archttpsrv.exe

Areca Technology Corporation

It runs as a windows Service named “ArcHttpProxyServer”.
Publisher:
Areca Technology Corporation  (signed and verified)

MD5:
dfaae634525bf7d91b5ceaba5bf3b714

SHA-1:
7b3b99a3039194008b1bbf712ef3ffd1fa8764ce

SHA-256:
595c81f538b5308de9270669c1f33cc221eec4c22178446b3f0044f96e452235

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
8/16/2018 11:29:14 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
BACKDOOR.Trojan
9.0.1.0358

File size:
932 KB (954,368 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mraid\archttp\archttpsrv.exe

Digital Signature
Authority:
Areca Technology Corporation

Valid from:
2/8/2011 10:15:32 AM

Valid to:
11/4/2013 10:15:32 AM

Subject:
E=support@areca.com.tw, CN=www.areca.com.tw, OU=Support, O=Areca Technology Corporation, S=Taipei, C=TW

Issuer:
E=support@areca.com.tw, CN=www.areca.com.tw, OU=Support, O=Areca Technology Corporation, S=Taipei, C=TW

Serial number:
00BB81800EA0BA5FB6

File PE Metadata
Compilation timestamp:
10/28/2013 11:41:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
24576:TzWwdppPy8u878x+h/7goGH149ijT2MU/fvckN2MU/fvckR2MU/fvckJ2MU/fvcT:TawVPy8u878x+h/7goGHikjg+6y3/

Entry address:
0x3DE6C

Entry point:
E8, D4, 94, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 14, 00, 7C, 29, 7F, 06, 83, 7D, 10, 00, 72, 21, 8B, 4D, 0C, 85, C9, 7C, 1A, 8B, 45, 08, 7F, 04, 85, C0, 72, 11, 2B, 45, 10, 1B, 4D, 14, 89, 45, 10, 89, 4D, 14, DF, 6D, 10, 5D, C3, E8, C5, E8, FF, FF, D9, EE, C7, 00, 16, 00, 00, 00, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 4C, A1, 4C, 39, 4E, 00, 33, C5, 89, 45, FC, 53, 33, DB, 57, 8B, F9, 89, 5D, C0, 89, 5D, BC, 3B, FB, 75, 1A, E8, 94, E8, FF, FF, C7, 00, 16, 00, 00, 00, E8, 57, 21, 00, 00, 83...
 
[+]

Entropy:
7.0474

Code size:
315.5 KB (323,072 bytes)

Service
Display name:
ArcHttpProxyServer

Type:
Win32OwnProcess, InteractiveProcess


Scan archttpsrv.exe - Powered by Reason Core Security