wferpftp.exe

Data Systems Consulting Co., Ltd.

Publisher:
Data Systems Consulting Co., Ltd.  (signed and verified)

MD5:
5584e77ccaaa97663108fe0c6d01dc0a

SHA-1:
1e1e583036f53089417c39d6a52d0f263733084b

SHA-256:
a43ec4344e3b9b8c054e7a89ebabf598d67a568f4ed455043967a6938cc9a572

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/26/2024 5:50:14 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Packed.Unknown
18263

IKARUS anti.virus
Trojan-Downloader
t3scan.1.6.1.0

File size:
139.6 KB (142,904 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\erp\leadersetup\patch\conductor\c_dsbin\wferpftp.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/14/2006 8:00:00 AM

Valid to:
11/18/2007 7:59:59 AM

Subject:
CN="Data Systems Consulting Co., Ltd.", OU=R & D Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Data Systems Consulting Co., Ltd.", L=Taipei, S=Taiwan, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
301C31A458495D2B72BB87354D60DAAE

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
1536:jl5dWkzKm63CF6mkvMBNIvP7mfmi5YMXrqsQnHrzQd142GT11T3s7Cs7kM/6sL8:rH1632RBNIvztiG+eHC42GTGCs7bY

Entry address:
0x1279C

Entry point:
55, 8B, EC, B9, 1D, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, 84, 23, 41, 00, E8, 1B, EB, FE, FF, 33, C0, 55, 68, 28, 2C, 41, 00, 64, FF, 30, 64, 89, 20, A1, A0, 5C, 41, 00, 8B, 00, E8, 75, F1, FE, FF, 33, C0, 55, 68, 5B, 28, 41, 00, 64, FF, 30, 64, 89, 20, 8D, 55, F0, B8, 44, 2C, 41, 00, E8, 52, EB, FE, FF, 8B, 55, F0, A1, D8, 31, 41, 00, E8, CD, E9, FE, FF, 68, 60, 2C, 41, 00, A1, D8, 31, 41, 00, 50, 8D, 45, E0, 50, E8, 71, E9, FE, FF, 83, C4, 0C, 8D, 45, E0, 50, 8D, 45, D0, 33, D2, E8...
 
[+]

Entropy:
6.4554

Developed / compiled with:
Microsoft Visual C++

Code size:
71.5 KB (73,216 bytes)

Scan wferpftp.exe - Powered by Reason Core Security