OrbitDM.exe

Orbit Downloader

Orbitdownloader.com

The application OrbitDM.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. While running, it connects to the Internet address 7e.02.acb8.ip4.static.sl-reverse.com on port 80 using the HTTP protocol.
Publisher:
Orbitdownloader.com

Product:
Orbit Downloader

Version:
4.1.1.17

MD5:
3734edf11c57c15742e1b8e9f880d9e7

SHA-1:
c7e98021596880c876d0000d3114e0b7271c2c0e

SHA-256:
e2ccb4ac444ea1dfd323f20f3dc252d859b1405b4bd36ba4b4cdbb3555785811

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 6:35:34 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.Orbitdownloader.H
188163

Kaspersky
Trojan-DDoS.Win32.OrboDDoS
14.0.0.4559

Quick Heal
TrojanDDoS.OrboDDoS.b
1.14.12.00

Reason Heuristics
PUP.OrbitDownloader (M)
16.11.28.22

File size:
2.5 MB (2,670,663 bytes)

Product version:
4.1.1.17

Copyright:
Copyright 2006 - 2013 Oribtdownloader.com

Original file name:
OrbitDM.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\orbitdownloader\orbitdm.exe

File PE Metadata
Compilation timestamp:
4/3/2013 2:59:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:7MXl1jFiMD7pOT02JfRIekn08lG4Zrthn1CvVmCuoSTjobcTtcTz:7M1jFi102RRIekn08lG41thnkvVmmLcc

Entry address:
0x15F6E8

Entry point:
55, 8B, EC, 6A, FF, 68, F0, 7A, 57, 00, 68, 2C, F5, 55, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, DC, F6, 56, 00, 59, 83, 0D, 34, FD, 59, 00, FF, 83, 0D, 38, FD, 59, 00, FF, FF, 15, D8, F6, 56, 00, 8B, 0D, 10, FD, 59, 00, 89, 08, FF, 15, D4, F6, 56, 00, 8B, 0D, 0C, FD, 59, 00, 89, 08, A1, D0, F6, 56, 00, 8B, 00, A3, 30, FD, 59, 00, E8, 44, 01, 00, 00, 39, 1D, 28, 88, 59, 00, 75, 0C, 68, 98, F8, 55, 00, FF, 15, CC, F6...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
1.4 MB (1,499,136 bytes)

Windows Firewall Allowed Program
Name:
C:\Program Files\Orbitdownloader\orbitdm.exe


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to 7e.02.acb8.ip4.static.sl-reverse.com  (184.172.2.126:80)

TCP (HTTP):
Connects to 6b.be.7e4b.ip4.static.sl-reverse.com  (75.126.190.107:80)

TCP (HTTP):
Connects to 94-182-97-2.shatel.ir  (94.182.97.2:80)

TCP (HTTP):
Connects to vip080.ssl.hwcdn.net  (205.185.208.80:80)

Remove OrbitDM.exe - Powered by Reason Core Security