snsme40e.tmp

The file snsme40e.tmp has been detected as a potentially unwanted program by 12 anti-malware scanners. The file has been seen being downloaded from d2htwdv930b0cg.cloudfront.net.
MD5:
8cada4eacf1fcecd84bc53cb2ad4b2c8

SHA-1:
cca86833a1609c1c571d7f1aef2f808c8ceb5754

SHA-256:
df6b41691f66f32e7f55695a80a18dfe8e45cbf0b3e230637bbbdf1c4552b913

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
3/10/2025 3:01:22 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Mikey.11348
5676356

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150514

Dr.Web
Adware.ClickMeIn.1001
9.0.1.0134

Emsisoft Anti-Malware
Gen:Variant.Mikey.11348
9.0.0.4799

ESET NOD32
Win32/Adware.ConvertAd.FE
9.11599

F-Secure
Gen:Variant.Mikey.11348
5.13.68

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2041

McAfee
RDN/Generic PUP.x!cwm
5600.6765

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.5.14.14

Sophos
Generic PUA FJ
4.98

VIPRE Antivirus
Threat.4150696
38950

File size:
125.5 KB (128,512 bytes)

Common path:
C:\users\{user}\appdata\local\8ab8715c-1428871879-11e0-a851-46345429cc61\snsme40e.tmp

File PE Metadata
Compilation timestamp:
4/12/2015 7:01:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:lhbUxHJl83z9pucptnJS+3GuDmSs+hoIUkm/DORk5WODM8OgOQpk2uy:lVUxplY/ucTXZDmSsl8UNWKM8OgRk2u

Entry address:
0xBB6C

Entry point:
E8, D4, 3D, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 40, 62, 41, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, A4, 60, 41, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 8B, 55, 08, 56, 57, 85, D2, 74, 07, 8B, 7D, 0C, 85, FF, 75, 13, E8, B1, 11, 00, 00, 6A, 16, 5E, 89, 30, E8, 55, 11, 00, 00, 8B, C6, EB, 33, 8B, 45...
 
[+]

Entropy:
6.3039

Code size:
83.5 KB (85,504 bytes)

The file snsme40e.tmp has been seen being distributed by the following URL.

Remove snsme40e.tmp - Powered by Reason Core Security