File name:

NexHub Sp00fer.exe

Full analysis: https://app.any.run/tasks/2fcb6847-b43b-4a02-b8b5-24cb847951d4
Verdict: Malicious activity
Analysis date: July 31, 2024, 21:05:50
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (console) x86-64, for MS Windows
MD5:

DF8D44C2F2DDDE16973970C954ACF712

SHA1:

9858386EE834D4F3AF3C8E7D40D09E4610BE234F

SHA256:

D87F1B5138C662D6A0969C12A6DCC7482DD9F320A578168671226A29D840A972

SSDEEP:

98304:6eMmS24/gQoaLjz9BNoLeBIurtMsF7NQrhJ48MiAJ0phYKWpGxOs60HrBz9mjsaU:YchW44obSPl9h

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • NexHub Sp00fer.exe (PID: 6728)
  • SUSPICIOUS

    • Application launched itself

      • NexHub Sp00fer.exe (PID: 6728)
    • Reads the BIOS version

      • NexHub Sp00fer.exe (PID: 6964)
    • Starts CMD.EXE for commands execution

      • NexHub Sp00fer.exe (PID: 6728)
    • Reads the date of Windows installation

      • NexHub Sp00fer.exe (PID: 6964)
    • Hides command output

      • cmd.exe (PID: 6880)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 6880)
  • INFO

    • Checks supported languages

      • NexHub Sp00fer.exe (PID: 6964)
      • NexHub Sp00fer.exe (PID: 6728)
    • Reads the computer name

      • NexHub Sp00fer.exe (PID: 6728)
      • NexHub Sp00fer.exe (PID: 6964)
    • Process checks whether UAC notifications are on

      • NexHub Sp00fer.exe (PID: 6964)
    • Reads product name

      • NexHub Sp00fer.exe (PID: 6964)
    • Reads Windows Product ID

      • NexHub Sp00fer.exe (PID: 6964)
    • Reads Environment values

      • NexHub Sp00fer.exe (PID: 6964)
    • Create files in a temporary directory

      • NexHub Sp00fer.exe (PID: 6728)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:07:22 05:09:17+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.4
CodeSize: 53760
InitializedDataSize: 6050304
UninitializedDataSize: -
EntryPoint: 0xac9b32
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start nexhub sp00fer.exe conhost.exe no specs cmd.exe no specs nexhub sp00fer.exe conhost.exe no specs cmd.exe no specs reg.exe no specs nexhub sp00fer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6552"C:\Users\admin\AppData\Local\Temp\NexHub Sp00fer.exe" C:\Users\admin\AppData\Local\Temp\NexHub Sp00fer.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\nexhub sp00fer.exe
c:\windows\system32\ntdll.dll
6728"C:\Users\admin\AppData\Local\Temp\NexHub Sp00fer.exe" C:\Users\admin\AppData\Local\Temp\NexHub Sp00fer.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nexhub sp00fer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6736reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore" /f C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6768\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeNexHub Sp00fer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6880C:\WINDOWS\system32\cmd.exe /c reg delete "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore" /f > nul 2>&1C:\Windows\System32\cmd.exeNexHub Sp00fer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
6888C:\WINDOWS\system32\cmd.exe /c clsC:\Windows\System32\cmd.exeNexHub Sp00fer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
6964ar C:\Users\admin\AppData\Local\Temp\NexHub Sp00fer.exe
NexHub Sp00fer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nexhub sp00fer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6976\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeNexHub Sp00fer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
600
Read events
593
Write events
0
Delete events
7

Modification events

(PID) Process:(6736) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5934daeb_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}
Operation:delete keyName:(default)
Value:
(PID) Process:(6736) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5934daeb_0
Operation:delete keyName:(default)
Value:
(PID) Process:(6736) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5bd7fff7_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}
Operation:delete keyName:(default)
Value:
(PID) Process:(6736) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\5bd7fff7_0
Operation:delete keyName:(default)
Value:
(PID) Process:(6736) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\fb78376_0\{219ED5A0-9CBF-4F3A-B927-37C9E5C5F14F}
Operation:delete keyName:(default)
Value:
(PID) Process:(6736) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\fb78376_0
Operation:delete keyName:(default)
Value:
(PID) Process:(6736) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore
Operation:delete keyName:(default)
Value:
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
35
DNS requests
15
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6964
NexHub Sp00fer.exe
POST
200
45.141.37.12:8080
http://141.95.84.21:3522/v9dhLA0go5
unknown
unknown
6964
NexHub Sp00fer.exe
POST
200
45.141.37.12:8080
http://141.95.84.21:3522/NG9Oubp8wI
unknown
unknown
4544
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4544
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6200
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6244
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5512
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4936
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
whitelisted
6964
NexHub Sp00fer.exe
45.141.37.12:8080
combahton GmbH
DE
unknown
5336
SearchApp.exe
2.23.209.189:443
www.bing.com
Akamai International B.V.
GB
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.110
whitelisted
www.bing.com
  • 2.23.209.189
  • 2.23.209.179
  • 2.23.209.149
  • 2.23.209.182
  • 2.23.209.130
  • 2.23.209.140
  • 2.23.209.133
  • 2.23.209.187
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
login.live.com
  • 40.126.32.138
  • 40.126.32.72
  • 40.126.32.134
  • 40.126.32.133
  • 20.190.160.17
  • 40.126.32.136
  • 40.126.32.76
  • 40.126.32.74
whitelisted
th.bing.com
  • 2.23.209.140
  • 2.23.209.187
  • 2.23.209.182
  • 2.23.209.189
  • 2.23.209.179
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.130
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted

Threats

PID
Process
Class
Message
6964
NexHub Sp00fer.exe
Potentially Bad Traffic
ET HUNTING curl User-Agent to Dotted Quad
6964
NexHub Sp00fer.exe
Potentially Bad Traffic
ET HUNTING curl User-Agent to Dotted Quad
No debug info