grefc0c.exe

Installer

The application grefc0c.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from storage.googleapis.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Product:
Installer

Description:
Installer-H

Version:
1.0.0.0

MD5:
a0d1a6ff80baac9ec721435cb48be724

SHA-1:
eee203e8a06091073dd0355edb2e5041f05deba5

SHA-256:
df240be3c44b815940a765c804f2240295afda0882725596250cfaebc129982d

Scanner detections:
9 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 7:41:09 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/Imali.303104.1
7.11.218.38

Baidu Antivirus
Adware.MSIL.Imali
4.0.3.15318

Dr.Web
Adware.Downware.10004
9.0.1.077

ESET NOD32
MSIL/Adware.Imali (variant)
9.11337

herdProtect (fuzzy)
2015.6.23.23

IKARUS anti.virus
PUA.MSIL.Downloader
t3scan.1.8.6.0

Kaspersky
not-a-virus:AdWare.MSIL.Agent
14.0.0.2329

Panda Antivirus
Generic Suspicious
15.06.23.11

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.26.3

File size:
2.9 MB (3,070,464 bytes)

Product version:
1.0.0.0

Original file name:
FinalInstaller_dotnet4.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\grefc0c.exe

File PE Metadata
Compilation timestamp:
3/18/2015 10:40:07 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:cZFUO6kcZwzMgmjjTySlH4eBjMxXRhCsNaMYFsqkN6:2xXc+zXmOaH4eZMxPNmsqkN

Entry address:
0x2CFACE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.4724

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.8 MB (2,939,904 bytes)

The file grefc0c.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove grefc0c.exe - Powered by Reason Core Security