drv0.exe

Mic_Driver

The executable drv0.exe has been detected as malware by 3 anti-virus scanners. This executable runs as a local area network (LAN) Internet proxy server listening on port 8877 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host. The file has been seen being downloaded from www.jcza.mx. While running, it connects to the Internet address ip-143-95-111-231.iplocal on port 80 using the HTTP protocol.
Product:
Mic_Driver

Description:
CleanDisk160703

Version:
1.0.0.0

MD5:
450cbcbb759468021d39c29892c5cc80

SHA-1:
d2d2d4f62f70748f8deb37b56a8c800b05798b72

SHA-256:
a81c6f8dac368b0cdb2724185ff849cd23e5263bd7c1e38830b5d088f08766c7

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
4/26/2024 1:18:20 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Gen:Variant.MSILPerseus.30028
16.07.11

ESET NOD32
MSIL/Spy.Agent.AOC trojan
8.0.319.0

Norman
Gen:Variant.MSILPerseus.30028
28.05.2016 15:32:18

File size:
23 KB (23,552 bytes)

Product version:
1.0.0.0

Copyright:
CleanDisk160703

Original file name:
dllSystem.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\windows\syswow64\drv0.exe

File PE Metadata
Compilation timestamp:
7/11/2016 5:00:55 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:8u3DJe+BidpmVRj5Pqs/3vuybZYTsYXpCx7JGy33Vlt5eiWeW5HYckin:8qa0yCVbZYPe/Vlt5FWdYckin

Entry address:
0x6476

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.4470

Code size:
17.5 KB (17,920 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:8877/

Local host port:
8877

Default credentials:
No


The file drv0.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to just58.justhost.com  (173.254.28.58:80)

TCP (HTTP):
Connects to ip-143-95-111-231.iplocal  (143.95.111.231:80)

TCP (HTTP):
Connects to box300.bluehost.com  (69.89.31.100:80)

Remove drv0.exe - Powered by Reason Core Security