cdn.exe

Setup

LLC

The application cdn.exe by LLC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from 113.171.224.210 and multiple other hosts.
Publisher:
Open Source  (signed by LLC )

Product:
Setup

Version:
1.2

MD5:
48be6bf921200c02862f78c33b7d5f0b

SHA-1:
bac65a21ada20b8601a5ba56a66bb4f539063a32

SHA-256:
9101c76d6725e7105652c754ffabb497dbeaa9c3af7ed9d931f3600bc67aecb1

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/5/2024 9:52:43 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize.OpenSource.Installer (M)
15.12.11.5

File size:
4.1 MB (4,299,824 bytes)

Product version:
1.2

Copyright:
2015 - Open Source

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\cdn.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/7/2015 3:00:00 AM

Valid to:
5/7/2016 2:59:59 AM

Subject:
CN="LLC ""YOPTA SOFT""", O="LLC ""YOPTA SOFT""", STREET="str.Tsytadelna, 7", L=Kiev, S=Kiev, PostalCode=01015, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1CAFDF1C4C426FC3DD811D48793D99C9

File PE Metadata
Compilation timestamp:
8/5/2015 3:47:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:e3MT9OyiosdgRDXPaOgVF7u8Z8aHSwfA+:X8yiosW7PaPVF7hZGwf9

Entry address:
0x3217

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 09, A3, B8, 67, 44, 00, E8, 05, 2E, 00, 00, A3, 04, 67, 44, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, B8, 94, 42, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, 00, 27, 44, 00, E8, AF, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, F0, 46, 00, 50, 55, E8, 9D, 2A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file cdn.exe has been seen being distributed by the following 2 URLs.

http://113.171.224.210/.../Cdn.exe

Remove cdn.exe - Powered by Reason Core Security