nso4a8b.tmpfs

The file nso4a8b.tmpfs has been detected as a potentially unwanted program by 20 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “RGB Digital”. The file has been seen being downloaded from d2htwdv930b0cg.cloudfront.net.
MD5:
027ba039e1019ef516f71c9a9fbf7c40

SHA-1:
9dd3cc9f43f958a88e63d7fe447d9f6840d79760

SHA-256:
75b3d8d9bc9bc257b49549f7844ab73dab305a132c046c3f7d5353f656227770

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 7:55:14 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Mikey.11849
628

Agnitum Outpost
PUA.ConvertAd
7.1.1

avast!
Win32:Dropper-gen [Drp]
2014.9-150518

AVG
Generic_r
2016.0.3132

Baidu Antivirus
Adware.Win32.ConvertAd
4.0.3.15518

Bitdefender
Gen:Variant.Mikey.11849
1.0.20.555

Emsisoft Anti-Malware
Gen:Variant.Mikey.11849
8.15.04.21.10

ESET NOD32
Win32/Adware.ConvertAd.IE (variant)
9.11533

Fortinet FortiGate
Riskware/ConvertAd
5/18/2015

F-Prot
W32/SuspPack.AA.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Mikey.11849
11.2015-18-05_2

G Data
Gen:Variant.Mikey.11849
15.5.25

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.9.0

McAfee
Artemis!027BA039E101
5600.6762

MicroWorld eScan
Gen:Variant.Mikey.11849
16.0.0.414

Qihoo 360 Security
HEUR/QVM00.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.5.22.10

Sophos
Generic PUA LD
4.98

Trend Micro House Call
Suspicious_GEN.F47V0422
7.2.138

VIPRE Antivirus
Trojan.Win32.Generic
39676

File size:
120.5 KB (123,392 bytes)

Common path:
C:\users\{user}\appdata\roaming\c535b6a5-1429649157-044e-8ed5-ed2dee72fa78\nso4a8b.tmpfs

File PE Metadata
Compilation timestamp:
4/22/2015 6:19:20 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:EkKj3lFdjt+dWzY/wXu3MU8poeoq6qaO3us:Qj3lFdjAWzY/wXu3MU8pohO+s

Entry address:
0x43B0

Entry point:
E8, EB, 3E, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 84, DC, 41, 00, FF, 15, 84, 60, 41, 00, 85, C0, 75, 18, 56, E8, 26, 04, 00, 00, 8B, F0, FF, 15, 30, 60, 41, 00, 50, E8, D6, 03, 00, 00, 59, 89, 06, 5E, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 80, 00, 00, 00, 72, 0E, 83, 3D, E4, F2, 41, 00, 00, 74, 05, E9, 0F, 3F, 00, 00, 57, 8B, F9, 83...
 
[+]

Entropy:
6.3946

Code size:
83.5 KB (85,504 bytes)

Service
Display name:
RGB Digital

Service name:
muzepiji

Description:
Socket Word Processor

Type:
Win32OwnProcess


The file nso4a8b.tmpfs has been seen being distributed by the following URL.

Remove nso4a8b.tmpfs - Powered by Reason Core Security