KMSAuto Net.exe

KMSAuto Net

Ratiborus MSFree Inc.

This is a setup program which is used to install the application.
Publisher:
MSFree Inc.  (signed by Ratiborus MSFree Inc.)

Product:
KMSAuto Net

Version:
1.3.5

MD5:
0ca71a9f5914eca4e62d52694b3c2302

SHA-1:
426dc93fa10d28ca6b93f851300026c0f58128c5

SHA-256:
0cada35dcb0f46630296241f4d2e1974b99c104cb0a6438f575c0bce51098362

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
1/13/2025 7:36:48 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/HackTool.KMSAuto.E potentially unsafe application
7.0.302.0

Microsoft Security Essentials
Threat.Undefined
1.215.1102.0

File size:
6.6 MB (6,970,104 bytes)

Product version:
1.3.5

Original file name:
KMSAuto Net.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
Ratiborus MSFree Inc.

Valid from:
7/26/2015 8:49:10 AM

Valid to:
1/1/2040 12:59:59 AM

Subject:
CN=Ratiborus MSFree Inc.

Issuer:
CN=Ratiborus MSFree Inc.

Serial number:
1EB52394D7A0F7804AC8F80D76139591

File PE Metadata
Compilation timestamp:
7/28/2015 11:21:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
196608:8ywBGqyw15cywuywQyw8ywlywaywTyw9lywfywEywFyw5ywwywmIBywyyweywiy0:hwBGnw1zwjwNwhwIw3w2w9IwqwJwow0Q

Entry address:
0x69AB1E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
6.6 MB (6,917,120 bytes)

The file KMSAuto Net.exe has been discovered within the following program.

www.Toolwiz.com
About 6% of users remove it
 
Powered by Should I Remove It?

The file KMSAuto Net.exe has been seen being distributed by the following 33 URLs.

ftp://mostrador/windows 10 activador/ACTIVADOR WINDOWS 10 FINAL/.../KMSAuto Net.exe

https://docs.google.com/uc?authuser=0&id=0B0VE8KrkWj0eeHh1aGJIU0RZaG8&export=download

about:internet

https://mega.nz/temporary/.../yF8ygTJC

http://software.zeke/.../KMSAuto Net.exe

https://mega.nz/persistent/.../UEsFwKwR

http://download948.mediafire.com/y85rd4k53evg/.../KMSAuto Net.exe

https://docs.google.com/uc?id=0B7k5-sPL_JSWNWV3WUxrVHFRSWc&export=download

ftp://192.168.4.100/un click master/programas/.../KMSAuto Net.exe

https://cloclo28.cldmail.ru/Tnwm4HQKRtePVUKfVEd/G/.../M88Nk7fK9?key=d442d48efaf0fb253cc18635b4a09bace35d50ad

https://cloclo30.cldmail.ru/mDpJg1wNC29NMK4cuiA/G/.../M88Nk7fK9?key=c87322f04586fd34eab25fb0c04d819ba5dfe345

https://docs.google.com/uc?authuser=0&id=0B89VcxvvRLCfSFA0djFmQWRqOUU&export=download

https://mega.nz/temporary/.../h9kzmKQB

https://cvws.icloud-content.com/B/.../KMSAuto Net.exe

https://docs.google.com/uc?authuser=0&id=0BwbKlBjSbXriZXpYcVBRM0RWMzA&export=download

https://mega.nz/temporary/.../UEsFwKwR

https://cloclo14.cldmail.ru/2xgfwjBxrjR4ddXrsVUX/G/.../M88Nk7fK9?key=41ebc6309a475d1ea7c3757394174ec5228195c8

https://cloclo39.cldmail.ru/VoU5ZR1Q72j1kR2RjjE/G/.../M88Nk7fK9?key=17016308c8051fedcf6c05f3e443fd7b793f556d

chrome-extension://bigefpfhnfcobdlfbedofhhaibnlghod/persistent/.../gxRF2bqA

chrome-extension://bigefpfhnfcobdlfbedofhhaibnlghod/persistent/.../EhNTHKDI

Latest 30 of 33 download URLs

Scan KMSAuto Net.exe - Powered by Reason Core Security