archttpsrv.exe

Areca Technology Corporation

It runs as a separate (within the context of its own process) windows Service named “ArcHttpProxyServer”.
Publisher:
Areca Technology Corporation  (signed and verified)

MD5:
64a22c7b2557618f2d7e35897541d30e

SHA-1:
b8ae379648d1004338a254ae3f0f4aa2dc8a4b5b

SHA-256:
374a517a71b68f54512ec624f284a4b535e19873b2c383fb22a7faa4bbede073

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 6:09:22 AM UTC  (today)

File size:
932 KB (954,368 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mraid\archttp\archttpsrv.exe

Digital Signature
Authority:
Areca Technology Corporation

Valid from:
2/8/2011 3:15:32 AM

Valid to:
11/4/2013 3:15:32 AM

Subject:
E=support@areca.com.tw, CN=www.areca.com.tw, OU=Support, O=Areca Technology Corporation, S=Taipei, C=TW

Issuer:
E=support@areca.com.tw, CN=www.areca.com.tw, OU=Support, O=Areca Technology Corporation, S=Taipei, C=TW

Serial number:
00BB81800EA0BA5FB6

File PE Metadata
Compilation timestamp:
1/28/2014 2:57:41 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
24576:ebWrxuPy8u878x+h/7goGH149E1T2MU/fvckN2MU/fvckR2MU/fvckJ2MU/fvckI:eir8Py8u878x+h/7goGHiu1g+6y3/

Entry address:
0x3DE6C

Entry point:
E8, D4, 94, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 14, 00, 7C, 29, 7F, 06, 83, 7D, 10, 00, 72, 21, 8B, 4D, 0C, 85, C9, 7C, 1A, 8B, 45, 08, 7F, 04, 85, C0, 72, 11, 2B, 45, 10, 1B, 4D, 14, 89, 45, 10, 89, 4D, 14, DF, 6D, 10, 5D, C3, E8, C5, E8, FF, FF, D9, EE, C7, 00, 16, 00, 00, 00, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 4C, A1, 4C, 39, 4E, 00, 33, C5, 89, 45, FC, 53, 33, DB, 57, 8B, F9, 89, 5D, C0, 89, 5D, BC, 3B, FB, 75, 1A, E8, 94, E8, FF, FF, C7, 00, 16, 00, 00, 00, E8, 57, 21, 00, 00, 83...
 
[+]

Entropy:
7.0475

Code size:
315.5 KB (323,072 bytes)

Service
Display name:
ArcHttpProxyServer

Type:
Win32OwnProcess


Scan archttpsrv.exe - Powered by Reason Core Security