nscc043.tmp

The file nscc043.tmp has been detected as a potentially unwanted program by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.codec13sudha.com.
MD5:
0d2fd0109f90fcd6bd5166c14ff32be9

SHA-1:
99c807e900d2d2245fdfd7fb0299a9f06d389ed8

SHA-256:
8ad39440ae5549a20b77992f1ae4915a5411a95ad846082ac540a09d4a92158e

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/26/2024 2:44:41 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Downloader
2015.03.30

AVG
AdLoad
2016.0.3149

Baidu Antivirus
PUA.Win32.InstallMonetizer
4.0.3.1544

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
Win32/InstallMonetizer.BC potentially unwanted (variant)
9.11398

G Data
NSIS.Adware.InstallMonetizer
15.4.25

herdProtect (fuzzy)
2015.7.8.23

K7 AntiVirus
Trojan
13.202.15424

NANO AntiVirus
Trojan.Nsis.Downloader.djhpgw
0.30.8.659

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.15402

File size:
249.4 KB (255,392 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\nscc043.tmp

File PE Metadata
Compilation timestamp:
12/5/2009 5:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:jY4FizYxCDRXJ845sFq2xyiODvf+4DApJCkOm9ESDHEpSMaRRnurx3yHMgtzXHoD:jFJ0eQID7pJ59ENzZyt5q2pd5A8Ww4J

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8601

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file nscc043.tmp has been seen being distributed by the following URL.

Remove nscc043.tmp - Powered by Reason Core Security