Orbitnet.exe

P2P service of Orbit Downloader

Orbitdownloader.com

The application Orbitnet.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Orbit Downloader 4.1.0.0 by Novin Pendar Co. Ltd.. While running, it connects to the Internet address 45.af.84ae.static.theplanet.com on port 443.
Publisher:
Orbitdownloader.com

Product:
P2P service of Orbit Downloader

Version:
2, 6, 0, 4

MD5:
9e596d692a608742e0907003388500be

SHA-1:
47bc642b7119cb72a74fc012c86650133abf8f2a

SHA-256:
063440b5b29c8a9b6864ecc8302226cd1a35514f8c2e92d8214647ac666fcbd1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 1:40:02 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OrbitDownloader.Meta
15.4.26.11

File size:
544 KB (557,056 bytes)

Product version:
2, 6, 0, 4

Copyright:
Copyright 2006 - 2009 Oribtdownloader.com

Original file name:
Orbitnet.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\orbitdownloader\orbitnet.exe

File PE Metadata
Compilation timestamp:
9/14/2012 12:13:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:SradmOY+H59nhjl8ucHFxjZhLvo2oaPC/:SradmOznhJ8u0FxVhQD

Entry address:
0x5F1C5

Entry point:
55, 8B, EC, 6A, FF, 68, 10, 3E, 47, 00, 68, 00, DB, 45, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 84, 30, 47, 00, 33, D2, 8A, D4, 89, 15, 80, E4, 48, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 7C, E4, 48, 00, C1, E1, 08, 03, CA, 89, 0D, 78, E4, 48, 00, C1, E8, 10, A3, 74, E4, 48, 00, 6A, 01, E8, CE, 5E, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, A7, 2F, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
456 KB (466,944 bytes)

3 Windows Firewall Allowed Programs
Name:
C:\Program Files (x86)\Orbitdownloader\orbitnet.exe

Name:
C:\Program Files\Orbitdownloader\orbitnet.exe

Name:
C:\downOrbt\orbitnet.exe


The file Orbitnet.exe has been discovered within the following program.

Orbit Downloader 4.1.0.0  by Novin Pendar Co. Ltd.
www.NPShop.Net
About 1% of users remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to 45.af.84ae.static.theplanet.com  (174.132.175.69:443)

TCP (HTTP):
Connects to 81.c5.a86c.ip4.static.sl-reverse.com  (108.168.197.129:80)

Remove Orbitnet.exe - Powered by Reason Core Security