grpconv.exe

  • File Path: C:\Windows\system32\grpconv.exe
  • Description: Windows Progman Group Converter

Hashes

Type Hash
MD5 FF2F3130C373AE4F8F01812D1D2AF6FA
SHA1 552875BF49749EB87AE97AA8B55E10ACA795CC28
SHA256 8B188B7050533BA36335AA17DFBFC579935EAF0A9BD5009A524754513216A978
SHA384 FE845CBC3F5B1F545C6C69C51AD6F5A77276EA84341742042F6C56FEA9DF11C1BCF1594964817E30819D417F25269920
SHA512 4AFFBA01E8BF7E29ECA56CCC7C751FCC8E5730D789698D5F6E6895D896BEFCCE4C913E4F206CFE3D5DAA2597C8BBC496D58C461E2BA9273641C92DCAE0916A36
SSDEEP 768:i4lLHWxurvlN2nxibl5IVn3lwOlYaj9elRhFYSKwpzYwSwES4cP8rVGyjlq3:i4lLHb328sShDKwpEwSwicOGyBq3
IMP 671EAFCFCFA86F159D56B51A22BF5C87
PESHA1 1FB37B4A1A989AA5DD9F745C921038F70BC70331
PE256 5B5224EDB77EBEC16BFAB3D6693E8AD33F0AEC6DDBDC98CE27E2DC7437EA501F

Signature

  • Status: Signature verified.
  • Serial: 33000001C422B2F79B793DACB20000000001C4
  • Thumbprint: AE9C1AE54763822EEC42474983D8B635116C8452
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: GRPCONV.EXE.MUI
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.17763.1 (WinBuild.160101.0800)
  • Product Version: 10.0.17763.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/72
  • VirusTotal Link: https://www.virustotal.com/gui/file/8b188b7050533ba36335aa17dfbfc579935eaf0a9bd5009a524754513216a978/detection/

Possible Misuse

The following table contains possible examples of grpconv.exe being misused. While grpconv.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma registry_event_asep_reg_keys_modification_wow6432node.yml - Details: 'grpconv -o' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.