archttpsrv.exe

Areca Technology Corporation

It runs as a windows Service named “ArcHttpProxyServer”.
Publisher:
Areca Technology Corporation  (signed and verified)

MD5:
523436f0ae5258efbdbbf0b89c79a26e

SHA-1:
dfceb6f34e2e0a9462dc6f4ab5727dffca8a3449

SHA-256:
701c009eec6c0c002690fcdfa44311c6fdb02f430eca08f4397d5ae744e233a5

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/17/2018 2:43:42 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
probably BACKDOOR.Trojan
9.0.1.05190

File size:
933 KB (955,392 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mraid\archttp\archttpsrv.exe

Digital Signature
Authority:
Areca Technology Corporation

Valid from:
2/8/2011 2:15:32 AM

Valid to:
11/4/2013 2:15:32 AM

Subject:
E=support@areca.com.tw, CN=www.areca.com.tw, OU=Support, O=Areca Technology Corporation, S=Taipei, C=TW

Issuer:
E=support@areca.com.tw, CN=www.areca.com.tw, OU=Support, O=Areca Technology Corporation, S=Taipei, C=TW

Serial number:
00BB81800EA0BA5FB6

File PE Metadata
Compilation timestamp:
5/19/2015 2:21:21 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
24576:IZJo1O414nr/hugC2v52MU/fvckc2MU/fvckR2MU/fvckN2MU/fvckt2MU/fvck7:f914nr/8T6CL6+eYC

Entry address:
0x3E12C

Entry point:
E8, 44, 95, 00, 00, E9, 95, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 14, 00, 7C, 29, 7F, 06, 83, 7D, 10, 00, 72, 21, 8B, 4D, 0C, 85, C9, 7C, 1A, 8B, 45, 08, 7F, 04, 85, C0, 72, 11, 2B, 45, 10, 1B, 4D, 14, 89, 45, 10, 89, 4D, 14, DF, 6D, 10, 5D, C3, E8, C5, E8, FF, FF, D9, EE, C7, 00, 16, 00, 00, 00, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 4C, A1, 64, 38, 4E, 00, 33, C5, 89, 45, FC, 53, 33, DB, 57, 8B, F9, 89, 5D, C0, 89, 5D, BC, 3B, FB, 75, 1A, E8, 94, E8, FF, FF, C7, 00, 16, 00, 00, 00, E8, C8, 21, 00, 00, 83...
 
[+]

Entropy:
7.0465

Code size:
316 KB (323,584 bytes)

Service
Display name:
ArcHttpProxyServer

Type:
Win32OwnProcess, InteractiveProcess


Scan archttpsrv.exe - Powered by Reason Core Security