nxTS.exe

nxTS

Korea Trade Network Co., Ltd

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘nxTS’.
Publisher:
Korea Trade network Co., Ltd.  (signed by Korea Trade Network Co., Ltd)

Product:
nxTS

Version:
1,0,0,4

MD5:
260083b9fe6d3945fc55b92454285646

SHA-1:
430304d02a212bc595af9f314dff9a66e2ccebc6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/25/2024 5:23:41 AM UTC  (today)

File size:
3.6 MB (3,816,880 bytes)

Product version:
1,0,0,4

Copyright:
Korea Trade Network Co., Ltd. All rights reserved.

Original file name:
nxTS.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\nxts\nxts.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/10/2015 9:00:00 AM

Valid to:
12/10/2016 8:59:59 AM

Subject:
CN="Korea Trade Network Co., Ltd", O="Korea Trade Network Co., Ltd", L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
46DD77805555B5964BCF0728947DBCFE

File PE Metadata
Compilation timestamp:
11/10/2015 4:00:57 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
98304:9w5ki9CjsXEr9X3gNbEzos+Qf9wZP04qN3:E8HgYkXh04qN3

Entry address:
0x19613E

Entry point:
E8, 11, 26, 01, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B8, 1E, 6E, 00, E8, EC, 12, 00, 00, E8, 26, B2, 00, 00, 0F, B7, F0, 6A, 02, E8, A4, 25, 01, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, E9, 72, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.2663

Code size:
2.4 MB (2,509,824 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
nxTS

Command:
"C:\Program Files\nxts\nxts.exe"


Scan nxTS.exe - Powered by Reason Core Security