ardg.exe

The executable ardg.exe has been detected as malware by 2 anti-virus scanners. While running, it connects to the Internet address box361.bluehost.com on port 80 using the HTTP protocol.
MD5:
63cf565bbc1257ada5beb92e976b0996

SHA-1:
2d01c3c9daf7c36f88c05cc238cf6689bdd3f57c

Scanner detections:
2 / 68

Status:
Malware

Analysis date:
11/6/2024 12:50:52 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160917-0

ESET NOD32
Win32/Sality virus
6.3.12010.0

File size:
96.7 KB (99,044 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
2/10/2002 8:15:37 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1040

Entry point:
E8, 00, 00, 00, 00, 59, 0F, 6E, D9, 0F, 7E, DD, 81, C5, 00, 02, 00, 00, 55, 8D, 05, 10, C5, 41, B2, C3, 40, 00, C3, 90, 90, 90, 9C, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BA, 10, 00, 00, 00, 10, 00, 00, A4, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D6, 10, 00, 00, 08, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AC, 10, 00, 00, 00, 00, 00, 00, C8, 10, 00, 00, 00, 00, 00, 00, 7D, 00, 45, 78, 69, 74, 50, 72, 6F, 63, 65, 73, 73, 00, 4B, 45, 52, 4E, 45, 4C...
 
[+]

Entropy:
6.9624

Code size:
512 Bytes (512 bytes)

Windows Firewall Allowed Program
Name:
C:\ardg.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to box361.bluehost.com  (69.89.31.161:80)

TCP (HTTP):
Connects to 217-160-0-4.elastic-ssl.ui-r.com  (217.160.0.4:80)

TCP (HTTP):
Connects to 217-160-0-39.elastic-ssl.ui-r.com  (217.160.0.39:80)

Remove ardg.exe - Powered by Reason Core Security