Gridinsoft Logo
File Icon

The FTPserver.exe (FTPserver) File Analysis

Technical Analysis

File Name FTPserver.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
SSDEEP Hash
768:b8sIwYR3PcpBVI5VmatlbtgzqCD+bbO+tdsS1r6fBsQ4ddAS5JmekKPSIRV:gp3SUwat0rDsbOXKr6fTSDAzIR
Scanner Version 1.0.182.174
Database Version 2024-07-15 03:00:21 UTC

Suspicious File Detected

Detected by 32 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
44%
Detection Rate
60,416
File Size (bytes)
32/73
Engines Detected
2024-07-15
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
dad1ad7d53c9d8a73198efef8c5297f1
SHA1
ff5dc7c000e5ce01658bf604bce8e2e95f124ec0
SHA256
d915352c0e9d0836f53fa769b73ac666fba9750efce4278edfeeab68707ecd0b
SHA512
9a4b9da12e9216054b990d8fe0382954462baf67fa9bf478ba4b9ce713f2c4cc2156a4a21e07529f4821bc404076b1bff3a8362ff61085658ccda6538f035184
ImpHash
66a4b5723752c83dafaf933d14498f62

Security Engines with Detections (32 of 73)

Bkav
W32.AIDetectMalware Malicious
Lionic
Trojan.Win32.Generic.4!c Malicious
Cynet
Malicious (score: 99) Malicious
FireEye
Generic.mg.dad1ad7d53c9d8a7 Malicious
ALYac
Trojan.GenericKD.73350913 Malicious
Cylance
Unsafe Malicious
Sangfor
Trojan.Win32.Agent.Va7e Malicious
CrowdStrike
win/malicious_confidence_90% (D) Malicious
Symantec
ML.Attribute.HighConfidence Malicious
APEX
Malicious Malicious
BitDefender
Trojan.GenericKD.73350913 Malicious
MicroWorld-eScan
Trojan.GenericKD.73350913 Malicious
Emsisoft
Trojan.GenericKD.73350913 (B) Malicious
F-Secure
Backdoor.BDS/Backdoor.Gen Malicious
VIPRE
Trojan.GenericKD.73350913 Malicious
McAfeeD
ti!D915352C0E9D Malicious
Trapmine
malicious.moderate.ml.score Malicious
Sophos
Generic Reputation PUA (PUA) Malicious
Paloalto
generic.ml Malicious
Google
Detected Malicious
Avira
BDS/Backdoor.Gen Malicious
MAX
malware (ai score=82) Malicious
Antiy-AVL
GrayWare/Win32.Wacapew Malicious
Microsoft
Program:Win32/Wacapew.C!ml Malicious
Arcabit
Trojan.Generic.D45F3F01 Malicious
GData
Win32.Trojan.Agent.CQTXPH Malicious
Varist
W32/ABApplication.VYAQ-6469 Malicious
Malwarebytes
Generic.Malware/Suspicious Malicious
Rising
[email protected] (RDMK:cmRtazpYZXHUY1DvF2g7d9Z6FM6V) Malicious
Ikarus
Backdoor.Agent Malicious
Fortinet
Malicious_Behavior.SB Malicious
DeepInstinct
MALICIOUS Malicious
41 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 9e268b9ee6980f30b689620446391180
Fuzzy: 8b21e82e21ed7fdc77f7d17ca9f8357c
dHash: 00f0f0f8f8b2b230
Image Base 0x00400000
Entry Point 0x0041f5a0
Compilation Time 2022-07-08 16:51:09
Checksum 0x00000000 (Actual: 0x0001e46f)
OS Version 6.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
Digital Signature The PE file does not contain a certificate table.
Imports 14 libraries
Exports 0 functions
Resources 19 Resources
Sections 3 Sections

Version Information

FileDescription FTPserver
FileVersion 2.0.0.0
InternalName FTPserver
LegalCopyright 版权所有 伊凡(C) 2010
OriginalFilename FTPserver.EXE
ProductName FTPserver
ProductVersion 2.0.0.0
Translation 0x0804 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
UPX0 0x00001000 94,208 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
UPX1 0x00018000 32,768 bytes 31,232 bytes 7.85 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2D1F28E8A01F4C6F8C74996FEDCDDADD
.rsrc 0x00020000 28,672 bytes 27,648 bytes 5.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 55AD178169C1A6DAA1F8966BFB211B06
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 19 (27,044 bytes)
Resource Type Count Total Size Percentage
AFX_DIALOG_LAYOUT 2 4 bytes
0%
RT_ICON 9 24,040 bytes
88.9%
RT_MENU 1 38 bytes
0.1%
RT_DIALOG 3 1,556 bytes
5.8%
RT_STRING 1 106 bytes
0.4%
RT_GROUP_ICON 1 132 bytes
0.5%
RT_VERSION 1 620 bytes
2.3%
RT_MANIFEST 1 548 bytes
2%

Certificate Chain Analysis

Certificate Information
Product FTPserver
Description FTPserver
File Version 2.0.0.0
Original Name FTPserver.EXE
Internal Name FTPserver
Copyright 版权所有 伊凡(C) 2010

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. 1
    Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
  2. 2
    Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
  3. 3
    Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
  4. 4
    Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Proactive Protection
32 security engines flagged this file. Could be a real threat, or could be a false alarm — common with keygens, game trainers, and legitimate system utilities. Check if the file has a valid digital signature and whether it came from the official source.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware