hfs262_rus.exe

Http File Server

rejetto

The application hfs262_rus.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. While running, it connects to the Internet address web1-dal1.u2-web.com on port 80 using the HTTP protocol.
Publisher:
rejetto

Product:
Http File Server

Version:
2.3.0.0

MD5:
66331a91a60023ea3523945551f1a4a3

SHA-1:
de29640747b6bae6441f14ad584c6c5ad8cf4f79

SHA-256:
dd9e83e5d6b85f2394dd4d66f96ef4de32208d89a8f7df6b0cd1d0ca4403853b

Scanner detections:
9 / 68

Status:
Potentially unwanted

Analysis date:
4/23/2024 1:44:10 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Server-Web
7.1.1

Avira AntiVirus
TR/HFS.A.18
7.11.117.196

Comodo Security
UnclassifiedMalware
17381

ESET NOD32
Win32/Server-Web.HFS (variant)
9.9128

Fortinet FortiGate
Riskware/SFH
10/17/2015

Kaspersky
not-a-virus:Server-FTP.Win32.SFH
14.0.0.1261

McAfee
Artemis!66331A91A600
5600.6609

NANO AntiVirus
Trojan.Win32.HFS.bqmuct
0.28.0.56582

Norman
Suspicious_Gen2.NWJBA
11.20151017

File size:
746 KB (763,904 bytes)

Product version:
2.3

Copyright:
Copyright (C) 2002-2010 Massimo Melina (www.rejetto.com)

Original file name:
hfs.exe

File type:
Executable application (Win32 EXE)

Language:
Italian (Italy)

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:wGlgVTSc73CI14jB3Mi/T25hGo+n5LoWyTRfouY1Lsv6IftrMBu2X4Ydg+sP8R+m:wGliSIt2B3MiqsCNdfoLu6IftrWVlW+z

Entry address:
0x233630

Entry point:
60, BE, 00, 30, 58, 00, 8D, BE, 00, E0, E7, FF, C7, 87, C4, 77, 18, 00, 66, 2A, 12, 30, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
708 KB (724,992 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to web1-dal1.u2-web.com  (65.99.251.251:80)

Remove hfs262_rus.exe - Powered by Reason Core Security