ciwr.exe

The application ciwr.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from d3jydz90x0ejp8.cloudfront.net.
MD5:
54b20c2b7ffca7c7b1051e668f6d3fc4

SHA-1:
665e02adf7802101117054859f0951ae8892742e

SHA-256:
3b97007793109b43e76698985dfc550989fe84730a5e953bc166c74e3ec7fc92

Scanner detections:
21 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 6:08:02 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2806435
459

Arcabit
Trojan.Generic.D2AD2A3
1.0.0.585

avast!
Win32:Dropper-gen [Drp]
2014.9-151102

Baidu Antivirus
Adware.Win32.Genome
4.0.3.15112

Bitdefender
Trojan.GenericKD.2806435
1.0.20.1530

Dr.Web
Trojan.DownLoader16.59998
9.0.1.0306

Emsisoft Anti-Malware
Trojan.GenericKD.2806435
8.15.11.02.02

Fortinet FortiGate
W32/Genome.VUQY!tr.dldr
11/2/2015

F-Secure
Trojan.GenericKD.2806435
11.2015-02-11_2

G Data
Trojan.GenericKD.2806435
15.11.25

K7 AntiVirus
Riskware
13.212.17709

Kaspersky
Trojan-Downloader.Win32.Genome
15.0.0.562

McAfee
RDN/Generic Downloader.x
5600.6593

MicroWorld eScan
Trojan.GenericKD.2806435
16.0.0.918

nProtect
Trojan.GenericKD.2806435
15.10.30.01

Panda Antivirus
Trj/CI.A
15.11.02.02

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro
TROJ_GEN.R03FC0OJK15
10.465.02

VIPRE Antivirus
Trojan.Win32.Generic
44922

ViRobot
Trojan.Win32.Z.Genome.67032[h]
2014.3.20.0

File size:
65.5 KB (67,032 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\ciwr.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:1oLDYsacy7mHMowHjXJAup/YoAkCvHWapccNtT:1oPyys5jXJAp5jpT

Entry address:
0x323F

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 98, 27, 7A, 00, E8, 09, 2C, 00, 00, A3, E4, 26, 7A, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, DC, 79, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, E0, 1E, 7A, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 80, 7A, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.4543

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file ciwr.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-84-142-154.compute-1.amazonaws.com  (54.84.142.154:80)

TCP (HTTP):
Connects to 208.43.241.179-static.reverse.softlayer.com  (208.43.241.179:80)

Remove ciwr.exe - Powered by Reason Core Security