BNTFTP.exe

Provisioning Services

Citrix Systems, Inc

It runs as a separate (within the context of its own process) windows Service named “Citrix PVS TFTP Service”.
Publisher:
Citrix, Systems Inc.  (signed by Citrix Systems, Inc)

Product:
Provisioning Services

Description:
Provisioning Services TFTP Service

Version:
5.1.1.2950

MD5:
ba20c103b13851669db3e42ee8c39f1b

SHA-1:
1c677f6c5a02139924edac7e21efd36d4fbba1f4

SHA-256:
d5eb3461ef7a21b7480a9c48b900d318ff8b2dcde4d87be7003b83a2f778f8cc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/10/2024 6:56:13 AM UTC  (today)

File size:
199.7 KB (204,464 bytes)

Product version:
5.1.1

Copyright:
© 2001-2009 Citrix Systems, Inc. All rights reserved.

Original file name:
BNTFTP.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\citrix\provisioning services\bntftp.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/24/2009 9:00:00 PM

Valid to:
8/25/2011 8:59:59 PM

Subject:
CN="Citrix Systems, Inc", OU=Virtualization and Management Division, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Citrix Systems, Inc", L=Bedford, S=Massachusetts, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
26007A7721F30F5C55305B1DC02156DD

File PE Metadata
Compilation timestamp:
9/9/2009 4:31:02 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
6144:5ZyqmmSz4XjVQ3qJohFM2MrlARq8/+GXse:5YGXjVYFMrYse

Entry address:
0x7EAC

Entry point:
48, 83, EC, 28, E8, F7, B9, 00, 00, 48, 83, C4, 28, E9, 56, FE, FF, FF, CC, CC, 48, 8B, C4, 48, 89, 58, 10, 48, 89, 68, 18, 48, 89, 70, 20, 89, 48, 08, 57, 48, 83, EC, 20, 48, 8B, CA, 48, 8B, DA, E8, A6, C5, 00, 00, 8B, 4B, 18, 48, 63, F0, F6, C1, 82, 75, 17, E8, F6, 03, 00, 00, C7, 00, 09, 00, 00, 00, 83, 4B, 18, 20, 83, C8, FF, E9, 34, 01, 00, 00, F6, C1, 40, 74, 0D, E8, DA, 03, 00, 00, C7, 00, 22, 00, 00, 00, EB, E2, 33, FF, F6, C1, 01, 74, 19, 89, 7B, 08, F6, C1, 10, 0F, 84, 89, 00, 00, 00, 48, 8B, 43...
 
[+]

Code size:
148.5 KB (152,064 bytes)

Service
Display name:
Citrix PVS TFTP Service

Service name:
BNTFTP

Type:
Win32OwnProcess