nss82d5.tmp

The file nss82d5.tmp has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from s3.amazonaws.com. While running, it connects to the Internet address server-54-240-190-28.jfk6.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
5e6fc8a6c662ed38aefe9b6d5c0793f7

SHA-1:
0f76f7319959dc23b4e0d79df59112a089324c02

SHA-256:
5b283bbd5c6da257e538d99ec66b8ccfec362650be5a8974b1b7d960d6db5107

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 11:15:17 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.VOPackage
2015.10.09

Arcabit
PUP.Adware.ConvertAd
1.0.0.582

Baidu Antivirus
Adware.Win32.Vopak
4.0.3.15119

Kaspersky
not-a-virus:AdWare.Win32.Vopak
14.0.0.1149

Panda Antivirus
Generic Suspicious
15.11.09.07

File size:
238.6 KB (244,312 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\nss82d5.tmp

File PE Metadata
Compilation timestamp:
12/6/2009 4:20:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:6e34bIAovoL/iIsHEPzh+R6AivxoGaXL2gA:kIAF46AiiGMJA

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8862

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file nss82d5.tmp has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-240-190-28.jfk6.r.cloudfront.net  (54.240.190.28:80)

TCP (HTTP):
Connects to server-54-230-38-89.jfk1.r.cloudfront.net  (54.230.38.89:80)

TCP (HTTP):
Connects to ec2-52-1-45-42.compute-1.amazonaws.com  (52.1.45.42:80)

TCP (HTTP):
Connects to ec2-107-21-122-166.compute-1.amazonaws.com  (107.21.122.166:80)

Remove nss82d5.tmp - Powered by Reason Core Security