KurumNet.exe

KurumNet

ALI ELCIN UGUR BILGISAYAR

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘KurumNet’.
Publisher:
Ugur Yazılım  (signed by ALI ELCIN UGUR BILGISAYAR)

Product:
KurumNet

Version:
4.09.0171

MD5:
76e1a881dce0d1dd30825fa4c77cd85a

SHA-1:
dcbecfb7d5245c0d296c78011a8d7fbbce177c52

SHA-256:
9470ee765f2ef57a184ebf2cbd7937ef72a90ba961fe925507da6f8c15055364

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/21/2025 4:04:39 PM UTC  (today)

File size:
5.3 MB (5,592,376 bytes)

Product version:
4.09.0171

Original file name:
KurumNet.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/20/2015 3:00:00 AM

Valid to:
10/20/2016 2:59:59 AM

Subject:
CN=ALI ELCIN UGUR BILGISAYAR, O=ALI ELCIN UGUR BILGISAYAR, STREET="KAT:2 DAIRE:3, NO:543 ANADOLU CADDESI", L=İzmir, S=Karşıyaka, PostalCode=35560, C=TR

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C8037678FD3F516C17597E6B0219D047

File PE Metadata
Compilation timestamp:
11/7/2015 9:48:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:njNB8efOKVmytxGpo5+PVSSmEP1idt1BCRCJc4QtWm7a/ztDDKxS:7+KVmytxGpo5+PVSSmEP1idt1BCRCJcq

Entry address:
0x76F64

Entry point:
68, F8, 72, 47, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 98, D9, ED, F7, EC, 0A, 1F, 42, A8, CB, 56, 0B, 5D, A3, 0D, C6, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4B, 75, 72, 75, 6D, 4E, 65, 74, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 0C, 00, 18, 82, 4A, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, AC, 84, 4A, 00, B0, 21, 95, 00, 00, 00, 00, 00, 40, 00, B6, 0B, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
5.3 MB (5,574,656 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
KurumNet

Command:
C:\kurumnet\terminal\kurumnet.exe


Scan KurumNet.exe - Powered by Reason Core Security