dsmanagersetup.exe

AssetsManager

AZTEC MEDIA INC.

The application dsmanagersetup.exe, “Assets Manager Install” by AZTEC MEDIA INC has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from download.cdn.aztecbe.com.
Publisher:
Aztec Media Inc  (signed by AZTEC MEDIA INC.)

Product:
AssetsManager

Description:
Assets Manager Install

Version:
5.0.0.15446

MD5:
c7ceb9e490c3a315e85777ae55aecc79

SHA-1:
6d341207c16dc6e10e08afb38ca5ce509121dfa4

SHA-256:
a0ad2b95079a5f39212358923ea352df4c58dc6ca6360a5ff98bfb4892eaea33

Scanner detections:
13 / 68

Status:
Adware

Analysis date:
5/17/2024 11:39:33 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.SearchSuite
4.0.3.1522

ESET NOD32
Win32/Toolbar.SearchSuite (variant)
9.11093

Fortinet FortiGate
Riskware/SearchSuite
2/2/2015

F-Prot
W32/S-a316f7dc
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Jatif.77
11.2015-02-02_2

G Data
Win32.Application.AztecSystemK
15.2.25

IKARUS anti.virus
AdWare.Bandoo
t3scan.1.8.6.0

Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite
14.0.0.2549

Malwarebytes
PUP.Optional.Linkey.A
v2015.02.02.02

Qihoo 360 Security
Win32/Virus.WebToolbar.d3d
1.0.0.1015

Reason Heuristics
PUP.Installer.Aztec Media
15.2.2.2

Sophos
SearchSuite
4.98

Trend Micro House Call
Suspicious_GEN.F47V0128
7.2.33

File size:
3.6 MB (3,741,264 bytes)

Product version:
5.0.0.15446

Copyright:
Copyright (c) 2005 - 2015

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\dsmanagersetup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/29/2014 1:00:00 AM

Valid to:
5/20/2015 1:59:59 AM

Subject:
CN=AZTEC MEDIA INC., OU=Development, O=AZTEC MEDIA INC., L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7DE0D719BBAF922D3A980DBD523B959A

File PE Metadata
Compilation timestamp:
2/24/2012 8:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:kMjwSyZVhG9eC7UJ3FkLhhiaBLKNGg08koZv:qVh/Gdh3BLK8cko1

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file dsmanagersetup.exe has been seen being distributed by the following URL.

Remove dsmanagersetup.exe - Powered by Reason Core Security