nsdb9f.tmp

The file nsdb9f.tmp has been detected as a potentially unwanted program by 6 anti-malware scanners. The file has been seen being downloaded from d1xd06pkl5614k.cloudfront.net. While running, it connects to the Internet address server-52-85-63-169.lhr50.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
ea3079c385c5f5b033d6f7c6d1101d79

SHA-1:
d91e29502d92e7ef08c5fa99f1542519b7270ef6

SHA-256:
c97663a81cb3fa239ba5cd8c34469ea6594865f5e4656b07ae99c1d8a9e29b39

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
5/1/2024 5:40:04 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Imali
4.0.3.151026

ESET NOD32
Win32/Adware.Imali.F application
7.0.302.0

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.1217

McAfee
PUP-FZQ
5600.6600

Reason Heuristics
Threat.Win.Reputation.IMP
15.11.6.14

Rising Antivirus
PE:Malware.RDM.31!5.25[F1]
23.00.65.151024

File size:
292.5 KB (299,520 bytes)

Common path:
C:\users\{user}\appdata\local\temp\nsdb9f.tmp

File PE Metadata
Compilation timestamp:
10/26/2015 5:55:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:nDTd9txyW7E0qOXbGEbmh/s2Kv0PA7fU2KTtjWhX8McVOKHlUvpCc+L0nvqA:nDTzCb0qOXtbmZsVv0o1EtjzCv5vqA

Entry address:
0x120AD

Entry point:
E8, 37, 71, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, D4, 23, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, B8, 20, 42, 00, C9, C2, 08, 00, FF, 35, C0, D1, 42, 00, FF, 15, 8C, 20, 42, 00, 85, C0, 74, 02, FF, D0, 6A, 19, E8, 28, 69, 00, 00, 6A, 01, 6A, 00, E8, 3B, 28, 00, 00, 83, C4, 0C, E9, 00, 28, 00, 00...
 
[+]

Code size:
129.5 KB (132,608 bytes)

The file nsdb9f.tmp has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to server-52-85-63-169.lhr50.r.cloudfront.net  (52.85.63.169:80)

Remove nsdb9f.tmp - Powered by Reason Core Security