dsmanagersetup.exe

AssetsManager

AZTEC MEDIA INC.

The application dsmanagersetup.exe, “Assets Manager Install” by AZTEC MEDIA INC has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from download.cdn.aztecbe.com.
Publisher:
Aztec Media Inc  (signed by AZTEC MEDIA INC.)

Product:
AssetsManager

Description:
Assets Manager Install

Version:
5.0.0.15946

MD5:
dc45754eabb3dfd47d445ea06697a13a

SHA-1:
2334a0de809e47be283311f6f6ba825e5e64159a

SHA-256:
2be09494d6248270016e5b373b6b5835644d418c35c9f49b8bafcf4ed9e551f3

Scanner detections:
23 / 68

Status:
Adware

Analysis date:
5/16/2024 11:26:35 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Linkey.B
680

AhnLab V3 Security
PUP/Win32.SearchA
2015.03.02

Avira AntiVirus
PUA/SeaSuite.Gen
7.11.217.28

avast!
Win32:Adware-gen [Adw]
2014.9-150326

Baidu Antivirus
Adware.Win32.SearchSuite
4.0.3.15326

ESET NOD32
Win32/Toolbar.SearchSuite.U potentially unwanted (variant)
9.11369

Fortinet FortiGate
Riskware/SearchSuite
3/26/2015

F-Prot
W32/S-a316f7dc
v6.4.7.1.166

F-Secure
Adware.Linkey.B
11.2015-26-03_5

G Data
Win32.Application.AztecSystemK
15.3.25

IKARUS anti.virus
AdWare.Bandoo
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.1915120

Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite
14.0.0.2286

Malwarebytes
PUP.Optional.Linkey.A
v2015.03.26.08

McAfee
Artemis!53AD8EC0F755
5600.6814

Microsoft Security Essentials
Threat.Undefined
1.193.1762.0

MicroWorld eScan
Adware.Linkey.B
16.0.0.255

Panda Antivirus
Generic Suspicious
15.03.26.08

Qihoo 360 Security
Win32/Virus.WebToolbar.d3d
1.0.0.1015

Reason Heuristics
PUP.Installer.Aztec Media
15.3.26.20

Sophos
SearchSuite
4.98

Trend Micro House Call
TROJ_GEN.R03EC0OBQ15
7.2.85

Trend Micro
TROJ_GEN.R03EC0OBQ15
10.465.26

File size:
3.4 MB (3,526,672 bytes)

Product version:
5.0.0.15946

Copyright:
Copyright (c) 2005 - 2015

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\dsmanagersetup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/29/2014 12:00:00 AM

Valid to:
5/19/2015 11:59:59 PM

Subject:
CN=AZTEC MEDIA INC., OU=Development, O=AZTEC MEDIA INC., L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7DE0D719BBAF922D3A980DBD523B959A

File PE Metadata
Compilation timestamp:
2/24/2012 7:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:1QudfVhFtdGjcSY4CEcp2n82WmvSFMlMILB:1vfVhrUjc14CX2n8USFMtLB

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file dsmanagersetup.exe has been seen being distributed by the following URL.

Remove dsmanagersetup.exe - Powered by Reason Core Security