servusetup.exe

Serv-U

Rhino Software, Inc.

This is a setup and installation application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Rhino Software, Inc.   (signed by Rhino Software, Inc.)

Product:
Serv-U

Description:
Serv-U Setup

Version:
14.0.0.6

MD5:
fd6188c233ae72789b8ce8bab915a510

SHA-1:
276ed2fde30bd691f641f54a71a84c298c3117d9

SHA-256:
890faa92f6fdb74101117929e440ff0f5d3cb764bfc43b58d39429ac6297c52a

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/18/2024 10:10:54 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.6379

File size:
19.2 MB (20,145,464 bytes)

Product version:
14.0.0.6

Copyright:
Copyright © 1995-2012 - Rhino Software, Inc.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\servusetup.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
2/16/2010 6:00:00 PM

Valid to:
3/12/2013 5:59:59 PM

Subject:
CN="Rhino Software, Inc.", O="Rhino Software, Inc.", STREET=P.O. Box 53, L=Helenville, S=WI, PostalCode=53137, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
455DFA2106B30E84965504A98D03FD68

File PE Metadata
Compilation timestamp:
10/9/2012 2:48:22 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:b3AfJ42xREIxEFP17golk51+gejtPI0FJXR1TGNvYNBurHeE:bksJP17gFQ5GvQoiE

Entry address:
0xF3BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 64, ED, 40, 00, E8, E8, 71, FF, FF, 33, C0, 55, 68, 89, FA, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 45, FA, 40, 00, 64, FF, 32, 64, 89, 22, A1, 48, 3B, 41, 00, E8, BE, F7, FF, FF, E8, 65, F3, FF, FF, 8D, 55, EC, 33, C0, E8, F7, C3, FF, FF, 8B, 55, EC, B8, 4C, 66, 41, 00, E8, 6A, 58, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 4C, 66, 41, 00, B2, 01...
 
[+]

Entropy:
7.9875

Developed / compiled with:
Microsoft Visual C++

Code size:
59 KB (60,416 bytes)

The file servusetup.exe has been seen being distributed by the following 3 URLs.

http://gsf-cf.softonic.com/276/ed2/.../file?SD_used=0&channel=WEB&fdh=no&id_file=4661&instance=softonic_es&type=PROGRAM&Expires=1480227456&Signature=eXTE8~DYresnQFpqdAzOyfbNj32q-qM-bTlJ2CdU46jDARGLOsY~g~1tz3CXnZe4Zv91xDd5GhL-YgikStqHu-gO4v4rBMU3dB5SwGgndZM7bx9DjAjorg2oA2c6W3uYjzox0-3AOEZFQxp50PTWdUeAJ2r~JCV-fio0wBHf4vs_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ServUSetup.exe

Scan servusetup.exe - Powered by Reason Core Security