Threat Database Adware Adware.OpenSUpdater.XC

Adware.OpenSUpdater.XC

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 15,107
Threat Level: 20 % (Normal)
Infected Computers: 4
First Seen: July 25, 2026
Last Seen: September 8, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Adware.OpenSUpdater.XC
Signature status: No Signature

Known Samples

MD5: e9f0e1046d8841661593b0c91ebdf506
SHA1: e83071323944f29a8952061cf1ff3178a3bf09f4
SHA256: 239868F2AF6F0821DA04F4CC8B964214107D7627D44080FC2F1B803427B149D3
File Size: 2.91 MB, 2908672 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
File Description SwiftShader libGLESv2 32-bit Dynamic Link Library
File Version 4.6.6.6
Internal Name libGLESv2
Legal Copyright Copyright (C) 2016 Google Inc.
Original Filename libGLESv2.dll
Private Build 4.6.6.6
Product Name SwiftShader libGLESv2 Dynamic Link Library
Product Version 4.6.6.6

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 7,194
Potentially Malicious Blocks: 1,778
Whitelisted Blocks: 5,416
Unknown Blocks: 0

Visual Map

0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x x 0 0 x 0 0 0 0 x 0 0 x 0 x x x x x 0 0 x 0 0 x 0 0 0 0 x x 0 x 0 0 0 0 x 0 0 x 0 0 0 0 x x x x 0 0 0 0 x x x x x x 0 0 x x x x 0 0 x x 0 x x 0 0 x x 0 0 0 1 0 0 x x x x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 x 0 0 0 0 x x x 0 x x 0 x x x 0 0 0 0 0 0 0 x 0 0 0 x x x x x x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 0 0 x 0 0 0 0 0 x x 0 0 0 x x 0 x x x x x 0 x 0 x x x x x x 0 x x x x x x 0 0 0 x x 0 0 0 x x x x 0 x x 0 x 0 x x 0 x x x x x x x x x x 0 x x x 0 x x x x 0 x x x x 0 0 x 0 0 x 0 0 0 0 x 0 0 x 0 x x x x x 0 0 0 0 0 0 0 x x x x 0 x 0 0 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x x 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 x x x x 0 0 x 0 0 0 0 x x x x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x x x x x x x 0 x x x 0 x x x x 0 x 0 0 x x 0 0 x 0 0 x x 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x x x 0 x x 0 0 x x x x x 0 x 0 x x x 0 x 0 0 0 0 1 0 0 0 0 0 0 0 0 0 x x x 0 x x x 0 0 x x x x x x 0 x 0 x 0 0 0 x x 0 0 x x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x x x x 0 x 0 x 0 x x 0 0 0 0 0 0 x 0 x 0 x 1 0 0 x 0 0 x x x 0 0 0 x x x 0 x x x 0 0 0 x x x x x x x 0 0 0 x x 0 x x 0 x x 0 0 x 0 0 x 0 0 0 x x 0 0 0 0 0 x 0 x x x 0 x x x x x x x x x 0 x x 0 x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 x x 0 0 x 0 x x x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x x x x 0 0 0 0 0 x x x 0 0 0 1 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 0 0 0 0 0 x 0 0 0 x x x 0 0 x 0 0 0 0 0 x x x x x x x x x x x x x x x x x x 0 x 0 0 0 0 0 0 0 x x x x x x x 0 x 0 x 0 0 x x x x x x x x x x 0 0 0 0 x x x x x x 0 0 0 x 0 x 0 x x x x x x x x x x x x x 0 x x x x x x 0 x x 0 x x 0 x x 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 x x x 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x x x x x x x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x x 0 0 0 x x x 0 0 0 x x 0 x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x 0 x 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 x 0 x 0 0 0 x 0 x x x 0 x x x x x 0 0 0 0 x x x x x x x x x x x 0 0 x x 0 0 0 x x 0 0 0 x x x x 0 0 x x x 0 0 x x 0 0 0 x 0 0 x 0 x 0 x 0 x 0 x x 0 0 x x x x 0 0 0 x 0 x x 0 x x x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x x x x x x x 0 x 0 x 0 0 0 x x 0 0 0 x 0 0 0 0 x x 0 x 0 x x 0 0 x x 0 x x x 0 x x 0 0 0 0 x x 0 0 x x x 0 0 0 x 0 0 0 0 x x x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x 0 x 0 x x x x x x x x x x 0 0 x x x x x x x x x x 0 0 x x x x x x x x x x 0 0 x x x x x x x x x x 0 0 x x x x x 0 x 0 0 0 x x x 0 x 0 x x 0 x x x 0 x x x 0 0 x x x x x x x x 0 0 0 x 0 0 0 x x 0 x x x 0 x 0 x 0 x 0 x x x x x x x x x x x x x x x 0 0 x x x 0 0 x x 0 x x 0 x 0 x 0 0 0 x x x x x x x x x x 0 0 x 0 x x 0 0 0 x 0 x x 0 x 0 x x x x x 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x x 0 x 0 0 x x 0 x x x 0 0 x x x x x 0 0 0 0 0 0 0 x x x x 0 x x 0 x x x 0 x x x x x 0 0 0 x 0 x x x x 0 x 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 x x x 0 0 0 x x x x 0 x x 0 0 x 0 0 0 0 0 0 0 0 x x x x 0 x 0 x x x x x x 0 0 0 x 0 0 x 0 0 x 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 x x x x 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 0 0 x 0 x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • OpenSUpdater.XC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e83071323944f29a8952061cf1ff3178a3bf09f4_0002908672.,LiQMAxHB