nscde.tmp

The file nscde.tmp has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from s3.amazonaws.com. While running, it connects to the Internet address server-54-230-52-85.jfk6.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
08a075f01a6f2f4ac3ffd6f60602de77

SHA-1:
a814a47ee46cdf4a399c62ac7e036972497c0b81

SHA-256:
38c1083f8a7e43afd804064350b3ae3e53b8ca9c670fc35aea0d6d160a7f7c39

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 12:19:19 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.VOPackage
2015.10.16

Arcabit
PUP.Adware.ConvertAd
1.0.0.582

Baidu Antivirus
Adware.Win32.Vopak
4.0.3.151117

Kaspersky
not-a-virus:AdWare.Win32.Vopak
14.0.0.1106

Panda Antivirus
Generic Suspicious
15.11.17.05

Qihoo 360 Security
QVM42.0.Malware.Gen
1.0.0.1077

File size:
124.5 KB (127,490 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\nscde.tmp

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:ugXdZt9P6D3XJMFFbaPYBRxBcdoOa2RTKbg7LUuyEdo4sV:ue34+haPYBRLcd3auLL7LO

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file nscde.tmp has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-52-85.jfk6.r.cloudfront.net  (54.230.52.85:80)

TCP (HTTP):
Connects to ec2-52-1-45-42.compute-1.amazonaws.com  (52.1.45.42:80)

TCP (HTTP):
Connects to ec2-107-21-122-166.compute-1.amazonaws.com  (107.21.122.166:80)

Remove nscde.tmp - Powered by Reason Core Security