ground.exe

The application ground.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address box361.bluehost.com on port 80 using the HTTP protocol.
MD5:
57b783b584affc844a71a8ea3a6e0392

SHA-1:
b4ccdad5ff5b72867790d2792a86fbfd93479aef

SHA-256:
0c3bb434b14e52ad2597d435496afc8fb8a38097a81c5f102733cecb908857e8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 3:31:39 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Downloader (M)
17.3.8.0

File size:
738.5 KB (756,224 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\ground.exe

File PE Metadata
Compilation timestamp:
7/1/2009 1:50:03 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xC3877

Entry point:
83, 3C, 24, FE, 77, FE, 8D, 64, 24, CC, 60, 83, EC, DC, E8, 81, 00, 00, 00, 4B, 66, 4B, 75, FC, F7, D6, B2, 1F, FF, 73, 3C, 59, 81, E9, FD, FF, FF, 7F, 0F, 83, E7, FF, FF, FF, 81, D9, E6, 13, 00, 00, 71, DF, 31, E0, 3C, 02, FF, B4, 19, E4, 13, 00, 80, 83, C4, 04, 66, 81, 44, 24, FC, B0, BA, 75, C8, 49, 86, C5, 40, E9, 97, FE, FF, FF, 6A, 04, 59, 58, AB, 48, F3, AB, C3, 68, 56, 46, 41, 3C, E9, 7D, 00, 00, 00, 5A, 59, 58, C2, 30, 00, 2B, C0, 48, B9, B5, EF, 00, 00, 47, 0F, AF, CA, 30, 4F, FF, 47, 28, 77, FE...
 
[+]

Entropy:
7.1173

Code size:
451 KB (461,824 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to box361.bluehost.com  (69.89.31.161:80)

Remove ground.exe - Powered by Reason Core Security