OTM.exe

OTM

OldTimer Tools

The executable OTM.exe has been detected as malware by 10 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from oldtimer.geekstogo.com.
Publisher:
OldTimer Tools

Product:
OTM

Version:
3.1.21.0

MD5:
2d782d49ebb48ef125e16b8b20e9e612

SHA-1:
ac466b6bfb9bc82fc2b8bb7d324ef08e4af07d59

SHA-256:
e292c1e68f8fdd8d06cdcfcf20f18b1e3a55b0397c57b39dcd6483eb6226ff80

Scanner detections:
10 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 10:18:27 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

AVG
Win32/Sality
2015.0.4591

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.96

Kaspersky
Virus.Win32.Sality
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.223.555.0

Norman
Win32.Sality.3
22.05.2016 07:18:28

File size:
587 KB (601,088 bytes)

Product version:
2.1.1.0

Original file name:
OTM.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\otm.exe

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:BmWW4gEg/CI8hW4nqu9GisnXGCuuUGk/lxYqS5xhAzp+XWMt:BmWWLEkpuKu9Gis13k/lxYV5x8p+G

Entry address:
0x1000

Entry point:
80, C7, 0A, F3, F2, 04, AC, 14, 5B, 81, F8, E8, 25, 03, AA, 81, F0, 64, 7A, 80, 00, 89, F6, 89, D2, FE, CD, 68, 61, CE, 11, 00, 68, 65, 52, 21, 00, 85, DF, 72, 09, 0F, B6, E9, 0F, AF, DB, 80, FB, 1E, E8, 15, 00, 00, 00, 85, C7, 73, 06, 24, 39, 21, D9, 87, C1, FE, C8, 0F, BE, E9, 81, FB, 82, 5F, 00, 00, 0F, AF, CB, 85, DE, 78, 0C, 0F, AF, C3, 8D, 2D, EE, 83, 55, E4, 0F, AF, FB, C7, C3, C3, 97, 79, 72, BA, 77, 56, 00, 00, 0F, AF, DE, 81, F2, 57, 54, 00, 00, 89, F6, 81, F2, 73, 03, 00, 00, 8D, 05, 10, A6, A1...
 
[+]

Entropy:
7.9777  (probably packed)

Code size:
1.5 MB (1,604,608 bytes)

The file OTM.exe has been seen being distributed by the following URL.

Remove OTM.exe - Powered by Reason Core Security