kms.exe

Kurupira Message

KURUPIRA.NET

Publisher:
KURUPIRA.NET  (signed and verified)

Product:
Kurupira Message

Version:
1.00

MD5:
0152ffc2b9ce91caf494804552d6db81

SHA-1:
4d37ff15babe93576f65454b69b22a7a42787f32

SHA-256:
38547ade9b868f2ded889557c43e89d5a3ccab1f79fb1e82e6916a3ab0ab47ba

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/19/2024 8:03:05 PM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Trojan.VBInject!1.64FA
23.00.65.15930

File size:
106.2 KB (108,728 bytes)

Product version:
1.00

Copyright:
Kurupira.NET (c)

Trademarks:
Kurupira.NET (c)

Original file name:
kms.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\application data\appdata\application data\appdata\application data\appdata\application data\appdata\application data\appdata\application data\kurupira\webfilter\kms.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/21/2012 9:00:00 PM

Valid to:
5/22/2015 8:59:59 PM

Subject:
CN=KURUPIRA.NET, O=KURUPIRA.NET, STREET="R. CRISTIANO OTONI, 275, SL 113", L=PEDRO LEOPOLDO, S=MG, PostalCode=33600-000, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
05F4AEE4F7D8C03989A29984E7DA6B83

File PE Metadata
Compilation timestamp:
5/17/2011 11:15:18 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:0EOx86WNb+mDmw66NUgaQXVxb7im68vHhYJHD:0EOjWNb+EJ6mXVxviFWq9D

Entry address:
0x30C0

Entry point:
68, 90, 31, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, EC, AD, 37, DE, 4F, 2A, B8, 45, 99, 99, B2, 25, 0F, B8, 1E, D9, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 66, 6F, 53, 69, 7A, 65, 4B, 4D, 53, 00, 0D, 0A, 20, 20, 00, 00, 00, 00, 01, 00, 04, 00, 74, 3F, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, 88, 40, 40, 00, 58, 70, 41, 00, 00, 00, 00, 00, 18, D9, 22, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 40, 31, 40, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
88 KB (90,112 bytes)

Scan kms.exe - Powered by Reason Core Security