sfcrypt.exe

HIBUN Advanced Edition

Hitachi Solutions, Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘sfcrypt’.
Publisher:
Hitachi Solutions, Ltd.  (signed and verified)

Product:
HIBUN Advanced Edition

Version:
9.50

MD5:
83ec7eb395da02f1708ef8bbc9fc2fb7

SHA-1:
af53b2561ddf436b212a5c621a7fa096c787a4a6

SHA-256:
45d5da95e529ac4caef6fad1d6dfbd627927e44504bfd04e7f56b0b477b5ea04

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 10:45:21 AM UTC  (today)

File size:
173.9 KB (178,056 bytes)

Product version:
09-50

Copyright:
Copyright (C) 1999, 2011, Hitachi Solutions, Ltd.

Trademarks:
HIBUN(R)

Original file name:
tasktray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\hibun-ae\bin\sfcrypt.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/4/2010 7:00:00 AM

Valid to:
11/5/2011 6:59:59 AM

Subject:
CN="Hitachi Solutions, Ltd.", OU=Product Life cycle Management Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Hitachi Solutions, Ltd.", L=Shinagawa-ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
36CBDB782669FC274E536DC52228088E

File PE Metadata
Compilation timestamp:
8/2/2011 2:42:00 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:AGKm8y2nD3QItlSO+GK6R4eQbzgkfPs8xhR0+X8q48wnFq+7XXGXZXoXsXIXbgXG:AGKND3QInSO+GK6+7bckPVhR58q48wn/

Entry address:
0x6ABA

Entry point:
E8, F1, 33, 00, 00, E9, 17, FE, FF, FF, 8B, 44, 24, 04, 85, C0, 56, 8B, F1, C6, 46, 0C, 00, 75, 63, E8, 1B, 31, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, 40, 6A, 41, 00, 74, 12, 8B, 0D, 5C, 69, 41, 00, 85, 48, 70, 75, 07, E8, 91, 3D, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 60, 68, 41, 00, 74, 16, 8B, 46, 08, 8B, 0D, 5C, 69, 41, 00, 85, 48, 70, 75, 08, E8, 32, 36, 00, 00, 89, 46, 04, 8B, 46, 08, F6, 40, 70, 02, 75, 14, 83, 48, 70, 02, C6, 46, 0C, 01, EB, 0A, 8B, 08, 89, 0E...
 
[+]

Entropy:
5.5790

Code size:
60 KB (61,440 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
sfcrypt

Command:
"C:\Program Files\hibun-ae\bin\sfcrypt.exe"


Scan sfcrypt.exe - Powered by Reason Core Security