CCEnhancer.exe

CCEnhancer

SingularLabs

This is a setup program which is used to install the application. The file has been seen being downloaded from rgho.st and multiple other hosts.
Publisher:
SingularLabs

Product:
CCEnhancer

Version:
4.4.0.0

MD5:
1f8148844d5ce910307175500ea38ca7

SHA-1:
4df4a6cdcc487b92166a7f26f981ed7eb61b8723

SHA-256:
da08ba22b1db9f1a2b44cb393958aac419ff9c5ecc779a120cec73ec7666e910

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/24/2024 1:32:03 AM UTC  (today)

Scan engine
Detection
Engine version

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1077

File size:
275.5 KB (282,112 bytes)

Product version:
4.4.0.0

Copyright:
Copyright © 2016

Original file name:
CCEnhancer.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

File PE Metadata
Compilation timestamp:
12/7/2015 1:17:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
80.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:wzjJHCiJ90k4ziA8K3OoB8CIuAdNj4M+E9J6Vfzxt+7x9EDNh/S8CIuAdNj4MehC:2dC8ox04WNj4AOVfPo3ExB4WNj4ton

Entry address:
0x3164E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
190 KB (194,560 bytes)

The file CCEnhancer.exe has been seen being distributed by the following 5 URLs.

http://rgho.st/download/6sCQLWy2d/.../CCEnhancer-4.4.exe

Scan CCEnhancer.exe - Powered by Reason Core Security