Threat Database Trojans Win32/DDoS.Orbiter.A

Win32/DDoS.Orbiter.A

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 7
First Seen: August 22, 2013
Last Seen: June 12, 2022
OS(es) Affected: Windows

Win32/DDoS.Orbiter.A is a dangerous version of a popular file downloading browser extension that includes DDoS (Distributed Denial of Service) capabilities. DDoS attacks are designed to take down a particular server by overloading it with requests and are usually carried out by a large number of computer systems working together to bombard the server. This is often accomplished through the use of botnets, large networks of infected computers that can be controlled by a criminal in order to carry out coordinated attacks. The legitimate version of Win32/DDoS.Orbiter.A is used to download files and to speed up file transfer rates. Win32/DDoS.Orbiter.A is often also used to download and save popular videos from YouTube and other streaming video websites. However, PC security researchers have become alarmed due to having found that some versions of this program, Orbit Downloader, also contains a component that can be used to carry out DDoS attacks.

Win32/DDoS.Orbiter.A and Orbit Downloader's Malicious Code

This browser extension has been active for several years, first released to the public in 2006 and is available as a free download. Win32/DDoS.Orbiter.A is often bundled with other software, adware or toolbars that are used by the developers of this program to generate a profit. These types of components are commonly known as PUPs, or Potentially Unwanted Programs and are not entirely malicious. Because of this, computer users can usually make the choice between downloading them or not downloading them as a way of supporting the developers of their freeware. However, the case of Win32/DDoS.Orbiter.A is more worrying. The Orbit Downloader's code contains portions that may allow a computer user to carry out DdoS attacks. The fact that this program is widely used and that Win32/DDoS.Orbiter.A already generates a very large amount of Web traffic means that Win32/DDoS.Orbiter.A can easily be adapted to carry out DdoS attacks. Versions of the Orbit Downloader that contain this malicious code are identified as Win32/DDoS.Orbiter.A.

Win32/DDoS.Orbiter.A also connects to a remote server to obtain updates and that this functionality has been present in Orbit Downloader for quite a while. Until the developers of this program explain the purpose of this added code or clarify the purpose of this DdoS functionality, ESG security analysts strongly recommend removing Win32/DDoS.Orbiter.A from your computer immediately by installing this Web browser add-on and then running a full scan with a strong, fully updated anti-malware application.

Trending

Most Viewed

Loading...