CCProxy.EXE

CCProxy

Youngzsoft Co., Ltd.

The application CCProxy.EXE by Youngzsoft Co. has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. While running, it connects to the Internet address li365-173.members.linode.com on port 80 using the HTTP protocol.
Publisher:
Youngzsoft  (signed by Youngzsoft Co., Ltd.)

Product:
CCProxy

Version:
8, 0, 0, 0

MD5:
970b6eecf43a78ba9ad34e7353208dfe

SHA-1:
34a84cb55df5c7b2388932577e6ca8d1834f1471

SHA-256:
15da67d9c4691d480def3d4607da8ab346d653db60c079a48c9aed21bef68a9e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
10/20/2018 4:37:17 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Youngzso
17.1.14.12

File size:
2.5 MB (2,639,216 bytes)

Product version:
8, 0, 0, 0

Copyright:
(c) Youngzsoft. All rights reserved.

Original file name:
CCProxy.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/26/2015 5:00:00 AM

Valid to:
5/15/2018 4:59:59 AM

Subject:
CN="Youngzsoft Co., Ltd.", OU=Software Development, O="Youngzsoft Co., Ltd.", L=Changsha, S=Hunan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
72D5CAF59A3CC644C573E13EA0892EAB

File PE Metadata
Compilation timestamp:
1/13/2017 8:20:40 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x12A324

Entry point:
E8, 4F, DE, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 58, 59, 87, 04, 24, FF, E0, 58, 59, 87, 04, 24, FF, E0, 8B, FF, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, A0, A3, 52, 00, 6A, 00, FF, 75, 0C, FF, 75, F8, FF, 75, 08, E8, B4, 6B, 03, 00, 8B, 45, 0C, 8B...
 
[+]

Entropy:
6.4840

Code size:
1.5 MB (1,528,320 bytes)

Windows Firewall Allowed Program
Name:
ccproxy


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to li365-173.members.linode.com  (96.126.108.173:80)

TCP:
Connects to 108.1.20.195.pp.com.pl  (195.20.1.108:49856)

TCP:
Connects to 104.1.20.195.pp.com.pl  (195.20.1.104:1466)

TCP (HTTP):
Connects to ir2.fp.vip.ir2.yahoo.com  (46.228.47.114:80)

TCP (HTTP):
Connects to a104-93-97-245.deploy.static.akamaitechnologies.com  (104.93.97.245:80)

TCP (HTTP SSL):
Connects to a104-93-200-166.deploy.static.akamaitechnologies.com  (104.93.200.166:443)

Remove CCProxy.EXE - Powered by Reason Core Security