cmmdwriter.exe

The application cmmdwriter.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from d2fpsq9kg43yka.cloudfront.net.
MD5:
c11172f6f3dad20483596226e4d4c7c7

SHA-1:
f3e7773cedfb22e184c2ad039761afe794e86c75

SHA-256:
9fc6d1e4ef673c5a9f7d4935f305d8d00b9e44af6cfed154c5ccd7b6c6007593

Scanner detections:
8 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 2:48:19 PM UTC  (today)

Scan engine
Detection
Engine version

Arcabit
Trojan.BF3E777
1.0.0.425

Baidu Antivirus
Adware.Win32.Downloader
4.0.3.15823

Dr.Web
Adware.ClickMeIn.1989
9.0.1.0235

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1682

McAfee
Generic PUP.y
5600.6664

Panda Antivirus
Generic Suspicious
15.08.23.05

Trend Micro House Call
ADW_ADBUNDLE
7.2.235

Trend Micro
ADW_ADBUNDLE
10.465.23

File size:
40.5 KB (41,440 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\cmmdwriter.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:s4wO7XBz+5Qm3W0tYdrQZHV4EWuWEUOg4jjfS3XJ2qsNGPZOnKUF:fLXB65939tY6HBg4sXJ2jN26

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
6.8331

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file cmmdwriter.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-85-75-165.compute-1.amazonaws.com  (54.85.75.165:80)

TCP (HTTP):
Connects to 208.43.241.178-static.reverse.softlayer.com  (208.43.241.178:80)

Remove cmmdwriter.exe - Powered by Reason Core Security