sfcrypt.exe

HIBUN Advanced Edition

Hitachi Solutions, Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘sfcrypt’.
Publisher:
Hitachi Solutions, Ltd.  (signed and verified)

Product:
HIBUN Advanced Edition

Version:
10.0

MD5:
0a8ff2cc670dd4c249a735d682643d0b

SHA-1:
d20f065a4834d052e4e6a3cbcd58ab4e7f17c944

SHA-256:
b49be95023dfad49e49ca7de963effbfb07e84b9e79da936ea0e15524950307c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 11:35:05 AM UTC  (today)

File size:
173.9 KB (178,056 bytes)

Product version:
10-00

Copyright:
Copyright (C) 1999, 2012, Hitachi Solutions, Ltd.

Trademarks:
HIBUN(R)

Original file name:
tasktray.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\hibun-ae\bin\sfcrypt.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/24/2011 6:00:00 PM

Valid to:
10/24/2012 5:59:59 PM

Subject:
CN="Hitachi Solutions, Ltd.", OU=Product Life cycle Management Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Hitachi Solutions, Ltd.", L=shinagawa-ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
67A4B2E816733888EC8EBB94034C3BF5

File PE Metadata
Compilation timestamp:
3/23/2012 2:35:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:/GKemQJU8mEQIOFSO+GK66+eQbzgkfP18lhR0+X8q48wnFq+7XXGXZXoXsXIXbgt:/GKQmEQIwSO+GK6n7bckP2hR58q48wnA

Entry address:
0x6ABA

Entry point:
E8, F1, 33, 00, 00, E9, 17, FE, FF, FF, 8B, 44, 24, 04, 85, C0, 56, 8B, F1, C6, 46, 0C, 00, 75, 63, E8, 1B, 31, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, 40, 6A, 41, 00, 74, 12, 8B, 0D, 5C, 69, 41, 00, 85, 48, 70, 75, 07, E8, 91, 3D, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 60, 68, 41, 00, 74, 16, 8B, 46, 08, 8B, 0D, 5C, 69, 41, 00, 85, 48, 70, 75, 08, E8, 32, 36, 00, 00, 89, 46, 04, 8B, 46, 08, F6, 40, 70, 02, 75, 14, 83, 48, 70, 02, C6, 46, 0C, 01, EB, 0A, 8B, 08, 89, 0E...
 
[+]

Entropy:
5.5785

Code size:
60 KB (61,440 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
sfcrypt

Command:
"C:\Program Files\hibun-ae\bin\sfcrypt.exe"


Scan sfcrypt.exe - Powered by Reason Core Security