KS.EXE

Sassafras K2

Sassafras Software Inc.

It runs as a separate (within the context of its own process) windows Service named “KeyServer”.
Publisher:
Sassafras Software Inc.  (signed and verified)

Product:
Sassafras K2

Description:
Sassafras K2: KeyServer 7.3

Version:
7.3.0.8

MD5:
594a61a8df7b41cd26fa4cd682ea25f9

SHA-1:
95414afbb04820aa802e3469f90baf14a3551d74

SHA-256:
a2f0b247d30f2cf5a93b83f868714a4f936025ff962d4f96d4ded3dbe41d377e

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/30/2024 7:23:57 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
AdWare.MSIL.Kranet.mfNx
2.1.4+

File size:
2.8 MB (2,916,688 bytes)

Product version:
7.3

Copyright:
(c)1990-2016 Sassafras Software Inc.

Trademarks:
Sassafras, KeyServer, and KeyAccess are registered trademarks of Sassafras Software Inc.

Original file name:
KS.EXE

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\sassafras k2\server\ks.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
11/16/2015 6:00:00 PM

Valid to:
11/17/2017 5:59:59 PM

Subject:
CN=Sassafras Software Inc., OU=Secure Application Development, O=Sassafras Software Inc., L=Hanover, S=New Hampshire, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0C16910318A849F138153A563528430E

File PE Metadata
Compilation timestamp:
1/28/2016 5:06:24 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x6F170

Entry point:
48, 89, 5C, 24, 10, 57, 48, 81, EC, 90, 00, 00, 00, FF, 15, 6D, F2, 12, 00, 48, 8B, D8, 80, 38, 22, 0F, 85, F3, 00, 00, 00, 90, 0F, B6, 43, 01, 48, 83, C3, 01, 84, C0, 74, 06, 3C, 22, 75, F0, EB, 05, 80, 3B, 22, 75, 04, 48, 83, C3, 01, 0F, B6, 03, 84, C0, 7E, 0F, 3C, 20, 7F, 0B, 8A, 43, 01, 48, 83, C3, 01, 84, C0, 7F, F1, 48, 8D, 4C, 24, 20, C7, 44, 24, 5C, 00, 00, 00, 00, FF, 15, 24, F2, 12, 00, F6, 44, 24, 5C, 01, 0F, B7, 7C, 24, 60, 75, 05, BF, 0A, 00, 00, 00, 33, C9, FF, 15, 13, F1, 12, 00, 44, 8B, C7...
 
[+]

Entropy:
6.3753

Code size:
1.6 MB (1,690,624 bytes)

Service
Display name:
KeyServer

Description:
KeyServer service

Type:
Win32OwnProcess


Scan KS.EXE - Powered by Reason Core Security