File name:

NXTPKIENT.exe

Full analysis: https://app.any.run/tasks/4f2832d4-3971-4ab7-a4f4-b27f852b7cab
Verdict: Malicious activity
Analysis date: January 26, 2024, 05:50:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

EB8D073840E95CF24C9C3F5A2B6470E0

SHA1:

2399567292F1E81630997FB4A151786D3E4938BB

SHA256:

0DD9AA5B650F519A55C96BF0DEE73162D9BA510B60521780C34811DE25CD7BB6

SSDEEP:

98304:jKOo2aRI8yRksFqyG6vi7aRysjGLIKxnRVEt2zwDC+STkbLHLIeskoNc5ZZotW5U:J5lYpXm/4x

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • NXTPKIENT.exe (PID: 1936)
      • NXTPKIENT.exe (PID: 980)
      • NXTPKIENT.tmp (PID: 2260)
    • Steals credentials from Web Browsers

      • RegCert.exe (PID: 3416)
    • Actions looks like stealing of personal data

      • RegCert.exe (PID: 3416)
      • RegCert.exe (PID: 3572)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NXTPKIENT.exe (PID: 1936)
      • NXTPKIENT.exe (PID: 980)
      • NXTPKIENT.tmp (PID: 2260)
    • Reads the Windows owner or organization settings

      • NXTPKIENT.tmp (PID: 2260)
    • Reads the Internet Settings

      • NXTPKIENT.tmp (PID: 2260)
    • Uses TASKKILL.EXE to kill Browsers

      • NXTPKIENT.tmp (PID: 2260)
    • Uses TASKKILL.EXE to kill process

      • NXTPKIENT.tmp (PID: 2260)
    • Process drops legitimate windows executable

      • NXTPKIENT.tmp (PID: 2260)
    • Executes as Windows Service

      • PWSLocalServer.exe (PID: 3452)
    • The process drops C-runtime libraries

      • NXTPKIENT.tmp (PID: 2260)
  • INFO

    • Checks supported languages

      • NXTPKIENT.exe (PID: 1936)
      • NXTPKIENT.tmp (PID: 2568)
      • wmpnscfg.exe (PID: 2712)
      • NXTPKIENT.exe (PID: 980)
      • NXTPKIENT.tmp (PID: 2260)
      • PWSLocalServer.exe (PID: 2528)
      • PWSLocalServer.exe (PID: 3244)
      • RegCert.exe (PID: 3416)
      • PWSLocalServer.exe (PID: 3452)
      • Locale.exe (PID: 3088)
      • RegCert.exe (PID: 3572)
    • Create files in a temporary directory

      • NXTPKIENT.exe (PID: 1936)
      • NXTPKIENT.exe (PID: 980)
    • Reads the computer name

      • NXTPKIENT.tmp (PID: 2568)
      • wmpnscfg.exe (PID: 2712)
      • NXTPKIENT.tmp (PID: 2260)
      • PWSLocalServer.exe (PID: 2528)
      • RegCert.exe (PID: 3416)
      • PWSLocalServer.exe (PID: 3244)
      • PWSLocalServer.exe (PID: 3452)
      • RegCert.exe (PID: 3572)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2712)
    • Creates files in the program directory

      • NXTPKIENT.tmp (PID: 2260)
    • Creates files or folders in the user directory

      • NXTPKIENT.tmp (PID: 2260)
      • RegCert.exe (PID: 3572)
    • Reads Environment values

      • PWSLocalServer.exe (PID: 2528)
    • Reads product name

      • PWSLocalServer.exe (PID: 2528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (81.5)
.exe | Win32 Executable Delphi generic (10.5)
.exe | Win32 Executable (generic) (3.3)
.exe | Win16/32 Executable Delphi generic (1.5)
.exe | Generic Win/DOS Executable (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41984
InitializedDataSize: 188416
UninitializedDataSize: -
EntryPoint: 0xaad0
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.2.8.9
ProductVersionNumber: 1.2.8.9
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: SGA Solutions Co.,Ltd.
FileDescription: TrustPKI Enterprise Non-ActiveX Client Setup
FileVersion: 1.2.8.9
LegalCopyright: Copyright 2015. SGA Solutions Co., Ltd. All rights reserved.
ProductName: TrustPKI Enterprise Non-ActiveX Client
ProductVersion: 1.2.8.9
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
19
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start nxtpkient.exe nxtpkient.tmp no specs wmpnscfg.exe no specs nxtpkient.exe nxtpkient.tmp taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs pwslocalserver.exe no specs pwslocalserver.exe no specs regcert.exe pwslocalserver.exe regcert.exe locale.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
980"C:\Users\admin\AppData\Local\Temp\NXTPKIENT.exe" /SPAWNWND=$1501BC /NOTIFYWND=$B017A C:\Users\admin\AppData\Local\Temp\NXTPKIENT.exe
NXTPKIENT.tmp
User:
admin
Company:
SGA Solutions Co.,Ltd.
Integrity Level:
HIGH
Description:
TrustPKI Enterprise Non-ActiveX Client Setup
Exit code:
0
Version:
1.2.8.9
Modules
Images
c:\users\admin\appdata\local\temp\nxtpkient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1232"C:\Windows\System32\taskkill.exe" /F /IM safari.exeC:\Windows\System32\taskkill.exeNXTPKIENT.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1484"C:\Windows\System32\taskkill.exe" /F /IM MicrosoftEdge.exeC:\Windows\System32\taskkill.exeNXTPKIENT.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1820"C:\Windows\System32\taskkill.exe" /F /IM chrome.exeC:\Windows\System32\taskkill.exeNXTPKIENT.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1936"C:\Users\admin\AppData\Local\Temp\NXTPKIENT.exe" C:\Users\admin\AppData\Local\Temp\NXTPKIENT.exe
explorer.exe
User:
admin
Company:
SGA Solutions Co.,Ltd.
Integrity Level:
MEDIUM
Description:
TrustPKI Enterprise Non-ActiveX Client Setup
Exit code:
0
Version:
1.2.8.9
Modules
Images
c:\users\admin\appdata\local\temp\nxtpkient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1972"C:\Windows\System32\taskkill.exe" /F /IM opera.exeC:\Windows\System32\taskkill.exeNXTPKIENT.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2260"C:\Users\admin\AppData\Local\Temp\is-20JHB.tmp\NXTPKIENT.tmp" /SL5="$F015E,6291726,231424,C:\Users\admin\AppData\Local\Temp\NXTPKIENT.exe" /SPAWNWND=$1501BC /NOTIFYWND=$B017A C:\Users\admin\AppData\Local\Temp\is-20JHB.tmp\NXTPKIENT.tmp
NXTPKIENT.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-20jhb.tmp\nxtpkient.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2452"C:\Windows\System32\taskkill.exe" /F /IM iexplore.exeC:\Windows\System32\taskkill.exeNXTPKIENT.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2528"C:\Program Files\EPS\Lib\Support\PWSLocalServer.exe" iC:\Program Files\EPS\Lib\Support\PWSLocalServer.exeNXTPKIENT.tmp
User:
admin
Company:
SGA Solutions
Integrity Level:
HIGH
Description:
SGA Solutions Client Support Service
Exit code:
0
Version:
1.1.11.6
Modules
Images
c:\program files\eps\lib\support\pwslocalserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2568"C:\Users\admin\AppData\Local\Temp\is-QCMVB.tmp\NXTPKIENT.tmp" /SL5="$B017A,6291726,231424,C:\Users\admin\AppData\Local\Temp\NXTPKIENT.exe" C:\Users\admin\AppData\Local\Temp\is-QCMVB.tmp\NXTPKIENT.tmpNXTPKIENT.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-qcmvb.tmp\nxtpkient.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
4 081
Read events
4 048
Write events
27
Delete events
6

Modification events

(PID) Process:(2260) NXTPKIENT.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2260) NXTPKIENT.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2260) NXTPKIENT.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2260) NXTPKIENT.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3416) RegCert.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3088) Locale.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage
Operation:writeName:ACP
Value:
1252
(PID) Process:(3088) Locale.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage
Operation:writeName:MACCP
Value:
10000
(PID) Process:(3088) Locale.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage
Operation:writeName:OEMCP
Value:
437
(PID) Process:(3088) Locale.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language
Operation:writeName:Default
Value:
0409
(PID) Process:(3088) Locale.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale
Operation:writeName:(Default)
Value:
00000409
Executable files
52
Suspicious files
113
Text files
6
Unknown types
13

Dropped files

PID
Process
Filename
Type
2260NXTPKIENT.tmpC:\Program Files\EPS\Lib\Support\is-NNN2G.tmpexecutable
MD5:44F35E5C41DB978B03F132A99B5AB6A9
SHA256:6585D2E22389C024BF427A2C3B91990BECAEBC963E8119927552CB2925B62DC4
2260NXTPKIENT.tmpC:\Program Files\EPS\Lib\Support\is-BUVPE.tmpexecutable
MD5:8E06FAE8E03485A85D5A12C7BDDD9726
SHA256:05CC3E5D9025A8836DD19099850C416633832BC729307E3187D43278A2C10BA5
2260NXTPKIENT.tmpC:\Program Files\EPS\Lib\Support\freebl3.dllexecutable
MD5:44F35E5C41DB978B03F132A99B5AB6A9
SHA256:6585D2E22389C024BF427A2C3B91990BECAEBC963E8119927552CB2925B62DC4
2260NXTPKIENT.tmpC:\Program Files\EPS\Lib\Support\libeay32.dllexecutable
MD5:8E06FAE8E03485A85D5A12C7BDDD9726
SHA256:05CC3E5D9025A8836DD19099850C416633832BC729307E3187D43278A2C10BA5
2260NXTPKIENT.tmpC:\Program Files\EPS\Lib\Support\is-GI18A.tmpexecutable
MD5:19D292B0D8D417C90440B41AEFD8A38E
SHA256:8809265003CC78CC7BFE708D0140F4045C86B2379B49B1B772EB25DF1A27E1BE
2260NXTPKIENT.tmpC:\Program Files\EPS\Lib\Support\mfc110.dllexecutable
MD5:19D292B0D8D417C90440B41AEFD8A38E
SHA256:8809265003CC78CC7BFE708D0140F4045C86B2379B49B1B772EB25DF1A27E1BE
2260NXTPKIENT.tmpC:\Program Files\EPS\Lib\Support\is-QUTVV.tmpexecutable
MD5:B5926F91E6818F2C89E9C344D2942A9C
SHA256:8D50E30528A6598B980B3D0FF9119B99B2564FA4E39936C9308F954F2AB406AD
2260NXTPKIENT.tmpC:\Program Files\EPS\Lib\Support\nspr4.dllexecutable
MD5:B5926F91E6818F2C89E9C344D2942A9C
SHA256:8D50E30528A6598B980B3D0FF9119B99B2564FA4E39936C9308F954F2AB406AD
2260NXTPKIENT.tmpC:\Program Files\EPS\Lib\Support\is-6P0OF.tmpexecutable
MD5:041648679A243407C234A5B2983BEF14
SHA256:BAE119709C87E3168F1604A255873EB4631D87DE5819A4EFADDC2F792F5D490F
2260NXTPKIENT.tmpC:\Program Files\EPS\Lib\Support\nss3.dllexecutable
MD5:041648679A243407C234A5B2983BEF14
SHA256:BAE119709C87E3168F1604A255873EB4631D87DE5819A4EFADDC2F792F5D490F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
PWSLocalServer.exe
·Î±× ¼³Á¤ ÆÄÀÏÀÌ ¾ø½À´Ï´Ù.