cirrusprocessing.exe

Datafiniti, LLC

The executable cirrusprocessing.exe has been detected as malware by 7 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘CirrusProcessing’.
Publisher:
Datafiniti, LLC  (signed and verified)

MD5:
3a9dd827621d48844eb457c54c828261

SHA-1:
6c6b48299e0ab02b123c6bd42afefde85ae792a0

SHA-256:
74ace5efad50c7a29e664df107784ba45dd4cf21aa8a9666313b6ec9498a6a26

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/26/2024 10:10:34 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Vitro
160326-0

Dr.Web
Win32.Virut.56
9.0.1.05190

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
16.03.27

ESET NOD32
Win32/Virut.NBP virus
7.0.302.0

F-Prot
W32/Sality.D.gen
4.6.5.141

Kaspersky
Virus.Win32.Virut
15.0.0.562

Sophos
Virus 'W32/Scribble-B'
5.23

File size:
1.1 MB (1,105,920 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\cirrusprocessing.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/1/2012 7:00:00 PM

Valid to:
9/7/2013 6:59:59 PM

Subject:
CN="Datafiniti, LLC", OU=Digital ID Class 3 - Java Object Signing, O="Datafiniti, LLC", L=Houston, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1DB498F52DE63D0D09A29CB34DDF18F8

File PE Metadata
Compilation timestamp:
8/30/1975 1:38:53 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Nx2Pf4gCrOimR38AthN+JYEWHClsXVsrpfIpmI0Bh2/21:3ifY+84pCssF1h1

Entry address:
0x129197

Entry point:
83, EC, 30, 60, 83, C4, 24, 0F, 84, 48, FE, FF, FF, E8, C9, FE, FF, FF, 8B, 5C, 24, FC, B3, 00, 83, EB, 1E, E9, AF, FD, FF, FF, 48, F3, AB, BA, 8A, B0, 8D, A1, C3, F5, 19, D4, 40, FF, A5, 73, FC, FF, FF, 41, 6C, 65, 42, 30, 00, 47, 68, C9, A8, 92, 51, 00, D5, E8, E7, FC, FF, FF, 8D, BC, 38, DD, 60, 7C, EC, 42, 8A, C5, 89, B5, 73, FC, FF, FF, 68, 78, 08, B8, E6, 20, D4, 8D, 41, E4, E8, C8, FC, FF, FF, 86, EE, 8D, 44, 24, 28, 89, 74, 24, 4C, 47, 96, F6, D2, 6A, FF, FF, 54, 24, 50, 84, EA, FE, 0C, 24, 75, F5...
 
[+]

Entropy:
6.5133

Code size:
879 KB (900,096 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
CirrusProcessing

Command:
C:\Program Files\cirrus processing\cirrusprocessing.exe


Remove cirrusprocessing.exe - Powered by Reason Core Security