CCProxy.EXE

CCProxy

Youngzsoft

The application CCProxy.EXE has been detected as adware by 30 anti-malware scanners. The file has been seen being downloaded from dx3.52z.com.
Publisher:
Youngzsoft

Product:
CCProxy

Version:
7, 3, 0, 0

MD5:
e090863fbd6ec22cf3109d774f4a0228

SHA-1:
4cc279f59a153594615d739ce82bd1ebe10dcddb

SHA-256:
3f31e3e1d275f86875d60e746a29f04c96c8d6ed886ac85f3ff99da82fcec466

Scanner detections:
30 / 68

Status:
Adware

Analysis date:
11/27/2024 8:29:33 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.DR.Injector
7.1.1

AhnLab V3 Security
Dropper/Win32.Injector
2013.09.05

Avira AntiVirus
TR/Rogue.KDZ.7051.157
7.11.100.176

avast!
Win32:Rootkit-gen [Rtk]
2014.9-130823

AVG
Dropper.Generic7
2014.0.3538

Bitdefender
Gen:Heur.Codenox.2
1.0.20.1175

Comodo Security
TrojWare.Win32.TrojanDownloader.Agent.RRR
16878

Dr.Web
Trojan.KillProc.22109
9.0.1.0235

Emsisoft Anti-Malware
Gen:Heur.Codenox
8.13.08.23.06

ESET NOD32
Win32/TrojanDownloader.Agent.RRR (variant)
7.8763

Fortinet FortiGate
W32/Agent.RRR!tr.dldr
8/23/2013

F-Secure
Gen:Heur.Codenox.2
11.2013-26-11_3

G Data
Gen:Heur.Codenox
13.8.22

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.2.0.127

K7 AntiVirus
Trojan
13.172.9484

Kaspersky
Trojan-Dropper.Win32.Injector
14.0.0.3766

Malwarebytes
Trojan.Chad
v2013.08.23.06

McAfee
Dropper-FDT!E090863FBD6E
5600.7176

MicroWorld eScan
Gen:Heur.Codenox.2
14.0.0.990

NANO AntiVirus
Trojan.Win32.KillProc.bktzic
0.26.0.54404

Norman
Troj_Generic.IOLUO
11.20130823

nProtect
Trojan.Generic.KDZ.7051
13.06.20.01

Panda Antivirus
Trj/Genetic.gen
13.08.23.06

Reason Heuristics
PUP.Youngzsoft.K
14.3.1.0

Rising Antivirus
Trojan.Win32.Generic.147BF0B3
23.00.65.13821

Sophos
Mal/Generic-S
4.91

Trend Micro House Call
TROJ_GEN.FC2CKCQ
7.2.235

Trend Micro
TROJ_GEN.FC2CKCQ
10.465.23

Vba32 AntiVirus
TrojanDropper.Injector
3.12.22.3

VIPRE Antivirus
Trojan.Win32.Generic
21168

File size:
6.8 MB (7,135,231 bytes)

Product version:
7, 3, 0, 0

Copyright:
Copyright(C) 2000

Original file name:
CCProxy.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ccproxy.exe

File PE Metadata
Compilation timestamp:
1/24/2013 6:32:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
196608:/K6JBANsYopeYHbDyqIDlYddHzSa41abLpE:SOWF+H7DyqIDaHz/4cbFE

Entry address:
0x1FF16

Entry point:
E8, B6, A5, 00, 00, E9, 16, FE, FF, FF, 6A, 0C, 68, C8, 66, 04, 01, E8, 64, 4F, 00, 00, 33, DB, 89, 5D, E4, 33, C0, 8B, 75, 08, 3B, F3, 0F, 95, C0, 3B, C3, 75, 20, E8, 90, 05, 00, 00, C7, 00, 16, 00, 00, 00, 53, 53, 53, 53, 53, E8, C7, DD, FF, FF, 83, C4, 14, 83, C8, FF, E9, 00, 01, 00, 00, 33, C0, 39, 5D, 0C, 0F, 95, C0, 3B, C3, 74, D4, 89, 75, 08, 56, E8, E4, 02, 00, 00, 59, 89, 5D, FC, F6, 46, 0C, 40, 0F, 85, A6, 00, 00, 00, 56, E8, 02, 6F, 00, 00, 59, 83, F8, FF, 74, 2E, 56, E8, F6, 6E, 00, 00, 59, 83...
 
[+]

Entropy:
7.9616  (probably packed)

Code size:
229 KB (234,496 bytes)

The file CCProxy.EXE has been seen being distributed by the following URL.

Remove CCProxy.EXE - Powered by Reason Core Security