dsmanagersetup.exe

AssetsManager

Aztec Media inc.

The application dsmanagersetup.exe, “Assets Manager Install” by Aztec Media inc has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from download.cdn.aztecbe.com.
Publisher:
Aztec Media Inc  (signed by Aztec Media inc.)

Product:
AssetsManager

Description:
Assets Manager Install

Version:
5.0.0.16186

MD5:
31b633f07a141fc8aba51cdc88fdde4e

SHA-1:
fa19681adafd9235f37a64f2ccc1d98f75b18543

SHA-256:
38d404ab6af0720875e849f722c57b01ea19d5e1cc6ddad86f63be43917a5b2a

Scanner detections:
15 / 68

Status:
Adware

Analysis date:
5/21/2024 2:47:11 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/SeaSuite.Gen
8.3.1.6

avast!
Win32:PUP-gen [PUP]
2014.9-150528

Baidu Antivirus
Adware.Win64.SearchSuite
4.0.3.15528

Dr.Web
Adware.Bandoo.283
9.0.1.0148

ESET NOD32
Win32/Toolbar.SearchSuite.AB potentially unwanted (variant)
9.11694

F-Secure
Gen:Variant.Adware.SearchSuite
11.2015-28-05_5

G Data
Win32.Application.Searchsuite
15.5.25

IKARUS anti.virus
not-a-virus:WebToolbar.SearchSuite
t3scan.1.9.2.0

K7 AntiVirus
Adware
13.204.16051

Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite
14.0.0.1971

Malwarebytes
PUP.Optional.AztecMedia.A
v2015.05.28.07

Panda Antivirus
PUP/Linkey
15.05.28.07

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.Aztec Media
15.5.28.15

Trend Micro House Call
Suspicious_GEN.F47V0527
7.2.148

File size:
3.3 MB (3,495,784 bytes)

Product version:
5.0.0.16186

Copyright:
Copyright (c) 2005 - 2015

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\dsmanagersetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/1/2015 1:00:00 AM

Valid to:
2/1/2018 11:59:59 PM

Subject:
CN=Aztec Media inc., O=Aztec Media inc., L=Panama City, S=Panama City, C=PA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2AF6396322BF5B08910274FFE4241447

File PE Metadata
Compilation timestamp:
2/24/2012 7:19:59 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:/sGgs1vKMlDxBI9elFnB7JCkFrlc15/4mxByrMReYAiE2X:EGgsjtBCiFn1JFlcD7BzRJAi5X

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Entropy:
7.9978

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file dsmanagersetup.exe has been seen being distributed by the following URL.

Remove dsmanagersetup.exe - Powered by Reason Core Security