kzmount2.exe

KuaiZip

Shanghai Guangle Network Technology Co., Ltd.

The application kzmount2.exe by Shanghai Guangle Network Technology Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:

Product:
KuaiZip

Version:
2.8.0.2

MD5:
5fe7755ef889e2bda2d38a83ec58f655

SHA-1:
722387a801e9bf937431941446317a9d8d0c1a01

SHA-256:
77d9aba2b8ca584d98f097b6cd3c26b5fe12fc015ed097411b20de43f2f56984

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 10:45:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.KuaiZip (M)
16.9.21.7

File size:
565.2 KB (578,720 bytes)

Product version:
2.8.0.1

Copyright:
Copyright (c) 上海广乐网络科技有限公司, All rights reserved

Original file name:
KZMount.dll

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\kuaizip\x64\kzmount2.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
7/13/2016 3:41:43 PM

Valid to:
7/13/2017 3:41:43 PM

Subject:
CN="Shanghai Guangle Network Technology Co., Ltd.", O="Shanghai Guangle Network Technology Co., Ltd.", L=Shanghai, S=Shanghai, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA G2, O=WoSign CA Limited, C=CN

Serial number:
40757B407A929353C165458EE6664935

File PE Metadata
Compilation timestamp:
7/11/2016 8:09:18 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:yrVx50BGhVaudIGexZdAtOA/27FfgbaBZWxGZtYn2pFRERpVlRZxX:yrVxPVaovexZd9SmBZzZtYn2rREfDB

Entry address:
0x2A65C

Entry point:
48, 83, EC, 28, E8, 0B, 65, 00, 00, 48, 83, C4, 28, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 2B, D1, 49, 83, F8, 08, 72, 22, F6, C1, 07, 74, 14, 66, 90, 8A, 01, 3A, 04, 0A, 75, 2C, 48, FF, C1, 49, FF, C8, F6, C1, 07, 75, EE, 4D, 8B, C8, 49, C1, E9, 03, 75, 1F, 4D, 85, C0, 74, 0F, 8A, 01, 3A, 04, 0A, 75, 0C, 48, FF, C1, 49, FF, C8, 75, F1, 48, 33, C0, C3, 1B, C0, 83, D8, FF, C3, 90, 49, C1, E9, 02, 74, 37, 48, 8B, 01, 48, 3B, 04, 0A, 75, 5B, 48, 8B, 41...
 
[+]

Code size:
275.5 KB (282,112 bytes)

Remove kzmount2.exe - Powered by Reason Core Security