| File name: | orbit-4-1-1-18-en-win.exe |
| Full analysis: | https://app.any.run/tasks/564a797b-ec23-48a7-ac62-6f00c19625a3 |
| Verdict: | Malicious activity |
| Analysis date: | November 25, 2023, 11:09:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 49055A8FFADE6718EA6C917779761C0D |
| SHA1: | 78C35FC3FAEBE0801562EA348BC579E65519E3FC |
| SHA256: | 6C34D1D257206F45A16DF918922CEEEFB9270119CB5CB9BD02801C0CAF1B5DA2 |
| SSDEEP: | 98304:dKyR5J1HQQ1mI9Rc5UjpWGj5ut1mMG/01xgyKz2kfjcobvfu/Bw:dRJumSkPcmMf1xbFAco7mJw |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:09:23 13:06:57+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 86016 |
| InitializedDataSize: | 60416 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x163c4 |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.1.1.19 |
| ProductVersionNumber: | 4.1.1.19 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | www.orbitdownloader.com |
| FileDescription: | Orbit Downloader setup |
| FileVersion: | 4.1.1.19 |
| LegalCopyright: | Copyright (C) 2006-2013 OrbitDownloader.com |
| ProductName: | Orbit Downloader 4.1.1.19 |
| ProductVersion: | 4.1.1.19 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6b6cf598,0x6b6cf5a8,0x6b6cf5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 684 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=3632 --field-trial-handle=1280,i,10210949888099266011,2158273766622572893,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 888 | "C:\Users\admin\AppData\Local\Temp\orbit-4-1-1-18-en-win.exe" | C:\Users\admin\AppData\Local\Temp\orbit-4-1-1-18-en-win.exe | — | explorer.exe | |||||||||||
User: admin Company: www.orbitdownloader.com Integrity Level: MEDIUM Description: Orbit Downloader setup Exit code: 0 Version: 4.1.1.19 Modules
| |||||||||||||||
| 944 | "C:\Program Files\Orbitdownloader\orbitdm.exe" /setup_showmainframeonlyonce | C:\Program Files\Orbitdownloader\orbitdm.exe | orbit-4-1-1-18-en-win.tmp | ||||||||||||
User: admin Company: Orbitdownloader.com Integrity Level: MEDIUM Description: Orbit Downloader Exit code: 1 Version: 4.1.1.19 Modules
| |||||||||||||||
| 1064 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3996 --field-trial-handle=1268,i,2418928533241258019,14291108835400545300,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1208 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.orbitdownloader.com/freeware-download/ | C:\Program Files\Microsoft\Edge\Application\msedge.exe | orbitdm.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1452 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Orbitdownloader\GrabPro.dll" | C:\Windows\System32\regsvr32.exe | — | orbit-4-1-1-18-en-win.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1884 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=3700 --field-trial-handle=1268,i,2418928533241258019,14291108835400545300,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1988 | "C:\Users\admin\AppData\Local\Temp\orbit-4-1-1-18-en-win.exe" /SPAWNWND=$D0182 /NOTIFYWND=$7019C | C:\Users\admin\AppData\Local\Temp\orbit-4-1-1-18-en-win.exe | orbit-4-1-1-18-en-win.tmp | ||||||||||||
User: admin Company: www.orbitdownloader.com Integrity Level: HIGH Description: Orbit Downloader setup Exit code: 0 Version: 4.1.1.19 Modules
| |||||||||||||||
| 2084 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1264 --field-trial-handle=1280,i,10210949888099266011,2158273766622572893,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (2232) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2232) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3592) orbit-4-1-1-18-en-win.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | SyncMode5 |
Value: 4 | |||
| (PID) Process: | (3592) orbit-4-1-1-18-en-win.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | Start Page |
Value: about:blank | |||
| (PID) Process: | (3592) orbit-4-1-1-18-en-win.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Orbit |
| Operation: | write | Name: | ShowGrabPro |
Value: 1 | |||
| (PID) Process: | (2584) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2584) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2584) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2584) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (944) orbitdm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3592 | orbit-4-1-1-18-en-win.tmp | C:\Program Files\Orbitdownloader\is-D0BS7.tmp | executable | |
MD5:236F518655EB360A64181235531D8556 | SHA256:A4D3394BC967869CE8554F5EA3A3AAF7A7CD907416F0168CCB14BE5AACD152C5 | |||
| 888 | orbit-4-1-1-18-en-win.exe | C:\Users\admin\AppData\Local\Temp\is-1SGQR.tmp\orbit-4-1-1-18-en-win.tmp | executable | |
MD5:7F1CDAB54CEA42548C6E8F457645B32A | SHA256:DC14FD3054EE69FE1CC12BA6EE7F16E57B023F4E5BE27E945CE1A4FA61612959 | |||
| 3592 | orbit-4-1-1-18-en-win.tmp | C:\Program Files\Orbitdownloader\libeay32.dll | executable | |
MD5:65A6892C19771DB7EDD6B105611BC42B | SHA256:66BE2B3228B6F1DCD3FE0F8DA61AD6B97A63EEA8ECFF63B2064AD223A7EAB9F3 | |||
| 3592 | orbit-4-1-1-18-en-win.tmp | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Orbit.lnk | binary | |
MD5:E7EE5F443BFF747C43F3DEC99642CB26 | SHA256:179BCF3DE6CD30507C9CE07A96524ADEDC8E6E32A7C6811EB9D68B6A32E39C76 | |||
| 3592 | orbit-4-1-1-18-en-win.tmp | C:\Users\admin\AppData\Local\Temp\is-IGTU7.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 3592 | orbit-4-1-1-18-en-win.tmp | C:\Users\admin\AppData\Roaming\Orbit\GrabConf.dat | text | |
MD5:78B92810947A8ADE4A49C448E8181950 | SHA256:BB2DE87D2C2AE1191919D0857ECD317B157F139FF0AC054CC2E5EACBEE0E84CE | |||
| 3592 | orbit-4-1-1-18-en-win.tmp | C:\Users\admin\AppData\Local\Temp\is-IGTU7.tmp\OCSetupHlp.dll | executable | |
MD5:6495734AAF71305A65A5A230D5AEB039 | SHA256:18A4343437FC094D4B61B608A8A6A9773A7F573657CE7D9D792368FE5D761C2E | |||
| 3592 | orbit-4-1-1-18-en-win.tmp | C:\Program Files\Orbitdownloader\unins000.exe | executable | |
MD5:6F3A2385DBE024534760460B46902B97 | SHA256:995A02CA3CB63333A89FDE262F98BCCB653FE53357BF4519138E02E701BB333A | |||
| 3592 | orbit-4-1-1-18-en-win.tmp | C:\Program Files\Orbitdownloader\is-FQAG5.tmp | executable | |
MD5:65A6892C19771DB7EDD6B105611BC42B | SHA256:66BE2B3228B6F1DCD3FE0F8DA61AD6B97A63EEA8ECFF63B2064AD223A7EAB9F3 | |||
| 1988 | orbit-4-1-1-18-en-win.exe | C:\Users\admin\AppData\Local\Temp\is-6D5H7.tmp\orbit-4-1-1-18-en-win.tmp | executable | |
MD5:7F1CDAB54CEA42548C6E8F457645B32A | SHA256:DC14FD3054EE69FE1CC12BA6EE7F16E57B023F4E5BE27E945CE1A4FA61612959 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
944 | orbitdm.exe | GET | — | 18.66.122.58:80 | http://wallpapers.com/new | unknown | — | — | unknown |
944 | orbitdm.exe | GET | — | 188.114.97.3:80 | http://obupdate.orbitdownloader.com/updataGv.php | unknown | — | — | unknown |
944 | orbitdm.exe | GET | — | 18.66.122.58:80 | http://wallpapers.com/new | unknown | — | — | unknown |
944 | orbitdm.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?526e0bcaf37d944d | unknown | compressed | 4.66 Kb | unknown |
944 | orbitdm.exe | GET | — | 188.114.97.3:80 | http://obupdate.orbitdownloader.com/updataAd.php | unknown | — | — | unknown |
944 | orbitdm.exe | GET | 301 | 188.114.96.3:80 | http://obupdate.orbitdownloader.com/update/myinfo.php | unknown | — | — | unknown |
944 | orbitdm.exe | GET | 200 | 108.138.2.173:80 | http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D | unknown | binary | 2.02 Kb | unknown |
1080 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?20da42ca9bb40799 | unknown | — | — | unknown |
944 | orbitdm.exe | GET | 200 | 18.66.142.79:80 | http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D | unknown | binary | 1.51 Kb | unknown |
3016 | orbitdm.exe | GET | — | 188.114.96.3:80 | http://obupdate.orbitdownloader.com/updataAd.php | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
944 | orbitdm.exe | 188.114.96.3:80 | obupdate.orbitdownloader.com | CLOUDFLARENET | NL | unknown |
944 | orbitdm.exe | 188.114.97.3:80 | obupdate.orbitdownloader.com | CLOUDFLARENET | NL | unknown |
944 | orbitdm.exe | 18.66.122.58:80 | wallpapers.com | AMAZON-02 | US | unknown |
944 | orbitdm.exe | 128.1.89.123:80 | orbit.brothersoft.com | ZEN-ECN | US | unknown |
944 | orbitdm.exe | 18.66.122.58:443 | wallpapers.com | AMAZON-02 | US | unknown |
944 | orbitdm.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
Domain | IP | Reputation |
|---|---|---|
api.opencandy.com |
| unknown |
obupdate.orbitdownloader.com |
| unknown |
wallpapers.com |
| unknown |
orbit.brothersoft.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
o.ss2.us |
| whitelisted |
ocsp.rootg2.amazontrust.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
config.edge.skype.com |
| whitelisted |
www.orbitdownloader.com |
| unknown |
Process | Message |
|---|---|
orbitdm.exe | 8 - Server: cloudflare
|
orbitdm.exe | 7 - Vary: Accept-Encoding
|
orbitdm.exe | 3 - Expires: Sat, 25 Nov 2023 12:09:52 GMT
|
orbitdm.exe | Fields:
|
orbitdm.exe | 9 - CF-RAY: 82b97123bea31c0b-FRA
|
orbitdm.exe | 1 - Connection: close
|
orbitdm.exe | 5 - Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=cXB%2FT5HiZRJpkuWg%2BovPZ9tHSm5BY0ZkJGcXaGpkOSXXV%2FkrO%2FoytZ9fAdeRF5eAqWhhGEtz9yRA0Ss451UP56M4tQzm1Dz9kYKtHcpTD1L2HEZlvA2IAqAoJFWDM%2BfPzwycZjT%2B1ggyhi5khItk"}],"group":"cf-nel","max_age":604800}
|
orbitdm.exe |
HTTP DEBUG HEADER --- START ---
protocol: [HTTP/1.1]
http minor version: [1]
uri: [(null)]
method: [(null)]
status code: [301]
reason phrase: [Moved Permanently]
body size: [0]
|
orbitdm.exe | 0 - Date: Sat, 25 Nov 2023 11:09:52 GMT
|
orbitdm.exe | 4 - Location: https://wallpapers.com/new
|