tftp.EXE

tftp Application

It runs as a scheduled task under the Windows Task Scheduler. The file has been seen being downloaded from www.dd-wrt.com and multiple other hosts.
Product:
tftp Application

Description:
tftp MFC Application

Version:
1, 0, 0, 1

MD5:
ee665224ee8b19ba66b8578dd471e0a8

SHA-1:
3ce7f797dc3d4505a513fb42d2580c765a5011bc

SHA-256:
acdff00ece50f2eb8ad15c5c531121acc5fa932c742e1ef31ff7c98b9d05a84f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 5:49:52 PM UTC  (today)

File size:
44.4 KB (45,456 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 1998

Original file name:
tftp.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\router stuff\gv5flash\gv5flash\tftp.exe

File PE Metadata
Compilation timestamp:
6/12/2001 9:33:20 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:NlPsT9/fQstJwJn89lhDXwayC51jbmcOdirJ3PCJZZpYp:ATtfQs8ne7DXwlC51jbmcO8J3PC3Z

Entry address:
0x4184

Entry point:
55, 8B, EC, 6A, FF, 68, F0, 5C, 40, 00, 68, E8, 42, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, B0, 52, 40, 00, 59, 83, 0D, E4, 71, 40, 00, FF, 83, 0D, E8, 71, 40, 00, FF, FF, 15, AC, 52, 40, 00, 8B, 0D, D8, 71, 40, 00, 89, 08, FF, 15, A8, 52, 40, 00, 8B, 0D, D4, 71, 40, 00, 89, 08, A1, A4, 52, 40, 00, 8B, 00, A3, E0, 71, 40, 00, E8, 22, 01, 00, 00, 39, 1D, C0, 70, 40, 00, 75, 0C, 68, 12, 43, 40, 00, FF, 15, A0, 52...
 
[+]

Entropy:
4.4486

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
16 KB (16,384 bytes)

Scheduled Task
Task name:
{C04948A8-9CBD-41D6-8E11-3BA11E572292}

Trigger:
Registration (Runs on registration)


The file tftp.EXE has been seen being distributed by the following 30 URLs.

http://www.dd-wrt.com/routerdb/de/download/Linksys/WRT54G-LA/v8/.../2236

http://dd-wrt.com/routerdb/de/download/Linksys/WRT54G/v8.2/.../2236

http://www.dd-wrt.com/routerdb/de/download/Linksys/WRT54G/v7.2/.../2236

Latest 30 of 30 download URLs

Scan tftp.EXE - Powered by Reason Core Security