nsic2c7.tmp

The file nsic2c7.tmp has been detected as a potentially unwanted program by 3 anti-malware scanners. The file has been seen being downloaded from d5qlpohh1zul3.cloudfront.net.
MD5:
ff730db826b81f3a956b004de26cb8e1

SHA-1:
9bbfceb1df7a04ee5fc7dfaa59732dd5dc8d2995

SHA-256:
aa0ac3c3cac0d3f2d9b6834135a190eb66ba8949df424b126d9dd55ed2387618

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 9:52:45 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-gen [Adw]
160216-0

AVG
Adware Generic6.CINH
2015.0.4522

Reason Heuristics
Adware.Generic.AT
16.2.29.16

File size:
424 KB (434,216 bytes)

Common path:
C:\users\{user}\appdata\local\temp\nsic2c7.tmp

File PE Metadata
Compilation timestamp:
5/4/2015 12:07:48 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:wl8xY18cx6mO6t7su6nwufIjXxX8aYU+a7:OD1x6mO6wuAsj98T3Q

Entry address:
0x2666F

Entry point:
E8, CF, DD, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 74, 10, 8B, 55, 0C, 85, D2, 74, 09, 8B, 4D, 10, 85, C9, 75, 16, 88, 0E, E8, D5, 24, 00, 00, 6A, 16, 5E, 89, 30, E8, A0, 6F, 00, 00, 8B, C6, 5E, 5D, C3, 57, 8B, FE, 2B, F9, 8A, 01, 88, 04, 0F, 41, 84, C0, 74, 03, 4A, 75, F3, 5F, 85, D2, 75, 0B, 88, 16, E8, A8, 24, 00, 00, 6A, 22, EB, D1, 33, C0, EB, D7, 55, 8B, EC, 56, 57, 8B, 7D, 08, 85, FF, 74, 11, 8B, 4D, 0C, 85, C9, 74, 0A, 8B, 75, 10, 85, F6, 75, 18, C6, 07, 00, E8, 7E, 24, 00...
 
[+]

Code size:
253.5 KB (259,584 bytes)

The file nsic2c7.tmp has been seen being distributed by the following URL.

Remove nsic2c7.tmp - Powered by Reason Core Security