sfcrypt.exe

HIBUN Advanced Edition

Hitachi Software Engineering Co., Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘sfcrypt’.
Publisher:
Hitachi Solutions, Ltd.  (signed by Hitachi Software Engineering Co., Ltd.)

Product:
HIBUN Advanced Edition

Version:
9.10

MD5:
a9691547193e4ec42583cc4d36165aac

SHA-1:
5cfc4dbcc1db8161a03ac591b390ad2c412b14f2

SHA-256:
67ffd7a45b605518d34ef223c89a555b5db5b8779d118b0dce0f3afda84649a8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 1:27:36 AM UTC  (today)

File size:
173.4 KB (177,568 bytes)

Product version:
09-10

Copyright:
Copyright (C) 1999, 2010, Hitachi Solutions, Ltd.

Trademarks:
HIBUN(R)

Original file name:
tasktray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\hibun-ae\bin\sfcrypt.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/16/2009 9:00:00 AM

Valid to:
11/17/2010 8:59:59 AM

Subject:
CN="Hitachi Software Engineering Co., Ltd.", OU=Product Life cycle Management Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Hitachi Software Engineering Co., Ltd.", L=Shinagawa-ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1D4C8CB4F452EA4AD5A641CF188BE9D3

File PE Metadata
Compilation timestamp:
8/31/2010 5:50:33 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:LGKoWw/vQIxsSO+GK6lYOPb7Nmb8uvRI+zll9lR919RpE8q48wnFq+7XXGXZXoXS:LGKW/vQICSO+GK6+EbApvRe8q48wnFqx

Entry address:
0x6A4A

Entry point:
E8, F1, 33, 00, 00, E9, 17, FE, FF, FF, 8B, 44, 24, 04, 85, C0, 56, 8B, F1, C6, 46, 0C, 00, 75, 63, E8, 1B, 31, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, 40, 6A, 41, 00, 74, 12, 8B, 0D, 5C, 69, 41, 00, 85, 48, 70, 75, 07, E8, 91, 3D, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 60, 68, 41, 00, 74, 16, 8B, 46, 08, 8B, 0D, 5C, 69, 41, 00, 85, 48, 70, 75, 08, E8, 32, 36, 00, 00, 89, 46, 04, 8B, 46, 08, F6, 40, 70, 02, 75, 14, 83, 48, 70, 02, C6, 46, 0C, 01, EB, 0A, 8B, 08, 89, 0E...
 
[+]

Entropy:
5.5686

Code size:
60 KB (61,440 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
sfcrypt

Command:
"C:\Program Files\hibun-ae\bin\sfcrypt.exe"


Scan sfcrypt.exe - Powered by Reason Core Security