fsd814a.exe

Installer

The application fsd814a.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. It is built using the Crossrider cross-browser extension toolkit. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider. The file has been seen being downloaded from 121.59.17.8 and multiple other hosts.
Product:
Installer

Description:
Installer-H

Version:
1.0.0.0

MD5:
a3078153a7a53bfc0a7a0b8fd20d757a

SHA-1:
9f650f399f426203134e0ed53bf37f438e8230bd

SHA-256:
67f5bd21a41b48ca7c3fb781b401d722e915855e5a2f3b877fc91d7b9130e072

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Analysis date:
10/24/2018 4:54:29 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Zusy.146056
5833325

AhnLab V3 Security
Adware/Win32.Imali
2015.08.24

Avira AntiVirus
TR/Dropper.MSIL.Gen
8.3.1.6

Arcabit
Trojan.Adware.Zusy.D23A88
1.0.0.425

Bitdefender
Gen:Variant.Adware.Zusy.146056
1.0.20.1180

Dr.Web
Trojan.Crossrider1.50845
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Zusy.146056
15.08.24

ESET NOD32
MSIL/Adware.Imali.E application
6.3.12010.0

F-Secure
Variant.Adware.Zusy
5.15.154

G Data
Gen:Variant.Adware.Zusy.146056
15.8.25

Kaspersky
not-a-virus:AdWare.MSIL.Agent
15.0.2.529

MicroWorld eScan
Gen:Variant.Adware.Zusy.146056
16.0.0.708

Norman
Gen:Variant.Adware.Zusy.146056
28.05.2016 15:32:18

Reason Heuristics
PUP.FinalInstaller (M)
17.2.8.13

Sophos
PUA 'Offer Installer' (of type Adware)
5.23

VIPRE Antivirus
Threat.4150696
47848

File size:
2.9 MB (3,030,016 bytes)

Product version:
1.0.0.0

Original file name:
FinalInstaller_dotnet4.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\fsd814a.exe

File PE Metadata
Compilation timestamp:
8/24/2015 8:45:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:78KOZFUIE6kcZwzMgmjjTySlH4eBjMxXRhCsI:7OgXc+zXmOaH4eZMxP

Entry address:
0x2D9B8E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.4389

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.8 MB (2,980,864 bytes)

The file fsd814a.exe has been seen being distributed by the following 10 URLs.

http://121.59.17.8/d22nes4susdva1.cloudfront.net/finalinstaller/.../FinalInstaller_dotnet4.exe

http://101.110.118.69/d22nes4susdva1.cloudfront.net/finalinstaller/.../FinalInstaller_dotnet4.exe

http://60.13.74.165:81/1Q2W3E4R5T6Y7U8I9O0P1Z2X3C4V5B/d22nes4susdva1.cloudfront.net/finalinstaller/.../FinalInstaller_dotnet4.exe

http://101.96.8.138/d22nes4susdva1.cloudfront.net/finalinstaller/.../FinalInstaller_dotnet4.exe

http://120.52.73.44/d22nes4susdva1.cloudfront.net/finalinstaller/.../FinalInstaller_dotnet4.exe

http://101.96.10.74/d22nes4susdva1.cloudfront.net/finalinstaller/.../FinalInstaller_dotnet4.exe

http://45.64.22.71/d22nes4susdva1.cloudfront.net/finalinstaller/.../FinalInstaller_dotnet4.exe

http://95.182.112.5/d22nes4susdva1.cloudfront.net/finalinstaller/.../FinalInstaller_dotnet4.exe

http://91.194.162.11/d22nes4susdva1.cloudfront.net/finalinstaller/.../FinalInstaller_dotnet4.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-52-1-45-42.compute-1.amazonaws.com  (52.1.45.42:80)

TCP (HTTP):
Connects to server-52-84-246-92.sfo20.r.cloudfront.net  (52.84.246.92:80)

TCP (HTTP):
Connects to server-54-230-5-58.dfw3.r.cloudfront.net  (54.230.5.58:80)

TCP (HTTP):
Connects to server-54-230-95-31.fra2.r.cloudfront.net  (54.230.95.31:80)

TCP (HTTP):
Connects to server-52-85-63-81.lhr50.r.cloudfront.net  (52.85.63.81:80)

TCP (HTTP):
Connects to server-52-84-246-95.sfo20.r.cloudfront.net  (52.84.246.95:80)

TCP (HTTP):
Connects to installer1.monetizus.com  (46.101.124.23:80)

Remove fsd814a.exe - Powered by Reason Core Security