appdrive.exe

The executable appdrive.exe has been detected as malware by 1 anti-virus scanner. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘winlogon.exe’. While running, it connects to the Internet address dev.ucoz.net on port 80 using the HTTP protocol.
MD5:
ed3560c2931f5c52fadddfa3b4d5cece

SHA-1:
1a589abacf0a8c00aec355db6e271457c406e3d4

SHA-256:
862dd5e27ec7d68c2e44677ed061b49c5307826e3e5fe478104b628b0c166cf7

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/26/2024 1:44:41 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.3.28.20

File size:
274.5 KB (281,088 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\appdrive.exe

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:Q/ncevL2IwvB2HPVz0GrP9A7BrGkfzEZQTnOG7JNwAIHYrz4VwimiQDIv:Q/ntL2FJGAJRaWJ1rviL

Entry address:
0x258F0

Entry point:
55, 8B, EC, B9, 0B, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, 56, 57, B8, A8, 57, 42, 00, E8, 1F, 0E, FE, FF, 33, C0, 55, 68, 89, 5D, 42, 00, 64, FF, 30, 64, 89, 20, A1, EC, 75, 42, 00, 33, D2, 89, 10, B3, 01, 33, C0, 55, 68, 6A, 59, 42, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 9C, 56, 42, 00, E8, 33, 0B, FE, FF, 8B, 45, EC, 50, 6A, 0A, 8B, 0D, C0, 76, 42, 00, 8B, 09, B2, 01, A1, 7C, 61, 41, 00, E8, 05, 35, FF, FF, A3, 5C, 9A, 42, 00, 33, C0, 5A, 59, 59, 64, 89, 10, EB, 0C, E9, 79, E1, FD, FF, 33...
 
[+]

Entropy:
6.1133

Developed / compiled with:
Microsoft Visual C++

Code size:
147.5 KB (151,040 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
winlogon.exe

Command:
C:\windows\temp\winlogon.exe


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to dev.ucoz.net  (193.109.247.229:80)

Remove appdrive.exe - Powered by Reason Core Security