File name:

nexigo_setup_v02.exe

Full analysis: https://app.any.run/tasks/105d16a4-74ac-4e9d-94c6-043868c00e80
Verdict: Malicious activity
Analysis date: December 05, 2023, 22:03:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

225B32359161E983DDBF689ADB3139F7

SHA1:

2534C8360A361C0DB96E47FD70A8593DE672EA37

SHA256:

43E0605E021FF7666F6D7C3A486386545844DEFF8AED2266FFDAD82F08DF2328

SSDEEP:

24576:R4nXubIQGyxbPV0db26fpaHKgh9dhv6F5r4MCSRdTkp+Fg5Fktcx1pi4Vx3X6nVb:Rqe3f6tpKdhioxSRdTmy4FQqh5wyC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • nexigo_setup_v02.exe (PID: 1236)
      • nexigo_setup_v02.exe (PID: 280)
      • nexigo_setup_v02.tmp (PID: 2464)
  • SUSPICIOUS

    • Reads the Internet Settings

      • NexiGo.exe (PID: 1116)
    • Reads the Windows owner or organization settings

      • nexigo_setup_v02.tmp (PID: 2464)
    • Process drops legitimate windows executable

      • nexigo_setup_v02.tmp (PID: 2464)
  • INFO

    • Checks supported languages

      • nexigo_setup_v02.exe (PID: 1236)
      • nexigo_setup_v02.tmp (PID: 3980)
      • nexigo_setup_v02.exe (PID: 280)
      • NexiGo.exe (PID: 1116)
      • wmpnscfg.exe (PID: 2336)
      • nexigo_setup_v02.tmp (PID: 2464)
    • Create files in a temporary directory

      • nexigo_setup_v02.exe (PID: 1236)
      • nexigo_setup_v02.exe (PID: 280)
    • Creates files in the program directory

      • nexigo_setup_v02.tmp (PID: 2464)
    • Reads the computer name

      • nexigo_setup_v02.tmp (PID: 3980)
      • NexiGo.exe (PID: 1116)
      • nexigo_setup_v02.tmp (PID: 2464)
      • wmpnscfg.exe (PID: 2336)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2336)
    • Reads the machine GUID from the registry

      • NexiGo.exe (PID: 1116)
    • Creates files or folders in the user directory

      • NexiGo.exe (PID: 1116)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:15 10:48:30+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 43008
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Nexight Inc
FileDescription: NexiGo Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: NexiGo
ProductVersion: 1.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start nexigo_setup_v02.exe no specs nexigo_setup_v02.tmp no specs nexigo_setup_v02.exe nexigo_setup_v02.tmp no specs nexigo.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280"C:\Users\admin\AppData\Local\Temp\nexigo_setup_v02.exe" /SPAWNWND=$1601F0 /NOTIFYWND=$25013A C:\Users\admin\AppData\Local\Temp\nexigo_setup_v02.exe
nexigo_setup_v02.tmp
User:
admin
Company:
Nexight Inc
Integrity Level:
HIGH
Description:
NexiGo Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\nexigo_setup_v02.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1116"C:\Program Files\NexiGo\NexiGo.exe"C:\Program Files\NexiGo\NexiGo.exenexigo_setup_v02.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
CamCtl
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\nexigo\nexigo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1236"C:\Users\admin\AppData\Local\Temp\nexigo_setup_v02.exe" C:\Users\admin\AppData\Local\Temp\nexigo_setup_v02.exeexplorer.exe
User:
admin
Company:
Nexight Inc
Integrity Level:
MEDIUM
Description:
NexiGo Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\nexigo_setup_v02.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2336"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2464"C:\Users\admin\AppData\Local\Temp\is-OVO5S.tmp\nexigo_setup_v02.tmp" /SL5="$1B0190,1188420,785408,C:\Users\admin\AppData\Local\Temp\nexigo_setup_v02.exe" /SPAWNWND=$1601F0 /NOTIFYWND=$25013A C:\Users\admin\AppData\Local\Temp\is-OVO5S.tmp\nexigo_setup_v02.tmpnexigo_setup_v02.exe
User:
admin
Company:
Nexight Inc
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-ovo5s.tmp\nexigo_setup_v02.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3980"C:\Users\admin\AppData\Local\Temp\is-8U65J.tmp\nexigo_setup_v02.tmp" /SL5="$25013A,1188420,785408,C:\Users\admin\AppData\Local\Temp\nexigo_setup_v02.exe" C:\Users\admin\AppData\Local\Temp\is-8U65J.tmp\nexigo_setup_v02.tmpnexigo_setup_v02.exe
User:
admin
Company:
Nexight Inc
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-8u65j.tmp\nexigo_setup_v02.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
1 234
Read events
1 220
Write events
8
Delete events
6

Modification events

(PID) Process:(1116) NexiGo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1116) NexiGo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1116) NexiGo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1116) NexiGo.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2464) nexigo_setup_v02.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
65957CB0218FFFB1D61A9DC0489CB6E9F4A5FCE681A40CBAD60494E9E34C0228
(PID) Process:(2464) nexigo_setup_v02.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\NexiGo\NexiGo.exe
(PID) Process:(2464) nexigo_setup_v02.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(2464) nexigo_setup_v02.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
C043006F78313450A3D832F665CA0601EC0EAC5CA549B838853AB7681E018988
(PID) Process:(2464) nexigo_setup_v02.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
A00900002E2EC5DCC627DA01
(PID) Process:(2464) nexigo_setup_v02.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
Executable files
24
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2464nexigo_setup_v02.tmpC:\Program Files\NexiGo\System.Buffers.dllexecutable
MD5:ECDFE8EDE869D2CCC6BF99981EA96400
SHA256:ACCCCFBE45D9F08FFEED9916E37B33E98C65BE012CFFF6E7FA7B67210CE1FEFB
2464nexigo_setup_v02.tmpC:\Program Files\NexiGo\is-H8BJE.tmpexecutable
MD5:0BD34AA29C7EA4181900797395A6DA78
SHA256:BAFA6ED04CA2782270074127A0498DDE022C2A9F4096C6BB2B8E3C08BB3D404D
2464nexigo_setup_v02.tmpC:\Program Files\NexiGo\AForge.Video.dllexecutable
MD5:0BD34AA29C7EA4181900797395A6DA78
SHA256:BAFA6ED04CA2782270074127A0498DDE022C2A9F4096C6BB2B8E3C08BB3D404D
2464nexigo_setup_v02.tmpC:\Program Files\NexiGo\PInvoke.Windows.Core.dllexecutable
MD5:B4530C26254BF6B35FCDACEA78A96463
SHA256:A5C4F42F0A6711D7275ADB2218862F66EFF6548211C7E7E6DC4024B50003DDC0
2464nexigo_setup_v02.tmpC:\Program Files\NexiGo\Newtonsoft.Json.dllexecutable
MD5:6815034209687816D8CF401877EC8133
SHA256:7F912B28A07C226E0BE3ACFB2F57F050538ABA0100FA1F0BF2C39F1A1F1DA814
2464nexigo_setup_v02.tmpC:\Program Files\NexiGo\is-GOVCO.tmpexecutable
MD5:94AE30B18028C00336C995F9FF78F219
SHA256:B6847497DB3CFC3A91A46AB95C925EA4389C0DA95F4B2B4B013E08E3270E5077
2464nexigo_setup_v02.tmpC:\Program Files\NexiGo\AForge.dllexecutable
MD5:02C63F568E598AAD85DD401D7B26E82A
SHA256:966A474060A8ACA70C73BA09D0B6FE2353035961C7107B9003EF879C010FF8DA
2464nexigo_setup_v02.tmpC:\Program Files\NexiGo\unins000.exeexecutable
MD5:94AE30B18028C00336C995F9FF78F219
SHA256:B6847497DB3CFC3A91A46AB95C925EA4389C0DA95F4B2B4B013E08E3270E5077
2464nexigo_setup_v02.tmpC:\Program Files\NexiGo\is-P0KJK.tmpexecutable
MD5:6FB95A357A3F7E88ADE5C1629E2801F8
SHA256:8E76318E8B06692ABF7DAB1169D27D15557F7F0A34D36AF6463EFF0FE21213C7
2464nexigo_setup_v02.tmpC:\Program Files\NexiGo\System.Memory.dllexecutable
MD5:6FB95A357A3F7E88ADE5C1629E2801F8
SHA256:8E76318E8B06692ABF7DAB1169D27D15557F7F0A34D36AF6463EFF0FE21213C7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
868
svchost.exe
23.35.228.137:80
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
88.221.124.138:80
armmf.adobe.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 88.221.124.138
whitelisted

Threats

No threats detected
No debug info