Savdm.exe

Savdm

Advernet Limited

The application Savdm.exe by Advernet Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This executable runs as a local area network (LAN) Internet proxy server listening on port 8877 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host. While running, it connects to the Internet address ip20.ip-91-121-54.eu on port 443.
Publisher:
Advernet  (signed by Advernet Limited)

Product:
Savdm

Version:
1.0.0.6

MD5:
36051c50715d8517d06405c7cc98d14e

SHA-1:
aa69ecc0a4c02099d62af19dffce3069a153d4d1

SHA-256:
98e98cd89ffe045beb1142dd5ed2525b72548ae0ed9d62eb6a0f4106c1562783

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 10:39:26 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Advernet (M)
16.3.23.21

File size:
151.6 KB (155,264 bytes)

Product version:
1.0.0.6

Copyright:
Copyright © Advernet 2011-2012

Original file name:
Savdm.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\savdm\savdm.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/11/2012 2:00:00 AM

Valid to:
7/1/2015 1:59:59 AM

Subject:
CN=Advernet Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Advernet Limited, L=Dublin, S=Dublin 8, C=IE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
054D2128EC82CC8BBD064732DEF892AA

File PE Metadata
Compilation timestamp:
12/18/2012 9:11:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:r8NwDt1R3ND9jSieN642KZkdnEinCe8Os3x2R2:ANwDtjND9m/KKjm2

Entry address:
0xDD2E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
47.5 KB (48,640 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:8877/

Local host port:
8877

Default credentials:
No


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 25.1a.36a9.ip4.static.sl-reverse.com  (169.54.26.37:80)

TCP (HTTP SSL):
Connects to a23-217-187-34.deploy.static.akamaitechnologies.com  (23.217.187.34:443)

TCP (HTTP):
Connects to vp-dl-javafx.oracle.com  (137.254.120.31:80)

TCP (HTTP):
Connects to s3-1-w.amazonaws.com  (52.216.80.176:80)

TCP (HTTP):
Connects to ir1.fp.vip.ir2.yahoo.com  (46.228.47.115:80)

TCP (HTTP SSL):
Connects to ip20.ip-91-121-54.eu  (91.121.54.20:443)

TCP (HTTP):
Connects to ec2-54-243-119-91.compute-1.amazonaws.com  (54.243.119.91:80)

TCP (HTTP):
Connects to ec2-54-235-213-225.compute-1.amazonaws.com  (54.235.213.225:80)

TCP (HTTP):

TCP (HTTP):
Connects to a88-221-112-203.deploy.akamaitechnologies.com  (88.221.112.203:80)

TCP (HTTP):
Connects to a88-221-112-187.deploy.akamaitechnologies.com  (88.221.112.187:80)

TCP (HTTP):
Connects to a2-16-121-236.deploy.akamaitechnologies.com  (2.16.121.236:80)

TCP (HTTP):
Connects to 2e.1a.36a9.ip4.static.sl-reverse.com  (169.54.26.46:80)

Remove Savdm.exe - Powered by Reason Core Security