0q1heuffm5.exe

AssetsManager

AZTEC MEDIA INC.

The application 0q1heuffm5.exe, “Assets Manager Install” by AZTEC MEDIA INC has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from download.cdn.aztecbe.com.
Publisher:
Aztec Media Inc  (signed by AZTEC MEDIA INC.)

Product:
AssetsManager

Description:
Assets Manager Install

Version:
5.0.0.15946

MD5:
4659eb753420e404e1b7f232572f3699

SHA-1:
1fd15a530caf23c1b0256df5dfcb06b33c55742f

SHA-256:
e12149ed8e59bf69ae976e9f30e0f63781b35c761e5fc58061b0f09cd1123255

Scanner detections:
13 / 68

Status:
Adware

Analysis date:
5/17/2024 1:45:04 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/SeaSuite.Gen
3.6.1.96

avast!
Win32:PUP-gen [PUP]
2014.9-150413

Dr.Web
Adware.Bandoo
9.0.1.05190

ESET NOD32
Win32/Toolbar.SearchSuite.U potentially unwanted application
7.0.302.0

F-Secure
Adware.Linkey.B
11.2015-13-04_2

G Data
Win32.Application.AztecSystemK
15.4.25

Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite
15.0.0.543

Malwarebytes
PUP.Optional.Linkey.A
v2015.04.13.02

McAfee
Trojan.Artemis!4659EB753420
16.8.708.2

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Installer.Aztec Media
15.4.13.1

Sophos
PUA 'SearchSuite' (of type Adware)
5.12

File size:
3.4 MB (3,526,696 bytes)

Product version:
5.0.0.15946

Copyright:
Copyright (c) 2005 - 2015

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\0q1heuffm5.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/28/2014 7:00:00 PM

Valid to:
5/19/2015 7:59:59 PM

Subject:
CN=AZTEC MEDIA INC., OU=Development, O=AZTEC MEDIA INC., L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7DE0D719BBAF922D3A980DBD523B959A

File PE Metadata
Compilation timestamp:
2/24/2012 2:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:qQB4qI2FGkJxhBHTy/UrDCw8YJ1cuD1uDIZeFXmtU9TyVTpzPvFgoA7KKgfpE6:RBpJFDoUrHvua1u0cFkUgVdwZqpE6

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file 0q1heuffm5.exe has been seen being distributed by the following URL.

Remove 0q1heuffm5.exe - Powered by Reason Core Security