kms.exe

Kurupira Message

KURUPIRA.NET

Publisher:
KURUPIRA.NET  (signed and verified)

Product:
Kurupira Message

Version:
1.00

MD5:
79afb7eb9552259515be1df545ef4fb1

SHA-1:
97c649c6725956d3ed778ec458b26497d380193f

SHA-256:
694ec3a1878af05d3bd66d43e0d4cd857ea5f05681bbeda544cef0c6019f36df

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/24/2024 10:49:44 PM UTC  (today)

Scan engine
Detection
Engine version

NANO AntiVirus
Trojan.Win32.VbCrypt.dzbhyh
1.0.10.5081

Rising Antivirus
PE:Trojan.VBInject!1.64FA
23.00.65.151208

File size:
106.2 KB (108,728 bytes)

Product version:
1.00

Copyright:
Kurupira.NET (c)

Trademarks:
Kurupira.NET (c)

Original file name:
kms.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\application data\appdata\application data\appdata\application data\appdata\application data\appdata\application data\appdata\application data\kurupira\webfilter\kms.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/21/2012 9:00:00 PM

Valid to:
5/22/2015 8:59:59 PM

Subject:
CN=KURUPIRA.NET, O=KURUPIRA.NET, STREET="R. CRISTIANO OTONI, 275, SL 113", L=PEDRO LEOPOLDO, S=MG, PostalCode=33600-000, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
05F4AEE4F7D8C03989A29984E7DA6B83

File PE Metadata
Compilation timestamp:
5/17/2011 11:15:18 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:XEOx86WNb+mDmw66NUgaQXVxb7im68vHhYJp:XEOjWNb+EJ6mXVxviFWq/

Entry address:
0x30C0

Entry point:
68, 90, 31, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, EC, AD, 37, DE, 4F, 2A, B8, 45, 99, 99, B2, 25, 0F, B8, 1E, D9, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 66, 6F, 53, 69, 7A, 65, 4B, 4D, 53, 00, 0D, 0A, 20, 20, 00, 00, 00, 00, 01, 00, 04, 00, 74, 3F, 40, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, 88, 40, 40, 00, 58, 70, 41, 00, 00, 00, 00, 00, 18, D9, 22, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 40, 31, 40, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
88 KB (90,112 bytes)

Scan kms.exe - Powered by Reason Core Security