grrwsftj.exe

Smart Mobail SOFTWARE, TOV

The file grrwsftj.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
Smart Mobail SOFTWARE, TOV  (signed and verified)

MD5:
46102c6c2ee71f0a53ffc982d706213e

SHA-1:
279f5b9389049dfdd157f933521ec908b74e8dbd

SHA-256:
ca4d970a89a3eeea72d916776bd6197d8e82a7903fc2b4eb62ac7bc980060058

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/27/2024 5:45:19 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.1.28.9

File size:
3.5 MB (3,629,672 bytes)

Common path:
C:\users\{user}\appdata\local\temp\grrwsftj.exe.part

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/8/2016 2:00:00 AM

Valid to:
6/9/2017 1:59:59 AM

Subject:
CN="Smart Mobail SOFTWARE, TOV", OU=IT, O="Smart Mobail SOFTWARE, TOV", STREET=Bud. 2 prospekt Gurova, L=Donetsk, S=Donetska, PostalCode=83000, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F63F9557DBEC1C49100D7027DEB267C3

File PE Metadata
Compilation timestamp:
12/29/2013 11:33:47 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x363150

Entry point:
55, 8B, EC, 81, EC, E4, 00, 00, 00, 0F, B6, 45, FE, 0B, 45, E4, 89, 85, 4C, FF, FF, FF, C7, 85, 44, FF, FF, FF, 00, 00, 00, 00, C7, 85, 38, FF, FF, FF, 00, 00, 00, 00, E8, D5, 2C, 00, 00, 6A, 06, 6A, 00, FF, 15, 64, 60, 76, 00, 0F, B7, 4D, F0, 0B, 4D, 94, 89, 4D, AC, BA, 62, 06, 05, 00, 2B, 55, B0, 81, C2, 14, B6, 00, 00, 89, 55, DC, 8B, 45, B8, 0D, 42, D2, 03, 00, 89, 85, 68, FF, FF, FF, 0F, B7, 8D, 78, FF, FF, FF, 81, C9, 28, 1D, 04, 00, 66, 89, 8D, 48, FF, FF, FF, C7, 85, 74, FF, FF, FF, 53, DF, 0D, 00...
 
[+]

Entropy:
5.6355

Developed / compiled with:
Microsoft Visual C++

Code size:
3.4 MB (3,559,424 bytes)

Remove grrwsftj.exe - Powered by Reason Core Security