nfwd.exe

nfwd

Internet Rimon Israel 2009 LTD

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘RUNSVCHOST’.
Publisher:
Internet Rimon Israel 2009 LTD  (signed and verified)

Product:
nfwd

Version:
1.0.0.0

MD5:
4aba99dcb1a52481c8396b2a563c2a5f

SHA-1:
6cff7fe1bffc609e6477f9f7734294beb913871c

SHA-256:
b2367a73309f4989ec13bc0f7bb54cac7188a6c125e05d56df8d5881bb3a76cc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/6/2024 4:51:18 AM UTC  (today)

File size:
60.6 KB (62,064 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2010

Original file name:
nfwd.exe

File type:
Executable application (Win64 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/3/2014 4:06:21 PM

Valid to:
3/3/2017 4:06:21 PM

Subject:
CN=Internet Rimon Israel 2009 LTD, O=Internet Rimon Israel 2009 LTD, L=Givat Shmuel, S=Israel, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E009CE6A8C6688EC6901BAD45E51B46F

File PE Metadata
Compilation timestamp:
7/24/2016 11:52:30 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:ipNqpJX/y++H31apP9FkbpT2hjWN9Ip9EU:iiobpT2hjWN9Ip93

Entry address:
0xEBBE

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.8306

Code size:
53 KB (54,272 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
RUNSVCHOST

Command:
C:\internetrimon\nfwd.exe


Scan nfwd.exe - Powered by Reason Core Security