nimbuscapture.exe

Nimbus Web Inc

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Nimbus’.
Publisher:
Nimbus Web Inc  (signed and verified)

MD5:
7cef6c5941446dc508c3a3efc618d947

SHA-1:
4355a9606107a7671b336de7b0412d405b621629

SHA-256:
6422a18b309ee17af86a70db6803967b0e954727a24b00152b439ee075ad36c1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:30:56 PM UTC  (today)

File size:
2 MB (2,080,328 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\nimbuscapture\nimbuscapture.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/7/2014 12:00:00 AM

Valid to:
11/7/2015 11:59:59 PM

Subject:
CN=Nimbus Web Inc, O=Nimbus Web Inc, STREET=4167 hinsdale rd, STREET=South Euclid, L=Cleveland, S=OH, PostalCode=44121, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F602C516E914AEABD0ECF8C45FDCB464

File PE Metadata
Compilation timestamp:
3/18/1972 11:25:04 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.24

CTPH (ssdeep):
49152:LiTq7E8a4hAvhqmgcyay9UEDsXCSkCT0P63V:uTq7E8a4hQqmgcyv9UED4CSkCQi3V

Entry address:
0x14C0

Entry point:
83, EC, 0C, C7, 05, E0, 01, 5D, 00, 01, 00, 00, 00, E8, 8E, A1, 0D, 00, 83, C4, 0C, E9, A6, FC, FF, FF, 8D, B6, 00, 00, 00, 00, 83, EC, 0C, C7, 05, E0, 01, 5D, 00, 00, 00, 00, 00, E8, 6E, A1, 0D, 00, 83, C4, 0C, E9, 86, FC, FF, FF, 90, 90, 90, 90, 90, 90, 55, 89, E5, 56, 53, 83, EC, 10, 8B, 1D, B0, 55, 5D, 00, C7, 04, 24, 00, 30, 51, 00, FF, D3, 89, C6, 83, EC, 04, 85, F6, B8, E8, C9, 4D, 00, 74, 29, C7, 04, 24, 00, 30, 51, 00, FF, 15, CC, 55, 5D, 00, 83, EC, 04, A3, 38, 00, 5D, 00, C7, 44, 24, 04, 13, 30...
 
[+]

Entropy:
6.8869

Code size:
1.1 MB (1,116,160 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Nimbus

Command:
C:\Program Files\nimbuscapture\nimbuscapture.exe


Scan nimbuscapture.exe - Powered by Reason Core Security