ComboFix.exe

ComboFix

Swearware

ComboFix is an application from sUBs that scans your computer for the most common and current malware, and when found, attempts to clean these infections. This is a setup and installation application. The file has been seen being downloaded from api.viglink.com.
Publisher:
Swearware

Product:
ComboFix

Description:
ComboFix NSIS Installer

Version:
16.07.25.01

MD5:
9370f9cf89df634f9229048b50193d34

SHA-1:
3704da38064a0eabc8c987a9540ac8077fda7025

SHA-256:
ce7c743db0b728b8a20c18e9a594fbafe901c287769ef0242bd616ff801b8b22

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/30/2024 8:24:44 AM UTC  (today)

File size:
5.5 MB (5,738,594 bytes)

Copyright:
sUBs

Original file name:
ComboFix.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\combofix.exe

File PE Metadata
Compilation timestamp:
5/11/2014 8:03:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:RIFTpzxXrnKvoaIuD4Axrjd/rFBfswXCqCyURY/90jF9FCuL6mbTaqTH1C:SKvNIKtjd5rX4yp/90jFOMHbrVC

Entry address:
0x314D0

Entry point:
85, D1, 76, 02, FE, C2, F3, 2D, C0, 0B, 87, 22, 69, C5, 39, 0A, A7, AC, 85, E8, 72, 07, 85, FF, C6, C4, A0, B0, 62, 85, F3, 76, 03, 0F, B6, CE, 8D, 15, 6D, E2, 46, 39, 8D, 3D, 7D, 4C, 00, 00, 0F, BF, C1, 81, F7, 46, 75, 00, 00, 89, EE, BD, 4F, 06, 28, 1A, 2B, DF, 0F, BF, C0, 8D, 2D, 16, 69, 69, 80, B1, 51, 33, D0, F2, B0, FB, 32, C0, 8B, F9, 69, FE, FB, 25, 56, CA, 68, 0F, F7, F7, 00, 8A, CF, 85, C0, E8, 19, 00, 00, 00, 69, C3, 4F, DF, 97, 8D, 86, E2, C6, C6, F8, 0F, B7, F5, 8B, F5, F2, 85, DE, 81, FF, 94...
 
[+]

Code size:
20 KB (20,480 bytes)

The file ComboFix.exe has been seen being distributed by the following URL.

Scan ComboFix.exe - Powered by Reason Core Security