fd6a258a147122bed5d7
SHA1: c9ceceaa926ea1deb46d5bd97646859ecd1d09aa
SHA256: 6D35473799965FFB6A0FCF1414AF70CE58C1FECCE86A0553C8D1E9CB0F8E5CDC
File Size: 3.57 MB, 3574320 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • arreestream ltd
  • navajowhitecodeteam
File Description
  • ArreeStream
  • NavajoWhiteCode
File Version 4.3.4.3
Internal Name
  • arreestream
  • navajowhitecode
Legal Copyright
  • ArreeStream Ltd 2022
  • NavajoWhiteCodeTeam 2022
Product Name
  • ArreeStream
  • NavajoWhiteCode
Product Version 4.3.4.3

Digital Signatures

Signer Root Status
arreestreamltd arreestreamltd Root Not Trusted
navajowhitecodeteam navajowhitecodeteam Root Not Trusted

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 8,998
Potentially Malicious Blocks: 505
Whitelisted Blocks: 8,224
Unknown Blocks: 269

Visual Map

0 0 0 ? ? 0 ? x ? ? x 0 0 ? 0 ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 ? ? ? ? ? 0 x 0 ? x x 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? x x ? ? ? 0 ? ? ? 0 0 0 0 0 ? x 0 x x x x x 0 x x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 x x 0 x ? x 0 x ? ? x x 0 x x x x x 0 x x ? x 0 x x ? x x 0 x x ? ? 0 0 x 0 x x 0 ? x x 0 x x ? x x 0 x x ? x x 0 x x x x 0 x x 0 ? x x 0 x x x x x 0 x x x ? ? x x 0 x x x x x x 0 x ? x 0 ? x x x 0 x x 0 x 0 x x 0 x x x 0 x x ? 0 x 0 x x ? x 0 x x 0 x x x 0 x x ? x x 0 x x 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 1 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? x x 0 x ? 0 x 0 x ? x x 0 x x 0 0 0 0 0 0 ? x x 0 x x ? x 0 x x 0 ? x x 0 x x ? ? x x 0 x x ? x x 0 x x ? 0 0 ? 0 0 ? 0 x 0 0 0 0 0 0 1 ? ? 0 ? 0 ? x 0 x x x x 0 x x 0 ? x x 0 x x 0 ? x x 0 x x x 0 x ? x 0 ? x x 0 x x ? x x 0 x x ? x x 0 x x ? x 0 x x 0 ? x x x 0 x x ? x x 0 x x x x 0 x x 0 ? x x 0 x x x x 0 x ? ? x x 0 x x ? x 0 x x 0 ? x x 0 x x 0 x x 0 x x 0 0 x 0 x x ? 0 x 0 x x x 0 x x x ? x x 0 x x ? x x 0 x x ? x x 0 x x 0 ? x x 0 x x ? x x 0 x x ? x x 0 x x ? x x 0 x x ? x x 0 x x ? x x 0 x x ? x x 0 x x 0 ? x 0 x x ? x x 0 x x ? x x 0 x x ? x x 0 x x ? x 0 x x 0 ? x x 0 x x ? x x 0 x x x x x 0 x x ? x 0 x x 0 ? x x 0 x x ? x x 0 x x x x x 0 x x ? x x 0 x x ? x x 0 x x ? x x 0 x x ? x x 0 x x ? x x 0 x x ? 0 x x 0 x x ? 0 x x 0 x x ? x x 0 x x x x x 0 x x ? x x 0 x x 0 ? x x 0 x x ? x x 0 x x 0 ? x x 0 x ? ? ? x 0 ? x x 0 x ? ? x x 0 x x ? ? x x 0 x x ? x x 0 x x ? x x 0 x x ? x x 0 x x ? x 0 x x 0 x x x 0 x x x x 0 x x ? x x 0 x ? ? x x x 0 x x ? x x 0 x x x x 0 x ? ? x x 0 x x ? x x 0 x x ? x 0 x x ? x x 0 x x x x x 0 x x ? x x 0 x x x 0 x x x x x 0 x x ? 0 x x 0 x x ? x x 0 x x ? x x 0 x x ? x x 0 x x ? x x 0 x x x x 0 x x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x ? x x 0 x ? x 0 x ? 0 x x x 0 x x ? x x 0 x ? ? x x 0 x ? ? x x 0 x ? ? x x 0 x ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x 0 0 x x x x x x x 0 x x 0 x 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • 1stBrowser.A
  • Agent.AG
  • Agent.DFGH
  • KuwanBar.B
  • OpenSUpdater.J
Show More
  • Redline.FAD
  • Redline.FAG
  • ShellcodeRunner.FN

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Related Posts

Trending

Most Viewed

Loading...