wswr.exe

The application wswr.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from d2htwdv930b0cg.cloudfront.net. While running, it connects to the Internet address 208.43.241.178-static.reverse.softlayer.com on port 80 using the HTTP protocol.
MD5:
29b1c823acce43942c17fa092ca2a391

SHA-1:
12c53c3aa58b303e0597025ec16eed66569d5ea2

SHA-256:
feac0cbc954c5a8c65c5cbc53ec51d964fe3a9a7f763b4e1c2c1d118730729a3

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
5/9/2024 1:15:25 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.VOPackage
2015.08.01

Avira AntiVirus
TR/Dldr.Megone.122994
8.3.1.6

avast!
Win32:Malware-gen
2014.9-150901

Baidu Antivirus
Adware.Win32.Downloader
4.0.3.1591

Fortinet FortiGate
PossibleThreat.P0
9/1/2015

Kaspersky
Trojan-Downloader.Win32.Genome
14.0.0.1494

McAfee
RDN/Generic Downloader.x
5600.6656

Panda Antivirus
Trj/CI.A
15.09.01.03

Sophos
Troj/DwnLdr-MTI
4.98

Trend Micro
TROJ_GEN.R0EBC0EHA15
10.465.01

VIPRE Antivirus
Trojan.Win32.Generic
43048

File size:
120.1 KB (122,994 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\wswr.exe

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:0gXdZt9P6D3XJf7WaxpUCkI/OaX/wy0tGRo4sB:0e34t7kCnOO0URu

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.7000

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file wswr.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-235-129-220.compute-1.amazonaws.com  (54.235.129.220:80)

TCP (HTTP):
Connects to 208.43.241.178-static.reverse.softlayer.com  (208.43.241.178:80)

Remove wswr.exe - Powered by Reason Core Security