ComboFix.exe

ComboFix

Swearware

ComboFix is an application from sUBs that scans your computer for the most common and current malware, and when found, attempts to clean these infections. This is a self-extracting archive and installer. The file has been seen being downloaded from download.bleepingcomputer.com and multiple other hosts.
Publisher:
Swearware

Product:
ComboFix

Description:
ComboFix NSIS Installer

Version:
15.10.01.01

MD5:
bafb0e7b5f685b0dfccb013eab835e0b

SHA-1:
74402a3d44f6aaffa8f4232088949c722a0a8e60

SHA-256:
8e9efd98e4816ac6bcaa89d3933cd1da8d8d746ecbe80c34f2798c16023b0866

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/8/2024 8:27:53 PM UTC  (today)

Scan engine
Detection
Engine version

Sophos
PUA 'NirCmd'
5.19

File size:
5.4 MB (5,636,125 bytes)

Copyright:
sUBs

Original file name:
ComboFix.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\combofix.exe

File PE Metadata
Compilation timestamp:
5/12/2014 5:33:36 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:fZUCAgaAusxIRvssOp53IeicL3+IDLIuNt9fe/h1b5HOujEZLE4ZXgC5MAVIFYhF:xUnjjl3eicbpPIu1O3VOuOLE4FgC5MaB

Entry address:
0x314D0

Entry point:
60, BE, 00, D0, 42, 00, 8D, BE, 00, 40, FD, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB...
 
[+]

Entropy:
7.9999

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
20 KB (20,480 bytes)

The file ComboFix.exe has been seen being distributed by the following 50 URLs.

http://download.bleepingcomputer.com/dl/1c10965688b99fc4b35e4dbf16e96694/560cecef/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/b68d03dbd53a92f2434a02fcb1bf2f43/560ed1b4/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/d84c93760186f897e21efbbffce52ecc/56111a84/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/ea497577361a4cafcb40aa8ccce351b7/560d50eb/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/e69eda26b54680b48ae78cd5566ced74/55660186/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/6ab1d086dc0b593276a7f5511354a1e5/560d4b76/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/2a719a4d7daf95223aef857aefce85a7/5612140e/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/62c502828dc0c975edc3db9f070d46ae/55325bb3/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/a14b2567af16e1b35858950590047a98/56119b48/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/ff777e41b54527e6fa12cbf88d3939a8/560d7711/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/2f84710120ded1b13de403c5ab56b437/561259d3/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/3195c86f28765d01ca90b3dbb8837d11/54c64cc6/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/123abace7379e189c9bfb8f260ff4b30/561396d3/windows/security/anti-virus/c/.../ComboFix.exe

https://d13dhn7ldhrcf6.cloudfront.net/download.php?os=&icon=aHR0cDovL3NjcmVlbnNob3QuaXQuc2Z0Y2RuLm5ldC9pdC9zY3JuLzc4MDAwLzc4MzU0L2NvbWJvZml4LTE3LmpwZw==&desc=RWxpbWluYSBpIHJvb3RraXQgYXV0b21hdGljYW1lbnRl&name=ComboFix&domain=combofix&ss=&lang=it_IT&url=aHR0cDovL2NvbWJvZml4LnNvZnRvbmljLml0&version=120115&ins=organic-forumer

http://download.bleepingcomputer.com/dl/0c98e03d52486badc4dc697ea5efeb42/56100adf/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/5d173d625776d3c23966561201bd2886/56124c4f/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/9b363ba281a4c191419b0e35448b2670/560fc940/windows/security/anti-virus/c/.../ComboFix.exe

http://download.bleepingcomputer.com/dl/ad3ee0ea38957e3f369df66a6dddf01e/54e3ad5a/windows/security/anti-virus/c/.../ComboFix.exe

Latest 30 of 57 download URLs

Scan ComboFix.exe - Powered by Reason Core Security