cfos6link-x64-v252.exe

cfos IPv6 Link

cFos Software GmbH

This is a setup program which is used to install the application. The file has been seen being downloaded from www.cfosspeed.de and multiple other hosts.
Publisher:
cFos Software GmbH  (signed and verified)

Product:
cfos IPv6 Link

Version:
0.0

MD5:
c596cd1a5c7aec2ce1daaf73d7bd9dd4

SHA-1:
6d9f6c197425c2a18f31b021accd055a19c211a3

SHA-256:
6f207653ba49f34a32e15fae2e34a80dcef754b8b91ab8bdce666f1c4172550c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 10:44:28 AM UTC  (today)

File size:
2.2 MB (2,354,520 bytes)

Product version:
0.0

Copyright:
Copyright © Lueders/Winkler

Original file name:
cfos6link.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\cfos6link-x64-v252.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/5/2007 2:52:09 PM

Valid to:
11/5/2010 2:52:09 PM

Subject:
E=cfos-support@cfos.de, CN=cFos Software GmbH, O=cFos Software GmbH, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
010000000001160FA746FA

File PE Metadata
Compilation timestamp:
12/2/2008 7:38:26 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:SGYn2PKOI5BiQNlRI8tMXw7KptInk/ydmy028M4lo2NOnPouS5t6dQWkIMS0C:knaYHrRpMg7YzoZ028M4zcPouK9XIiC

Entry address:
0x1F60

Entry point:
48, 83, EC, 28, 33, C9, FF, 15, 54, 11, 00, 00, 41, B9, 0A, 00, 00, 00, 45, 33, C0, 48, 8B, C8, 33, D2, E8, DD, FC, FF, FF, 8B, C8, FF, 15, 31, 11, 00, 00, CC, 48, 89, 7C, 24, 08, 33, FF, 4C, 8B, C9, 4C, 3B, C7, 74, 30, 0F, B7, 02, 48, 83, C2, 02, 66, 89, 01, 48, 83, C1, 02, 66, 3B, C7, 74, 06, 49, 83, E8, 01, 75, E7, 4C, 3B, C7, 74, 12, 49, 83, E8, 01, 74, 0C, 0F, B7, C7, 48, 8B, F9, 49, 8B, C8, 66, F3, AB, 48, 8B, 7C, 24, 08, 49, 8B, C1, C3, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9918  (probably packed)

Code size:
5.5 KB (5,632 bytes)

The file cfos6link-x64-v252.exe has been seen being distributed by the following 3 URLs.

Scan cfos6link-x64-v252.exe - Powered by Reason Core Security