cliconfg.exe

  • File Path: C:\windows\system32\cliconfg.exe
  • Description: SQL Client Configuration Utility EXE

Screenshot

cliconfg.exe

Hashes

Type Hash
MD5 1A81668402876DBDE84C5E111C8D4A78
SHA1 55DFD84E981B79DCEAE385925F7B45DCA29BC090
SHA256 641DCCAA69D021E469A3E6C27FE166D03D512EF7A5E2E01C8883979AE109C139
SHA384 9A13B56411F5790591BF74B4348401A79DF9F20FAE1457508CD3486654E971C9252740C1D787D0CD1D60A223D8D416FB
SHA512 0D94999BDC0DA6F7764B2A20CF6B0D4AA8C1670124D7F14A28FBF7CF8E7A410185C2DAA9D562A1D3415E42BF38C3E5E4A418E0FC4F87A3C6BA149806B8366161
SSDEEP 384:Ut8oYa7wE5uYGR5xw7/SmWCwWSPXuNvBQAMYJQ2JQSkdowyo:88oj7wWbGua6wuI30lJBkvT

Signature

  • Status: The file C:\windows\system32\cliconfg.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at http://go.microsoft.com/fwlink/?LinkID=135170
  • Serial: ``
  • Thumbprint: ``
  • Issuer:
  • Subject:

File Metadata

  • Original Filename: cliconfg.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 6.3.9600.17415 (winblue_r4.141028-1500)
  • Product Version: 6.3.9600.17415
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\WINDOWS\system32\cliconfg.exe 55
C:\Windows\system32\cliconfg.exe 57
C:\WINDOWS\system32\cliconfg.exe 55
C:\Windows\system32\cliconfg.exe 61
C:\Windows\system32\cliconfg.exe 60
C:\WINDOWS\SysWOW64\cliconfg.exe 61
C:\WINDOWS\SysWOW64\cliconfg.exe 63
C:\Windows\SysWOW64\cliconfg.exe 66
C:\Windows\SysWOW64\cliconfg.exe 68
C:\Windows\SysWOW64\cliconfg.exe 61
C:\windows\SysWOW64\cliconfg.exe 69

Possible Misuse

The following table contains possible examples of cliconfg.exe being misused. While cliconfg.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
signature-base apt_op_honeybee.yar $x2 = “del /f /q %TEMP%\setup.cab && cliconfg.exe” CC BY-NC 4.0
signature-base apt_op_honeybee.yar $x1 = “cmd /c taskkill /im cliconfg.exe /f /t && del /f /q” fullword ascii CC BY-NC 4.0

MIT License. Copyright (c) 2020-2021 Strontic.