oldfreda.exe

yssoft

The application oldfreda.exe, “LuckyTool Application” by yssoft has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The file has been seen being downloaded from down.luckytool.net. While running, it connects to the Internet address 16.234.212.118.adsl-pool.jx.chinaunicom.com on port 443.
Publisher:
luckytool  (signed by yssoft)

Product:
luckytool

Description:
LuckyTool Application

Version:
1.0.0.1

MD5:
99c4ed48a89c2875275cdcec6c232fb8

SHA-1:
9a0b575d6897076e7c6921c2e6de7b0cacabcee7

SHA-256:
7f5cee09ddd66debb8d735a9df50fa5d97728323b5eda7ead9a9f516126d9930

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
2/26/2025 6:49:39 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.yssoft (M)
16.4.21.6

File size:
3.6 MB (3,757,240 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2014 luckytool

Original file name:
luckytool

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\oldfred\oldfreda.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/24/2016 9:00:00 AM

Valid to:
5/24/2018 8:59:59 AM

Subject:
CN=yssoft, O=yssoft, L=Chilgok-gun, S=Gyeongsangbuk-do, C=KR

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
4FFD8833DCF52D25418DA64CD58D741A

File PE Metadata
Compilation timestamp:
4/21/2015 4:38:36 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
98304:iu545ZyhKmtQf5lD+N0H8A528B5d7OFLOAkGkzdnEVomFHKnPH:FeU1KS828B5d7OFLOyomFHKnPH

Entry address:
0x1442C8

Entry point:
E8, 0B, CD, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 60, AE, 5B, 00, E8, C2, 19, 00, 00, E8, 93, 66, 00, 00, 0F, B7, F0, 6A, 02, E8, 9E, CC, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, BC, 9D, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.7342

Code size:
1.4 MB (1,494,016 bytes)

The file oldfreda.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to hn.kd.ny.adsl  (42.236.126.144:443)

TCP (HTTP):
Connects to mbox06.hanafos.com  (211.110.197.26:80)

TCP (HTTP):
Connects to ec2-52-87-81-29.compute-1.amazonaws.com  (52.87.81.29:80)

TCP (HTTP):

TCP (HTTP SSL):
Connects to 190.203.215.139.adsl-pool.jlccptt.net.cn  (139.215.203.190:443)

TCP (HTTP SSL):
Connects to 16.234.212.118.adsl-pool.jx.chinaunicom.com  (118.212.234.16:443)

TCP (HTTP SSL):
Connects to 13.234.212.118.adsl-pool.jx.chinaunicom.com  (118.212.234.13:443)

TCP (HTTP SSL):
Connects to 103.234.212.118.adsl-pool.jx.chinaunicom.com  (118.212.234.103:443)

TCP (HTTP):

TCP (HTTP SSL):
Connects to 15.234.212.118.adsl-pool.jx.chinaunicom.com  (118.212.234.15:443)

TCP (HTTP SSL):
Connects to 14.234.212.118.adsl-pool.jx.chinaunicom.com  (118.212.234.14:443)

Remove oldfreda.exe - Powered by Reason Core Security