cliconfg.exe

  • File Path: C:\Windows\system32\cliconfg.exe
  • Description: SQL Client Configuration Utility EXE

Screenshot

cliconfg.exe

Hashes

Type Hash
MD5 FF9932C30F72B19E57D9B07F230487E7
SHA1 0B7A0E55A69820062D9C9A4D6522B2CD3CB4414F
SHA256 FBD7F130718C6A73E0AFD15D1F8D843426604A866EC63624357F8A952B484AD1
SHA384 04D2E87133F9930DC6764E91CE81C487774608A814D5A18F86104E5F856F473223734CBEDF347F110592062F49E77382
SHA512 735DAB7C2165A5A29B64B80D64F11551DCFEC7F2D7B099E7EBCC5DE9EFD0554AD537273E13EB4DBB7DA1C37A744D27D9F743C0F995049B58FA5982C33A1055AF
SSDEEP 384:nhjdkMnHDyWjUyEurzWkpWrwWlPXuNvBQAMYJQ2JQSkdowyo:nhjRnHlcGbiLuI30lJBkvT

Signature

  • Status: Signature verified.
  • Serial: 33000000BCE120FDD27CC8EE930000000000BC
  • Thumbprint: E85459B23C232DB3CB94C7A56D47678F58E8E51E
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: cliconfg.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.14393.0 (rs1_release.160715-1616)
  • Product Version: 10.0.14393.0
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

File Similarity (ssdeep match)

File Score
C:\windows\system32\cliconfg.exe 60
C:\WINDOWS\system32\cliconfg.exe 58
C:\Windows\system32\cliconfg.exe 57
C:\WINDOWS\system32\cliconfg.exe 60
C:\Windows\system32\cliconfg.exe 60
C:\WINDOWS\SysWOW64\cliconfg.exe 63
C:\WINDOWS\SysWOW64\cliconfg.exe 65
C:\Windows\SysWOW64\cliconfg.exe 58
C:\Windows\SysWOW64\cliconfg.exe 63
C:\Windows\SysWOW64\cliconfg.exe 63
C:\windows\SysWOW64\cliconfg.exe 63

Possible Misuse

The following table contains possible examples of cliconfg.exe being misused. While cliconfg.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
signature-base apt_op_honeybee.yar $x2 = “del /f /q %TEMP%\setup.cab && cliconfg.exe” CC BY-NC 4.0
signature-base apt_op_honeybee.yar $x1 = “cmd /c taskkill /im cliconfg.exe /f /t && del /f /q” fullword ascii CC BY-NC 4.0

MIT License. Copyright (c) 2020-2021 Strontic.