Threat Database Adware Adware.OpenSUpdater.LC

Adware.OpenSUpdater.LC

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 18,056
Threat Level: 20 % (Normal)
Infected Computers: 2,481
First Seen: July 6, 2021
Last Seen: March 29, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Adware.OpenSUpdater.LC
Signature status: No Signature

Known Samples

MD5: 3321edd6307ebe08f27e31abbf6c0e81
SHA1: e6545a92470c53524442c9593f36d079f6c0e1eb
SHA256: 307782D3A38E434BC13306FE6591262C1C4D149A1E9DB80DF094FAD0CC0ECAD1
File Size: 4.88 MB, 4877536 bytes
MD5: e30eebe19be03f1f548868e6eb486871
SHA1: e09b1bf4a44d5a694903bd648b33ebd3365fcca8
SHA256: 49545FD8150DB05E6D0428490D8C8E098B81BB495BCA6CFF5145E142D78E4977
File Size: 1.11 MB, 1110162 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • EaseNet
  • Mellifluous Company
  • 网之易
File Description
  • OneMellifluousUpdater
  • Warcraft official Gaming Platform Installation Programs
  • 魔兽争霸官方对战平台安装程序
File Version
  • 1.8.70.8597
  • 1.0.0.0
Legal Copyright
  • Copyright (C) 2015 EaseNet. All rights reserved
  • Copyright (C) 2015 网之易。保留所有权利
  • © Mellifluous Company 2020
Product Name
  • OneMellifluousUpdater
  • Warcraft III Battle Platform
  • 魔兽争霸官方对战平台
Product Version
  • 1.8.70.8597
  • 1.0.0.0[5/23/2020.18:51:04]

Digital Signatures

Signer Root Status
OneMellifluousUpdaterCode OneMellifluousUpdaterCode Root Not Trusted

File Traits

  • dll
  • HighEntropy
  • imgui
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsga81a.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nshaa8c.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_check.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_combox.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_combox_drop.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_install_big.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_install_input.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_install_medium1.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_install_medium2.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_install_small.png Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_login_logo_normal.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_login_logo_normal_en.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_process_bg.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_process_front.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\btn_title_line.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\dlg_agree_scrollbar.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\dlg_agree_scrollbar2.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\dlg_bg.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\dlg_bg2.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\dlg_bg_frame.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\dlg_close.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\dlg_min.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\exit_install.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\install_finished.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\install_finished_en.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\logo.ico Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\image\pic_title_bg.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\license\license_cn.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\license\license_en.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\sys.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\trans\lang_cn.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\uires.idx Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\xml\dlg_main.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\xml\init.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\xml\page_ins_agree.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\xml\page_ins_exit.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\xml\page_ins_finish.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\xml\page_ins_folder.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\xml\page_ins_installing.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\xml\page_ins_start.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\xml\page_unins_finish.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\xml\page_unins_start.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nshaa8c.tmp\uires\xml\page_unins_uninstalling.xml Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsk38ee.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsp37d5.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsraa7b.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\~nsua.tmp\un_a.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Xqncadgk\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=c:\users\user\downloads\
"C:\Users\Dtttsnlw\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=c:\users\user\downloads\

Trending

Most Viewed

Loading...