grawim2070w2kxp.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from www1.medion.de and multiple other hosts.
MD5:
41a585e1f0f520d7840393737ebdd030

SHA-1:
f2189ca19d0bb74c7fb2073a8d344d0694299827

SHA-256:
4d73a76e9df58cfc2b79765cd283628c1cee2ec00d097a9b9b34f4cdb0a84db6

Scanner detections:
3 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/27/2024 4:55:43 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.6379

K7 AntiVirus
Riskware
13.204.15935

Rising Antivirus
PE:Trojan.Barys!6.50A
23.00.65.16108

File size:
4.4 MB (4,639,280 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\grawim2070w2kxp.exe

File PE Metadata
Compilation timestamp:
8/25/1999 9:02:31 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
3.10

CTPH (ssdeep):
98304:/DiC4dzLkcfinHSSSbDgfAIuj31bXC6x9aPYMMOT1RO8n8:/R4dzFWbubVJx9OYBO5o8n8

Entry address:
0x7E60

Entry point:
55, 8B, EC, 83, EC, 44, 56, FF, 15, 00, 33, 44, 00, 8B, F0, 8A, 00, 3C, 22, 75, 17, 84, C0, 74, 0B, 80, 3E, 22, 74, 0B, 46, 80, 3E, 00, 75, F5, 80, 3E, 22, 75, 0D, 46, EB, 0A, 3C, 20, 7E, 06, 46, 80, 3E, 20, 7F, FA, 80, 3E, 00, 74, 0B, 80, 3E, 20, 7F, 06, 46, 80, 3E, 00, 75, F5, C7, 45, E8, 00, 00, 00, 00, 8D, 4D, BC, 51, FF, 15, FC, 32, 44, 00, F6, 45, E8, 01, B8, 0A, 00, 00, 00, 74, 04, 0F, B7, 45, EC, 50, 56, 6A, 00, 6A, 00, FF, 15, E4, 32, 44, 00, 50, E8, 70, F8, FF, FF, 50, FF, 15, D4, 32, 44, 00, 5E...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
28 KB (28,672 bytes)

The file grawim2070w2kxp.exe has been seen being distributed by the following 2 URLs.

Scan grawim2070w2kxp.exe - Powered by Reason Core Security