CCProxy.EXE

CCProxy

Youngzsoft

The application CCProxy.EXE has been detected as adware by 2 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “CCProxy”. While running, it connects to the Internet address li365-173.members.linode.com on port 80 using the HTTP protocol.
Publisher:
Youngzsoft

Product:
CCProxy

Version:
7, 3, 0, 0

MD5:
4354053e4287dfa7a613eae21b6f8859

SHA-1:
3e1c3f179071a3eacbd99e481e5ae830d8669253

SHA-256:
b8530632e8aa5c6024b46060372b39fa7e041b53b57c0e2e8a34921ac15b8e50

Scanner detections:
2 / 68

Status:
Adware

Analysis date:
4/25/2024 10:39:13 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:CCProxy-D [PUP]
2014.9-140317

Reason Heuristics
PUP.Youngzsoft.H
14.3.17.6

File size:
2 MB (2,124,288 bytes)

Product version:
7, 3, 0, 0

Copyright:
Copyright(C) 2000

Original file name:
CCProxy.EXE

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\ccproxy\ccproxy.exe

File PE Metadata
Compilation timestamp:
12/6/2013 9:15:51 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:rxeirAIyLb8MoHyCvc9HY0SCg8sAAcf3iR0uCQazRNtwaoR8N869cKStjWtoyUl/:rxeSAIg2Jvk2CgDLRo3RzLoR639t+yyD

Entry address:
0xE048C

Entry point:
48, 83, EC, 28, E8, A7, 3F, 01, 00, 48, 83, C4, 28, E9, 12, FE, FF, FF, CC, CC, 40, 53, 48, 83, EC, 30, 4D, 8B, D8, 4D, 85, C9, 75, 0E, 48, 85, C9, 75, 0E, 48, 85, D2, 75, 20, 33, C0, EB, 3F, 48, 85, C9, 74, 17, 48, 85, D2, 74, 12, 4D, 85, C9, 75, 05, 44, 88, 09, EB, E8, 4D, 85, C0, 75, 2C, 44, 88, 01, E8, E3, 00, 00, 00, BB, 16, 00, 00, 00, 48, 83, 64, 24, 20, 00, 45, 33, C9, 45, 33, C0, 33, D2, 33, C9, 89, 18, E8, 87, 92, FF, FF, 8B, C3, 48, 83, C4, 30, 5B, C3, 4C, 8B, D1, 4C, 8B, C2, 49, 83, F9, FF, 75...
 
[+]

Code size:
1.1 MB (1,177,088 bytes)

Service
Display name:
CCProxy

Type:
Win32OwnProcess


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to li365-173.members.linode.com  (96.126.108.173:80)

TCP (HTTP):
Connects to ps30400.dreamhost.com  (208.113.182.130:80)

Remove CCProxy.EXE - Powered by Reason Core Security