nstftpd.exe

Extreme Networks, Inc

It runs as a separate (within the context of its own process) windows Service named “NetSight TFTP Service”.
Publisher:
Extreme Networks, Inc  (signed and verified)

MD5:
565d3212133fed9075992eb06b4fb7a1

SHA-1:
bcfab3b524155807d89a78188318044e01bdea70

SHA-256:
94c8ed794bc0909005c788ea43d7562ae60159eaf7a890724c1b8d27744b8768

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 7:08:42 PM UTC  (today)

File size:
271.9 KB (278,456 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\extreme networks\netsight\services\nstftpd.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/4/2013 6:00:00 PM

Valid to:
12/4/2016 5:59:59 PM

Subject:
CN="Extreme Networks, Inc", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Extreme Networks, Inc", L=San Jose, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
68E8B57749080BE1428B1469B00E0E7C

File PE Metadata
Compilation timestamp:
5/29/2015 9:23:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.22

CTPH (ssdeep):
3072:wfBcPb3y78x1CIcWls5evHs9T/F+IvkC1+V7r4Ssczh/:ABczCgxUIcWeprF+IsC1+trj/

Entry address:
0x14E0

Entry point:
83, EC, 0C, C7, 05, BC, 84, 41, 00, 00, 00, 00, 00, E8, 4E, 57, 00, 00, 83, C4, 0C, E9, 86, FC, FF, FF, 90, 90, 90, 90, 90, 90, 8B, 44, 24, 04, 2B, 44, 24, 08, C3, 83, EC, 1C, 89, 5C, 24, 10, 89, 74, 24, 14, 89, 7C, 24, 18, 8B, 7C, 24, 20, 8B, 74, 24, 28, C7, 04, 24, 14, 00, 00, 00, E8, 8C, AA, 00, 00, 89, C3, 85, C0, 74, 52, 89, 38, C7, 40, 04, 00, 00, 00, 00, 8B, 44, 24, 24, 89, 43, 08, 85, F6, B8, 00, 15, 40, 00, 0F, 44, F0, 89, 73, 0C, C1, E7, 02, 89, 3C, 24, E8, 5E, AA, 00, 00, 89, 43, 10, 85, C0, 74...
 
[+]

Entropy:
5.7172

Code size:
45 KB (46,080 bytes)

Service
Display name:
NetSight TFTP Service

Description:
NetSight TFTP Service (nstftpd.exe) Manages TFTP transactions.

Type:
Win32OwnProcess


Scan nstftpd.exe - Powered by Reason Core Security