nfwd.exe

nfwd

Internet Rimon Israel 2009 LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RUNSVCHOST’.
Publisher:
Internet Rimon Israel 2009 LTD  (signed and verified)

Product:
nfwd

Version:
1.0.0.0

MD5:
4a96955e03b25dccb9bf8a2f03a545ba

SHA-1:
2b20114c197af26d6661b5d8bc0596210e9551aa

SHA-256:
b3ff0e42b8433ab2a30da3f36ac36a887817a01202ec8f732a3e53c869c94567

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 11:24:16 AM UTC  (today)

File size:
61.1 KB (62,576 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2010

Original file name:
nfwd.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/3/2014 4:06:21 PM

Valid to:
3/3/2017 4:06:21 PM

Subject:
CN=Internet Rimon Israel 2009 LTD, O=Internet Rimon Israel 2009 LTD, L=Givat Shmuel, S=Israel, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E009CE6A8C6688EC6901BAD45E51B46F

File PE Metadata
Compilation timestamp:
6/3/2015 2:37:50 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:GAR48FUW7btL7bhhTuZFVaH1XevGcq9yFv+1heoxEkb9L6QW/1g92chpUZ:GA7G2IZLaH1uvGF9yFv+OoxJ9LZW/Gps

Entry address:
0xF40E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.7622

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
53.5 KB (54,784 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RUNSVCHOST

Command:
C:\internetrimon\nfwd.exe


Scan nfwd.exe - Powered by Reason Core Security