grvstubsetup.exe

The executable grvstubsetup.exe has been detected as malware by 10 anti-virus scanners. The file has been seen being downloaded from dm930xmxv1gqs.cloudfront.net.
MD5:
c55105f705ef643267eaf1da1b120792

SHA-1:
034e338f52576f22617c38d3a0bd6cba43318fb3

SHA-256:
2d3e9aa668756a8c025ccecda2e52973bf60bc063c53f5075ccd6dd2a664f994

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
11/23/2024 7:58:54 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1870912
857

avast!
Win32:Dropper-gen [Drp]
2014.9-140930

Bitdefender
Trojan.GenericKD.1870912
1.0.20.1365

Emsisoft Anti-Malware
Trojan.GenericKD.1870912
8.14.09.30.06

F-Secure
Trojan.GenericKD.1870912
11.2014-30-09_3

G Data
Trojan.GenericKD.1870912
14.9.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.7.8.0

McAfee
Artemis!C55105F705EF
5600.6991

MicroWorld eScan
Trojan.GenericKD.1870912
15.0.0.819

nProtect
Trojan.GenericKD.1870912
14.09.24.01

File size:
391.5 KB (400,896 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\grvstubsetup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:C2TXkQ8e1iGyP6PimgLO2SjRMZR53FLxS1pNN:h7k4UGywijO/jRcxS1pNN

Entry address:
0x55074

Entry point:
55, 8B, EC, 83, C4, F0, B8, DC, 4E, 45, 00, E8, D4, 1C, FB, FF, 68, B0, 50, 45, 00, 6A, 00, 6A, 00, 6A, 00, 33, C9, BA, CC, 50, 45, 00, B8, F4, 50, 45, 00, E8, E4, B4, FF, FF, E8, AF, F6, FA, FF, 00, 00, 00, FF, FF, FF, FF, 10, 00, 00, 00, 4A, 2D, 34, 2C, 6A, 61, 2D, 30, 2C, 62, 77, 67, 62, 2E, 60, 58, 00, 00, 00, 00, FF, FF, FF, FF, 1C, 00, 00, 00, 2D, 30, 2C, 70, 2C, 2D, 6F, 7A, 6B, 67, 6D, 64, 6D, 75, 6D, 7A, 2D, 32, 2D, 2D, 2C, 6B, 67, 69, 2D, 38, 2C, 48, 00, 00, 00, 00, FF, FF, FF, FF, 09, 00, 00, 00...
 
[+]

Entropy:
6.5862

Developed / compiled with:
Microsoft Visual C++

Code size:
336.5 KB (344,576 bytes)

The file grvstubsetup.exe has been seen being distributed by the following URL.

Remove grvstubsetup.exe - Powered by Reason Core Security