| File name: | clickchartsetup.exe |
| Full analysis: | https://app.any.run/tasks/9a28503e-d193-411e-8e4b-d9a8161d64df |
| Verdict: | Malicious activity |
| Analysis date: | April 19, 2024, 09:38:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 4E15216D0C9521E39867B8D7A8D916E5 |
| SHA1: | 969F18950C229EC01FAF9239CD201AF6A9D5351A |
| SHA256: | 1F0AF11F39D9B7D6873066B390572AAEB84768D58BE786BEE646DAD05ADB1E08 |
| SSDEEP: | 98304:peI9GiG2BJmYDMou65CSApfv7PPSInBIlEJ3Ur8S7xp8dIR3+BDIsC+CpjFjbMIi:/6H |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:09:21 05:45:58+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 2560 |
| InitializedDataSize: | 1733632 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1286 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (Australian) |
| CharacterSet: | Unicode |
| CompanyName: | NCH Software |
| FileDescription: | ClickCharts Diagram Flowchart Software |
| FileVersion: | 9.22+ |
| ProductVersion: | 9.22+ |
| ProductName: | ClickCharts |
| LegalCopyright: | NCH Software |
| InternalName: | ClickCharts |
| OriginalFileName: | ClickCharts.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1172 | "C:\Program Files\NCH Software\ClickCharts\clickcharts.exe" | C:\Program Files\NCH Software\ClickCharts\clickcharts.exe | nchsetup.exe | ||||||||||||
User: admin Company: NCH Software Integrity Level: MEDIUM Description: ClickCharts Diagram Flowchart Software Version: 9.22+ Modules
| |||||||||||||||
| 2548 | "C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe" -installer "C:\Users\admin\AppData\Local\Temp\clickchartsetup.exe" -instdata "C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat" | C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe | clickchartsetup.exe | ||||||||||||
User: admin Company: NCH Software Integrity Level: HIGH Description: ClickCharts Diagram Flowchart Software Exit code: 0 Version: 9.22+ Modules
| |||||||||||||||
| 3264 | "C:\Program Files\NCH Software\ClickCharts\zlib1v3.exe" -LQUIET -instby fiClickCharts -instsvar CLICKCHARTSRelatedprogramspaidoffLLIBInstquickoff | C:\Program Files\NCH Software\ClickCharts\zlib1v3.exe | nchsetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3468 | "C:\Program Files\NCH Software\ClickCharts\clickcharts.exe" -installsched | C:\Program Files\NCH Software\ClickCharts\clickcharts.exe | — | nchsetup.exe | |||||||||||
User: admin Company: NCH Software Integrity Level: MEDIUM Description: ClickCharts Diagram Flowchart Software Exit code: 0 Version: 9.22+ Modules
| |||||||||||||||
| 3636 | "C:\Users\admin\AppData\Local\Temp\ClickCharts-3456-1\ppadsetup.exe" -LQUIET -instby suClickCharts -instsvar CLICKCHARTSRelatedprogramspaidoffLLIBInstquickoffLLIBControloffVUweCLICKCHARTSSearchbarv2onEg0hCLICKCHARTSMoverecentfilesonCLICKCHARTSHometabnewbtnonDvekCLICKCHARTSSelectalldrpdwnoffX7zoBtooHVQlXZLeCLICKCHARTSNewblankgraphoffCLICKCHARTSGraphtaboptonCLICKCHARTSHelptabreportonCLICKCHARTSSwapviewgraphtabsoffCLICKCHARTSSymbolstaboffCLICKCHARTSHelptabv2offCLICKCHARTSTtbhamoffCLICKCHARTSSofttbsonH1snCLICKCHARTSSearchlightv2offCLICKCHARTSSucav2offCLICKCHARTSPreviewplaytutorialoffGgdhOEVlE7bfVd4bQILaYZiiKzeeWVPaJX2rCLICKCHARTSCatalogselectorupdateoffGvodCLICKCHARTSDefaultshapelinesettingsonJ1tuCLICKCHARTSAutoconnectwhenselectedoffCLICKCHARTSShowlocksymbolicononSTkhZYUmPOlnRLBv | C:\Users\admin\AppData\Local\Temp\ClickCharts-3456-1\ppadsetup.exe | — | clickcharts.exe | |||||||||||
User: admin Company: NCH Software Integrity Level: MEDIUM Description: PhotoPad Image Editor Exit code: 3221226540 Version: 13.18+ Modules
| |||||||||||||||
| 3768 | "C:\Users\admin\AppData\Local\Temp\clickchartsetup.exe" | C:\Users\admin\AppData\Local\Temp\clickchartsetup.exe | — | explorer.exe | |||||||||||
User: admin Company: NCH Software Integrity Level: MEDIUM Description: ClickCharts Diagram Flowchart Software Exit code: 3221226540 Version: 9.22+ Modules
| |||||||||||||||
| 3876 | "C:\Users\admin\AppData\Local\Temp\clickchartsetup.exe" | C:\Users\admin\AppData\Local\Temp\clickchartsetup.exe | explorer.exe | ||||||||||||
User: admin Company: NCH Software Integrity Level: HIGH Description: ClickCharts Diagram Flowchart Software Exit code: 0 Version: 9.22+ Modules
| |||||||||||||||
| (PID) Process: | (3876) clickchartsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3876) clickchartsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3876) clickchartsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3876) clickchartsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2548) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | ClickChartsInstall |
Value: C:\Users\admin\AppData\Local\Temp\clickchartsetup.exe | |||
| (PID) Process: | (2548) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\NCH Software\ClickCharts\Software |
| Operation: | write | Name: | SVar |
Value: CLICKCHARTSRelatedprogramspaidoff | |||
| (PID) Process: | (2548) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\NCH Software\ClickCharts\Settings |
| Operation: | write | Name: | InstalledByAdmin |
Value: 1 | |||
| (PID) Process: | (2548) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\NCH Software\ClickCharts\UsageStatsChoice |
| Operation: | write | Name: | llinad |
Value: 1 | |||
| (PID) Process: | (2548) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\NCH Software\ClickCharts\Software |
| Operation: | write | Name: | SVar |
Value: CLICKCHARTSRelatedprogramspaidoffLLIBInstquickoff | |||
| (PID) Process: | (2548) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3876 | clickchartsetup.exe | C:\Users\admin\AppData\Local\Temp\n1s\nchdata.cab | compressed | |
MD5:0B2D268F71A627C7C003C9BF4B022455 | SHA256:E0522E766FF5E228CE230F2498E16CA1D2BA436E7FFACC98D02658CA77372FC3 | |||
| 3876 | clickchartsetup.exe | C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe | executable | |
MD5:A67AAFBAA1E60D4AA985D9D26E089899 | SHA256:CE48581F05B4D6951FC2F4BF740211C45F4E906B262697249CD5CD5BDE2F7528 | |||
| 3876 | clickchartsetup.exe | C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.cab | compressed | |
MD5:4D157009EFB09638F677DD51907AAD3C | SHA256:F20DF4905051CABE3A5E07E6370320A96454753A59F35ABA140604A489A06854 | |||
| 2548 | nchsetup.exe | C:\Program Files\NCH Software\ClickCharts\clickcharts.exe | executable | |
MD5:A67AAFBAA1E60D4AA985D9D26E089899 | SHA256:CE48581F05B4D6951FC2F4BF740211C45F4E906B262697249CD5CD5BDE2F7528 | |||
| 2548 | nchsetup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Express Burn CD, DVD or Blu-Ray.lnk | lnk | |
MD5:37B67ACEA2DD3C7EF2A8D361EC4322E6 | SHA256:82C3A54640233F78BA8A547232F396C1CB68F02F30BBF964B5E216979B8EFADA | |||
| 2548 | nchsetup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Audio File Converter.lnk | lnk | |
MD5:27C3956FF62270939D3043F7ECC09094 | SHA256:E808C8501AEA77738F9A3D8D019F6CB9AE8D06CB26083107B97DCAF34DF7E110 | |||
| 2548 | nchsetup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Video Editing Software.lnk | lnk | |
MD5:BB7C734A29B5469443F8880C463FFF90 | SHA256:38ACB5D4B56CDF2C1E97FDB4F74A4458013978B044D248120F69B9BD882FDB45 | |||
| 2548 | nchsetup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Audio Editing Software.lnk | lnk | |
MD5:A78C907B166B33B1092D4C797B55B101 | SHA256:E53EECB36F0D38D50104F68795E859BC6E78B1EE39203E8032DF49EF1C509651 | |||
| 2548 | nchsetup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Video Capture Software.lnk | lnk | |
MD5:B164F790F73A373FE678ABCCA20103A0 | SHA256:83B7EF71C0AF1DF59C258FB196146260DB31039DA3A5A48774AAAFCDA5633E7C | |||
| 2548 | nchsetup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Transcription Software.lnk | lnk | |
MD5:CF6CDC2E312CA858E028CC925A64E796 | SHA256:2A8D40077B4C49A49288E2BF827D275060300BD569F089A9B5F762BE9CAD14D1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1172 | clickcharts.exe | GET | — | 173.247.250.125:80 | http://audiochannel.net/components/ppadsetup.exe | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2548 | nchsetup.exe | 173.247.253.164:443 | secure.nch.com.au | INMOTION | US | unknown |
1172 | clickcharts.exe | 173.247.250.125:80 | audiochannel.net | INMOTION | US | unknown |
Domain | IP | Reputation |
|---|---|---|
secure.nch.com.au |
| unknown |
audiochannel.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potential Corporate Privacy Violation | AV POLICY HTTP request for .exe file with no User-Agent |
— | — | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
— | — | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |