ostotohotspot.exe

Shenzhen DriveTheLife Software Technology Co.Ltd

The application ostotohotspot.exe by Shenzhen DriveTheLife Software Technology Co.Ltd has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘OSTotoHotspot’. While running, it connects to the Internet address 82-166-201-185.barak-online.net on port 80 using the HTTP protocol.
Publisher:

Version:
4, 1, 9, 4

MD5:
96cba8a142274d262552280c8986145a

SHA-1:
94913d8b7a7fb84c4b6cba5a1b01e61ca4358f66

SHA-256:
1f1e789b4c1cb9e544e54e0f648771553b9c3e2d24b95babe52e3086c4e10c37

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 8:31:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OstotoHotspot (L)
16.10.17.21

File size:
1.2 MB (1,278,320 bytes)

Product version:
4, 1, 9, 4

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\ostotohotspot\ostotohotspot.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/25/2014 4:00:00 PM

Valid to:
1/25/2016 3:59:59 PM

Subject:
CN=Shenzhen DriveTheLife Software Technology Co.Ltd, OU=驱动人生, O=Shenzhen DriveTheLife Software Technology Co.Ltd, L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
40107F784B1F742478A35B1DADC1710D

File PE Metadata
Compilation timestamp:
9/9/2015 6:35:25 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:VOEy7jIjZ+XUKJYM7X7n+ApJkuDNDHxW:i0qUKJl7X7n+ApGuDND4

Entry address:
0x684A5

Entry point:
E8, 03, FC, 00, 00, E9, 79, FE, FF, FF, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 00, 01, 00, 00, 72, 0E, 83, 3D, F8, 72, 4A, 00, 00, 74, 05, E9, BE, FC, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA, 01, 75, F6, 8B, 44, 24, 08, 5F, C3...
 
[+]

Entropy:
6.0316

Code size:
528.5 KB (541,184 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
OSTotoHotspot

Command:
"C:\Program Files\ostotohotspot\ostotohotspot.exe" -auto


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):

TCP (HTTP):
Connects to 82-166-201-185.barak-online.net  (82.166.201.185:80)

Remove ostotohotspot.exe - Powered by Reason Core Security