rnsuaf1d.exe

The application rnsuaf1d.exe has been detected as a potentially unwanted program by 10 anti-malware scanners. The file has been seen being downloaded from d2fpsq9kg43yka.cloudfront.net.
MD5:
0e8313990764450a8f9339b84c9d54f5

SHA-1:
5ad68268e7e4bf20ca1322ff6884bcf55c42bdc2

SHA-256:
f09c595f27aac72b92e6f1d3a298e479a8cea87cb27ed3b3b4ba3c4ffc209192

Scanner detections:
10 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 1:59:55 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.ConvertAd
7.1.1

AhnLab V3 Security
PUP/Win32.VOPackage
2015.05.13

AVG
Adware Generic6
2016.0.3078

Dr.Web
Adware.ClickMeIn.226
9.0.1.0165

ESET NOD32
Win32/Adware.ConvertAd.EA (variant)
9.11617

herdProtect (fuzzy)
2015.6.14.19

IKARUS anti.virus
AdWare.Vopak
t3scan.1.8.9.0

K7 AntiVirus
Adware
13.203.15889

SUPERAntiSpyware
Trojan.Agent/Gen-Vopak
9813

VIPRE Antivirus
Threat.4150696
39676

File size:
32.5 KB (33,280 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\cfcee813-1425647910-8e40-a63c-5b623ea3032f\rnsuaf1d.exe

File PE Metadata
Compilation timestamp:
3/6/2015 12:30:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
384:Et2LFzCdak/cLCwENHmBZttYWh8g++t9zOF6/74Vjhrg/EDHt6b0nuhg1G+fQaGN:K2BzhkELBENMZteWh2+tEDwAnPoa/G

Entry address:
0x1450

Entry point:
E8, FA, 13, 00, 00, E9, 89, FE, FF, FF, 66, 0F, EF, C0, 51, 53, 8B, C1, 83, E0, 0F, 85, C0, 75, 7F, 8B, C2, 83, E2, 7F, C1, E8, 07, 74, 37, 8D, A4, 24, 00, 00, 00, 00, 66, 0F, 7F, 01, 66, 0F, 7F, 41, 10, 66, 0F, 7F, 41, 20, 66, 0F, 7F, 41, 30, 66, 0F, 7F, 41, 40, 66, 0F, 7F, 41, 50, 66, 0F, 7F, 41, 60, 66, 0F, 7F, 41, 70, 8D, 89, 80, 00, 00, 00, 48, 75, D0, 85, D2, 74, 37, 8B, C2, C1, E8, 04, 74, 0F, EB, 03, 8D, 49, 00, 66, 0F, 7F, 01, 8D, 49, 10, 48, 75, F6, 83, E2, 0F, 74, 1C, 8B, C2, 33, DB, C1, EA, 02...
 
[+]

Entropy:
5.8806

Code size:
17.5 KB (17,920 bytes)

The file rnsuaf1d.exe has been seen being distributed by the following URL.

Remove rnsuaf1d.exe - Powered by Reason Core Security