NexGuard.exe

NexCafé

Nextar

The application NexGuard.exe has been detected as a potentially unwanted program by 13 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘nexguard’. While running, it connects to the Internet address 200-157-208-249.ded.intelignet.com.br on port 80 using the HTTP protocol.
Publisher:
Nextar

Product:
NexCafé

Description:
NexGuard

Version:
5.0.0.209

MD5:
3ca15635e7bbb6b5d17f71911ea69169

SHA-1:
24919096b1312f1cc35d448f996943eca48b1247

SHA-256:
b488c38cb387f9ce58f0df7d0d0db31d7730654fdab0dfd25de62d84ed6255a3

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
4/23/2024 10:17:20 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.TaskManagerBlock
7.1.1

Avira AntiVirus
TR/Agent.18795520
3.6.1.96

avast!
Win32:Dropper-gen [Drp]
2014.9-151202

Baidu Antivirus
Hacktool.Win32.TaskManagerBlock
4.0.3.15122

G Data
Win32.Trojan.Agent.P5SC54
15.12.25

IKARUS anti.virus
Trojan.Win32.Diztakun
t3scan.1.8.9.0

K7 AntiVirus
Riskware
13.202.15652

Kaspersky
not-a-virus:RiskTool.Win32.TaskManagerBlock
14.0.0.1031

McAfee
Artemis!3CA15635E7BB
5600.6563

Panda Antivirus
Generic Suspicious
15.12.02.09

Qihoo 360 Security
Win32/Trojan.59b
1.0.0.1015

Trend Micro House Call
TROJ_NOTOOLS.BMC
7.2.336

Trend Micro
TROJ_NOTOOLS.BMC
10.465.02

File size:
17.9 MB (18,795,520 bytes)

Product version:
5.0

Original file name:
NexGuard.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

File PE Metadata
Compilation timestamp:
3/10/2015 10:06:22 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:CX4Ag32DoOG+YPljgXehKUzXeB9uX/xxr2rG2lQfUzAxx+RcxvGk+eWvrIvrO:8Rd8OZwGryImx+GxvyvcD

Entry address:
0x855AC8

Entry point:
55, 8B, EC, B9, 0E, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, 28, 72, C4, 00, E8, 4F, 2B, 7B, FF, 33, C0, 55, 68, 9B, 64, C5, 00, 64, FF, 30, 64, 89, 20, A1, 1C, ED, CA, 00, BA, B4, 64, C5, 00, E8, D6, 01, 7B, FF, E8, 71, FC, FC, FF, 33, C9, B2, 01, A1, DC, 43, C2, 00, E8, 5B, 94, 7D, FF, C6, 40, 0F, 01, 33, D2, B8, C8, 64, C5, 00, E8, 77, EB, 8A, FF, A1, 9C, EE, CA, 00, 8B, 00, E8, 4F, A4, 83, FF, E8, 32, F7, FC, FF, C6, 05, 8C, 9E, DF, 00, 00, 8D, 55, E8, 33, C0, E8, 11, DB, 7A, FF, 8B...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
8.3 MB (8,736,768 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
nexguard

Command:
"C:\nexcafe\nexguard.exe"


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ec2-54-94-144-67.sa-east-1.compute.amazonaws.com  (54.94.144.67:80)

TCP (HTTP SSL):
Connects to edge-star-shv-01-gru2.facebook.com  (31.13.85.8:443)

TCP (HTTP):
Connects to mpr1.ngd.vip.ne1.yahoo.com  (98.138.49.44:80)

TCP (HTTP):
Connects to e1.ycpi.vip.bra.yahoo.com  (200.152.162.135:80)

TCP (HTTP SSL):
Connects to ec2-34-206-143-31.compute-1.amazonaws.com  (34.206.143.31:443)

TCP (HTTP):
Connects to mpr2.ngd.vip.ne1.yahoo.com  (216.155.194.56:80)

TCP:
Connects to ec2-34-200-198-210.compute-1.amazonaws.com  (34.200.198.210:1935)

TCP (HTTP SSL):
Connects to server-54-192-227-61.gig50.r.cloudfront.net  (54.192.227.61:443)

TCP (HTTP):
Connects to ec2-54-243-122-57.compute-1.amazonaws.com  (54.243.122.57:80)

TCP (HTTP):
Connects to mpr1.ngd.vip.bf1.yahoo.com  (72.30.3.43:80)

TCP (HTTP SSL):
Connects to e2.ycpi.vip.bra.yahoo.com  (200.152.162.161:443)

TCP (HTTP):
Connects to ec2-54-225-217-148.compute-1.amazonaws.com  (54.225.217.148:80)

TCP:
Connects to ec2-34-199-243-170.compute-1.amazonaws.com  (34.199.243.170:1935)

TCP (HTTP SSL):
Connects to server-54-192-227-39.gig50.r.cloudfront.net  (54.192.227.39:443)

TCP (HTTP):
Connects to s3-website-sa-east-1.amazonaws.com  (52.92.74.3:80)

TCP (HTTP):
Connects to ec2-184-73-209-238.compute-1.amazonaws.com  (184.73.209.238:80)

TCP (HTTP SSL):
Connects to 200-147-73-193.static.uol.com.br  (200.147.73.193:443)

TCP (HTTP):
Connects to mpr2.ngd.vip.bf1.yahoo.com  (98.139.225.43:80)

TCP (HTTP SSL):
Connects to ec2-52-54-118-80.compute-1.amazonaws.com  (52.54.118.80:443)

TCP (HTTP):
Connects to a72-246-216-43.deploy.akamaitechnologies.com  (72.246.216.43:80)

Remove NexGuard.exe - Powered by Reason Core Security