Apoint.exe

Alps Pointing-device Driver

Alps Electric Co., Ltd.

The executable Apoint.exe has been detected as malware by 10 anti-virus scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Apoint’. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. While running, it connects to the Internet address box361.bluehost.com on port 80 using the HTTP protocol.
Publisher:
Alps Electric Co., Ltd.

Product:
Alps Pointing-device Driver

Version:
8.0.0.281

MD5:
a4fff7c403f1eabe1f34984ccd23edf3

SHA-1:
d9f3a3841fcaf803b07281d35eeeec09f7debb3b

SHA-256:
3d2997682761d81e708d6e4d32de6fd14442bbc2419184701a4da0d2bf0e9e30

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
11/23/2024 12:11:24 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160503-1

AVG
Win32/Sality
2015.0.4591

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.E.gen
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.968.0

Norman
Win32.Sality.3
19.05.2016 01:04:49

File size:
581.9 KB (595,864 bytes)

Product version:
8.0.0.281

Copyright:
Copyright (C) 1999-2012 Alps Electric Co., Ltd.

Original file name:
Apoint.exe

File type:
Executable application (Win32 EXE)

Language:
Japanese (Japan)

Common path:
C:\Program Files\apoint2k\apoint.exe

File PE Metadata
Compilation timestamp:
11/9/2012 4:27:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:OkIgQMtGdFc7krZZQAb+f0MB0oOXdis3hd7lHByHzW1y/b4ITNQUkVTMxHs3D6QN:Vyi7kTlbUoEsPlHVONQXRmHsnaErzh

Entry address:
0x26421

Entry point:
60, 69, EF, 4B, F9, 33, F4, FE, CC, B3, 0D, B9, FB, 53, 81, BA, 8D, 0D, AC, 17, 0B, 59, 76, 0D, B9, 38, DB, B7, B6, 8B, C7, 8D, 1D, 03, 6B, 54, 8E, 0F, BE, FD, 0F, BE, DD, 03, D3, 86, C9, F2, 8B, D2, 72, 07, 0F, AF, CE, 14, C8, FE, CC, 0F, AF, D1, 4D, E8, 5E, 00, 00, 00, 80, E5, BE, F3, 81, FE, 7E, 36, 00, 00, 72, 09, 0F, AF, FF, 0F, AF, CE, 80, CA, B2, 89, C5, 84, CF, F6, C5, 17, 8D, 0D, CC, A0, 6F, EE, 33, C0, 81, FE, DA, 54, 00, 00, 74, 09, 8D, 3D, F3, 17, C9, 45, F3, 8A, DB, B8, 15, 84, 08, 00, 3D, DA...
 
[+]

Code size:
192 KB (196,608 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Apoint

Command:
C:\Program Files\apoint2k\apoint.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to box361.bluehost.com  (69.89.31.161:80)

TCP (HTTP):
Connects to 217-160-0-39.elastic-ssl.ui-r.com  (217.160.0.39:80)

TCP (HTTP):
Connects to 217-160-0-4.elastic-ssl.ui-r.com  (217.160.0.4:80)

TCP (HTTP):
Connects to box383.bluehost.com  (69.89.31.183:80)

TCP (HTTP):
Connects to h30.default-host.net  (138.201.56.16:80)

Remove Apoint.exe - Powered by Reason Core Security