| File name: | freegate-7.90-installer.exe |
| Full analysis: | https://app.any.run/tasks/412ed9cf-535f-4e98-ae44-fd2ca5c5a909 |
| Verdict: | Malicious activity |
| Analysis date: | April 23, 2024, 14:01:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | D1FCF054536B7F934743B2C61D2FA7C6 |
| SHA1: | 305EF7D7DC5914F68CDDB3FACE2350A73ECC1561 |
| SHA256: | 20017FD064A42E743ECB6F6FD5B8B60EFC21E7F3979B07FCD23A811514F23111 |
| SSDEEP: | 196608:+HJVlCcGjxFv0O4vYCeQxNlrgzRsb/p2FX:4/wDjxmOKpeQBIRY2d |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:09:17 03:01:55+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 6264320 |
| InitializedDataSize: | 3223040 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xdcd058 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 7.9.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | Dynamic Internet Technology, Inc. |
| FileDescription: | Freegate |
| FileVersion: | 7, 9, 0, 0 |
| InternalName: | Freegate.exe |
| LegalCopyright: | Copyright (C) 2011 - 2020 |
| LegalTrademarks: | - |
| OriginalFileName: | - |
| PrivateBuild: | - |
| ProductName: | - |
| ProductVersion: | 0, 0, 0, 0 |
| SpecialBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1424 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1560 | "C:\program files\Internet Explorer\iexplore.exe" SCODEF:4092 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2788 | C:\Windows\System32\sdiagnhost.exe -Embedding | C:\Windows\System32\sdiagnhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Scripted Diagnostics Native Host Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3168 | -modal 1376628 -skip TRUE -path C:\Windows\diagnostics\system\networking -af C:\Users\admin\AppData\Local\Temp\NDF9847.tmp -ep NetworkDiagnosticsWeb | C:\Windows\System32\msdt.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Diagnostics Troubleshooting Wizard Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3416 | "C:\Users\admin\AppData\Local\Temp\freegate-7.90-installer.exe" | C:\Users\admin\AppData\Local\Temp\freegate-7.90-installer.exe | explorer.exe | ||||||||||||
User: admin Company: Dynamic Internet Technology, Inc. Integrity Level: MEDIUM Description: Freegate Version: 7, 9, 0, 0 Modules
| |||||||||||||||
| 3708 | "C:\program files\Internet Explorer\iexplore.exe" SCODEF:4092 CREDAT:267533 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 4092 | "C:\program files\Internet Explorer\iexplore.exe" http://dongtaiwang.com/loc/phome.php?v=7.90p&l=409 | C:\Program Files\Internet Explorer\iexplore.exe | — | freegate-7.90-installer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (3416) freegate-7.90-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | Kuprnaur |
Value: WuNa53obge2bNF7A5iT35PQsw3BBCKIdGGFZZ5 | |||
| (PID) Process: | (3416) freegate-7.90-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3416) freegate-7.90-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3416) freegate-7.90-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (3416) freegate-7.90-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (3416) freegate-7.90-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (3416) freegate-7.90-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (3416) freegate-7.90-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3416) freegate-7.90-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (3416) freegate-7.90-installer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1560 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\phome[1].htm | html | |
MD5:5D7414A2FCA93B2A083B31364DDF36FB | SHA256:1650F7D2CC2AACF57F57A046D34814146763C30901C826AA42EE8E842679415C | |||
| 3416 | freegate-7.90-installer.exe | C:\Users\admin\AppData\Local\Temp\eula.txt | text | |
MD5:A036EACB9A1767ABD13351D03CB04999 | SHA256:C72F5850CB2DEC62B7A3C4E43CF9ACFA63A8B4370EE43F2936829938E80EBE19 | |||
| 1560 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\global3[1].css | text | |
MD5:74852E0D7732EF9C64C34A488B074EBF | SHA256:40914B2AF4E8D4CE4FF65924CBA688D7C6043AE3285B705B4BC3B795A4053015 | |||
| 3416 | freegate-7.90-installer.exe | C:\Users\admin\AppData\Local\Temp\dtwpc.dat | text | |
MD5:E54A185042388A05ECB5679738CFD54F | SHA256:1E2C9BD5AA087B31185286F37D5B962B01B8547542A1F3EEE0F10DD5C537FF9E | |||
| 3416 | freegate-7.90-installer.exe | C:\Users\admin\AppData\Local\Temp\fg.ini | text | |
MD5:CF132E88497863A84D8111AF14B7B555 | SHA256:9A7DD94A11236416A12A037C91E13778828354125CD08D9340FB478E94E01EDF | |||
| 4092 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | image | |
MD5:DA597791BE3B6E732F0BC8B20E38EE62 | SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07 | |||
| 4092 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\favicon[1].ico | image | |
MD5:DA597791BE3B6E732F0BC8B20E38EE62 | SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07 | |||
| 4092 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:013C7E3961F64048B3434C09D5547B52 | SHA256:EE986BEDE1D3637A0A642750C186E5AEB351A1D4AE8341BE0B46957F3EDF3114 | |||
| 4092 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_C5130A0BDC8C859A2757D77746C10868 | der | |
MD5:914EFCD7A4FF879D6946881E490322C4 | SHA256:7B243191934BCB26EF7D79ACE225F0CC74518450CA6B546FF4DFA44C1AB34706 | |||
| 4092 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_C5130A0BDC8C859A2757D77746C10868 | binary | |
MD5:41A4330E5FAFE1121E8160C2DDF50C87 | SHA256:C5A4270302C0EFCCA4D4F488464DC603F0B307D5482E1D12E343BCCA9DB9CDAC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3416 | freegate-7.90-installer.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f793572f73ae117c | unknown | — | — | unknown |
3416 | freegate-7.90-installer.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ef4e5f9451bbaa0c | unknown | — | — | unknown |
3416 | freegate-7.90-installer.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?19f07cd4ab637647 | unknown | — | — | unknown |
3416 | freegate-7.90-installer.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8c0d802b6ec9050d | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3416 | freegate-7.90-installer.exe | 13.33.158.127:443 | d2c9q1vj8yz76f.cloudfront.net | — | US | unknown |
3416 | freegate-7.90-installer.exe | 13.33.158.220:443 | d2c9q1vj8yz76f.cloudfront.net | — | US | unknown |
3416 | freegate-7.90-installer.exe | 13.33.158.172:443 | d2c9q1vj8yz76f.cloudfront.net | — | US | unknown |
3416 | freegate-7.90-installer.exe | 13.33.158.222:443 | d2c9q1vj8yz76f.cloudfront.net | — | US | unknown |
3416 | freegate-7.90-installer.exe | 13.33.81.75:443 | — | AMAZON-02 | US | unknown |
3416 | freegate-7.90-installer.exe | 13.33.82.147:443 | — | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
windowsupdate.microsoft.com |
| whitelisted |
d2c9q1vj8yz76f.cloudfront.net |
| unknown |
d3cabiic91qtuo.cloudfront.net |
| unknown |
d2fftkxjmzlswm.cloudfront.net |
| unknown |
d15dybyic2v9sh.cloudfront.net |
| unknown |
7revs.csis.org |
| unknown |
media.tommy.com |
| unknown |
login.news-leader.com |
| unknown |
dtuiqk.74lmth4.wmssh.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |