4c603d76...4e89 | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 94/100
Dynamic Analysis Report
Classification: Keylogger, Spyware

4c603d763a2b79e36492413ff788e1dd795bc09c67b2f4eccad5f339ebe44e89 (SHA256)

nstpeer.exe

Windows Exe (x86-32)

Created at 2018-11-01 09:56:00

Top Threat Indicators (View all 26 threat indicators)

Screenshots

Monitored Processes

Analysis Information

Creation Time 2018-11-01 10:56 (UTC+1)
Analysis Duration 00:04:00
Number of Monitored Processes 9
Execution Successful True
Reputation Enabled True
WHOIS Enabled True
YARA Enabled True
Termination Reason Timeout
Tags

Sample Information

ID #261139
MD5 8ac61890b22ca596db61d0f74da67b5d Copy to Clipboard
SHA1 2132beb454eaffd9b970015dcaa7d73a989d53ed Copy to Clipboard
SHA256 4c603d763a2b79e36492413ff788e1dd795bc09c67b2f4eccad5f339ebe44e89 Copy to Clipboard
SSDeep 24576:PjgCLkNHOU+dS88agRuBvYS3EXiCOLIKmV5rw:PjgvfR/HdCmXE Copy to Clipboard
ImpHash 3822da640a00d3b07c8e8dac576e47c9 Copy to Clipboard
Filename nstpeer.exe
File Size 1.11 MB
File Type Windows Exe (x86-32)

Analyzer Information

Dynamic Analyzer Build Date 2018-10-25 12:55 (UTC+2)
Dynamic Analyzer Version 2.3.2
Static Analyzer Version 1.0.1
VTI Ruleset Version 3.1
YARA Built-in Ruleset Version 1.1
Analysis Report Layout Version 3
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image