omegabot_client.exe

The executable omegabot_client.exe has been detected as malware by 5 anti-virus scanners. This is a setup program which is used to install the application. It runs as a scheduled task under the Windows Task Scheduler named Wireless triggered to execute each time a user logs in. The file has been seen being downloaded from ddl7.data.hu.
MD5:
d00f59380a4fed54386f414c4173a56c

SHA-1:
828507d908fce420131d14183a2ab67e1dcf0786

SHA-256:
a1a741492ffe3d00f4dddc59499e47ef8740f6450d41ecd06b4ea8fcca68bab8

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
12/29/2024 3:52:39 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Trojan.DownLoader19.10221
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Midie.6858
10.0.0.5366

ESET NOD32
Win32/Kryptik.EMHI trojan
7.0.302.0

F-Secure
Variant.Midie.6858
5.15.21

Norman
Gen:Variant.Midie.6858
11.01.2016 17:30:26

File size:
940 KB (962,560 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\omegabot_client.exe

File PE Metadata
Compilation timestamp:
7/2/2014 12:59:29 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:0itsSrSkSsSSSSS2BMuJXMGrH4xiCXpumEDO4gY:0KsSrSkSsSSSSS2BHXTCiWpuJDCY

Entry address:
0x18A2

Entry point:
E8, 88, 16, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 78, 18, 41, 00, 89, 0D, 74, 18, 41, 00, 89, 15, 70, 18, 41, 00, 89, 1D, 6C, 18, 41, 00, 89, 35, 68, 18, 41, 00, 89, 3D, 64, 18, 41, 00, 66, 8C, 15, 90, 18, 41, 00, 66, 8C, 0D, 84, 18, 41, 00, 66, 8C, 1D, 60, 18, 41, 00, 66, 8C, 05, 5C, 18, 41, 00, 66, 8C, 25, 58, 18, 41, 00, 66, 8C, 2D, 54, 18, 41, 00, 9C, 8F, 05, 88, 18, 41, 00, 8B, 45, 00, A3, 7C, 18, 41, 00, 8B, 45, 04, A3, 80, 18, 41, 00, 8D, 45, 08, A3, 8C, 18, 41...
 
[+]

Code size:
17.5 KB (17,920 bytes)

Scheduled Task
Task name:
Wireless

Trigger:
Logon (Runs on logon)


The file omegabot_client.exe has been seen being distributed by the following URL.

Remove omegabot_client.exe - Powered by Reason Core Security