cirrusprocessing.exe

Plura Processing L.P.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘CirrusProcessing’.
Publisher:
Plura Processing L.P.  (signed and verified)

MD5:
b892f07038a1df79c70eee75e8d84736

SHA-1:
9081d3ea2ae4916f571f25d5d05c406b0afade4f

SHA-256:
3a27892e7c7de500d779e9aa7fd2fd8eee320c3cd48b4b8e8383c387c16ca6dd

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 11:58:01 AM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
TROJ_GEN.F47V0822
7.2.357

File size:
1 MB (1,084,416 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\cirrus processing\cirrusprocessing.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/4/2011 3:00:00 AM

Valid to:
9/8/2012 2:59:59 AM

Subject:
CN=Plura Processing L.P., OU=Digital ID Class 3 - Java Object Signing, O=Plura Processing L.P., L=Houston, S=Texas, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
30D0E143F198F2579B16E47EDA3E16AB

File PE Metadata
Compilation timestamp:
2/26/2012 11:52:11 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:hx2M+z8vlHHTFgWhr+c3zBGYIeNpJJRgDhqbUxunS:LFYwFNispII7Jpp

Entry address:
0xDC9FC

Entry point:
55, 8B, EC, 83, C4, F0, B8, C8, B8, 4D, 00, E8, DC, C3, F2, FF, 68, 6C, CA, 4D, 00, 6A, 00, 6A, 00, E8, 9A, C8, F2, FF, E8, 4D, CA, F2, FF, 3D, B7, 00, 00, 00, 74, 3E, A1, 64, 59, 4E, 00, 8B, 00, E8, E6, 2D, FF, FF, A1, 64, 59, 4E, 00, 8B, 00, 33, D2, E8, 30, 49, FF, FF, 8B, 0D, 84, 5A, 4E, 00, A1, 64, 59, 4E, 00, 8B, 00, 8B, 15, 94, A4, 4D, 00, E8, D8, 2D, FF, FF, A1, 64, 59, 4E, 00, 8B, 00, E8, 1C, 2F, FF, FF, E8, 0F, 89, F2, FF, 00, 00, 00, 50, 00, 6C, 00, 75, 00, 72, 00, 61, 00, 6C, 00, 5F, 00, 69, 00...
 
[+]

Entropy:
6.4727

Developed / compiled with:
Microsoft Visual C++

Code size:
878 KB (899,072 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
CirrusProcessing

Command:
C:\Program Files\cirrus processing\cirrusprocessing.exe


Scan cirrusprocessing.exe - Powered by Reason Core Security