setup_nexcafe_w8.exe

NexCafé

Nextar Software

This is a setup program which is used to install the application. The file has been seen being downloaded from www.google.com and multiple other hosts.
Publisher:
Nextar Software

Product:
NexCafé

Version:
5.0.0.210

MD5:
406e52df0310362cc1697b4543dd3280

SHA-1:
1a3300a8856814e70d8944c77cd07c3fb4b3e880

SHA-256:
488061cd113d118f25dd0905a2bd5e7f5752d75b0f73a4aaa554951b91d3910d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 7:24:25 AM UTC  (today)

File size:
34.2 MB (35,844,608 bytes)

Product version:
5.0

Original file name:
Setup_NexCafe.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup_nexcafe_w8.exe

File PE Metadata
Compilation timestamp:
4/2/2015 2:37:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
786432:bSbKzBpipvmxp0mQRnjlB0QFt+58209iTZlifn0plN14wJsebHIh:bSbKzTiMx+lFba582c6mMpJdsuI

Entry address:
0x2C8A84

Entry point:
55, 8B, EC, 83, C4, F0, B8, 7C, 51, 6C, 00, E8, 74, F1, D3, FF, A1, C4, 55, 6D, 00, 8B, 00, E8, E4, 55, E1, FF, A1, C4, 55, 6D, 00, 8B, 00, B2, 01, E8, BE, 74, E1, FF, A1, C4, 55, 6D, 00, 8B, 00, BA, F0, 8A, 6C, 00, E8, 7D, 50, E1, FF, 8B, 0D, A4, 59, 6D, 00, A1, C4, 55, 6D, 00, 8B, 00, 8B, 15, 7C, 37, 6C, 00, E8, C5, 55, E1, FF, A1, C4, 55, 6D, 00, 8B, 00, E8, F1, 56, E1, FF, E8, A4, C7, D3, FF, FF, FF, FF, FF, 20, 00, 00, 00, 4E, 65, 78, 43, 61, 66, E9, 20, 2D, 20, 50, 72, 6F, 67, 72, 61, 6D, 61, 20, 64...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2.8 MB (2,913,792 bytes)

The file setup_nexcafe_w8.exe has been seen being distributed by the following 4 URLs.

https://www.google.com/url?hl=pt-BR&q=http://t.email.nextar.com/.../click?upn=amMi1bQug-2FlWau8keV2nyp-2FcJXK9DEeVCW3AydDWiMRrqL-2BhD8iQXKdgW4ZtFUdfmgMXNRT91Qcyp9bzUOmXM40PqSrb-2Fzge-2FS0Tw8saEUBr5sMUW9cjN5Z8ryzOUFCG4EdfN4jzqMdkTZVAztQdu-2FSXNz03cZEmHFMzK7CLZik-3D_u4FGEeSYpS-2F8-2FDHlqk-2BVG0jBd3ENBnPYiwdJhFpk281oEDyTYc1Cc4OJ0w9Op7oGeXBrFvqEyJ3LiqvdzWShAw-2Bf-2B082IfW8vh4WhKXP3L-2BdO5PG2Y2oJkWs-2F4j66rG3h74fkWO4ITAwJWs8dwmtk0G8LGjgx2JpnOjs2aw80H0WzleB-2Bs8R2FwiAJZQxCAov5DqgSXedyhlKBVWD7GuKKWccDdymAsSzfgDA6fqAbc9goou-2B8BbDUY-2BAqOlsI6Xj00g9A5tXtMb3ibR38fj9wRDsur1iDfZ5Xx6jxuNSuRh76cNcOwy53W4VAHYNoCwMiZqMBPCfH2t4YeHckV1ke4iQxI1DDxIMM9wGPticfTUE1wZKXTmh0zn217qzL8VjyCitFt4q5gYm4bu0j5A0ewkNS59NnirJToieDhOTvcks5-2FubprfKU46xlVZvw9piomzSTjHBdDOlu5MEnKE50u9514UM7n-2FCr5rh5zxRzs-3D&source=gmail&ust=1486779629320000&usg=AFQjCNHDXt1ZckNNvHnL0kjzJwBIlQsviA

http://nexcafe.us6.list-manage.com/.../click?u=fe2d1f66d672c936f9941deaa&id=97c7a5ee85&e=bbba8b752c

Scan setup_nexcafe_w8.exe - Powered by Reason Core Security