drevidt.exe

лḒώҍЌ難ωώЗр骨み難иҘь難えώЀḈϟЉḆ骨о争гьҘ

まЦώḒ六ӧиьωώ予сьаҘе骨иきмώмлууеҍめ革Џ

The executable drevidt.exe, “ӧかҞӨ革まеҘЊЗώ四ь骨Ҷяϐふはеъӧひおьひ与Шае” has been detected as malware by 22 anti-virus scanners. The file has been seen being downloaded from www.weebly.com.
Publisher:
まЦώḒ六ӧиьωώ予сьаҘе骨иきмώмлууеҍめ革Џ

Product:
лḒώҍЌ難ωώЗр骨み難иҘь難えώЀḈϟЉḆ骨о争гьҘ

Description:
ӧかҞӨ革まеҘЊЗώ四ь骨Ҷяϐふはеъӧひおьひ与Шае

Version:
5.6.7.8

MD5:
9e5f4137c2c24548ad15065f4b3e5a3a

SHA-1:
a800c56bc495834fc12f95f1ddbf07c47f229362

SHA-256:
0b4cd3109406877b8236a261e49035dee7e29fea5b4234fddc897c19f5d85bf0

Scanner detections:
22 / 68

Status:
Malware

Analysis date:
5/8/2024 4:05:30 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.387941
336

AhnLab V3 Security
Trojan/Win32.Krypt
2014.06.19

Avira AntiVirus
TR/Kazy.387941
7.11.155.128

avast!
Win32:Malware-gen
2014.9-160305

Baidu Antivirus
Trojan.MSIL.Kryptik
4.0.3.1635

Bitdefender
Gen:Variant.Kazy.387941
1.0.20.325

Comodo Security
UnclassifiedMalware
18590

Emsisoft Anti-Malware
Gen:Variant.Kazy.387941
8.16.03.05.07

ESET NOD32
MSIL/Kryptik.TR (variant)
10.9962

Fortinet FortiGate
MSIL/Kryptik.TR!tr
3/5/2016

F-Secure
Gen:Variant.Kazy.387941
11.2016-05-03_7

G Data
Gen:Variant.Kazy.387941
16.3.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.1712436

Kaspersky
Trojan-Dropper.Win32.Sysn
14.0.0.564

McAfee
Artemis!9E5F4137C2C2
5600.6470

MicroWorld eScan
Gen:Variant.Kazy.387941
17.0.0.195

Norman
Suspicious_Gen5.ARJLL
11.20160305

Panda Antivirus
Trj/CI.A
16.03.05.07

Qihoo 360 Security
Win32/Trojan.8f7
1.0.0.1015

Sophos
Mal/Generic-S
4.98

Trend Micro House Call
TROJ_GEN.R0CBH07FI14
7.2.65

File size:
2.9 MB (3,065,344 bytes)

Product version:
5.6.7.8

Copyright:
Copyright © ӧかҞӨ革まеҘЊЗώ四ь骨Ҷяϐふはеъӧひおьひ与Шае 2014

Original file name:
Server.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\drevidt.exe

File PE Metadata
Compilation timestamp:
6/13/2014 2:33:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:8JpUtq5+x0CQnxAYcN82Uj0pPZokOyOUYUCNxDP8VC4j:

Entry address:
0x2EACDE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1083

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.9 MB (3,051,008 bytes)

The file drevidt.exe has been seen being distributed by the following URL.

Remove drevidt.exe - Powered by Reason Core Security