SppClient.exe

Specops Password Client

Specops Software Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Specops Password Client’.
Publisher:
Specops Software  (signed by Specops Software Inc.)

Product:
Specops Password Client

Version:
5,5,20307,1

MD5:
63df442b1fd9107580dce1ab48587a92

SHA-1:
69389af32ed05888a5c2d18d746e405eb8bd2b41

SHA-256:
b8b28d3c8fb496e0601877ccc3a7f2f549fa9d337dc57c183852c99b064d74ac

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 12:14:58 PM UTC  (today)

File size:
878.4 KB (899,472 bytes)

Product version:
5,5,20307,1

Copyright:
Copyright © 2001-2011 Specops Software

Original file name:
SppClient.exe

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

Common path:
C:\Windows\System32\sppclient.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
1/26/2011 12:00:00 AM

Valid to:
1/25/2013 11:59:59 PM

Subject:
CN=Specops Software Inc., O=Specops Software Inc., L=Toronto, S=Ontario, C=CA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
45620ABF0327F991350E156FA38A11AB

File PE Metadata
Compilation timestamp:
3/7/2012 2:47:02 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:CwZI7IhIZzTpSV5ImSPr/wZWkIWtg8Nrzqv:CBZISzwZhi8lOv

Entry address:
0x119C8

Entry point:
48, 83, EC, 28, E8, 6B, 4D, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 48, 89, 5C, 24, 10, 4C, 89, 44, 24, 18, 55, 56, 57, 41, 54, 41, 55, 41, 56, 41, 57, 48, 83, EC, 20, 4C, 8B, A4, 24, 98, 00, 00, 00, 4C, 8B, AC, 24, 88, 00, 00, 00, 48, 8B, F1, 33, C9, 4D, 8B, F9, 49, 8B, F8, 44, 8B, C9, 89, 4C, 24, 60, 4C, 8B, F2, 48, 85, F6, 74, 0A, 48, 85, D2, 75, 10, 4D, 85, C0, 74, 10, 41, B9, 01, 00, 00, 00, E9, D1, 01, 00, 00, 4D, 85, C0, 74, F0, 4D, 85, FF, 75, 0C, 48, 39, 8C, 24, 80, 00, 00, 00, 75, E1...
 
[+]

Entropy:
3.6100

Code size:
135 KB (138,240 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Specops Password Client

Command:
C:\Windows\System32\sppclient.exe


Scan SppClient.exe - Powered by Reason Core Security