Popular download government module has dark DDoS component, researchers say

Recent versions of Orbit Downloader, a renouned Windows module for downloading embedded media calm and other forms of files from websites, turns computers into bots and uses them to launch distributed denial-of-service (DDoS) attacks, according to confidence researchers.

Starting with chronicle 4.1.1.14 expelled in December, a Orbit Downloader module silently downloads and uses a DLL (Dynamic Link Library) member that has DDoS functionality, malware researchers from antivirus businessman ESET pronounced Wednesday in a blog post.

The brute member is downloaded from a plcae on a program’s central website, orbitdownloader.com, a ESET researchers said. An encrypted pattern record containing a list of websites and IP (Internet Protocol) addresses to offer as targets for attacks is downloaded from a same site, they said.

Orbit Downloader has been grown given during slightest 2006 and judging by download statistics from module placement sites like CNET’s Download.com and Softpedia.com it is, or used to be, a renouned program.

Orbit Downloader was downloaded roughly 36 million times from Download.com to date and around 12,500 times final week. Its latest chronicle is 4.1.1.18 and was expelled in May.

In a examination of a program, a CNET editor remarkable that it installs additional “junk programs” and suggested alternatives to users who need a dedicated download government application.

When they rescued a DDoS component, a ESET researchers were indeed questioning a “junk programs” commissioned by Orbit Downloader in sequence to establish if a module should be flagged as a “potentially neglected application,” famous in a attention as PUA.

“The developer [of Orbit Downloader], Innoshock, generates a income from bundled offers, such as OpenCandy, that is used to implement third-party module as good as to arrangement advertisements,” a researchers said, observant that such promotion arrangements are normal function for giveaway programs these days.

“What is unusual, though, is to see a renouned focus containing additional formula for behaving Denial of Service (DoS) attacks,” they said.

The brute Orbit Downloader DDoS member is now rescued by ESET products as a Trojan module called Win32/DDoS.Orbiter.A. It is able of rising several forms of attacks, a researchers said.

First, it checks if a focus called WinPcap is commissioned on a computer. This is a legitimate third-party focus that provides low-level network functionality, including promulgation and capturing network packets. It is not bundled with Orbit Downloader, yet can be commissioned on computers by other applications that need it.

If WinPcap is installed, Orbit’s DDoS member uses a apparatus to send TCP SYN packets on pier 80 (HTTP) to a IP addresses specified in a pattern file. “This kind of conflict is famous as a SYN flood,” a ESET researchers said.

If WinPcap is not present, a brute member directly sends HTTP tie requests on pier 80 to a targeted machines, as good as UDP packets on pier 53 (DNS).

The attacks also use IP spoofing techniques, a source IP addresses for a requests descending into IP residence ranges that are hardcoded in a DLL file.

“On a exam mechanism in a lab with a gigabit Ethernet port, HTTP tie requests were sent during a rate of about 140,000 packets per second, with falsified source addresses mostly appearing to come from IP ranges allocated to Vietnam,” a ESET researchers said.

After adding a showing signature for a DLL component, a ESET researchers also identified an comparison record called orbitnet.exe that had roughly a same functionality as a DLL file, yet downloaded a pattern from a conflicting website, not orbitdownloader.com.

This suggests that Orbit Downloader competence have had DDoS functionality given before chronicle 4.1.1.14. The orbitnet.exe record is not bundled with any comparison Orbit Downloader installers, yet it competence have been downloaded post-installation, like a DLL component.

This is a possibility, yet it can’t be demonstrated with certainty, Peter Kosinar, a technical associate during ESET who was concerned in a investigation, pronounced Thursday. It competence also be distributed yet other means, he said.

Adding to a difficulty is that an comparison chronicle of orbitnet.exe than a one found by ESET is distributed with Orbit Downloader 4.1.1.18. The reason for this is misleading given Orbit Downloader 4.1.1.18 also downloads and uses a DLL DDoS component. However, it indicates a transparent attribute between orbitnet.exe and Orbit Downloader.

The fact that a renouned module like Orbit Downloader is used as a DDoS apparatus creates problems not usually for a websites that it’s used to attack, yet also for a users whose computers are being abused.

According to Kosinar, there is no rate extent implemented for a packets sent by a DDoS component. This means that rising these attacks can simply devour a user’s Internet tie bandwidth, inspiring his ability to entrance a Internet by other programs.

Users who implement Orbit Downloader design a module to streamline their downloads and boost their speed, yet it turns out that a focus has a conflicting effect.

Orbit Downloader is grown by a organisation called Innoshock, yet it’s not transparent if this is a association or only a group of developers. Attempts to hit Innoshock for criticism Thursday around dual Gmail addresses listed on a website and a Orbit Downloader site, as good as around Twitter, remained unanswered.

The program’s users also seem to have beheld a DDoS function judging by comments left on Download.com and a Orbit Downloader support forum.

Orbit Downloder chronicle 4.1.1.18 is generating a really high volume of DDoS traffic, a user named raj_21er said on a support forum on Jun 12. “The DDoS flooding is so outrageous that it only hangs a gateway devices/network switches totally and breaks down a whole network operation.”

“I was regulating Orbit Downloader for a past one week on my desktop when we unexpected beheld that a internet entrance was flattering most passed in a final 2 days,” another user named Orbit_User_5500 said. Turning off a desktop complement easy Internet entrance to a other network computers and devices, he said.

Since adding showing of this DDoS component, ESET perceived tens of thousands of showing reports per week from deployments of a antivirus products, Kosinar said.

Article source: http://www.pcworld.com/article/2047240/popular-download-management-program-has-hidden-ddos-component-researchers-say.html#tk.rss_all