| File name: | Injector Nova.exe |
| Full analysis: | https://app.any.run/tasks/db96c276-a51b-400f-b8b1-690157e33139 |
| Verdict: | Malicious activity |
| Analysis date: | October 29, 2023, 22:06:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows |
| MD5: | 150D4DF3609CC0478D23D0E4088397F0 |
| SHA1: | 67EDBAD3159EBC8A382B424733BDAD24DD29FF69 |
| SHA256: | E7CD16293C227159D514591C5519E4A5A18FBAE38BF27B73FB9C4117A1E3B6F7 |
| SSDEEP: | 98304:AL5/O63SLBhAfJ+rhVgCgxLOWNNVTVXDgH4tMqswIZh7/FYGNFnIhNwbKDdwzfDA:nRib8UpbrG8Nb8kgNpML |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2023:10:26 13:42:00+02:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.35 |
| CodeSize: | 171008 |
| InitializedDataSize: | 94720 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xc260 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.0.22621.1 |
| ProductVersionNumber: | 10.0.22621.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corporation |
| FileDescription: | NetBT Unattend Generic Command |
| FileVersion: | 10.0.22621.1 (WinBuild.160101.0800) |
| InternalName: | netbtugc.exe |
| LegalCopyright: | © Microsoft Corporation. All rights reserved. |
| OriginalFileName: | netbtugc.exe |
| ProductName: | Microsoft® Windows® Operating System |
| ProductVersion: | 10.0.22621.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 992 | "C:\Users\admin\AppData\Local\Temp\Injector Nova.exe" | C:\Users\admin\AppData\Local\Temp\Injector Nova.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: NetBT Unattend Generic Command Exit code: 0 Version: 10.0.22621.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3036 | "C:\Users\admin\AppData\Local\Temp\Injector Nova.exe" | C:\Users\admin\AppData\Local\Temp\Injector Nova.exe | — | Injector Nova.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: NetBT Unattend Generic Command Exit code: 0 Version: 10.0.22621.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 992 | Injector Nova.exe | C:\Users\admin\AppData\Local\Temp\_MEI9922\_decimal.pyd | executable | |
MD5:E3FB8BF23D857B1EB860923CCC47BAA5 | SHA256:7DA13DF1F416D3FFD32843C895948E460AF4DC02CF05C521909555061ED108E3 | |||
| 992 | Injector Nova.exe | C:\Users\admin\AppData\Local\Temp\_MEI9922\_bz2.pyd | executable | |
MD5:C413931B63DEF8C71374D7826FBF3AB4 | SHA256:17BFA656CABF7EF75741003497A1C315B10237805FF171D44625A04C16532293 | |||
| 992 | Injector Nova.exe | C:\Users\admin\AppData\Local\Temp\_MEI9922\VCRUNTIME140.dll | executable | |
MD5:49C96CECDA5C6C660A107D378FDFC3D4 | SHA256:69320F278D90EFAAEB67E2A1B55E5B0543883125834C812C8D9C39676E0494FC | |||
| 992 | Injector Nova.exe | C:\Users\admin\AppData\Local\Temp\_MEI9922\blank.aes | binary | |
MD5:19F48C8AF0326E86D5EF13429CBD3624 | SHA256:84841289ABA9682C917E7B2C9CFA2080979DBF9282A49CEC84F311D3BDF12D7A | |||
| 992 | Injector Nova.exe | C:\Users\admin\AppData\Local\Temp\_MEI9922\_ctypes.pyd | executable | |
MD5:00F75DAAA7F8A897F2A330E00FAD78AC | SHA256:9FFADCB2C40AE6B67AB611ACC09E050BBE544672CF05E8402A7AA3936326DE1F | |||
| 992 | Injector Nova.exe | C:\Users\admin\AppData\Local\Temp\_MEI9922\_lzma.pyd | executable | |
MD5:542EAB18252D569C8ABEF7C58D303547 | SHA256:D2A7111FEEAACAC8B3A71727482565C46141CC7A5A3D837D8349166BEA5054C9 | |||
| 992 | Injector Nova.exe | C:\Users\admin\AppData\Local\Temp\_MEI9922\_sqlite3.pyd | executable | |
MD5:1A8FDC36F7138EDCC84EE506C5EC9B92 | SHA256:8E4B9DA9C95915E864C89856E2D7671CD888028578A623E761AEAC2FECA04882 | |||
| 992 | Injector Nova.exe | C:\Users\admin\AppData\Local\Temp\_MEI9922\_socket.pyd | executable | |
MD5:1A34253AA7C77F9534561DC66AC5CF49 | SHA256:DC03D32F681634E682B02E9A60FDFCE420DB9F26754AEFB9A58654A064DC0F9F | |||
| 992 | Injector Nova.exe | C:\Users\admin\AppData\Local\Temp\_MEI9922\_ssl.pyd | executable | |
MD5:F9CC7385B4617DF1DDF030F594F37323 | SHA256:B093AA2E84A30790ABEEE82CF32A7C2209978D862451F1E0B0786C4D22833CB6 | |||
| 992 | Injector Nova.exe | C:\Users\admin\AppData\Local\Temp\_MEI9922\bound.blank | binary | |
MD5:C50ECC5CCC2AEE99B9E5D289556456B7 | SHA256:36238372690021888717B1DC0BF72AAAE9778A6391145A3B6A0D4E4C48BC813E | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |