ns-downloader.exe

Next Search

ClientConnect LTD

The file belongs to the ClientConnect (Conduit/Perion) platform, a utility that bundles and monetizes search toolbars and browser add-ons. The application ns-downloader.exe by ClientConnect has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from cdn.chironexfleckerigray.com. While running, it connects to the Internet address cms.dmccint.com on port 80 using the HTTP protocol.
Publisher:
ClientConnect  (signed by ClientConnect LTD)

Product:
Next Search

Version:
1.2.0.7

MD5:
23ee44729a866792ac800ed0925509ae

SHA-1:
65695eae19536a061556e93b9eb0d727f75e4bfb

SHA-256:
18db587e88083e911c4afa24b662568777bec008ec0f2fbaf9f1c21c33472468

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Analysis date:
12/26/2024 11:22:19 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/ClientConnect.A potentially unwanted application
7.0.302.0

K7 AntiVirus
Unwanted-Program
13.194.14964

Reason Heuristics
Threat.Conduit.Installer
15.4.2.1

VIPRE Antivirus
Threat.4786236
36694

File size:
147.5 KB (151,048 bytes)

Product version:
1.2.0.7

Copyright:
© 2014 ClientConnect Ltd.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ns-downloader.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
10/2/2014 2:00:00 AM

Valid to:
10/4/2015 1:59:59 AM

Subject:
CN=ClientConnect LTD, OU=Next Search, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
1CABAC4D3E9F4D2D0D78D81CA571F1CA

File PE Metadata
Compilation timestamp:
7/6/2011 4:31:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:8cmVWD5ltbmP3Q7yxCw9ARMoVjbohE2O1Xpx9+UFEjl71SS8JaGm:jmJIhwwVjbohE2O10UFEfSHJaB

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.7827

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file ns-downloader.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to cms.dmccint.com  (23.67.242.80:80)

 
http://cms.dmccint.com/DynamicOffer/17649210/17670333/?mainofferId=17645776&CurrentStep=2&TotalSteps=4&DownloadBrowser=IE&CType=-1&UserMode=-1&DMVersion=1.3.7.76.17669199.01&Language=US-EN

Remove ns-downloader.exe - Powered by Reason Core Security