rfginst-t22.exe

Refog Inc.

The application rfginst-t22.exe by Refog has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from account.refog.com and multiple other hosts.
Publisher:
Refog Inc.  (signed and verified)

Version:
8.6.7.2650

MD5:
0dbd241bb3348878c32bc4ec262e263b

SHA-1:
be356ee7ba0f946bd956ee958d7933d5b073385c

SHA-256:
d79fe8b7129d2f37638eb16666fd51fff0201ce56ab0983922da84724cad6555

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
7/13/2025 11:16:12 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Refog (M)
16.5.10.8

File size:
12.6 MB (13,206,976 bytes)

Product version:
8.6.7.2650

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\rfginst-t22.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
3/3/2016 9:00:00 PM

Valid to:
4/3/2018 8:59:59 PM

Subject:
CN=Refog Inc., O=Refog Inc., L=Alexandria, S=Virginia, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
50E9ECB0A3DD83DEC773133A47225D97

File PE Metadata
Compilation timestamp:
5/5/2016 10:16:01 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:MVxZ/FUabJPREoSkXbioCd1R4F3ZuC+SuKOBuRIp:z2/SkRCdv8juKOBuRIp

Entry address:
0x2068C4

Entry point:
55, 8B, EC, 83, C4, F0, B8, 9C, 44, 5F, 00, E8, 84, 43, E0, FF, A1, 98, 42, 61, 00, 8B, 00, E8, C0, F3, F3, FF, A1, 98, 42, 61, 00, 8B, 00, B2, 01, E8, AE, 16, F4, FF, 8B, 0D, D8, 40, 61, 00, A1, 98, 42, 61, 00, 8B, 00, 8B, 15, 04, F9, 5E, 00, E8, BA, F3, F3, FF, A1, 98, 42, 61, 00, 8B, 00, E8, 4E, F5, F3, FF, E8, 59, 02, E0, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
2 MB (2,119,168 bytes)

The file rfginst-t22.exe has been seen being distributed by the following 19 URLs.

https://account.refog.com/mail/.../?url=download?pid=rkl&ver=8.6.7.2650&hash=3pVBrqBy9d4yRp32tht6UMoqwV1OH3RHm9jkBt4xiDk8-r0DcTzw12pIxeDVgH1F

https://account.refog.com/mail/.../?url=download?pid=rkl&ver=8.6.7.2650&hash=9yNQMGFsuc8EpSw1MazO9coqwV1OH3RHm9jkBt4xiDk8-r0DcTzw12pIxeDVgH1F

https://www.google.com/url?hl=es&q=https://account.refog.com/mail/.../?url=download?pid=rkl&ver=8.6.7.2650&hash=N34AwvTCgE25OgnuyFCeKsoqwV1OH3RHm9jkBt4xiDk8-r0DcTzw12pIxeDVgH1F&source=gmail&ust=1469231197832000&usg=AFQjCNHrP3VNTlTUyQ_czn-eqK57eqsrag

https://account.refog.com/mail/.../?url=download?pid=rkl&ver=8.6.7.2650&hash=tAyLToqlG59f6zcwIcZ6lsoqwV1OH3RHm9jkBt4xiDk8-r0DcTzw12pIxeDVgH1F

https://account.refog.com/mail/.../?url=download?pid=rkl&ver=8.6.7.2650&hash=QYAI46cHYOsz06syQkQ5q8oqwV1OH3RHm9jkBt4xiDk8-r0DcTzw12pIxeDVgH1F

https://account.refog.com/mail/.../?url=download?pid=rkl&ver=8.6.7.2650&hash=_wcqKbBhhgg34otVNQRrgMoqwV1OH3RHm9jkBt4xiDk8-r0DcTzw12pIxeDVgH1F

https://account.refog.com/mail/.../?url=download?pid=rkl&ver=8.6.7.2650&hash=vnBlXQkWhKRrLRfoMn-xJsoqwV1OH3RHm9jkBt4xiDk8-r0DcTzw12pIxeDVgH1F

https://rep1.refog.com/.../rfginst-gwt.exe

https://rep1.refog.com/.../rfginst-g98.exe

https://www.google.com/url?hl=pt-BR&q=https://account.refog.com/mail/.../?url=download?pid=rkl&ver=8.6.7.2650&hash=xdJ29CzxH4LiQtZPXAFiAcoqwV1OH3RHm9jkBt4xiDk8-r0DcTzw12pIxeDVgH1F&source=gmail&ust=1469407068243000&usg=AFQjCNFmW8-rsJiP0nsW1DMm8rmdGp6cwA

Remove rfginst-t22.exe - Powered by Reason Core Security