IOC Report
ibk0BQaWAo

loading gif

Files

File Path
Type
Category
Malicious
ibk0BQaWAo.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Orbit.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=0, Archive, ctime=Thu Nov 21 03:58:08 2024, mtime=Thu Nov 21 03:58:08 2024, atime=Thu Nov 21 03:58:19 2024, length=2674456, window=hide
dropped
C:\Users\user\AppData\Roaming\Orbit\conf.dat
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Orbit\softI.dat
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\ibk0BQaWAo.exe
"C:\Users\user\Desktop\ibk0BQaWAo.exe"
malicious

URLs

Name
IP
Malicious
http://obupdate.orbitdownloader.com/updataAd.php
188.114.96.6
malicious
https://orbitdownloader.com/
188.114.96.6
malicious
http://obupdate.orbitdownloader.com/update/myinfo.php
188.114.96.6
malicious
http://orbitdownloader.com/
188.114.96.6
malicious
http://obupdate.orbitdownloader.com/update/autoup.php?version=4.1.1.19&guid=C34B8125B23A4CE5B6DCAAC768A52F4B84DA&vendor=ORBITDMX&language=USA
188.114.96.6
malicious
http://obupdate.orbitdownloader.com/updataGv.php
188.114.96.6
malicious
http://oblogin.rep.orbitdownloader.com/login/login.html?version=4.1.1.19&guid=C34B8125B23A4CE5B6DCAAC768A52F4B84DA&vendor=ORBITDMX&showcnt=0&lastlogin=0&lastexit=0&dltimes=0&ntdlgshowtimes=0&dlsuctipscnt=0&grabpro=0&obproxyrun=0&pcode=&sm=0.9.1033
188.114.96.6
malicious
http://oblogin.rep.orbitdownloader.com/login/login.html?version=4.1.1.19&guid=C34B8125B23A4CE5B6DCAA
unknown
http://www.orbitdownloader.com/link.php?type=2
unknown
https://orbitdownloader.co
unknown
https://orbitdownloader.com/comments/feed/
unknown
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/spline-sans-mono/SplineSansMono-Ital
unknown
http://orbit.brothersoft.com/get.phpAdConfig.xmlhttp://orbit.brothersoft.com/show.phphttp://obupdate
unknown
http://www.orbitdownloader.com/link.php?type=1
unknown
http://obbug.rep.orbitdownloader.com/bugreport/report_bug.php
unknown
http://www.orbitdownloader.com/support.htm
unknown
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
unknown
http://www.orbitdownloader.com/link.php?type=20
unknown
http://www.diginotar.nl/cps/pkioverheid0
unknown
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader-270x270.jpg
unknown
https://orbitdownloader.com/#bread
unknown
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/gloock/Gloock-Regular.ttf
unknown
http://www.freevideozilla.com/
unknown
http://www.orbitdownloader.com/faq.htmhttp://www.orbitdownloader.com/index.htmhttp://www.orbitdownlo
unknown
ftp://https://http://ehrmfkEHRMFKaAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ0123456789-_.%0
unknown
http://oblogin.rep.orbitdownloader.com/login/login.html?
unknown
http://obupdate.orbitdownloader.com/update/
unknown
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader-300x300.jpg
unknown
http://obupdate.orbitdownloader.com/updataAd.phpesoft
unknown
https://orbitdownloader.com/#/schema/logo/image/
unknown
https://orbitdownloader.com/feed
unknown
https://orbitdownloader.com/category/downloaders/
unknown
https://orbitdownloader.com/feed/
unknown
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/figtree/Figtree-VariableFont_wght.tt
unknown
https://schema.org
unknown
http://obinstallup.rep.orbitdownloader.com/install/instupdate.html?
unknown
http://www.orbitdownloader.com/faq.htm
unknown
http://orbit.brothersoft.com/givesoft_get.phphttp://obupdate.orbitdownloader.com/updataGv.phpzipURLz
unknown
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader.jpg
unknown
http://oblang.rep.orbitdownloader.com/lang.html?version=
unknown
http://www.orbitdownloader.com/file(
unknown
http://obvideo.orbitdownloader.com/orbit/getVideoUrl.php
unknown
https://yt4all.com
unknown
http://www.orbitdownloader.com0
unknown
http://www.orbitdownloader.com/
unknown
https://orbitdownloader.com/#website
unknown
https://orbitdownloader.com/er.com3g
unknown
http://crl.entrust.net/2048ca.crl0
unknown
http://obinstall.rep.orbitdownloader.com/install/install.html?http://obinstallup.rep.orbitdownloader
unknown
http://www.orbitdownloader.com/index.htm
unknown
http://search.orbitdownloader.com/osearch.php?q=%s&type=%s
unknown
https://orbitdownloader.com/xmlrpc.php?rsd
unknown
http://ocsp.entrust.net03
unknown
http://www.orbitdownloader.com/link.php?type=1se
unknown
https://yoast.com/wordpress/plugins/seo/
unknown
http://orbit.brothersoft.com/givesoft_get.php:bottom
unknown
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader-192x192.jpg
unknown
http://obuninstall.rep.orbitdownloader.com/install/uninstall.html?
unknown
http://orbit.brothersoft.com/get.php
unknown
http://www.ie7pro.com
unknown
http://www.freemusiczilla.com/
unknown
http://obupdate.orbitdownloader.com/updataGv.php&
unknown
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader-32x32.jpg
unknown
http://orbit.brothersoft.com/show.php
unknown
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/spline-sans-mono/SplineSansMono-Vari
unknown
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/geologica/Geologica-VariableFont_CRS
unknown
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/source-serif-pro/SourceSerif4Variabl
unknown
http://ocsp.entrust.net0D
unknown
https://orbitdownloader.com/#organization
unknown
https://orbitdownloader.cob
unknown
http://obupdate.orbitdownloader.com/update/autoup.php?version=4.1.1.19&guid=C34B8125B23A4CE5B6DCAAC7
unknown
http://orbit.brothersoft.com/givesoft_get.php
unknown
http://obvideo.orbitdownloader.com/orbit/getVideoUrl.php%s
unknown
https://orbitdownloader.com/#breadcrumb
unknown
http://crl.entrust.net/server1.crl0
unknown
http://obupdate.orbitdownloader.com/update/myinfo.phpABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstu
unknown
https://orbitdownloader.com/wp-content/uploads/2024/07/cropped-orbitdownloader-150x150.jpg
unknown
https://orbitdownloader.com/0
unknown
http://www.orbitdownloader.com/freeware-download/
unknown
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/lora/Lora-Italic-VariableFont_wght.t
unknown
https://api.w.org/
unknown
https://orbitdownloader.com/wp-content/themes/raft/assets/css/build/style.css?ver=1.1.5
unknown
https://orbitdownloader.com/wp-json/
unknown
https://orbitdownloader.com/#brea
unknown
http://oblogin.rep.orbitdownloader.com/login/login.html?DLSUCTIPSNTDLGSHOWTIMESDLTIMESSHOWFRAMELOGOU
unknown
https://orbitdownloader.com/#/sche
unknown
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/figtree/Figtree-Italic-VariableFont_
unknown
https://orbitdownloader.com/?s=
unknown
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/spline-sans/SplineSans-VariableFont_
unknown
http://forum.orbitdownloader.com/
unknown
https://orbitdownloader.com/wp-content/themes/raft/assets/fonts/outfit/Outfit-VariableFont_wght.ttf
unknown
https://orbitdownloader.com/wp-includes/blocks/navigation/style.min.css?ver=6.6.1
unknown
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
unknown
http://www.orbitdownloader.com/donation.htm
unknown
https://orbitdownloader.com/wp-content/uploads/2024/07/Orbit-Downloader-new.webp
unknown
https://orbitdownloader.com/wp-includes/blocks/
unknown
http://obinstall.rep.orbitdownloader.com/install/install.html?
unknown
http://www.orbitdownloader.com/update.php
unknown
https://orbitdownloader.com/er.com/g
unknown
http://www.orbitdownloader.com/link.php?type=10
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
oblogin.rep.orbitdownloader.com
188.114.96.6
malicious
obupdate.orbitdownloader.com
188.114.96.6
malicious
bg.microsoft.map.fastly.net
199.232.210.172
orbitdownloader.com
188.114.96.6

IPs

IP
Domain
Country
Malicious
188.114.96.6
oblogin.rep.orbitdownloader.com
European Union
188.114.97.6
unknown
European Union

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
Blob
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\orbit
updatetime
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings

Memdumps

Base Address
Regiontype
Protect
Malicious
740000
heap
page read and write
70B000
heap
page read and write
740000
heap
page read and write
755000
heap
page read and write
3691000
heap
page read and write
4080000
remote allocation
page read and write
7D0000
heap
page read and write
220A000
heap
page read and write
20DF000
stack
page read and write
3F30000
trusted library allocation
page read and write
701000
heap
page read and write
3F30000
trusted library allocation
page read and write
3F30000
trusted library allocation
page read and write
844000
heap
page read and write
5A0000
unkown
page readonly
28FF000
stack
page read and write
71A000
heap
page read and write
724000
heap
page read and write
633000
unkown
page readonly
755000
heap
page read and write
3F30000
trusted library allocation
page read and write
3F30000
trusted library allocation
page read and write
620000
unkown
page readonly
2200000
heap
page read and write
3F30000
trusted library allocation
page read and write
56F000
unkown
page readonly
36A3000
heap
page read and write
3B8C000
stack
page read and write
3F30000
trusted library allocation
page read and write
3EED000
stack
page read and write
3F30000
trusted library allocation
page read and write
7DA000
heap
page read and write
765000
heap
page read and write
712000
heap
page read and write
6FB000
heap
page read and write
5A0000
unkown
page readonly
6FB000
heap
page read and write
667000
unkown
page readonly
755000
heap
page read and write
340000
heap
page read and write
664000
unkown
page readonly
6FB000
heap
page read and write
3F30000
trusted library allocation
page read and write
7DE000
heap
page read and write
6DF000
heap
page read and write
614000
unkown
page readonly
701000
heap
page read and write
3F30000
trusted library allocation
page read and write
3F30000
trusted library allocation
page read and write
3DAC000
stack
page read and write
35EF000
stack
page read and write
36B3000
heap
page read and write
747000
heap
page read and write
401000
unkown
page execute read
61E000
unkown
page readonly
58D000
unkown
page write copy
6CA000
heap
page read and write
73D000
heap
page read and write
85D000
heap
page read and write
747000
heap
page read and write
65D000
unkown
page readonly
474E000
stack
page read and write
2227000
heap
page read and write
3F30000
trusted library allocation
page read and write
614000
unkown
page readonly
879000
heap
page read and write
717000
heap
page read and write
747000
heap
page read and write
3ABD000
stack
page read and write
3F30000
trusted library allocation
page read and write
6FE000
heap
page read and write
66A000
unkown
page readonly
61B000
unkown
page readonly
593000
unkown
page read and write
58D000
unkown
page read and write
8E8000
heap
page read and write
671000
unkown
page readonly
484F000
stack
page read and write
6CA000
heap
page read and write
733000
heap
page read and write
3F30000
trusted library allocation
page read and write
740000
heap
page read and write
90B000
heap
page read and write
65F000
unkown
page readonly
747000
heap
page read and write
7D6000
heap
page read and write
4080000
remote allocation
page read and write
701000
heap
page read and write
332F000
stack
page read and write
715000
heap
page read and write
82E000
heap
page read and write
671000
unkown
page readonly
4510000
heap
page read and write
76D000
heap
page read and write
70B000
heap
page read and write
720000
heap
page read and write
755000
heap
page read and write
27CB000
heap
page read and write
65A000
unkown
page readonly
732000
heap
page read and write
773000
heap
page read and write
773000
heap
page read and write
400000
unkown
page readonly
3FE000
stack
page read and write
66C000
unkown
page readonly
260F000
stack
page read and write
4523000
heap
page read and write
8AE000
heap
page read and write
598000
unkown
page read and write
36B3000
heap
page read and write
8C0000
heap
page read and write
8B6000
heap
page read and write
3F30000
trusted library allocation
page read and write
3F30000
trusted library allocation
page read and write
623000
unkown
page readonly
457B000
heap
page read and write
270F000
stack
page read and write
6A0000
heap
page read and write
747000
heap
page read and write
739000
heap
page read and write
3DEC000
stack
page read and write
3F30000
trusted library allocation
page read and write
10000
heap
page read and write
709000
heap
page read and write
740000
heap
page read and write
6BD000
heap
page read and write
362C000
stack
page read and write
56F000
unkown
page readonly
592000
unkown
page write copy
635000
unkown
page readonly
8EC000
heap
page read and write
594000
unkown
page write copy
71A000
heap
page read and write
732000
heap
page read and write
740000
heap
page read and write
3AC0000
trusted library allocation
page read and write
336E000
stack
page read and write
3F30000
trusted library allocation
page read and write
33AC000
stack
page read and write
623000
unkown
page readonly
27C4000
heap
page read and write
715000
heap
page read and write
274E000
stack
page read and write
82A000
heap
page read and write
611000
unkown
page readonly
65D000
unkown
page readonly
738000
heap
page read and write
3F6F000
stack
page read and write
635000
unkown
page readonly
732000
heap
page read and write
430F000
stack
page read and write
3F30000
trusted library allocation
page read and write
662000
unkown
page readonly
747000
heap
page read and write
616000
unkown
page readonly
4517000
heap
page read and write
65A000
unkown
page readonly
3F30000
trusted library allocation
page read and write
27C0000
heap
page read and write
2132000
heap
page read and write
773000
heap
page read and write
33B0000
heap
page read and write
3F30000
trusted library allocation
page read and write
6E4000
heap
page read and write
3F30000
trusted library allocation
page read and write
3692000
heap
page read and write
3F30000
trusted library allocation
page read and write
732000
heap
page read and write
740000
heap
page read and write
6BF000
heap
page read and write
619000
unkown
page readonly
86000
stack
page read and write
740000
heap
page read and write
4090000
heap
page read and write
2114000
heap
page read and write
3F30000
trusted library allocation
page read and write
667000
unkown
page readonly
701000
heap
page read and write
705000
heap
page read and write
620000
unkown
page readonly
732000
heap
page read and write
611000
unkown
page readonly
4050000
heap
page read and write
420F000
stack
page read and write
400000
unkown
page readonly
86F000
heap
page read and write
767000
heap
page read and write
734000
heap
page read and write
747000
heap
page read and write
66A000
unkown
page readonly
38BE000
stack
page read and write
27C8000
heap
page read and write
820000
heap
page read and write
740000
heap
page read and write
81F000
stack
page read and write
2110000
heap
page read and write
8EF000
heap
page read and write
827000
heap
page read and write
755000
heap
page read and write
61E000
unkown
page readonly
61B000
unkown
page readonly
616000
unkown
page readonly
662000
unkown
page readonly
218E000
stack
page read and write
701000
heap
page read and write
664000
unkown
page readonly
4539000
heap
page read and write
748000
heap
page read and write
6FB000
heap
page read and write
3F30000
trusted library allocation
page read and write
3F30000
trusted library allocation
page read and write
701000
heap
page read and write
3F30000
trusted library allocation
page read and write
709000
heap
page read and write
66C000
unkown
page readonly
619000
unkown
page readonly
65F000
unkown
page readonly
6CE000
heap
page read and write
755000
heap
page read and write
70B000
heap
page read and write
701000
heap
page read and write
39BD000
stack
page read and write
3680000
heap
page read and write
452B000
heap
page read and write
71E000
heap
page read and write
3BA0000
heap
page read and write
773000
heap
page read and write
747000
heap
page read and write
36A2000
heap
page read and write
3F30000
trusted library allocation
page read and write
401000
unkown
page execute read
410E000
stack
page read and write
186000
stack
page read and write
633000
unkown
page readonly
762000
heap
page read and write
747000
heap
page read and write
There are 226 hidden memdumps, click here to show them.