ciwr.exe

The application ciwr.exe has been detected as a potentially unwanted program by 17 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from d3jydz90x0ejp8.cloudfront.net. While running, it connects to the Internet address 208.43.241.178-static.reverse.softlayer.com on port 80 using the HTTP protocol.
MD5:
138d992aebeb9755b7422c6cd5c8ccb3

SHA-1:
a7aa75475094649c42e658ad8ec66e53aa048003

SHA-256:
074ccce5697bfdb3ee1004d899a2a7d86190d1eecc31db512856c7d91a3f1599

Scanner detections:
17 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 9:02:22 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2493970
575

Arcabit
Trojan.Generic.D260E12
1.0.0.425

avast!
Win32:Adware-gen [Adw]
2014.9-150709

Baidu Antivirus
Adware.Win32.Downloader
4.0.3.15610

Bitdefender
Trojan.GenericKD.2493970
1.0.20.950

Emsisoft Anti-Malware
Trojan.GenericKD.2493970
8.15.07.09.09

ESET NOD32
Win32/Adware.ConvertAd.SU.gen (variant)
9.11882

F-Secure
Trojan.GenericKD.2493970
11.2015-09-07_5

G Data
Trojan.GenericKD.2493970
15.7.25

K7 AntiVirus
Adware
13.205.16445

Kaspersky
Trojan-Downloader.Win32.Genome
14.0.0.1761

McAfee
Artemis!138D992AEBEB
5600.6709

MicroWorld eScan
Trojan.GenericKD.2493970
16.0.0.570

nProtect
Trojan.GenericKD.2493970
15.07.03.01

Panda Antivirus
Trj/CI.A
15.07.09.09

Trend Micro
TROJ_GEN.R0EBC0OFM15
10.465.09

VIPRE Antivirus
Trojan.Win32.Generic
41668

File size:
67.2 KB (68,816 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\uqdq6ma8\ciwr.exe

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:apgpHzb9dZVX9fHMvG0D3XJjCRz4ylMYgjrzZ4YELVUWosb+o41ahfE:YgXdZt9P6D3XJjCRz4yqjrtW0o4sS

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.4169

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file ciwr.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-85-75-165.compute-1.amazonaws.com  (54.85.75.165:80)

TCP (HTTP):
Connects to 208.43.241.179-static.reverse.softlayer.com  (208.43.241.179:80)

TCP (HTTP):
Connects to 208.43.241.178-static.reverse.softlayer.com  (208.43.241.178:80)

Remove ciwr.exe - Powered by Reason Core Security