vms watch.exe

HeroSpeed Digital Technology Co.,Ltd

It runs as a separate (within the context of its own process) windows Service named “VMS_Server”.
Publisher:
HeroSpeed Digital Technology Co.,Ltd  (signed and verified)

MD5:
c3ecfe4d167170f852078b20d503d81d

SHA-1:
2f11106de083f5ed5023a0862cd81a332d2ac3b5

SHA-256:
0107e2f5b9dbc50b134c7c271d54b70a154eec797ff798e17fa67ba05dd06df6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/6/2024 8:22:22 AM UTC  (today)

File size:
16.7 KB (17,136 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\vms management\vms watch.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/21/2015 5:43:57 AM

Valid to:
5/3/2016 7:01:12 AM

Subject:
E=info@herospeed.cn, CN="HeroSpeed Digital Technology Co.,Ltd", OU=IT Dept., O="HeroSpeed Digital Technology Co.,Ltd", L=GuangZhou, S=GuangDong, C=CN

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121DD3E0BC9AD659510AF855C14F23CE41D

File PE Metadata
Compilation timestamp:
3/8/2016 2:58:04 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
384:ewzpE1yeb6HFVeLKjSHuGEDMQ3DQdrn7vISOEFS:5zOyebAFHSHE8n7bw

Entry address:
0x18CA

Entry point:
E8, 7A, 04, 00, 00, E9, B3, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 60, 31, 40, 00, 89, 0D, 5C, 31, 40, 00, 89, 15, 58, 31, 40, 00, 89, 1D, 54, 31, 40, 00, 89, 35, 50, 31, 40, 00, 89, 3D, 4C, 31, 40, 00, 66, 8C, 15, 78, 31, 40, 00, 66, 8C, 0D, 6C, 31, 40, 00, 66, 8C, 1D, 48, 31, 40, 00, 66, 8C, 05, 44, 31, 40, 00, 66, 8C, 25, 40, 31, 40, 00, 66, 8C, 2D, 3C, 31, 40, 00, 9C, 8F, 05, 70, 31, 40, 00, 8B, 45, 00, A3, 64, 31, 40, 00, 8B, 45, 04, A3, 68, 31, 40, 00, 8D, 45, 08, A3, 74, 31, 40...
 
[+]

Code size:
4 KB (4,096 bytes)

Service
Display name:
VMS_Server

Type:
Win32OwnProcess


Scan vms watch.exe - Powered by Reason Core Security