nskd2fc.tmp

The file nskd2fc.tmp has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from s3.amazonaws.com. While running, it connects to the Internet address server-54-230-53-88.jfk6.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
8810ec1410b981c835329c2b803b13b6

SHA-1:
411de4b633e7e480d94fd95d3bedf829c517185c

SHA-256:
c98cbd676183eb7fdda3ab2b42d74d8e99986a4902ee6d708de7024b9d02afbc

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 11:09:12 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.VOPackage
2015.10.16

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

Arcabit
PUP.Adware.ConvertAd
1.0.0.582

Baidu Antivirus
Adware.Win32.Vopak
4.0.3.151117

K7 AntiVirus
Riskware
13.212.17767

Kaspersky
not-a-virus:AdWare.Win32.Vopak
14.0.0.1108

Panda Antivirus
Generic Suspicious
15.11.17.09

File size:
126 KB (129,031 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\nskd2fc.tmp

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:ygXdZt9P6D3XJbQFZgxopIYVY/CInWw+89qEB993o4sl:ye34tJxopIhafuZ3e

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file nskd2fc.tmp has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-53-88.jfk6.r.cloudfront.net  (54.230.53.88:80)

TCP (HTTP):
Connects to ec2-54-235-132-107.compute-1.amazonaws.com  (54.235.132.107:80)

TCP (HTTP):
Connects to ec2-52-1-45-42.compute-1.amazonaws.com  (52.1.45.42:80)

Remove nskd2fc.tmp - Powered by Reason Core Security