nss2b9e.tmp

The file nss2b9e.tmp has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from s3.amazonaws.com. While running, it connects to the Internet address server-54-230-52-168.jfk6.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
6ac8cf3bcdff57ddfff1afbab515393a

SHA-1:
f1b17fe18f2c41028e7a60afede36d1a1d8a5699

SHA-256:
6299d3867f3e042860a1919169b155bf724e3621c0529372edc0d7c7518ab266

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 7:17:43 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.VOPackage
2015.10.06

Arcabit
PUP.Adware.ConvertAd
1.0.0.568

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1319

Panda Antivirus
Generic Suspicious
15.11.05.11

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1015

Vba32 AntiVirus
AdWare.Vopak
3.12.26.4

File size:
237.7 KB (243,412 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\nss2b9e.tmp

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:ie34B75xag+3fmqNAdriowWhvS89TgMKDR45VD:25xwf1NAdWo/tFEMS45VD

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file nss2b9e.tmp has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-52-168.jfk6.r.cloudfront.net  (54.230.52.168:80)

TCP (HTTP):
Connects to ec2-54-235-132-107.compute-1.amazonaws.com  (54.235.132.107:80)

TCP (HTTP):
Connects to ec2-52-1-45-42.compute-1.amazonaws.com  (52.1.45.42:80)

Remove nss2b9e.tmp - Powered by Reason Core Security