fg727p.exe

Dynamic Internet Technology Inc.

This is a setup program which is used to install the application. This executable runs as a local area network (LAN) Internet proxy server listening on port 8580. The file has been seen being downloaded from mg.mail.yahoo.com and multiple other hosts.
Publisher:
Dynamic Internet Technology, Inc.  (signed by Dynamic Internet Technology Inc.)

Description:
Fast and Secure Gateway to Internet Freedom

Version:
7, 2, 7, 0

MD5:
6e94be6cf708de178f4948cbae48c603

SHA-1:
34aefafaf9efb867ce8a990202df187d7541e57f

SHA-256:
faa9696d7222edeead98390615107ae32a97a91053f8ba308a4511177bbd1f62

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/20/2024 1:23:01 AM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.131225

File size:
1.8 MB (1,862,424 bytes)

Product version:
0, 0, 0, 0

Copyright:
Copyright (C) 2003-2010

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/28/2010 2:41:22 AM

Valid to:
7/28/2013 2:41:17 AM

Subject:
CN=Dynamic Internet Technology Inc., O=Dynamic Internet Technology Inc., C=US

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012A154E407D

File PE Metadata
Compilation timestamp:
3/21/2012 2:35:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:xFdglo8w2bRwucZiG7yKf2smKMjS/kvQDC+1WmLkhA:jdglo8BriHfXkvQDF11

Entry address:
0x51FD3

Entry point:
52, BA, 64, 00, 00, 00, 85, D2, 74, 1D, B9, 00, 10, 00, 00, 85, C9, 74, 07, 01, C8, 01, D8, 49, EB, F5, 52, 54, 54, FF, 15, 33, A0, 53, 00, 5A, 4A, EB, DF, 5A, E9, 00, 60, 3A, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 06, 00, 58, 12, 00, 80, 48, 00, 00, 80, 03, 00, 00, 00, 88, 00, 00, 80, 04, 00, 00, 00, E0, 00, 00, 80, 05, 00, 00, 00, F8, 00, 00, 80, 06, 00, 00, 00, D8, 01, 00, 80, 0E, 00, 00, 00, A8, 02, 00, 80, 10, 00, 00, 00, D0, 02, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9129  (probably packed)

Code size:
600 KB (614,400 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:8580/

Local host port:
8580

Default credentials:
No


2 Windows Firewall Allowed Programs
Name:
D:\翻\fg727p.exe

Name:
C:\Documents and Settings\fatan\My Documents\Toolz\Freegate\fg727p.exe


The file fg727p.exe has been seen being distributed by the following 4 URLs.

https://mg.mail.yahoo.com/ya/.../AitWx7KGN0&fid=Inbox&pid=2&clean=0&appid=YahooMailNeo

https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjJ-OPt1QwpdpBIHBtgUBcq41BZxYDBUXTj3p3qb5UZHlw50z6cTUjk6iGlghWkNj4gHyqtsdt-jko-uK0ko8KHOrw/messages/@.id==AHNaimIAABSkUVSfngnOyzOzCTU/content/parts/@.id==2/raw?appid=YahooMailNeo&token=zitEzqOML3j84e6ealFTT5U7-km5qEQF52lp7AcCuBafQ5byjHXy9sMg-UOK4QH_mMhGeHwcT_UQFHgYhMO2HQ&error=https://mg.mail.yahoo.com/.../iframemsg?id=ccd354f3-5f78-968a-5540-1b22600a8722&ymreqid=374c737e-89a6-4f58-011a-9e0017010000

https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjJ-8Wmjo9pit9wCfGL_q-wXO2R62KAyoqVoh49O7-wcPoBqjTCDY2kPd3weSjIh32oy-OZtZrw2rULBXQ-scIJXZQ/messages/@.id==AOwfimIAANrlUGgb6QiGcgfigB4/content/parts/@.id==2/raw?appid=YahooMailNeo&token=zitEzqOML3j84e6ealFTT5U7-km5qEQF52lp7AcCuBZl7akuVllMRRPsZNq3UyTYGQZx4ae-OBra8cq7Pigd---RUCUW2Jsn177HgndddSM6y0cZDZK87O4GU8LnZAz6&error=https://mg.mail.yahoo.com/.../iframemsg?id=5fc89717-4299-3a9d-858c-83f5d8bf2490&ymreqid=9e00cc16-c3bb-6499-01c0-720011010000

Scan fg727p.exe - Powered by Reason Core Security