drpanel.exe

The executable drpanel.exe has been detected as malware by 23 anti-virus scanners. While running, it connects to the Internet address adp5.prolocation.net on port 80 using the HTTP protocol.
MD5:
7a993ace402c724d022ad6f58f76ff58

SHA-1:
b49a52ffeb36895e0f26ed871655e954a7da898d

SHA-256:
ce1804382228ac4722ec5a72c7733655dbbdbe482783e03930be6cf90cbade64

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
11/27/2024 4:24:52 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.426688
893

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
Dropper/Win32.Necurs
2014.08.26

Avira AntiVirus
TR/Graftor.2081254
7.11.169.62

avast!
Win32:Malware-gen
140813-1

AVG
Found Win32/DH{fyB8ZA}
2014.0.4007

Bitdefender
Gen:Variant.Kazy.426688
1.0.20.1185

Dr.Web
Trojan.Siggen6.22689
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Kazy.426688
9.0.0.4324

ESET NOD32
Win32/Agent.VPS trojan
7.0.302.0

Fortinet FortiGate
W32/Agent.VPS!tr
8/25/2014

F-Prot
W32/new-malware
4.6.5.141

F-Secure
Gen:Variant.Kazy.6550
11.2014-25-08_2

G Data
Gen:Variant.Kazy.426688
14.8.24

IKARUS anti.virus
Trojan-Ransom.Win32.Blocker
t3scan.1.7.5.0

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3352

MicroWorld eScan
Gen:Variant.Kazy.426688
15.0.0.711

NANO AntiVirus
Trojan.Win32.Graftor.dedqmf
0.28.2.61721

Qihoo 360 Security
Win32/Trojan.617
1.0.0.1015

Sophos
Troj/Agent-AIGC
4.98

Trend Micro House Call
TROJ_GEN.R08NC0RHP14
7.2.237

Trend Micro
TROJ_GEN.R08NC0RHP14
10.465.25

VIPRE Antivirus
Threat.4150696
32210

File size:
98 KB (100,352 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Application data\microsoft\windows\ieupdate\drpanel.exe

File PE Metadata
Compilation timestamp:
8/23/2004 10:53:57 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

CTPH (ssdeep):
3072:ZFq9JQyZ/fi0ni/qBr6VIsSBIBhJfaATQqxmTTg5:Lqx5q0iSeIsSBIB3faAwT

Entry address:
0x560F

Entry point:
55, 8B, EC, 83, E4, F8, 81, EC, 0C, 08, 00, 00, 53, 56, 57, E8, 7D, BF, FF, FF, E8, F8, F9, FF, FF, 33, F6, 84, C0, 0F, 84, FC, 02, 00, 00, 8D, 84, 24, 88, 06, 00, 00, 50, 68, 02, 02, 00, 00, FF, 15, 30, 53, 41, 00, 85, C0, 0F, 85, E1, 02, 00, 00, 8D, 44, 24, 14, 50, 6A, 0A, 89, 74, 24, 18, FF, 15, E8, 50, 41, 00, 50, FF, 15, 0C, 50, 41, 00, 85, C0, 74, 23, 8D, 44, 24, 10, 50, 6A, 01, 6A, 02, 56, 68, 00, 00, 00, 02, FF, 74, 24, 28, FF, 15, 04, 50, 41, 00, FF, 74, 24, 14, E8, C2, 06, 00, 00, 59, 56, FF, 74...
 
[+]

Entropy:
6.6873

Developed / compiled with:
Microsoft Visual C++

Code size:
77.5 KB (79,360 bytes)

Scrnsave
Name:
drpanel.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to track-eu.adform.net  (85.235.246.3:80)

TCP (HTTP):
Connects to server-54-230-61-125.mad50.r.cloudfront.net  (54.230.61.125:80)

TCP (HTTP):
Connects to s3-website-us-east-1.amazonaws.com  (54.231.14.212:80)

TCP (HTTP):
Connects to s3-1-w.amazonaws.com  (176.32.102.81:80)

TCP (HTTP):
Connects to retarget.xa.dc.openx.org  (173.241.240.7:80)

TCP (HTTP):
Connects to pr.pbp.vip.ir2.yahoo.com  (188.125.82.57:80)

TCP (HTTP):
Connects to m-prd-umpxl-adcom-mtc.evip.aol.com  (64.12.68.41:80)

TCP (HTTP):
Connects to m-prd-pxl-adcom-mtc.evip.aol.com  (64.12.106.9:80)

TCP (HTTP):
Connects to mpr1.ngd.vip.ch1.yahoo.com  (217.163.21.34:80)

TCP (HTTP):
Connects to mil02s06-in-f27.1e100.net  (173.194.40.27:80)

TCP (HTTP):
Connects to mil02s06-in-f26.1e100.net  (173.194.40.26:80)

TCP (HTTP):
Connects to mil02s05-in-f27.1e100.net  (74.125.232.155:80)

TCP (HTTP):
Connects to mil02s05-in-f13.1e100.net  (74.125.232.141:80)

TCP (HTTP):
Connects to mil01s16-in-f28.1e100.net  (173.194.35.28:80)

TCP (HTTP SSL):
Connects to mil01s16-in-f27.1e100.net  (173.194.35.27:443)

TCP (HTTP):
Connects to mail.dz4ms.com  (69.90.155.234:80)

TCP (HTTP):
Connects to hostby.echoromeonet.co.uk  (89.144.2.20:8080)

TCP (HTTP):

TCP (HTTP):
Connects to fw1.fwed.net  (144.76.207.229:80)

TCP (HTTP SSL):
Connects to float.779.bm-impbus.prod.ams1.adnexus.net  (37.252.162.71:443)

Remove drpanel.exe - Powered by Reason Core Security