kumawarsetup1a.exe

Kuma, LLC

This is a setup program which is used to install the application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Kuma, LLC  (signed and verified)

MD5:
6d7b4e21efdfb967587ec81ae002c368

SHA-1:
d1ff5667d7a681a401f8c6fe1106c23e3aadcccc

SHA-256:
2a24235e9b796d13579e1f64d58d951576f5059027622a22ce50d68d09e5beea

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/27/2024 6:43:33 PM UTC  (today)

Scan engine
Detection
Engine version

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

File size:
303.5 KB (310,744 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\kumawarsetup1a.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/27/2005 5:00:00 PM

Valid to:
9/28/2006 4:59:59 PM

Subject:
CN="Kuma, LLC", OU=Kuma Reality Games, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Kuma, LLC", L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5D527D33CCEEF5AE2BBE33C5D381D221

File PE Metadata
Compilation timestamp:
11/19/2003 5:13:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:nJ1P9uogR1csGYdIqyJzfGcjtvtiR5tbbS:n1wDGKIBEI8bbS

Entry address:
0x4069

Entry point:
83, EC, 10, 53, 55, 56, 57, C7, 44, 24, 14, F0, 91, 40, 00, 33, ED, C6, 44, 24, 13, 20, FF, 15, 2C, 70, 40, 00, 55, FF, 15, 88, 72, 40, 00, BE, 00, D4, 42, 00, BF, 00, 04, 00, 00, 56, 57, A3, 60, 6F, 42, 00, FF, 15, C4, 70, 40, 00, E8, 9F, FF, FF, FF, 8B, 1D, 90, 70, 40, 00, 85, C0, 75, 21, 68, FB, 03, 00, 00, 56, FF, 15, 60, 71, 40, 00, 68, E4, 91, 40, 00, 56, FF, D3, E8, 7C, FF, FF, FF, 85, C0, 0F, 84, 59, 01, 00, 00, BE, E0, 66, 42, 00, 56, FF, 15, 68, 70, 40, 00, 68, D8, 91, 40, 00, 56, E8, FE, 27, 00...
 
[+]

Entropy:
7.7941  (probably packed)

Code size:
23 KB (23,552 bytes)

The file kumawarsetup1a.exe has been seen being distributed by the following 15 URLs.

http://gsf-cf.softonic.com/d1f/f56/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53457&instance=softonic_en&type=PROGRAM&Expires=1487288785&Signature=QUaPuuHQQlGRUpkqke7102edjm5ANggFVlvsLkOF7PJLhPztkHE1zGFauKH~7ryj~RhXWBqQz5bKa6xV~OdLiI1Z1YTpSK5ktsFdtM3YDIMH9kvUb6NlcAnyAao4rJAfkAIz6bWr9t6KrCxR8J9Q0zchHixBwl4KJ9OVXpt4EeM_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=KumaWarSetup1A.exe

http://gsf-cf.softonic.com/d1f/f56/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53457&instance=softonic_en&type=PROGRAM&Expires=1480405819&Signature=BzMOYFKt02fUOOjoi55bhmlvsuroFkeI6GPJemQUCm8E23evxMUGY6~9FVAKNCmKzppZZhwWSW2cKmgUBuFi7nHLQ9zU31iyYysaBmuKmzdX5euXHHsEZtKKQR-BFauPFGGOZ3V5TdzPYqfNFDFbUBKzt4CnYFDT5E9JGYM1gF0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=KumaWarSetup1A.exe

http://gsf-cf.softonic.com/d1f/f56/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53457&instance=softonic_en&type=PROGRAM&Expires=1476505169&Signature=YmGtqO-f2KHvZENLG3EiPGYjIyg0nQB6jIBuyR3GRfUP00bx72FUGjvm1uEfaMCoM0RUor2KiG5AJ-j-8xrO90OWRfVIkpIwT9V2Fbz0PWj8LCJYgJScEefMjRxv6cbyaeUFuw0ZiQp5vfwhlOWVRzqeiQ8aW0r7Z7dQe854ofY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=KumaWarSetup1A.exe

http://gsf-cf.softonic.com/d1f/f56/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53457&instance=softonic_en&type=PROGRAM&Expires=1448264147&Signature=KFxh6tdj0KGZB8Nj-UijMSmkCefK5s4eaDo8adlG5F4EpS52J2zuTOUI5fSCmC6OPVKYFlVoabIoR30rCxb-t-O6U~KtqTHCsrX2sb8yOzzt2VIyvf0EANL6QmBahcTNBEHuvw6QNJKfS5c27mcCtNAjvcwD9oQX64wzYnfrxlw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=KumaWarSetup1A.exe

http://gsf-cf.softonic.com/d1f/f56/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53457&instance=softonic_en&type=PROGRAM&Expires=1478224841&Signature=P~9tPbhRz3kxx5WB5IM-XqU2EffrxmATFLATN3D1U6v988ulqqKRiw7eKYGgUJYtU0YS2ql0Wtl0RpD4y9eI7qECelG45qV1~LPIpAjmx1aBgKgzDJqa9y5ORQc3c9t6vWqpAHnu8QRNcvmAx616BLfMcbKA-vhcnwkRGAf3Yyg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=KumaWarSetup1A.exe

http://gsf-cf.softonic.com/d1f/f56/.../file?SD_used=0&channel=WEB&fdh=no&id_file=53457&instance=softonic_en&type=PROGRAM&Expires=1477021820&Signature=hJRbE9lRPw5PqXehoPM1LB1g1rDV-mwRpsb54pIMOJPwXGhgtHXl69XNbhIYzcpcfP~GZAv2SEJkZArRegaTuRd0CYJ43MkvKYf5ndNxZtXxVdheIbB9fdqPyEazPCQGy7xeOLSfmHk2fXRnjt6EbQEWHZ1deTFmMym~7KsV~xw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=KumaWarSetup1A.exe

http://www.bitsfarmclean.com/Ze717GeWI7azANYbJv6uUjhrBKlvT8GW7k25JNl3bJ2vS_nqP9hloZfE_IemfxVZpwq rJx3 hgJqWRbbEHn4uERAFTp4J5zP_TCNv4NNm4vRDP0ko1LKHrGs8BVGOIrfsJb_gE1HqgYtFLzNm5Vij6uCapdPMb8cGG2uihT1EGfHUi qDq fxuFh60sXYQKpsRu_iBy-G08AAGRgnq2tCe7UwSZElFlUktn2OT2f1xLwhebjOLutaCpzeH3tNfip71D_7eXHU3Sxm4fMeI6r1VL_xzYwozD5AL2IEgxCkzhC4w==

Scan kumawarsetup1a.exe - Powered by Reason Core Security