nsx7f3e.tmp

The file nsx7f3e.tmp has been detected as malware by 13 anti-virus scanners. The file has been seen being downloaded from d27bgrkrsz14kh.cloudfront.net and multiple other hosts. While running, it connects to the Internet address server-54-192-55-142.jfk6.r.cloudfront.net on port 80 using the HTTP protocol.
Version:
1.0.1.22

MD5:
c5ec0deb645f57fbe914688c0a2db77d

SHA-1:
97f25be1f29e09475d7041e1264b2fc1ce2408f2

SHA-256:
f5041013f2e3531ff2e38d4e28d083fef8629e421f05f1cf92502aad341b84cd

Scanner detections:
13 / 68

Status:
Malware

Analysis date:
12/15/2017 1:48:33 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.259726
391

Arcabit
Trojan.Graftor.D3F68E
1.0.0.637

avast!
Win32:Dropper-gen [Drp]
2014.9-160110

Bitdefender
Gen:Variant.Graftor.259726
1.0.20.50

Dr.Web
Trojan.MulDrop6.17304
9.0.1.010

Emsisoft Anti-Malware
Gen:Variant.Graftor.259726
8.16.01.10.11

F-Secure
Gen:Variant.Graftor.259726
11.2016-10-01_1

G Data
Gen:Variant.Graftor.259726
16.1.25

McAfee
Artemis!C5EC0DEB645F
5600.6525

McAfee Web Gateway
Artemis!Trojan
7.6525

MicroWorld eScan
Gen:Variant.Graftor.259726
17.0.0.30

Quick Heal
(Suspicious) - DNAScan
11.15.14.00

Zillya! Antivirus
Trojan.Kryptik.Win32.823281
2.0.0.2579

File size:
243.5 KB (249,344 bytes)

Product version:
1.0.1.22

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\nsx7f3e.tmp

File PE Metadata
Compilation timestamp:
11/29/2015 2:50:06 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
14.0

CTPH (ssdeep):
3072:FDJPjM5DI9jOI/RjmKzoC4xEDYpa6udSzbK:FNyDkYpGdebK

Entry address:
0x4F8A

Entry point:
E8, 24, 03, 00, 00, E9, 7A, FE, FF, FF, 55, 8B, EC, F6, 45, 08, 01, 56, 8B, F1, C7, 06, 3C, 22, 41, 00, 74, 0A, 6A, 0C, 56, E8, 9D, FD, FF, FF, 59, 59, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 51, 56, FF, 75, 08, 8B, F1, 89, 75, FC, E8, AA, F9, FF, FF, C7, 06, 44, 22, 41, 00, 8B, C6, 5E, 8B, E5, 5D, C2, 04, 00, 83, 61, 04, 00, 8B, C1, 83, 61, 08, 00, C7, 41, 04, 4C, 22, 41, 00, C7, 01, 44, 22, 41, 00, C3, CC, 55, 8B, EC, 83, EC, 0C, 8D, 4D, F4, E8, 5C, F9, FF, FF, 68, 44, 75, 41, 00, 8D, 45, F4, 50, E8, C2...
 
[+]

Entropy:
5.1782

Code size:
65 KB (66,560 bytes)

The file nsx7f3e.tmp has been seen being distributed by the following 3 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to server-54-230-55-199.jfk6.r.cloudfront.net  (54.230.55.199:443)

TCP (HTTP SSL):
Connects to server-54-230-54-30.jfk6.r.cloudfront.net  (54.230.54.30:443)

TCP (HTTP SSL):
Connects to server-54-230-53-86.jfk6.r.cloudfront.net  (54.230.53.86:443)

TCP (HTTP SSL):
Connects to server-54-230-53-83.jfk6.r.cloudfront.net  (54.230.53.83:443)

TCP (HTTP SSL):
Connects to server-54-230-52-98.jfk6.r.cloudfront.net  (54.230.52.98:443)

TCP (HTTP SSL):
Connects to server-54-230-52-252.jfk6.r.cloudfront.net  (54.230.52.252:443)

TCP (HTTP):
Connects to server-54-230-52-246.jfk6.r.cloudfront.net  (54.230.52.246:80)

TCP (HTTP):
Connects to server-54-230-39-90.jfk1.r.cloudfront.net  (54.230.39.90:80)

TCP (HTTP SSL):
Connects to server-54-230-39-153.jfk1.r.cloudfront.net  (54.230.39.153:443)

TCP (HTTP SSL):
Connects to server-54-230-39-137.jfk1.r.cloudfront.net  (54.230.39.137:443)

TCP (HTTP SSL):
Connects to server-54-230-38-68.jfk1.r.cloudfront.net  (54.230.38.68:443)

TCP (HTTP SSL):
Connects to server-54-230-38-228.jfk1.r.cloudfront.net  (54.230.38.228:443)

TCP (HTTP SSL):
Connects to server-54-230-38-227.jfk1.r.cloudfront.net  (54.230.38.227:443)

TCP (HTTP):
Connects to server-54-230-38-219.jfk1.r.cloudfront.net  (54.230.38.219:80)

TCP (HTTP SSL):
Connects to server-54-230-38-184.jfk1.r.cloudfront.net  (54.230.38.184:443)

TCP (HTTP SSL):
Connects to server-54-230-38-152.jfk1.r.cloudfront.net  (54.230.38.152:443)

TCP (HTTP SSL):
Connects to server-54-230-38-150.jfk1.r.cloudfront.net  (54.230.38.150:443)

TCP (HTTP SSL):
Connects to server-54-230-38-127.jfk1.r.cloudfront.net  (54.230.38.127:443)

TCP (HTTP SSL):
Connects to server-54-230-36-247.jfk1.r.cloudfront.net  (54.230.36.247:443)

TCP (HTTP SSL):
Connects to server-54-192-55-184.jfk6.r.cloudfront.net  (54.192.55.184:443)

Remove nsx7f3e.tmp - Powered by Reason Core Security