snsxc4a9.tmp

The file snsxc4a9.tmp has been detected as a potentially unwanted program by 15 anti-malware scanners. The file has been seen being downloaded from d2htwdv930b0cg.cloudfront.net. While running, it connects to the Internet address dl19.clickmein.com on port 80 using the HTTP protocol.
MD5:
66020a9d5514e7fa2300f8fc446efc8f

SHA-1:
77c92659f9e583957b7e862a679ccf9639d1e7f6

SHA-256:
94e9895444447c4e45c9b839ac5eb0fea74ff5e50b306bb2a13fd117704a12ab

Scanner detections:
15 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 12:25:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Mikey.12999
636

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150529

Bitdefender
Gen:Variant.Mikey.12999
1.0.20.650

Emsisoft Anti-Malware
Gen:Variant.Mikey.12999
8.15.05.10.08

ESET NOD32
Win32/Adware.ConvertAd.NW (variant)
9.11679

F-Prot
W32/SuspPack.AA.gen
v6.4.6.5.141

F-Secure
Gen:Variant.Mikey.12999
11.2015-10-05_1

G Data
Gen:Variant.Mikey.12999
15.5.25

herdProtect (fuzzy)
2015.8.7.19

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2063

MicroWorld eScan
Gen:Variant.Mikey.12999
16.0.0.390

Qihoo 360 Security
HEUR/QVM00.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.5.29.14

Trend Micro House Call
Suspicious_GEN.F47V0510
7.2.219

VIPRE Antivirus
Trojan.Win32.Generic
40318

File size:
230.5 KB (236,032 bytes)

Common path:
C:\users\{user}\appdata\local\4eb69060-1431213293-11d5-bd9e-bcaec5e1940c\snsxc4a9.tmp

File PE Metadata
Compilation timestamp:
5/9/2015 8:30:24 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:/f8OCzE9+tbbu1Q3Ez/1IVC/8ZNTQVZLPGpQ6jnJ52/MK9BvjWJsaHLpZGjw69R5:/R4h8WMffvsTvVMa0Hy6jznF

Entry address:
0x1476C

Entry point:
E8, 1D, 3A, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 60, E5, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 44, E0, 42, 00, C9, C2, 08, 00, 57, 8B, C6, 83, E0, 0F, 85, C0, 0F, 85, C1, 00, 00, 00, 8B, D1, 83, E1, 7F, C1, EA, 07, 74, 65, EB, 06, 8D, 9B, 00, 00, 00, 00, 66, 0F, 6F, 06, 66, 0F, 6F, 4E, 10, 66...
 
[+]

Entropy:
6.2614

Code size:
178 KB (182,272 bytes)

The file snsxc4a9.tmp has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to dl19.clickmein.com  (50.7.184.162:80)

Remove snsxc4a9.tmp - Powered by Reason Core Security