Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
ibk0BQaWAo.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Orbit.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon
number=0, Archive, ctime=Thu Nov 21 03:58:08 2024, mtime=Thu Nov 21 03:58:08 2024, atime=Thu Nov 21 03:58:19 2024, length=2674456,
window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Orbit\conf.dat
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Roaming\Orbit\softI.dat
|
ASCII text, with CRLF line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\ibk0BQaWAo.exe
|
"C:\Users\user\Desktop\ibk0BQaWAo.exe"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://obupdate.orbitdownloader.com/updataAd.php
|
188.114.96.6
|
||
https://orbitdownloader.com/
|
188.114.96.6
|
||
http://obupdate.orbitdownloader.com/update/myinfo.php
|
188.114.96.6
|
||
http://orbitdownloader.com/
|
188.114.96.6
|
||
http://obupdate.orbitdownloader.com/update/autoup.php?version=4.1.1.19&guid=C34B8125B23A4CE5B6DCAAC768A52F4B84DA&vendor=ORBITDMX&language=USA
|
188.114.96.6
|
||
http://obupdate.orbitdownloader.com/updataGv.php
|
188.114.96.6
|
||
http://oblogin.rep.orbitdownloader.com/login/login.html?version=4.1.1.19&guid=C34B8125B23A4CE5B6DCAAC768A52F4B84DA&vendor=ORBITDMX&showcnt=0&lastlogin=0&lastexit=0&dltimes=0&ntdlgshowtimes=0&dlsuctipscnt=0&grabpro=0&obproxyrun=0&pcode=&sm=0.9.1033
|
188.114.96.6
|
||
http://oblogin.rep.orbitdownloader.com/login/login.html?version=4.1.1.19&guid=C34B8125B23A4CE5B6DCAA
|
unknown
|
||
http://www.orbitdownloader.com/link.php?type=2
|
unknown
|
||
https://orbitdownloader.co
|
unknown
|
||
https://orbitdownloader.com/comments/feed/
|
unknown
|
||
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/spline-sans-mono/SplineSansMono-Ital
|
unknown
|
||
http://orbit.brothersoft.com/get.phpAdConfig.xmlhttp://orbit.brothersoft.com/show.phphttp://obupdate
|
unknown
|
||
http://www.orbitdownloader.com/link.php?type=1
|
unknown
|
||
http://obbug.rep.orbitdownloader.com/bugreport/report_bug.php
|
unknown
|
||
http://www.orbitdownloader.com/support.htm
|
unknown
|
||
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
|
unknown
|
||
http://www.orbitdownloader.com/link.php?type=20
|
unknown
|
||
http://www.diginotar.nl/cps/pkioverheid0
|
unknown
|
||
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader-270x270.jpg
|
unknown
|
||
https://orbitdownloader.com/#bread
|
unknown
|
||
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/gloock/Gloock-Regular.ttf
|
unknown
|
||
http://www.freevideozilla.com/
|
unknown
|
||
http://www.orbitdownloader.com/faq.htmhttp://www.orbitdownloader.com/index.htmhttp://www.orbitdownlo
|
unknown
|
||
ftp://https://http://ehrmfkEHRMFKaAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ0123456789-_.%0
|
unknown
|
||
http://oblogin.rep.orbitdownloader.com/login/login.html?
|
unknown
|
||
http://obupdate.orbitdownloader.com/update/
|
unknown
|
||
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader-300x300.jpg
|
unknown
|
||
http://obupdate.orbitdownloader.com/updataAd.phpesoft
|
unknown
|
||
https://orbitdownloader.com/#/schema/logo/image/
|
unknown
|
||
https://orbitdownloader.com/feed
|
unknown
|
||
https://orbitdownloader.com/category/downloaders/
|
unknown
|
||
https://orbitdownloader.com/feed/
|
unknown
|
||
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/figtree/Figtree-VariableFont_wght.tt
|
unknown
|
||
https://schema.org
|
unknown
|
||
http://obinstallup.rep.orbitdownloader.com/install/instupdate.html?
|
unknown
|
||
http://www.orbitdownloader.com/faq.htm
|
unknown
|
||
http://orbit.brothersoft.com/givesoft_get.phphttp://obupdate.orbitdownloader.com/updataGv.phpzipURLz
|
unknown
|
||
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader.jpg
|
unknown
|
||
http://oblang.rep.orbitdownloader.com/lang.html?version=
|
unknown
|
||
http://www.orbitdownloader.com/file(
|
unknown
|
||
http://obvideo.orbitdownloader.com/orbit/getVideoUrl.php
|
unknown
|
||
https://yt4all.com
|
unknown
|
||
http://www.orbitdownloader.com0
|
unknown
|
||
http://www.orbitdownloader.com/
|
unknown
|
||
https://orbitdownloader.com/#website
|
unknown
|
||
https://orbitdownloader.com/er.com3g
|
unknown
|
||
http://crl.entrust.net/2048ca.crl0
|
unknown
|
||
http://obinstall.rep.orbitdownloader.com/install/install.html?http://obinstallup.rep.orbitdownloader
|
unknown
|
||
http://www.orbitdownloader.com/index.htm
|
unknown
|
||
http://search.orbitdownloader.com/osearch.php?q=%s&type=%s
|
unknown
|
||
https://orbitdownloader.com/xmlrpc.php?rsd
|
unknown
|
||
http://ocsp.entrust.net03
|
unknown
|
||
http://www.orbitdownloader.com/link.php?type=1se
|
unknown
|
||
https://yoast.com/wordpress/plugins/seo/
|
unknown
|
||
http://orbit.brothersoft.com/givesoft_get.php:bottom
|
unknown
|
||
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader-192x192.jpg
|
unknown
|
||
http://obuninstall.rep.orbitdownloader.com/install/uninstall.html?
|
unknown
|
||
http://orbit.brothersoft.com/get.php
|
unknown
|
||
http://www.ie7pro.com
|
unknown
|
||
http://www.freemusiczilla.com/
|
unknown
|
||
http://obupdate.orbitdownloader.com/updataGv.php&
|
unknown
|
||
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader-32x32.jpg
|
unknown
|
||
http://orbit.brothersoft.com/show.php
|
unknown
|
||
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/spline-sans-mono/SplineSansMono-Vari
|
unknown
|
||
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/geologica/Geologica-VariableFont_CRS
|
unknown
|
||
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/source-serif-pro/SourceSerif4Variabl
|
unknown
|
||
http://ocsp.entrust.net0D
|
unknown
|
||
https://orbitdownloader.com/#organization
|
unknown
|
||
https://orbitdownloader.cob
|
unknown
|
||
http://obupdate.orbitdownloader.com/update/autoup.php?version=4.1.1.19&guid=C34B8125B23A4CE5B6DCAAC7
|
unknown
|
||
http://orbit.brothersoft.com/givesoft_get.php
|
unknown
|
||
http://obvideo.orbitdownloader.com/orbit/getVideoUrl.php%s
|
unknown
|
||
https://orbitdownloader.com/#breadcrumb
|
unknown
|
||
http://crl.entrust.net/server1.crl0
|
unknown
|
||
http://obupdate.orbitdownloader.com/update/myinfo.phpABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstu
|
unknown
|
||
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader-150x150.jpg
|
unknown
|
||
https://orbitdownloader.com/0
|
unknown
|
||
http://www.orbitdownloader.com/freeware-download/
|
unknown
|
||
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/lora/Lora-Italic-VariableFont_wght.t
|
unknown
|
||
https://api.w.org/
|
unknown
|
||
https://orbitdownloader.com/wp-content/themes/raft/assets/css/build/style.css?ver=1.1.5
|
unknown
|
||
https://orbitdownloader.com/wp-json/
|
unknown
|
||
https://orbitdownloader.com/#brea
|
unknown
|
||
http://oblogin.rep.orbitdownloader.com/login/login.html?DLSUCTIPSNTDLGSHOWTIMESDLTIMESSHOWFRAMELOGOU
|
unknown
|
||
https://orbitdownloader.com/#/sche
|
unknown
|
||
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/figtree/Figtree-Italic-VariableFont_
|
unknown
|
||
https://orbitdownloader.com/?s=
|
unknown
|
||
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/spline-sans/SplineSans-VariableFont_
|
unknown
|
||
http://forum.orbitdownloader.com/
|
unknown
|
||
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/outfit/Outfit-VariableFont_wght.ttf
|
unknown
|
||
https://orbitdownloader.com/wp-includes/blocks/navigation/style.min.css?ver=6.6.1
|
unknown
|
||
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
|
unknown
|
||
http://www.orbitdownloader.com/donation.htm
|
unknown
|
||
https://orbitdownloader.com/wp-content/uploads/2024/07/Orbit-Downloader-new.webp
|
unknown
|
||
https://orbitdownloader.com/wp-includes/blocks/
|
unknown
|
||
http://obinstall.rep.orbitdownloader.com/install/install.html?
|
unknown
|
||
http://www.orbitdownloader.com/update.php
|
unknown
|
||
https://orbitdownloader.com/er.com/g
|
unknown
|
||
http://www.orbitdownloader.com/link.php?type=10
|
unknown
|
There are 90 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
oblogin.rep.orbitdownloader.com
|
188.114.96.6
|
||
obupdate.orbitdownloader.com
|
188.114.96.6
|
||
bg.microsoft.map.fastly.net
|
199.232.210.172
|
||
orbitdownloader.com
|
188.114.96.6
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
188.114.96.6
|
oblogin.rep.orbitdownloader.com
|
European Union
|
||
188.114.97.6
|
unknown
|
European Union
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
|
Blob
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
|
Blob
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\orbit
|
updatetime
|
||
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
|
SavedLegacySettings
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
740000
|
heap
|
page read and write
|
||
70B000
|
heap
|
page read and write
|
||
740000
|
heap
|
page read and write
|
||
755000
|
heap
|
page read and write
|
||
3691000
|
heap
|
page read and write
|
||
4080000
|
remote allocation
|
page read and write
|
||
7D0000
|
heap
|
page read and write
|
||
220A000
|
heap
|
page read and write
|
||
20DF000
|
stack
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
701000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
844000
|
heap
|
page read and write
|
||
5A0000
|
unkown
|
page readonly
|
||
28FF000
|
stack
|
page read and write
|
||
71A000
|
heap
|
page read and write
|
||
724000
|
heap
|
page read and write
|
||
633000
|
unkown
|
page readonly
|
||
755000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
620000
|
unkown
|
page readonly
|
||
2200000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
56F000
|
unkown
|
page readonly
|
||
36A3000
|
heap
|
page read and write
|
||
3B8C000
|
stack
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
3EED000
|
stack
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
7DA000
|
heap
|
page read and write
|
||
765000
|
heap
|
page read and write
|
||
712000
|
heap
|
page read and write
|
||
6FB000
|
heap
|
page read and write
|
||
5A0000
|
unkown
|
page readonly
|
||
6FB000
|
heap
|
page read and write
|
||
667000
|
unkown
|
page readonly
|
||
755000
|
heap
|
page read and write
|
||
340000
|
heap
|
page read and write
|
||
664000
|
unkown
|
page readonly
|
||
6FB000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
7DE000
|
heap
|
page read and write
|
||
6DF000
|
heap
|
page read and write
|
||
614000
|
unkown
|
page readonly
|
||
701000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
3DAC000
|
stack
|
page read and write
|
||
35EF000
|
stack
|
page read and write
|
||
36B3000
|
heap
|
page read and write
|
||
747000
|
heap
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
61E000
|
unkown
|
page readonly
|
||
58D000
|
unkown
|
page write copy
|
||
6CA000
|
heap
|
page read and write
|
||
73D000
|
heap
|
page read and write
|
||
85D000
|
heap
|
page read and write
|
||
747000
|
heap
|
page read and write
|
||
65D000
|
unkown
|
page readonly
|
||
474E000
|
stack
|
page read and write
|
||
2227000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
614000
|
unkown
|
page readonly
|
||
879000
|
heap
|
page read and write
|
||
717000
|
heap
|
page read and write
|
||
747000
|
heap
|
page read and write
|
||
3ABD000
|
stack
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
6FE000
|
heap
|
page read and write
|
||
66A000
|
unkown
|
page readonly
|
||
61B000
|
unkown
|
page readonly
|
||
593000
|
unkown
|
page read and write
|
||
58D000
|
unkown
|
page read and write
|
||
8E8000
|
heap
|
page read and write
|
||
671000
|
unkown
|
page readonly
|
||
484F000
|
stack
|
page read and write
|
||
6CA000
|
heap
|
page read and write
|
||
733000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
740000
|
heap
|
page read and write
|
||
90B000
|
heap
|
page read and write
|
||
65F000
|
unkown
|
page readonly
|
||
747000
|
heap
|
page read and write
|
||
7D6000
|
heap
|
page read and write
|
||
4080000
|
remote allocation
|
page read and write
|
||
701000
|
heap
|
page read and write
|
||
332F000
|
stack
|
page read and write
|
||
715000
|
heap
|
page read and write
|
||
82E000
|
heap
|
page read and write
|
||
671000
|
unkown
|
page readonly
|
||
4510000
|
heap
|
page read and write
|
||
76D000
|
heap
|
page read and write
|
||
70B000
|
heap
|
page read and write
|
||
720000
|
heap
|
page read and write
|
||
755000
|
heap
|
page read and write
|
||
27CB000
|
heap
|
page read and write
|
||
65A000
|
unkown
|
page readonly
|
||
732000
|
heap
|
page read and write
|
||
773000
|
heap
|
page read and write
|
||
773000
|
heap
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
3FE000
|
stack
|
page read and write
|
||
66C000
|
unkown
|
page readonly
|
||
260F000
|
stack
|
page read and write
|
||
4523000
|
heap
|
page read and write
|
||
8AE000
|
heap
|
page read and write
|
||
598000
|
unkown
|
page read and write
|
||
36B3000
|
heap
|
page read and write
|
||
8C0000
|
heap
|
page read and write
|
||
8B6000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
623000
|
unkown
|
page readonly
|
||
457B000
|
heap
|
page read and write
|
||
270F000
|
stack
|
page read and write
|
||
6A0000
|
heap
|
page read and write
|
||
747000
|
heap
|
page read and write
|
||
739000
|
heap
|
page read and write
|
||
3DEC000
|
stack
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
10000
|
heap
|
page read and write
|
||
709000
|
heap
|
page read and write
|
||
740000
|
heap
|
page read and write
|
||
6BD000
|
heap
|
page read and write
|
||
362C000
|
stack
|
page read and write
|
||
56F000
|
unkown
|
page readonly
|
||
592000
|
unkown
|
page write copy
|
||
635000
|
unkown
|
page readonly
|
||
8EC000
|
heap
|
page read and write
|
||
594000
|
unkown
|
page write copy
|
||
71A000
|
heap
|
page read and write
|
||
732000
|
heap
|
page read and write
|
||
740000
|
heap
|
page read and write
|
||
3AC0000
|
trusted library allocation
|
page read and write
|
||
336E000
|
stack
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
33AC000
|
stack
|
page read and write
|
||
623000
|
unkown
|
page readonly
|
||
27C4000
|
heap
|
page read and write
|
||
715000
|
heap
|
page read and write
|
||
274E000
|
stack
|
page read and write
|
||
82A000
|
heap
|
page read and write
|
||
611000
|
unkown
|
page readonly
|
||
65D000
|
unkown
|
page readonly
|
||
738000
|
heap
|
page read and write
|
||
3F6F000
|
stack
|
page read and write
|
||
635000
|
unkown
|
page readonly
|
||
732000
|
heap
|
page read and write
|
||
430F000
|
stack
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
662000
|
unkown
|
page readonly
|
||
747000
|
heap
|
page read and write
|
||
616000
|
unkown
|
page readonly
|
||
4517000
|
heap
|
page read and write
|
||
65A000
|
unkown
|
page readonly
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
27C0000
|
heap
|
page read and write
|
||
2132000
|
heap
|
page read and write
|
||
773000
|
heap
|
page read and write
|
||
33B0000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
6E4000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
3692000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
732000
|
heap
|
page read and write
|
||
740000
|
heap
|
page read and write
|
||
6BF000
|
heap
|
page read and write
|
||
619000
|
unkown
|
page readonly
|
||
86000
|
stack
|
page read and write
|
||
740000
|
heap
|
page read and write
|
||
4090000
|
heap
|
page read and write
|
||
2114000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
667000
|
unkown
|
page readonly
|
||
701000
|
heap
|
page read and write
|
||
705000
|
heap
|
page read and write
|
||
620000
|
unkown
|
page readonly
|
||
732000
|
heap
|
page read and write
|
||
611000
|
unkown
|
page readonly
|
||
4050000
|
heap
|
page read and write
|
||
420F000
|
stack
|
page read and write
|
||
400000
|
unkown
|
page readonly
|
||
86F000
|
heap
|
page read and write
|
||
767000
|
heap
|
page read and write
|
||
734000
|
heap
|
page read and write
|
||
747000
|
heap
|
page read and write
|
||
66A000
|
unkown
|
page readonly
|
||
38BE000
|
stack
|
page read and write
|
||
27C8000
|
heap
|
page read and write
|
||
820000
|
heap
|
page read and write
|
||
740000
|
heap
|
page read and write
|
||
81F000
|
stack
|
page read and write
|
||
2110000
|
heap
|
page read and write
|
||
8EF000
|
heap
|
page read and write
|
||
827000
|
heap
|
page read and write
|
||
755000
|
heap
|
page read and write
|
||
61E000
|
unkown
|
page readonly
|
||
61B000
|
unkown
|
page readonly
|
||
616000
|
unkown
|
page readonly
|
||
662000
|
unkown
|
page readonly
|
||
218E000
|
stack
|
page read and write
|
||
701000
|
heap
|
page read and write
|
||
664000
|
unkown
|
page readonly
|
||
4539000
|
heap
|
page read and write
|
||
748000
|
heap
|
page read and write
|
||
6FB000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
701000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
709000
|
heap
|
page read and write
|
||
66C000
|
unkown
|
page readonly
|
||
619000
|
unkown
|
page readonly
|
||
65F000
|
unkown
|
page readonly
|
||
6CE000
|
heap
|
page read and write
|
||
755000
|
heap
|
page read and write
|
||
70B000
|
heap
|
page read and write
|
||
701000
|
heap
|
page read and write
|
||
39BD000
|
stack
|
page read and write
|
||
3680000
|
heap
|
page read and write
|
||
452B000
|
heap
|
page read and write
|
||
71E000
|
heap
|
page read and write
|
||
3BA0000
|
heap
|
page read and write
|
||
773000
|
heap
|
page read and write
|
||
747000
|
heap
|
page read and write
|
||
36A2000
|
heap
|
page read and write
|
||
3F30000
|
trusted library allocation
|
page read and write
|
||
401000
|
unkown
|
page execute read
|
||
410E000
|
stack
|
page read and write
|
||
186000
|
stack
|
page read and write
|
||
633000
|
unkown
|
page readonly
|
||
762000
|
heap
|
page read and write
|
||
747000
|
heap
|
page read and write
|
There are 226 hidden memdumps, click here to show them.