nsc5d65.tmp

The file nsc5d65.tmp has been detected as a potentially unwanted program by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from livestatscounter.com. While running, it connects to the Internet address dl22.clickmein.com on port 80 using the HTTP protocol.
Version:
1.0.0.0

MD5:
806e26966939544bea956b5c4c317ee7

SHA-1:
3d521b3761ad6b967b10a02b3fb8882fd5f36dec

SHA-256:
862781576079c6f5f39b190515b95a6d59c10d7436120c493d00249f592aa7c4

Scanner detections:
9 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 9:01:12 PM UTC  (today)

Scan engine
Detection
Engine version

Arcabit
Trojan.B3D521B
1.0.0.425

avast!
Win32:Dropper-gen [Drp]
2014.9-150716

Baidu Antivirus
Adware.Win32.Downloader
4.0.3.15716

ESET NOD32
Win32/Adware.ConvertAd.TH.gen (variant)
9.11854

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1872

NANO AntiVirus
Riskware.Nsis.ConvertAd.dtccvd
0.30.24.2266

Panda Antivirus
Generic Suspicious
15.07.16.01

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1015

VIPRE Antivirus
Trojan.Win32.Generic
41508

File size:
279.7 KB (286,396 bytes)

Product version:
1.0.0.0

Copyright:
Copyright 2013

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\nsc5d65.tmp

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:FzfZOBg4NCeD/YJa6VX0Iyrf+qIOCv1ORFjkYKmmRJMd+OOLP:vOBVC2Aa6ZyQOb9WP

Entry address:
0x323F

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 98, 27, 7A, 00, E8, 09, 2C, 00, 00, A3, E4, 26, 7A, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, DC, 79, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, E0, 1E, 7A, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 80, 7A, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.8796

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file nsc5d65.tmp has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to dl22.clickmein.com  (216.227.128.162:80)

Remove nsc5d65.tmp - Powered by Reason Core Security