ArcHttpSrv.exe

Areca Technology Corporation

It runs as a windows Service named “ArcHttpProxyServer”.
Publisher:
Areca Technology Corporation  (signed and verified)

MD5:
ab73375d0d2c9fadf84c755a9657e020

SHA-1:
0fc273daa4ecc404732c2c95cec00e117a31eb14

SHA-256:
28362f4ddb2ce5de1a28751a2e22dd15242f7151f68264421e06f5ef45fb76fb

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
4/25/2024 12:16:20 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
BACKDOOR.Trojan
9.0.1.0282

K7 AntiVirus
Spyware
13.175.11028

File size:
929.5 KB (951,808 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mraid\archttp\archttpsrv.exe

Digital Signature
Authority:
Areca Technology Corporation

Valid from:
2/8/2011 3:15:32 AM

Valid to:
11/4/2013 3:15:32 AM

Subject:
E=support@areca.com.tw, CN=www.areca.com.tw, OU=Support, O=Areca Technology Corporation, S=Taipei, C=TW

Issuer:
E=support@areca.com.tw, CN=www.areca.com.tw, OU=Support, O=Areca Technology Corporation, S=Taipei, C=TW

Serial number:
00BB81800EA0BA5FB6

File PE Metadata
Compilation timestamp:
3/24/2013 11:05:40 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
24576:LfkT4qoY572MU/fvckq2MU/fvckF2MU/fvckZ2MU/fvck52MU/fvckQ2MU/fvckk:zkT4g5IVWiC3

Entry address:
0x3D97C

Entry point:
E8, 44, 95, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 14, 00, 7C, 29, 7F, 06, 83, 7D, 10, 00, 72, 21, 8B, 4D, 0C, 85, C9, 7C, 1A, 8B, 45, 08, 7F, 04, 85, C0, 72, 11, 2B, 45, 10, 1B, 4D, 14, 89, 45, 10, 89, 4D, 14, DF, 6D, 10, 5D, C3, E8, C5, E8, FF, FF, D9, EE, C7, 00, 16, 00, 00, 00, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 4C, A1, 84, 37, 4E, 00, 33, C5, 89, 45, FC, 53, 33, DB, 57, 8B, F9, 89, 5D, C0, 89, 5D, BC, 3B, FB, 75, 1A, E8, 94, E8, FF, FF, C7, 00, 16, 00, 00, 00, E8, C8, 21, 00, 00, 83...
 
[+]

Entropy:
7.0510

Code size:
314 KB (321,536 bytes)

Service
Display name:
ArcHttpProxyServer

Type:
Win32OwnProcess, InteractiveProcess


Scan ArcHttpSrv.exe - Powered by Reason Core Security