Downloader.Drepitt

By JubileeX in Trojan Downloader

Threat Scorecard

Popularity Rank: 12,882
Threat Level: 90 % (High)
Infected Computers: 1,298
First Seen: December 23, 2011
Last Seen: October 26, 2025
OS(es) Affected: Windows

Downloader.Drepitt is a Trojan downloader which affects PCs running Microsoft Windows operating system. Downloader.Drepitt is made to exploit system vulnerabilities and to download malicious files to the corrupted PCs. When active, Downloader.Drepitt will download and install other malware infections onto the compromised PC system. Downloader.Drepitt will communicate with remote websites to receive commands and download and execute infected files. Downloader.Drepitt can block the affected web browser or network. Downloader.Drepitt can lead to restarts of the infected computer system or sudden shut downs of applications. Downloader.Drepitt also modifies the registry so that it can start every time you boot up Windows. Get rid of Downloader.Drepitt as soon as possible.

File System Details

Downloader.Drepitt may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\[RANDOM CHARACTERS].exe
2. %Temp%\[RANDOM CHARACTERS].dll

Registry Details

Downloader.Drepitt may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\”%UserProfile%\Application Data\[RANDOM CHARACTERS].exe" = "%UserProfile%\Application Data\[RANDOM CHARACTERS].exe:*:En
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%UserProfile%\Application Data\[RANDOM CHARACTERS].exe" = "%UserProfile%\Application Data\[RANDOM CHARACTERS].exe:*:Enable

Analysis Report

General information

Family Name: Trojan.Korplug.BA
Signature status: No Signature

Known Samples

MD5: 95420e5840b123c13845bb9efb842ea3
SHA1: fe5833019b61b0192a3efde530c9c1a95b85beda
SHA256: BB4FEC0FD378D6C51252CDE0A850BFC5297C86D8ACCC84C95D966CAD638666DC
File Size: 20.48 KB, 20480 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • x86

Block Information

Total Blocks: 8
Potentially Malicious Blocks: 6
Whitelisted Blocks: 2
Unknown Blocks: 0

Visual Map

x x x x x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Korplug.BA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\fe5833019b61b0192a3efde530c9c1a95b85beda_0000020480.,LiQMAxHB

1 Comment

Excellent items from you, man. I have be aware your stuff prior to and you're simply too magnificent. I actually like what you've received here, certainly like what you're stating and the way in which in which you assert it. You are making it enjoyable and you continue to care for to keep it smart. I can not wait to learn far more from you. This is actually a terrific website.

Trending

Most Viewed

Loading...