bncsaui.exe

Bradford Networks Persistent Agent

Bradford Networks

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘bncsaui.exe’.
Publisher:
Bradford Networks  (signed and verified)

Product:
Bradford Networks Persistent Agent

Description:
Persistent Agent UI

Version:


MD5:
d493409c68b50c8fc2e7cbef13cdaf6e

SHA-1:
4ebbbb50d6868fa9a547a8a7f948796cd90cd82c

SHA-256:
4fd0f39ea525e27545e52910833d7ced694e01e53db675063ee47f5f9ce06684

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 12:20:27 PM UTC  (today)

File size:
2.6 MB (2,734,224 bytes)

Product version:


Copyright:
© Bradford Networks. All rights reserved.

Original file name:
bncsaui.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\bradford networks\persistent agent\bncsaui.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/13/2011 8:00:00 PM

Valid to:
10/13/2014 7:59:59 PM

Subject:
CN=Bradford Networks, OU=Operations, O=Bradford Networks, STREET=162 Pembroke Road, L=Concord, S=New Hampshire, PostalCode=03301, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008DFB94F9762E61E8F47C55F16175B1B7

File PE Metadata
Compilation timestamp:
9/24/2013 1:13:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:EJBpBspSy77fa/hKUi6+FYuY5MrTAHktn:YpBskyff6m2uYxH6n

Entry address:
0x23620

Entry point:
E8, AD, 84, 00, 00, E9, 16, FE, FF, FF, 6A, 0C, 68, B8, D3, 65, 00, E8, 7E, 08, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, C8, 2C, 6C, 00, 77, 22, 6A, 04, E8, 2F, 64, 00, 00, 59, 83, 65, FC, 00, 56, E8, 71, 6C, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, 8A, 08, 00, 00, C3, 6A, 04, E8, 2C, 63, 00, 00, 59, C3, 55, 8B, 6C, 24, 08, 83, FD, E0, 0F, 87, 9F, 00, 00, 00, 53, 8B, 1D, 0C, 13, 5F, 00, 56, 57, 33, F6, 39, 35, 80, AB, 69, 00, 8B, FD, 75, 18, E8, 38, 34, 00...
 
[+]

Entropy:
6.3576

Code size:
1.9 MB (2,031,616 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
bncsaui.exe

Command:
C:\Program Files\bradford networks\persistent agent\bncsaui.exe


Scan bncsaui.exe - Powered by Reason Core Security