Windows KMS Activator Ultimate 2015 v2.6.exe

Windows KMS Activator Ultimate 2015

The application Windows KMS Activator Ultimate 2015 v2.6.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. While running, it connects to the Internet address n1nw8shg121.shr.prod.ams1.secureserver.net on port 80 using the HTTP protocol.
Product:
Windows KMS Activator Ultimate 2015

Version:
2.6.0.0

MD5:
4a71b9641b0f09e8618f91b55216b8da

SHA-1:
2b3160570824c74ec11ee889fb877d4cc9287391

SHA-256:
b808dca3a61c4d81601587a2c636fa5e421812801fab288707dc52ba6037e7eb

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 12:51:48 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.ProcPatcher
7.1.1

avast!
Win32:Dropper-gen [Drp]
2014.9-151002

Baidu Antivirus
Trojan.MSIL.HackTool.WinActivator
4.0.3.15102

Comodo Security
UnclassifiedMalware
23315

ESET NOD32
MSIL/Riskware.HackTool.WinActivator (variant)
9.12320

Fortinet FortiGate
Riskware/HackTool_WinActivator
10/2/2015

G Data
Win32.Application.Agent.6D63TR
15.10.25

K7 AntiVirus
Riskware
13.210.17345

Kaspersky
not-a-virus:NetTool.Win64.RPCHook
14.0.0.1339

McAfee
Artemis!4A71B9641B0F
5600.6625

Microsoft Security Essentials
HackTool:Win32/AutoKMS
1.1.12101.0

Panda Antivirus
Trj/CI.A
15.10.02.05

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Sophos
Generic PUA CL (PUA)
4.98

Trend Micro
TROJ_GEN.R01TC0OIR15
10.465.02

VIPRE Antivirus
Trojan.Win32.Generic
44118

File size:
16.5 MB (17,347,072 bytes)

Product version:
2.6.0.0

Copyright:
Copyright © 2013

Original file name:
Windows KMS Activator Ultimate 2015 v2.6.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\windows kms activator ultimate 2015 v2.6\windows kms activator ultimate 2015 v2.6.exe

File PE Metadata
Compilation timestamp:
8/25/2015 3:31:53 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
393216:dKgMDF/2RKN/Hiu0MTXldf9QZkjjqgU57xMgHT9yWXV:dKn4Ju0MTNQoSfL

Entry address:
0x107317E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9049

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16.4 MB (17,240,576 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to n1nw8shg121.shr.prod.ams1.secureserver.net  (188.121.41.137:80)

Remove Windows KMS Activator Ultimate 2015 v2.6.exe - Powered by Reason Core Security