drs-original.exe

The executable drs-original.exe has been detected as malware by 15 anti-virus scanners. While running, it connects to the Internet address ekiaiomcig.c06.mtsvc.net on port 80 using the HTTP protocol.
MD5:
c9d66788bc7b3eab56724b1bb1b87e6a

SHA-1:
723a8eaa24ba70870f420d4cb04bb1d88a7bdeea

Scanner detections:
15 / 68

Status:
Malware

Analysis date:
11/27/2024 5:37:58 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Dropper/Win32.Agent
2011.01.01

Clam AntiVirus
PUA.Packed.MoleBox.2X
0.98/17411

Comodo Security
TrojWare.Win32.TrojanDropper.Agent.dpoj
7253

Emsisoft Anti-Malware
Trojan-Dropper.Agent!IK
8.14.09.21.01

Fortinet FortiGate
W32/Agent.DPOJ!tr
9/21/2014

IKARUS anti.virus
Trojan-Dropper.Agent
t3scan.1.1.90.0

Kaspersky
Trojan-Dropper.Win32.Agent
14.0.0.3217

McAfee
Artemis!C9D66788BC7B
5600.7000

Norman
W32/Suspicious_P1!genr
11.20140921

nProtect
Trojan-Dropper/W32.Agent.3340215
10.12.31.01

Panda Antivirus
Generic Trojan
14.09.21.01

Quick Heal
TrojanDropper.Agent.dpoj
9.14.11.00

Trend Micro
PAK_Molebox
10.465.21

Vba32 AntiVirus
TrojanDropper.Agent.dpoj
3.12.14.2

VIPRE Antivirus
Trojan-Dropper.Win32.Agent
7905

File size:
3.2 MB (3,340,215 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\documents and settings\shengg\桌面\音樂\lf2\drs\drs-original.exe

File PE Metadata
Compilation timestamp:
7/11/2009 1:15:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:4+3X/clYf7iNakl2X/JdIDVFqfJyv+xINMy9ESWgiPMLUThyRB2LJVcrNea5x:460ly720PJdIDVsfGMy9EAiQvBe2h

Entry address:
0x350BD3

Entry point:
E8, 00, 00, 00, 00, 60, E8, 4F, 00, 00, 00, A6, 0F, B6, 5A, 94, 28, DB, 2A, 14, 8C, D6, 2C, AA, 91, 47, CF, 28, 9D, B8, 61, CF, B8, 61, DA, 9C, B2, B9, 64, B0, B8, 6A, 49, 2E, F0, 76, 93, 14, 46, CD, BF, 7E, 06, 71, 8B, 1B, 5D, E0, 31, 33, 99, 5E, B0, F6, 6D, FF, 7D, 33, 99, 5E, B0, F6, 6D, FF, 7D, E9, 2A, 6E, 00, 00, E9, 3E, 6E, 00, 00, E9, 39, 6E, 00, 00, E8, 6E, FB, FF, FF, CE, 03, 01, 00, A1, 9A, 00, 00, 38, 38, 66, 67, 61, FF, 01, F2, 14, D0, 54, DB, 5F, A0, F1, B2, FE, E9, F0, 87, 96, AF, C9, 52, E2...
 
[+]

Entropy:
6.0268

Packer / compiler:
MoleBox v2.0

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ekiaiomcig.c06.mtsvc.net  (205.186.187.204:80)

Remove drs-original.exe - Powered by Reason Core Security