File name:

freegate-7.90-installer.exe

Full analysis: https://app.any.run/tasks/412ed9cf-535f-4e98-ae44-fd2ca5c5a909
Verdict: Malicious activity
Analysis date: April 23, 2024, 14:01:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D1FCF054536B7F934743B2C61D2FA7C6

SHA1:

305EF7D7DC5914F68CDDB3FACE2350A73ECC1561

SHA256:

20017FD064A42E743ECB6F6FD5B8B60EFC21E7F3979B07FCD23A811514F23111

SSDEEP:

196608:+HJVlCcGjxFv0O4vYCeQxNlrgzRsb/p2FX:4/wDjxmOKpeQBIRY2d

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • freegate-7.90-installer.exe (PID: 3416)
  • SUSPICIOUS

    • Reads the BIOS version

      • freegate-7.90-installer.exe (PID: 3416)
    • Reads the Internet Settings

      • freegate-7.90-installer.exe (PID: 3416)
      • sdiagnhost.exe (PID: 2788)
    • Reads settings of System Certificates

      • freegate-7.90-installer.exe (PID: 3416)
    • Executable content was dropped or overwritten

      • freegate-7.90-installer.exe (PID: 3416)
  • INFO

    • Manual execution by a user

      • wmpnscfg.exe (PID: 1424)
    • Reads the machine GUID from the registry

      • freegate-7.90-installer.exe (PID: 3416)
    • Reads the computer name

      • freegate-7.90-installer.exe (PID: 3416)
      • wmpnscfg.exe (PID: 1424)
    • Checks supported languages

      • freegate-7.90-installer.exe (PID: 3416)
      • wmpnscfg.exe (PID: 1424)
    • Create files in a temporary directory

      • freegate-7.90-installer.exe (PID: 3416)
      • msdt.exe (PID: 3168)
    • Checks proxy server information

      • freegate-7.90-installer.exe (PID: 3416)
    • Application launched itself

      • iexplore.exe (PID: 4092)
    • Reads the software policy settings

      • freegate-7.90-installer.exe (PID: 3416)
      • msdt.exe (PID: 3168)
    • Reads security settings of Internet Explorer

      • msdt.exe (PID: 3168)
      • sdiagnhost.exe (PID: 2788)
    • Drops the executable file immediately after the start

      • msdt.exe (PID: 3168)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:09:17 03:01:55+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 6264320
InitializedDataSize: 3223040
UninitializedDataSize: -
EntryPoint: 0xdcd058
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 7.9.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: -
CompanyName: Dynamic Internet Technology, Inc.
FileDescription: Freegate
FileVersion: 7, 9, 0, 0
InternalName: Freegate.exe
LegalCopyright: Copyright (C) 2011 - 2020
LegalTrademarks: -
OriginalFileName: -
PrivateBuild: -
ProductName: -
ProductVersion: 0, 0, 0, 0
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start freegate-7.90-installer.exe wmpnscfg.exe no specs iexplore.exe no specs iexplore.exe no specs iexplore.exe no specs msdt.exe no specs sdiagnhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1424"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1560"C:\program files\Internet Explorer\iexplore.exe" SCODEF:4092 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2788C:\Windows\System32\sdiagnhost.exe -EmbeddingC:\Windows\System32\sdiagnhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Scripted Diagnostics Native Host
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sdiagnhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3168 -modal 1376628 -skip TRUE -path C:\Windows\diagnostics\system\networking -af C:\Users\admin\AppData\Local\Temp\NDF9847.tmp -ep NetworkDiagnosticsWebC:\Windows\System32\msdt.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Diagnostics Troubleshooting Wizard
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msdt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3416"C:\Users\admin\AppData\Local\Temp\freegate-7.90-installer.exe" C:\Users\admin\AppData\Local\Temp\freegate-7.90-installer.exe
explorer.exe
User:
admin
Company:
Dynamic Internet Technology, Inc.
Integrity Level:
MEDIUM
Description:
Freegate
Version:
7, 9, 0, 0
Modules
Images
c:\users\admin\appdata\local\temp\freegate-7.90-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3708"C:\program files\Internet Explorer\iexplore.exe" SCODEF:4092 CREDAT:267533 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
4092"C:\program files\Internet Explorer\iexplore.exe" http://dongtaiwang.com/loc/phome.php?v=7.90p&l=409C:\Program Files\Internet Explorer\iexplore.exefreegate-7.90-installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
22 837
Read events
22 653
Write events
148
Delete events
36

Modification events

(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:Kuprnaur
Value:
WuNa53obge2bNF7A5iT35PQsw3BBCKIdGGFZZ5
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\freegate-7_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(3416) freegate-7.90-installer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
Executable files
3
Suspicious files
13
Text files
38
Unknown types
3

Dropped files

PID
Process
Filename
Type
3416freegate-7.90-installer.exeC:\Users\admin\AppData\Local\Temp\fg.initext
MD5:CF132E88497863A84D8111AF14B7B555
SHA256:9A7DD94A11236416A12A037C91E13778828354125CD08D9340FB478E94E01EDF
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\phome[1].htmhtml
MD5:5D7414A2FCA93B2A083B31364DDF36FB
SHA256:1650F7D2CC2AACF57F57A046D34814146763C30901C826AA42EE8E842679415C
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\wrapper_bg_orange[1].jpgimage
MD5:76C77D590CFBB8FC39A3070B25A55A8D
SHA256:50D450A0B9020AE027EBD16CC43357D44EDFCEA5B9E4F7F0A0D5B4185303EC5E
3416freegate-7.90-installer.exeC:\Users\admin\AppData\Local\Temp\eula.txttext
MD5:A036EACB9A1767ABD13351D03CB04999
SHA256:C72F5850CB2DEC62B7A3C4E43CF9ACFA63A8B4370EE43F2936829938E80EBE19
3416freegate-7.90-installer.exeC:\Users\admin\AppData\Local\Temp\dtwpc.dattext
MD5:E54A185042388A05ECB5679738CFD54F
SHA256:1E2C9BD5AA087B31185286F37D5B962B01B8547542A1F3EEE0F10DD5C537FF9E
4092iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\imagestore\f7ruq93\imagestore.datbinary
MD5:B430A9B7717D65BF809A8F3EE48B5BE1
SHA256:8A538681E050C6E684F3D3296EDFE28A1A82F0D5CABBE9199B76F2AC3AEAD68E
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\top_header_orange_en[1].pngimage
MD5:DCADFCA386FB1B18B2BF4E97710B2689
SHA256:A9B19D28782659938B411008C01999344B61407CA63B83BC4A47F5B45ABF02F6
3416freegate-7.90-installer.exeC:\Users\admin\AppData\Local\Temp\Cekbokeqbinary
MD5:22CCFDC68C25174C7A71C5638D0BC38C
SHA256:AC3CD5743258CC127FB32F12A9019F6B635B82DDE5D138E8C55F766BDA3E0CBC
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\global3[1].csstext
MD5:74852E0D7732EF9C64C34A488B074EBF
SHA256:40914B2AF4E8D4CE4FF65924CBA688D7C6043AE3285B705B4BC3B795A4053015
1560iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\global_eng[1].csstext
MD5:9409177B690518077A82180E735C20BD
SHA256:7E7B08BDFC63CAF85843BE4731FAF5112D7FE8E5337C5701DD18ECE5A1805C21
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
100
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3416
freegate-7.90-installer.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f793572f73ae117c
unknown
3416
freegate-7.90-installer.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ef4e5f9451bbaa0c
unknown
3416
freegate-7.90-installer.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?19f07cd4ab637647
unknown
3416
freegate-7.90-installer.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8c0d802b6ec9050d
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3416
freegate-7.90-installer.exe
13.33.158.127:443
d2c9q1vj8yz76f.cloudfront.net
US
unknown
3416
freegate-7.90-installer.exe
13.33.158.220:443
d2c9q1vj8yz76f.cloudfront.net
US
unknown
3416
freegate-7.90-installer.exe
13.33.158.172:443
d2c9q1vj8yz76f.cloudfront.net
US
unknown
3416
freegate-7.90-installer.exe
13.33.158.222:443
d2c9q1vj8yz76f.cloudfront.net
US
unknown
3416
freegate-7.90-installer.exe
13.33.81.75:443
AMAZON-02
US
unknown
3416
freegate-7.90-installer.exe
13.33.82.147:443
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
windowsupdate.microsoft.com
  • 20.72.235.82
unknown
d2c9q1vj8yz76f.cloudfront.net
  • 13.33.158.127
  • 13.33.158.220
  • 13.33.158.172
  • 13.33.158.222
unknown
d3cabiic91qtuo.cloudfront.net
unknown
d2fftkxjmzlswm.cloudfront.net
  • 143.204.102.83
  • 143.204.102.148
  • 143.204.102.32
  • 143.204.102.72
unknown
d15dybyic2v9sh.cloudfront.net
unknown
7revs.csis.org
  • 104.22.12.209
  • 104.22.13.209
  • 172.67.13.187
unknown
media.tommy.com
  • 151.101.194.197
  • 151.101.66.197
  • 151.101.2.197
  • 151.101.130.197
unknown
login.news-leader.com
  • 151.101.2.62
  • 151.101.194.62
  • 151.101.130.62
  • 151.101.66.62
unknown
dtuiqk.74lmth4.wmssh.com
  • 132.203.30.159
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
unknown

Threats

No threats detected
No debug info