ciwr.exe

The application ciwr.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from d3jydz90x0ejp8.cloudfront.net. While running, it connects to the Internet address 208.43.241.179-static.reverse.softlayer.com on port 80 using the HTTP protocol.
MD5:
239e05e905e53eba92e8673fd606d976

SHA-1:
5891e338677a295f849a09c766468d6c6a47ab6a

SHA-256:
4899214fed9abe6c8d531b3d9e16b4aa2f9067d528c3878a6913febda8c6268f

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 5:51:39 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Genome
4.0.3.151110

K7 AntiVirus
Riskware
13.212.17797

Kaspersky
Trojan-Downloader.Win32.Genome
14.0.0.1144

McAfee
Artemis!239E05E905E5
5600.6586

Panda Antivirus
Generic Suspicious
15.11.10.04

Qihoo 360 Security
Win32/Trojan.Multi.daf
1.0.0.1077

Vba32 AntiVirus
TrojanDownloader.Genome
3.12.26.4

ViRobot
Trojan.Win32.A.Downloader.150172.A[h]
2014.3.20.0

File size:
146.7 KB (150,172 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\ciwr.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:VoPyys5jXJLA7g2Nb8NjEldWfzpKeqacRz1f5+UovLRgJL:VzfZA7gkbMNfzkacRZYa

Entry address:
0x323F

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 98, 27, 7A, 00, E8, 09, 2C, 00, 00, A3, E4, 26, 7A, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, DC, 79, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, E0, 1E, 7A, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 80, 7A, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.8163

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file ciwr.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-84-142-154.compute-1.amazonaws.com  (54.84.142.154:80)

TCP (HTTP):
Connects to 208.43.241.179-static.reverse.softlayer.com  (208.43.241.179:80)

TCP (HTTP):
Connects to 208.43.241.178-static.reverse.softlayer.com  (208.43.241.178:80)

Remove ciwr.exe - Powered by Reason Core Security