groovorio_soft_partner.exe

The application groovorio_soft_partner.exe has been detected as a potentially unwanted program by 17 anti-malware scanners. The file has been seen being downloaded from dm930xmxv1gqs.cloudfront.net.
MD5:
1d797c2393877d5d12410249a15919b9

SHA-1:
d04fd97c2b604502325dff538d9a8a46864cc6aa

SHA-256:
351d4bef4d127e983eeb54f7f78d5638206c7a0888e252a9aca3e9731197a3ea

Scanner detections:
17 / 68

Status:
Potentially unwanted

Analysis date:
5/6/2024 12:34:46 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1926393
491

Agnitum Outpost
PUA.DL.Agent
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.181.228

avast!
Win32:Dropper-gen [Drp]
2014.9-151002

AVG
AdInstaller.Astromenda
2016.0.2969

Bitdefender
Trojan.GenericKD.1926393
1.0.20.1375

Emsisoft Anti-Malware
Trojan.GenericKD.1926393
8.15.10.02.05

ESET NOD32
Win32/DealPly (variant)
9.10632

F-Secure
Trojan.GenericKD.1926393
11.2015-02-10_6

G Data
Trojan.GenericKD.1926393
15.10.24

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.7.8.0

McAfee
Artemis!1D797C239387
5600.6625

MicroWorld eScan
Trojan.GenericKD.1926393
16.0.0.825

nProtect
Trojan.GenericKD.1926393
14.10.28.01

Reason Heuristics
PUP.Bundler.Meta (L)
15.10.2.5

Trend Micro House Call
TROJ_GEN.R02SH09JQ14
7.2.275

VIPRE Antivirus
Trojan.Win32.Generic
34310

File size:
390.5 KB (399,872 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\groovorio_soft_partner.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:f2zr8g8K5zGPiezO8g7HdktrEEHQB1avjZP6R:+H88VGPbOVHKtrFwB1avjZP6R

Entry address:
0x55228

Entry point:
55, 8B, EC, 83, C4, F0, B8, 90, 50, 45, 00, E8, 20, 1B, FB, FF, 68, 60, 52, 45, 00, 6A, 00, 6A, 00, 6A, 00, 33, C9, BA, 7C, 52, 45, 00, 33, C0, E8, 7F, B3, FF, FF, E8, FE, F4, FA, FF, 00, 00, FF, FF, FF, FF, 10, 00, 00, 00, 4A, 2D, 34, 2C, 6A, 61, 2D, 30, 2C, 62, 77, 67, 62, 2E, 60, 58, 00, 00, 00, 00, FF, FF, FF, FF, 1C, 00, 00, 00, 2D, 30, 2C, 70, 2C, 2D, 6F, 7A, 6B, 67, 6D, 64, 6D, 75, 6D, 7A, 2D, 32, 2D, 2D, 2C, 6B, 67, 69, 2D, 38, 2C, 48, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6056

Developed / compiled with:
Microsoft Visual C++

Code size:
337 KB (345,088 bytes)

The file groovorio_soft_partner.exe has been seen being distributed by the following URL.

Remove groovorio_soft_partner.exe - Powered by Reason Core Security