startUp.exe

startUp Application

HIKVISION DIGITAL TECHNOLOGY CO.,LTD.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SPUpDateServerrun’.
Publisher:
HIKVISION DIGITAL TECHNOLOGY CO.,LTD.  (signed and verified)

Product:
startUp Application

Version:
1, 0, 1, 20

MD5:
13e4451e21359b79d97c9e206ae1c82b

SHA-1:
2fcfad87a55173ec96bb077e0144e019641ebc36

SHA-256:
5ba0335c621b84b9bba0ee510e20972e218d48bc0da3b46be0bba5e6b8ed82e9

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
5/14/2024 12:31:15 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Sality.AT
7.11.30.172

File size:
14.9 KB (15,232 bytes)

Product version:
1, 0, 1, 20

Copyright:
Copyright (C) 2014

Original file name:
startUp.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\hik\update_server\startup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/30/2014 3:00:00 AM

Valid to:
7/30/2016 2:59:59 AM

Subject:
CN="HIKVISION DIGITAL TECHNOLOGY CO.,LTD.", OU=Product Development Dept., O="HIKVISION DIGITAL TECHNOLOGY CO.,LTD.", L=Hangzhou, S=Zhejiang, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
302DC8ABA5EE9CA6C41862ECF1EC8320

File PE Metadata
Compilation timestamp:
8/25/2015 9:33:18 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
192:hmiqaPcEXDjJjysN2kRJ2yJN1yhNmW8B980QyMrj1WrddMbpr9ZCspE+TMmRr8+D:h0GjtVN2kRpxW8h7MGsceMED

Entry address:
0x1633

Entry point:
E8, 80, 03, 00, 00, E9, 9F, FD, FF, FF, 3B, 0D, 18, 30, 40, 00, 75, 02, F3, C3, E9, 02, 04, 00, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 2A, 83, 78, 10, 03, 75, 24, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 05, E8, CC, 04, 00, 00, 33, C0, 5D, C2, 04, 00, 68, 4C, 16, 40, 00, FF, 15, 4C, 20, 40, 00, 33, C0, C3, FF, 25, D4, 20, 40, 00, 6A, 14, 68, F8, 22, 40, 00, E8, 5E, 02, 00, 00, FF, 35, 9C, 33, 40...
 
[+]

Entropy:
6.3233

Code size:
3 KB (3,072 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SPUpDateServerrun

Command:
C:\Program Files\hik\update_server\startup.exe


Scan startUp.exe - Powered by Reason Core Security