File name:

freegate-7.90-installer.exe

Full analysis: https://app.any.run/tasks/412ed9cf-535f-4e98-ae44-fd2ca5c5a909
Verdict: Malicious activity
Analysis date: April 23, 2024, 14:01:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D1FCF054536B7F934743B2C61D2FA7C6

SHA1:

305EF7D7DC5914F68CDDB3FACE2350A73ECC1561

SHA256:

20017FD064A42E743ECB6F6FD5B8B60EFC21E7F3979B07FCD23A811514F23111

SSDEEP:

196608:+HJVlCcGjxFv0O4vYCeQxNlrgzRsb/p2FX:4/wDjxmOKpeQBIRY2d

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • freegate-7.90-installer.exe (PID: 3416)
  • SUSPICIOUS

    • Reads the BIOS version

      • freegate-7.90-installer.exe (PID: 3416)
    • Executable content was dropped or overwritten

      • freegate-7.90-installer.exe (PID: 3416)
    • Reads the Internet Settings

      • freegate-7.90-installer.exe (PID: 3416)
      • sdiagnhost.exe (PID: 2788)
    • Reads settings of System Certificates

      • freegate-7.90-installer.exe (PID: 3416)
  • INFO

    • Checks proxy server information

      • freegate-7.90-installer.exe (PID: 3416)
    • Reads the computer name

      • wmpnscfg.exe (PID: 1424)
      • freegate-7.90-installer.exe (PID: 3416)
    • Application launched itself

      • iexplore.exe (PID: 4092)
    • Reads security settings of Internet Explorer

      • sdiagnhost.exe (PID: 2788)
      • msdt.exe (PID: 3168)
    • Reads the software policy settings

      • freegate-7.90-installer.exe (PID: 3416)
      • msdt.exe (PID: 3168)
    • Create files in a temporary directory

      • msdt.exe (PID: 3168)
      • freegate-7.90-installer.exe (PID: 3416)
    • Drops the executable file immediately after the start

      • msdt.exe (PID: 3168)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1424)
    • Checks supported languages

      • wmpnscfg.exe (PID: 1424)
      • freegate-7.90-installer.exe (PID: 3416)
    • Reads the machine GUID from the registry

      • freegate-7.90-installer.exe (PID: 3416)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:09:17 03:01:55+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 6264320
InitializedDataSize: 3223040
UninitializedDataSize: -
EntryPoint: 0xdcd058
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 7.9.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: -
CompanyName: Dynamic Internet Technology, Inc.
FileDescription: Freegate
FileVersion: 7, 9, 0, 0
InternalName: Freegate.exe
LegalCopyright: Copyright (C) 2011 - 2020
LegalTrademarks: -
OriginalFileName: -
PrivateBuild: -
ProductName: -
ProductVersion: 0, 0, 0, 0
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start freegate-7.90-installer.exe wmpnscfg.exe no specs iexplore.exe no specs iexplore.exe no specs iexplore.exe no specs msdt.exe no specs sdiagnhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1424"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1560"C:\program files\Internet Explorer\iexplore.exe" SCODEF:4092 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2788C:\Windows\System32\sdiagnhost.exe -EmbeddingC:\Windows\System32\sdiagnhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Scripted Diagnostics Native Host
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sdiagnhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3168 -modal 1376628 -skip TRUE -path C:\Windows\diagnostics\system\networking -af C:\Users\admin\AppData\Local\Temp\NDF9847.tmp -ep NetworkDiagnosticsWebC:\Windows\System32\msdt.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Diagnostics Troubleshooting Wizard
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msdt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3416"C:\Users\admin\AppData\Local\Temp\freegate-7.90-installer.exe" C:\Users\admin\AppData\Local\Temp\freegate-7.90-installer.exe
explorer.exe
User:
admin
Company:
Dynamic Internet Technology, Inc.
Integrity Level:
MEDIUM
Description:
Freegate
Version:
7, 9, 0, 0
Modules
Images
c:\users\admin\appdata\local\temp\freegate-7.90-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3708"C:\program files\Internet Explorer\iexplore.exe" SCODEF:4092 CREDAT:267533 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
4092"C:\program files\Internet Explorer\iexplore.exe" http://dongtaiwang.com/loc/phome.php?v=7.90p&l=409C:\Program Files\Internet Explorer\iexplore.exefreegate-7.90-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
22 837
Read events
22 653
Write events
148
Delete events
36

Modification events

(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:Kuprnaur
Value:
WuNa53obge2bNF7A5iT35PQsw3BBCKIdGGFZZ5
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
Executable files
3
Suspicious files
13
Text files
38
Unknown types
3

Dropped files

PID
Process
Filename
Type
3416freegate-7.90-installer.exeC:\Users\admin\AppData\Local\Temp\eula.txttext
MD5:A036EACB9A1767ABD13351D03CB04999
SHA256:C72F5850CB2DEC62B7A3C4E43CF9ACFA63A8B4370EE43F2936829938E80EBE19
3416freegate-7.90-installer.exeC:\Users\admin\AppData\Local\Temp\fg.initext
MD5:CF132E88497863A84D8111AF14B7B555
SHA256:9A7DD94A11236416A12A037C91E13778828354125CD08D9340FB478E94E01EDF
4092iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\favicon[1].icoimage
MD5:F251D7BDD4D74A479A16EBADBD0C7B54
SHA256:1D1EC1D347A42D41073BA929DAA08F1090E564942E34840E18C584ECF61A5BAE
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\top_header_orange_en[1].pngimage
MD5:DCADFCA386FB1B18B2BF4E97710B2689
SHA256:A9B19D28782659938B411008C01999344B61407CA63B83BC4A47F5B45ABF02F6
3416freegate-7.90-installer.exeC:\Users\admin\AppData\Local\Temp\~zfnjfzqbinary
MD5:5E0E2C9A7768A88E32D79864A31DE73A
SHA256:6CE2B54E3A5C8B55447FA9462CE31B356E29F4DDAFE845914D7B1338AF7A5B1A
3416freegate-7.90-installer.exeC:\Users\admin\AppData\Local\Temp\Cekbokeqbinary
MD5:22CCFDC68C25174C7A71C5638D0BC38C
SHA256:AC3CD5743258CC127FB32F12A9019F6B635B82DDE5D138E8C55F766BDA3E0CBC
4092iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\favicon[1].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
4092iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\imagestore\f7ruq93\imagestore.datbinary
MD5:B430A9B7717D65BF809A8F3EE48B5BE1
SHA256:8A538681E050C6E684F3D3296EDFE28A1A82F0D5CABBE9199B76F2AC3AEAD68E
4092iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:013C7E3961F64048B3434C09D5547B52
SHA256:EE986BEDE1D3637A0A642750C186E5AEB351A1D4AE8341BE0B46957F3EDF3114
4092iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\favicon[2].icoimage
MD5:DA597791BE3B6E732F0BC8B20E38EE62
SHA256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
100
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3416
freegate-7.90-installer.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f793572f73ae117c
unknown
unknown
3416
freegate-7.90-installer.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ef4e5f9451bbaa0c
unknown
unknown
3416
freegate-7.90-installer.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8c0d802b6ec9050d
unknown
unknown
3416
freegate-7.90-installer.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?19f07cd4ab637647
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3416
freegate-7.90-installer.exe
13.33.158.127:443
d2c9q1vj8yz76f.cloudfront.net
US
unknown
3416
freegate-7.90-installer.exe
13.33.158.220:443
d2c9q1vj8yz76f.cloudfront.net
US
unknown
3416
freegate-7.90-installer.exe
13.33.158.172:443
d2c9q1vj8yz76f.cloudfront.net
US
unknown
3416
freegate-7.90-installer.exe
13.33.158.222:443
d2c9q1vj8yz76f.cloudfront.net
US
unknown
3416
freegate-7.90-installer.exe
13.33.81.75:443
AMAZON-02
US
unknown
3416
freegate-7.90-installer.exe
13.33.82.147:443
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
windowsupdate.microsoft.com
  • 20.72.235.82
whitelisted
d2c9q1vj8yz76f.cloudfront.net
  • 13.33.158.127
  • 13.33.158.220
  • 13.33.158.172
  • 13.33.158.222
unknown
d3cabiic91qtuo.cloudfront.net
unknown
d2fftkxjmzlswm.cloudfront.net
  • 143.204.102.83
  • 143.204.102.148
  • 143.204.102.32
  • 143.204.102.72
unknown
d15dybyic2v9sh.cloudfront.net
unknown
7revs.csis.org
  • 104.22.12.209
  • 104.22.13.209
  • 172.67.13.187
unknown
media.tommy.com
  • 151.101.194.197
  • 151.101.66.197
  • 151.101.2.197
  • 151.101.130.197
unknown
login.news-leader.com
  • 151.101.2.62
  • 151.101.194.62
  • 151.101.130.62
  • 151.101.66.62
unknown
dtuiqk.74lmth4.wmssh.com
  • 132.203.30.159
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted

Threats

No threats detected
No debug info