nsadb70.tmp

The file nsadb70.tmp has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from s3.amazonaws.com. While running, it connects to the Internet address server-54-192-55-67.jfk6.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
4657b9a3bf1bb7830e91aef6522eeb26

SHA-1:
eae59adfb387b31e5f8eb3f1b67b6c499fdca8a9

SHA-256:
e2ae615b7c3158187dc8a450b185cf386a28dc0478073c2e0f2a9b018de6c030

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
5/4/2024 9:18:47 AM UTC  (today)

Scan engine
Detection
Engine version

Arcabit
PUP.Adware.ConvertAd
1.0.0.628

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1022

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1077

Reason Heuristics
Adware.Generic.ABT (M)
16.2.29.18

File size:
219.5 KB (224,746 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\nsadb70.tmp

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:zoPyys5jXJQCgcvs0ucqqiRCc5XMTbPedkad1lFko7yRXACLxnQAJTB00fwwO:zzfHbVu3qqCc5cTbPCk2KtLxfTKL

Entry address:
0x323F

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 98, 27, 7A, 00, E8, 09, 2C, 00, 00, A3, E4, 26, 7A, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, DC, 79, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, E0, 1E, 7A, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 80, 7A, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9078

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file nsadb70.tmp has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-38-28.jfk1.r.cloudfront.net  (54.230.38.28:80)

TCP (HTTP):
Connects to server-54-192-55-67.jfk6.r.cloudfront.net  (54.192.55.67:80)

TCP (HTTP):
Connects to server-54-192-55-32.jfk6.r.cloudfront.net  (54.192.55.32:80)

TCP (HTTP):
Connects to server-54-192-55-175.jfk6.r.cloudfront.net  (54.192.55.175:80)

TCP (HTTP):
Connects to ec2-54-225-164-100.compute-1.amazonaws.com  (54.225.164.100:80)

TCP (HTTP):
Connects to ec2-52-1-45-42.compute-1.amazonaws.com  (52.1.45.42:80)

TCP (HTTP):
Connects to ec2-107-22-235-143.compute-1.amazonaws.com  (107.22.235.143:80)

Remove nsadb70.tmp - Powered by Reason Core Security