ocs_v71b.exe

OCS

The application ocs_v71b.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. While running, it connects to the Internet address dls.thinklabs-cluster.de on port 80 using the HTTP protocol.
Publisher:
OCS

Product:
OCS

Version:
1.0.0.0

MD5:
600d51d9fd68606dde6a20830c9c5e9e

SHA-1:
fcb8ca6c49f1967a0cf8603e9be120c382d5dbc4

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 10:27:27 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.OMO
705

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.213.4

Baidu Antivirus
Trojan.Win32.DownloadSponsor
4.0.3.14710

Bitdefender
Adware.Agent.OMO
1.0.20.300

Comodo Security
UnclassifiedMalware
21254

Emsisoft Anti-Malware
Adware.Agent.OMO
8.15.03.01.01

ESET NOD32
Win32/DownloadSponsor (variant)
8.10068

F-Secure
Adware.Agent.OMO
11.2015-01-03_1

G Data
Adware.Agent.OMO
15.3.25

IKARUS anti.virus
AdWare.DownloadSponsor
t3scan.1.6.1.0

MicroWorld eScan
Adware.Agent.OMO
16.0.0.180

NANO AntiVirus
Trojan.Win32.DownloadSponsor.dkkydc
0.30.0.296

nProtect
Adware.Agent.OMO
15.02.27.01

Trend Micro House Call
TROJ_GEN.R0C1H09B315
7.2.60

VIPRE Antivirus
DownloadSponsor
31112

File size:
312.5 KB (320,000 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Project OCS

Original file name:
OCS.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\windows\temp\ocs\ocs_v71b.exe

File PE Metadata
Compilation timestamp:
7/8/2014 4:35:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:0TCOaDJLUMGLOjkWF1H/GwAOP6MgJtcC/0csO+z1SPhWXK4jH3kpag32NK4YV20T:0TCXkigO/k6u7SIw6ihdqrWL4PVfP

Entry address:
0x4C1FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
297 KB (304,128 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www1.thinklabs-cluster.de  (148.251.198.118:80)

TCP (HTTP):
Connects to dls.thinklabs-cluster.de  (148.251.198.116:80)

TCP (HTTP):
Connects to www2.thinklabs-cluster.de  (148.251.198.119:80)

TCP (HTTP):
Connects to sl1-1.thinklabs-cluster.de  (148.251.198.115:80)

Remove ocs_v71b.exe - Powered by Reason Core Security