CCProxy.EXE

CCProxy

Youngzsoft Co., Ltd.

The application CCProxy.EXE by Youngzsoft Co. has been detected as adware by 3 anti-malware scanners. While running, it connects to the Internet address li365-173.members.linode.com on port 80 using the HTTP protocol.
Publisher:
Youngzsoft  (signed by Youngzsoft Co., Ltd.)

Product:
CCProxy

Version:
8, 0, 0, 0

MD5:
0d90f5326a9ae2a8861ed9a672937aae

SHA-1:
7dc33b74cbbe441ae378004d58a8cc74d3c0f516

SHA-256:
50b17b022dde03abcdfed13bbe7d8b48ee76ac5650f212689fa694ebbcdddc8d

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
6/24/2018 2:01:34 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.7383

Malwarebytes
PUP.Optional.CCProxy
v2015.10.28.10

Reason Heuristics
Win32.Generic.YoungzsoftCo.Meta
15.10.28.22

File size:
2.5 MB (2,585,968 bytes)

Product version:
8, 0, 0, 0

Copyright:
(c) Youngzsoft. All rights reserved.

Original file name:
CCProxy.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/25/2015 5:00:00 PM

Valid to:
5/14/2018 4:59:59 PM

Subject:
CN="Youngzsoft Co., Ltd.", OU=Software Development, O="Youngzsoft Co., Ltd.", L=Changsha, S=Hunan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
72D5CAF59A3CC644C573E13EA0892EAB

File PE Metadata
Compilation timestamp:
10/8/2015 6:37:13 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:86i0fE8cGNJYP5bReqih9ozXptE+3WTIyyA0N:86i0BdAGqihEtEAA0N

Entry address:
0x11F00C

Entry point:
E8, 27, DC, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 58, 59, 87, 04, 24, FF, E0, 58, 59, 87, 04, 24, FF, E0, 8B, FF, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, 88, F0, 51, 00, 6A, 00, FF, 75, 0C, FF, 75, F8, FF, 75, 08, E8, 32, 6D, 03, 00, 8B, 45, 0C, 8B...
 
[+]

Entropy:
6.4717

Code size:
1.4 MB (1,481,216 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to li365-173.members.linode.com  (96.126.108.173:80)

Remove CCProxy.EXE - Powered by Reason Core Security