esvc.exe

esvc

IProNet Sistemas, S.A.

It runs as a separate (within the context of its own process) windows Service named “e-netcamCLIENT Pro Recordings and Alarms Service”.
Publisher:
IProNet Sistemas, S.A.  (signed and verified)

Product:
esvc

Version:
7.00.0049

MD5:
caa842e5bd91e40409709f0e666d0067

SHA-1:
11499e2cdbfef7885b8bc4710d9ca43ba3c03752

SHA-256:
4860349839c87fb95ed14d8bebfe2794abea21054a935407ef03b2c385baa6ee

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/28/2024 12:39:26 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
probably BACKDOOR.Trojan
9.0.1.05190

F-Prot
W32/VB-Backdoor-HRS-based!Maxim
4.6.5.141

File size:
458.8 KB (469,808 bytes)

Product version:
7.00.0049

Original file name:
esvc.exe

File type:
Executable application (Win32 EXE)

Language:
Spanish

Common path:
C:\Program Files\ipronet\e-netcamclient 7.0\esvc.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
7/12/2015 7:00:00 PM

Valid to:
7/13/2017 6:59:59 PM

Subject:
CN="IProNet Sistemas, S.A.", OU=WINDOWS APLICATION DEVELOPMENT, O="IProNet Sistemas, S.A.", L=Bilbao, S=Bizkaia, C=ES

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
02BBD4BF61028F0616B5B94C5EC2C36A

File PE Metadata
Compilation timestamp:
4/4/2016 5:39:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:DU7d+W72GaZFRgkxUGue+8hjABJ4Nd7BCbWgyos07YE:DU8RLxUGue3hjABJ4Nd7BCbWgn7YE

Entry address:
0x41CC

Entry point:
68, 20, 4C, 40, 00, E8, F0, FF, FF, FF, 00, 00, 48, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, B9, 40, 73, 0C, DF, 78, F8, 44, B8, 7F, 51, 05, D1, 94, 9D, 81, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 41, 00, 86, 50, 82, 01, 65, 5F, 6E, 65, 74, 63, 61, 6D, 53, 56, 43, 00, FC, FA, 80, 04, 00, 00, 00, 00, 10, F9, 88, 02, C0, 00, 00, 00, 90, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 1A, 00, 00, 00, CC, 67, 5D, A5, F5, AD, 03, 4F, 97, 1E, B9, AA, F2, B2, 32, 06, 01, 00, 00, 00, A0, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
420 KB (430,080 bytes)

Service
Display name:
e-netcamCLIENT Pro Recordings and Alarms Service

Service name:
e_ncsvcpro

Type:
Win32OwnProcess

Depends on:
e_diskmonpro


Scan esvc.exe - Powered by Reason Core Security