BackgroundTransferHost.exe

  • File Path: C:\Windows\system32\BackgroundTransferHost.exe
  • Description: Download/Upload Host

Hashes

Type Hash
MD5 C5D813D92E83CDE3FECD9343933E3421
SHA1 255A49C1F659DB44D8CDBEE3B66563433C220D6B
SHA256 BD5F35555DE04FFCC3564DBE10711ACB7010ACCC40132BE616A519C29B9538B4
SHA384 2211AED541F3F0D5C86240FAB56558289D14869EB2AB16F42D95099F939E993E5FC9FD3AF624E16EE1C1C65902DEA49F
SHA512 C0D14922CC9D847E8788891B9C9B00457723B81B6C67243007A9DC793AA597FFEE498C54D9A911605FE9F2A9A0E95170492474E7685ADFEA805A268C3FD7A6D9
SSDEEP 384:tqS559RJCFpc6x0kcVPG+W2Z+wZX2LWsp2YVeN4xW0mgW5QE0g7qW2RPT/8rFeZN:ouYHq9W2r2LFeN4iB2a
IMP 43BA7C14F952D3784267C6946F79BD81
PESHA1 A785DB20193F07C1D2B3403700F769C3E5310850
PE256 8500BF9C6CEE7F4B1FE6C4C6A0F1F37298CAF19C094D4DC85FEF01EC03ABF64A

Runtime Data

Loaded Modules:

Path
C:\Windows\system32\BackgroundTransferHost.exe
C:\Windows\System32\combase.dll
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\ucrtbase.dll

Signature

  • Status: Signature verified.
  • Serial: 33000002EC6579AD1E670890130000000002EC
  • Thumbprint: F7C2F2C96A328C13CDA8CDB57B715BDEA2CBD1D9
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: BackgroundTransferHost.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.746 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.746
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/bd5f35555de04ffcc3564dbe10711acb7010accc40132be616a519c29b9538b4/detection

File Similarity (ssdeep match)

File Score
C:\WINDOWS\system32\BackgroundTransferHost.exe 47
C:\Windows\system32\BackgroundTransferHost.exe 54
C:\Windows\system32\BackgroundTransferHost.exe 47
C:\WINDOWS\system32\BackgroundTransferHost.exe 44
C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe 49
C:\Windows\SysWOW64\BackgroundTransferHost.exe 50
C:\Windows\SysWOW64\BackgroundTransferHost.exe 49
C:\Windows\SysWOW64\BackgroundTransferHost.exe 49
C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe 49

MIT License. Copyright (c) 2020-2021 Strontic.