| File name: | nextrp.exe |
| Full analysis: | https://app.any.run/tasks/eb0e5a5b-21ae-4410-a5e6-d33b6de722c2 |
| Verdict: | Malicious activity |
| Analysis date: | May 18, 2024, 18:46:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | C2B3D43AD2E38430507FA416B91F3B21 |
| SHA1: | BA3D0D190AD9B9E05CBA2E7FC0118950C17BF7A2 |
| SHA256: | 562B0434D8F225C6D9696CD62CB4C562598250972AC2EBDE6560DDD75704406E |
| SSDEEP: | 6144:qbjEyARGAAmKDABAnEyALGAAmKDARAWOh5G:C7Ac7A+h5G |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2051:04:21 13:59:32+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 137216 |
| InitializedDataSize: | 132608 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2368a |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | - |
| FileDescription: | nextrp |
| FileVersion: | 1.0.0.0 |
| InternalName: | NEXTRP.exe |
| LegalCopyright: | Copyright © 2021 |
| LegalTrademarks: | - |
| OriginalFileName: | NEXTRP.exe |
| ProductName: | nextrp |
| ProductVersion: | 1.0.0.0 |
| AssemblyVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1112 | "C:\Users\admin\AppData\Local\Temp\nextrp-launcher.exe" /n | C:\Users\admin\AppData\Local\Temp\nextrp-launcher.exe | nextrp.exe | ||||||||||||
User: admin Company: IP Lipatnikov Matvey Nikolaevich Integrity Level: HIGH Description: NEXTRP Launcher Version: 2023.5.16 Modules
| |||||||||||||||
| 3984 | "C:\Users\admin\AppData\Local\Temp\nextrp.exe" | C:\Users\admin\AppData\Local\Temp\nextrp.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: nextrp Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 4084 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3984) nextrp.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: nextrp.exe | |||
| (PID) Process: | (3984) nextrp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nextrp_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3984) nextrp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nextrp_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3984) nextrp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nextrp_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (3984) nextrp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nextrp_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (3984) nextrp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nextrp_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (3984) nextrp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nextrp_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (3984) nextrp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nextrp_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3984) nextrp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nextrp_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3984) nextrp.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\nextrp_RASMANCS |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3984 | nextrp.exe | C:\Users\admin\AppData\Local\Temp\nextrp-launcher.exe.temp | — | |
MD5:— | SHA256:— | |||
| 3984 | nextrp.exe | C:\Users\admin\AppData\Local\Temp\nextrp-launcher.exe | — | |
MD5:— | SHA256:— | |||
| 1112 | nextrp-launcher.exe | C:\Users\admin\AppData\Local\Temp\nss86A.tmp\app-32.7z | — | |
MD5:— | SHA256:— | |||
| 1112 | nextrp-launcher.exe | C:\Program Files\NEXTRP Launcher\extras\icons\favicon.png | — | |
MD5:— | SHA256:— | |||
| 1112 | nextrp-launcher.exe | C:\Program Files\NEXTRP Launcher\extras\icons\512x512.png | image | |
MD5:53CE6ED7E554FE5B396C0B1FD34CB6BB | SHA256:1479F8CD0F4D630958EA3632687BB8F17F64256039E340B7C83E31AE7F20FA32 | |||
| 1112 | nextrp-launcher.exe | C:\Users\admin\AppData\Local\Temp\nss86A.tmp\nsProcess.dll | executable | |
MD5:F0438A894F3A7E01A4AAE8D1B5DD0289 | SHA256:30C6C3DD3CC7FCEA6E6081CE821ADC7B2888542DAE30BF00E881C0A105EB4D11 | |||
| 1112 | nextrp-launcher.exe | C:\Program Files\NEXTRP Launcher\extras\lt\base_library.zip | compressed | |
MD5:9CBBC1DCE526EF58878AD7E94AD8BDF2 | SHA256:FEACD30B21AD6362E6F7E5C136F0E6DBE220AF8117F9DB773AD9EF7B83466307 | |||
| 1112 | nextrp-launcher.exe | C:\Program Files\NEXTRP Launcher\extras\icons\icon.ico | image | |
MD5:67C4F70A97147BA21EC179AD186A9C30 | SHA256:8F434137B356E81CD17B7DF92EC3EEABBF375275A0E1D9CEF5B8D5E814C89065 | |||
| 1112 | nextrp-launcher.exe | C:\Program Files\NEXTRP Launcher\extras\icons\64x64.png | image | |
MD5:FD69CD1F23840CA76F106B07DB617DC6 | SHA256:535933A5EEAF2F80CDAD43DEF271481BEBBCD97B047A8D0A1285FF9F123C1F9E | |||
| 1112 | nextrp-launcher.exe | C:\Users\admin\AppData\Local\Temp\nss86A.tmp\System.dll | executable | |
MD5:0D7AD4F45DC6F5AA87F606D0331C6901 | SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3984 | nextrp.exe | 89.248.192.205:443 | download.gamecluster.nextrp.ru | OOO Network of data-centers Selectel | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
download.gamecluster.nextrp.ru |
| unknown |