omegabot.exe

The executable omegabot.exe has been detected as malware by 3 anti-virus scanners. The file has been seen being downloaded from ddl3.data.hu.
MD5:
9d7cb2d264fd1c458f29732af07f0100

SHA-1:
f8ce7459cd638653fbe25bc36c23e36ce33c9528

SHA-256:
2e2f0b336d9156e54a5fc5898c95c2289a195ca58c7558e74c97a26c43523cb8

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
11/24/2024 10:14:40 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.DownLoader19.10221
9.0.1.05190

Emsisoft Anti-Malware
Trojan.GenericKD.3018466
10.0.0.5366

Kaspersky
Trojan.Win32.Scarsi
15.0.0.562

File size:
992.5 KB (1,016,320 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\omegabot.exe

File PE Metadata
Compilation timestamp:
7/4/2014 10:43:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:JtsSrSkSsSSSSS2BMuJXMG++QCvShg1Bg:jsSrSkSsSSSSS2BHX+hE71Bg

Entry address:
0x18A2

Entry point:
E8, 88, 16, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 78, 18, 41, 00, 89, 0D, 74, 18, 41, 00, 89, 15, 70, 18, 41, 00, 89, 1D, 6C, 18, 41, 00, 89, 35, 68, 18, 41, 00, 89, 3D, 64, 18, 41, 00, 66, 8C, 15, 90, 18, 41, 00, 66, 8C, 0D, 84, 18, 41, 00, 66, 8C, 1D, 60, 18, 41, 00, 66, 8C, 05, 5C, 18, 41, 00, 66, 8C, 25, 58, 18, 41, 00, 66, 8C, 2D, 54, 18, 41, 00, 9C, 8F, 05, 88, 18, 41, 00, 8B, 45, 00, A3, 7C, 18, 41, 00, 8B, 45, 04, A3, 80, 18, 41, 00, 8D, 45, 08, A3, 8C, 18, 41...
 
[+]

Entropy:
5.7878

Code size:
17.5 KB (17,920 bytes)

The file omegabot.exe has been seen being distributed by the following URL.

Remove omegabot.exe - Powered by Reason Core Security