dnmw_7103.exe

The application dnmw_7103.exe has been detected as a potentially unwanted program by 13 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from cdn.guttastatdk.us.
MD5:
abe810f378da6e7d7246342ffceec451

SHA-1:
991d822a2964f51c9b7ee27f4e314e00c35fd0e0

SHA-256:
a681031002d07323811cd0e74c3f77610f8a2579c90e2606b1f73dc92fdc84d3

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/26/2024 7:52:24 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
NSIS:Adware-JK [PUP]
2014.9-131126

AVG
Skodna.Generic_c
2014.0.3543

Baidu Antivirus
Trojan.Win32.DownWare
4.0.3.131126

Bkav FE
W32.Clod270.Trojan
1.3.0.4613

Dr.Web
Adware.Downware.863
9.0.1.0330

ESET NOD32
Win32/InstallMonetizer.AG
7.9190

K7 AntiVirus
Trojan
13.174.10609

Malwarebytes
PUP.Optional.InstallMonetizer.A
v2013.12.11.03

McAfee
RDN/Generic PUP.x!bjv
5600.7285

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.131209

SUPERAntiSpyware
Heur.Agent/Gen-WhiteBox
10707

Trend Micro House Call
TROJ_GEN.R2KH1E4
7.2.241

VIPRE Antivirus
InstallMonetizer
24692

File size:
258.3 KB (264,534 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\dnmw_7103.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:ke34q855t5q2pd5A8Wbpb49Eot8vgNl12pMz7JK7p8yic:J8XbJd5A8EpGwvQl1BHJK7pL

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.7207

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file dnmw_7103.exe has been seen being distributed by the following URL.

Remove dnmw_7103.exe - Powered by Reason Core Security