nst1eea.tmp

The file nst1eea.tmp has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from s3.amazonaws.com. While running, it connects to the Internet address server-54-230-53-82.jfk6.r.cloudfront.net on port 80 using the HTTP protocol.
MD5:
b23664eda387338128f4acea09810f5c

SHA-1:
a5243295f18ddaef476ccab27e79d8644f1a18cd

SHA-256:
b2e8bc2617f0951aff9d9682d2035bba33d581dd605978e9bdf0d079b17eac8f

Scanner detections:
7 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 1:49:17 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.VOPackage
2015.10.28

Arcabit
PUP.Adware.ConvertAd
1.0.0.585

Baidu Antivirus
Adware.Win32.Vopak
4.0.3.15121

Clam AntiVirus
Win.Adware.Browsefox-14026
0.98/21511

Kaspersky
not-a-virus:AdWare.Win32.Vopak
15.0.0.562

Panda Antivirus
Generic Suspicious
15.12.01.05

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1077

File size:
229.4 KB (234,870 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\nst1eea.tmp

File PE Metadata
Compilation timestamp:
12/6/2009 1:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:Ge34N9Pne3/Xy3ABL7WEuKUrbkRHANANj8:qxne3/XMXEAsx8

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.8812

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file nst1eea.tmp has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-54-230-53-82.jfk6.r.cloudfront.net  (54.230.53.82:80)

TCP (HTTP):
Connects to ec2-52-1-45-42.compute-1.amazonaws.com  (52.1.45.42:80)

TCP (HTTP):
Connects to ec2-23-23-142-135.compute-1.amazonaws.com  (23.23.142.135:80)

Remove nst1eea.tmp - Powered by Reason Core Security