bfrepair.exe

Cloud IT-All Ltd

The application bfrepair.exe by Cloud IT-All has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
CloudIT-All  (signed by Cloud IT-All Ltd)

Description:
BigFix Repair

Version:
1,0,0,0

MD5:
a1358f382c318892617a68e816b7310d

SHA-1:
6c16e59335c65a32895eb5e01f09a658b9f92277

SHA-256:
a17d71d6cae377b90e34d7a92b4da464a0a2321cd96edb070323ce9ed0c5f7c9

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/8/2024 3:31:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.10.3.13

File size:
11.6 MB (12,185,088 bytes)

Product version:
1.0.0.0

Copyright:
CloudIT-All

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Authority:
Cloud IT-All Ltd

Valid from:
5/13/2015 12:34:54 PM

Valid to:
5/10/2025 12:34:54 PM

Subject:
CN=Arthur Barenshtein, O=Cloud IT-All Ltd

Issuer:
CN=Arthur Barenshtein, O=Cloud IT-All Ltd

Serial number:
23B4CA2F

File PE Metadata
Compilation timestamp:
7/30/2014 12:14:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

CTPH (ssdeep):
196608:6zytBeaNk4LEqBievzutCX1bQ0sGa12f4vu3bu0OtytugtuMjaoVQf+V0TSgq:6zys4Qkrva4XBXszkJbZqytTuMjav+0o

Entry address:
0x1000

Entry point:
68, D0, 00, 00, 00, 68, 00, 00, 00, 00, 68, 04, B0, 40, 00, E8, 7C, 21, 00, 00, 83, C4, 0C, 68, 00, 00, 00, 00, E8, 75, 21, 00, 00, A3, 08, B0, 40, 00, 68, 00, 00, 00, 00, 68, 00, 10, 00, 00, 68, 00, 00, 00, 00, E8, 62, 21, 00, 00, A3, 04, B0, 40, 00, E8, BC, 1F, 00, 00, E8, 07, 67, 00, 00, E8, 99, 5A, 00, 00, E8, CD, 52, 00, 00, E8, BB, 3C, 00, 00, E8, E3, 32, 00, 00, E8, 8E, 2F, 00, 00, E8, 19, 2B, 00, 00, E8, 6D, 28, 00, 00, 68, 07, 00, 00, 00, 68, 34, A2, 40, 00, 8D, 05, D0, B0, 40, 00, 50, 68, 08, 00...
 
[+]

Packer / compiler:
PKLITE32, 0x1.1

Code size:
27.5 KB (28,160 bytes)

Remove bfrepair.exe - Powered by Reason Core Security