File name:

AutoClicker-3.0.exe

Full analysis: https://app.any.run/tasks/cd2da639-4f76-46fd-a0e0-0e15a58c216a
Verdict: Malicious activity
Analysis date: November 27, 2023, 11:56:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7ECFC8CD7455DD9998F7DAD88F2A8A9D

SHA1:

1751D9389ADB1E7187AFA4938A3559E58739DCE6

SHA256:

2E67D5E7D96AEC62A9DDA4C0259167A44908AF863C2B3AF2A019723205ABBA9E

SSDEEP:

12288:GaWzgMg7v3qnCiWErQohh0F49CJ8lnybQg9BFg9UmTRHlM:BaHMv6CGrjBnybQg+mmhG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • CCleaner.exe (PID: 2508)
    • Drops the executable file immediately after the start

      • CCleaner.exe (PID: 2508)
    • Actions looks like stealing of personal data

      • CCleaner.exe (PID: 2508)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • CCleaner.exe (PID: 2508)
    • Reads Internet Explorer settings

      • CCleaner.exe (PID: 2508)
    • Application launched itself

      • CCleaner.exe (PID: 3376)
    • Searches for installed software

      • CCleaner.exe (PID: 2508)
    • Reads security settings of Internet Explorer

      • CCleaner.exe (PID: 2508)
    • Reads settings of System Certificates

      • CCleaner.exe (PID: 2508)
    • Reads the Internet Settings

      • CCleaner.exe (PID: 2508)
      • CCleaner.exe (PID: 3376)
    • Reads Microsoft Outlook installation path

      • CCleaner.exe (PID: 2508)
  • INFO

    • Create files in a temporary directory

      • AutoClicker-3.0.exe (PID: 128)
    • Checks supported languages

      • AutoClicker-3.0.exe (PID: 128)
      • CCleaner.exe (PID: 3376)
      • wmpnscfg.exe (PID: 3108)
      • CCleaner.exe (PID: 2508)
    • Reads product name

      • CCleaner.exe (PID: 2508)
    • Creates files in the program directory

      • CCleaner.exe (PID: 2508)
    • Reads the computer name

      • AutoClicker-3.0.exe (PID: 128)
      • CCleaner.exe (PID: 3376)
      • CCleaner.exe (PID: 2508)
      • wmpnscfg.exe (PID: 3108)
    • Reads mouse settings

      • AutoClicker-3.0.exe (PID: 128)
    • Manual execution by a user

      • CCleaner.exe (PID: 3376)
      • wmpnscfg.exe (PID: 3108)
    • Reads Environment values

      • CCleaner.exe (PID: 3376)
      • CCleaner.exe (PID: 2508)
    • Creates files or folders in the user directory

      • CCleaner.exe (PID: 2508)
    • Checks proxy server information

      • CCleaner.exe (PID: 2508)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3108)
      • CCleaner.exe (PID: 2508)
    • Reads CPU info

      • CCleaner.exe (PID: 2508)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:03:14 21:01:24+01:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 524800
InitializedDataSize: 126976
UninitializedDataSize: -
EntryPoint: 0x16310
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 3.0.0.0
ProductVersionNumber: 3.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: www.opautoclicker.com
FileDescription: OP Auto Clicker
FileVersion: 3
LegalCopyright: www.opautoclicker.com
ProductName: OP Auto Clicker
ProductVersion: 3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start autoclicker-3.0.exe no specs ccleaner.exe no specs ccleaner.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Users\admin\AppData\Local\Temp\AutoClicker-3.0.exe" C:\Users\admin\AppData\Local\Temp\AutoClicker-3.0.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
OP Auto Clicker
Exit code:
0
Version:
3.0
Modules
Images
c:\users\admin\appdata\local\temp\autoclicker-3.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2508"C:\Program Files\CCleaner\CCleaner.exe" C:\Users\Public\Desktop\Firefox.lnk /uacC:\Program Files\CCleaner\CCleaner.exe
CCleaner.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
6.14.0.10584
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
3108"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3376"C:\Program Files\CCleaner\CCleaner.exe" C:\Users\Public\Desktop\Firefox.lnkC:\Program Files\CCleaner\CCleaner.exeexplorer.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
CCleaner
Exit code:
0
Version:
6.14.0.10584
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
Total events
16 043
Read events
15 882
Write events
106
Delete events
55

Modification events

(PID) Process:(3376) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3376) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3376) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3376) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2508) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Piriform\CCleaner
Operation:writeName:DAST
Value:
07/06/2023 15:07:35
(PID) Process:(2508) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Piriform\CCleaner
Operation:writeName:T8062
Value:
1
(PID) Process:(2508) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Piriform\CCleaner
Operation:writeName:UpdateBackground
Value:
0
(PID) Process:(2508) CCleaner.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2508) CCleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
Operation:writeName:SystemRestorePointCreationFrequency
Value:
0
(PID) Process:(2508) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Piriform\CCleaner
Operation:writeName:FTU
Value:
02/11/2020|9|1
Executable files
3
Suspicious files
26
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
2508CCleaner.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NWFZI4N4YJRXNTXPF5SO.tempbinary
MD5:D343725C8EB55131FD3F0D71EE1AB6C7
SHA256:29BF19E1FBEB1AD7575F715392DB49A1D313AB3BA6A671E3C4F1537EDBAC3C43
128AutoClicker-3.0.exeC:\Users\admin\AppData\Local\Temp\ACLib\record.icoimage
MD5:1111E06679F96FF28C1E229B06CE7B41
SHA256:59D5E9106E907FA61A560294A51C14ABCDE024FDD690E41A7F4D6C88DB7287A6
128AutoClicker-3.0.exeC:\Users\admin\AppData\Local\Temp\ACLib\playback.icoimage
MD5:A20254EA7F9EF810C1681FA314EDAA28
SHA256:5375290E66A20BFF81FB4D80346756F2D442184789681297CD1B84446A3FE80D
128AutoClicker-3.0.exeC:\Users\admin\AppData\Local\Temp\kvavygytext
MD5:639672958DA0757DE2FD63C1F5686D74
SHA256:D41B2AA7A6A3CD2C42AE669AF4496A97ED21D2FD0F17B9C1790E248E8374FDF8
2508CCleaner.exeC:\Program Files\CCleaner\gcapi_dll.dllexecutable
MD5:F637D5D3C3A60FDDB5DD397556FE9B1D
SHA256:641B843CB6EE7538EC267212694C9EF0616B9AC9AB14A0ABD7CF020678D50B02
2508CCleaner.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:5509FF8AAE1B81AA1A720D3876AB2725
SHA256:258E281C1294EC51E79FC7574D6A38F27E11B4084A7B4600D0C6D0EDD1F3BAB0
2508CCleaner.exeC:\Program Files\CCleaner\gcapi_17010862202508.dllexecutable
MD5:F637D5D3C3A60FDDB5DD397556FE9B1D
SHA256:641B843CB6EE7538EC267212694C9EF0616B9AC9AB14A0ABD7CF020678D50B02
2508CCleaner.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C14B8B0A2EE22456F473D640ACAEFE25_E8D81A862CD7EA1B65C696850DB341AEbinary
MD5:401929D5E7631F3EB32F01ED53F847FE
SHA256:4A6E9403AF5196CBC2A67A3121EBD5729B19B83724A5ACB646D02A33A986A7FE
2508CCleaner.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2508CCleaner.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E1012488CD9FFF2ACF3EB5078120F962_24BEA0882352FD0902DF40E54E74305Dbinary
MD5:F689F4618F27F342CCCF95E24A774C03
SHA256:4C32A51ECD975932E79F55FE3E27A713381A5D850FABCFB0A62780A605F605BD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
23
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2508
CCleaner.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?04bcff39cdbe8bfc
unknown
compressed
4.66 Kb
unknown
2508
CCleaner.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f98de0129cb76be2
unknown
compressed
4.66 Kb
unknown
2508
CCleaner.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?cff1f7311e05ad8b
unknown
compressed
4.66 Kb
unknown
2508
CCleaner.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/s/gts1d4/91LZUgfONYY/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQDbZTnFanxDPwpP%2Boz3GV%2FE
unknown
binary
472 b
unknown
2508
CCleaner.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/s/gts1d4/VcE3oVK8Y7w/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQCazWGSsgPbSQnI0sPJ6DzW
unknown
binary
472 b
unknown
2508
CCleaner.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQChuVoVf7HVAxLxWCb2kXo7
unknown
binary
472 b
unknown
2508
CCleaner.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/s/gts1d4/HCBR1rPY_zA/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQCuJrycnyDuAAkjSCsH18s3
unknown
binary
472 b
unknown
2508
CCleaner.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
2508
CCleaner.exe
GET
200
104.124.11.43:80
http://ncc.avast.com/ncc.txt
unknown
text
26 b
unknown
2508
CCleaner.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?557a66d7b90844b7
unknown
compressed
4.66 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2508
CCleaner.exe
104.124.11.43:80
ncc.avast.com
Akamai International B.V.
DE
unknown
2508
CCleaner.exe
34.117.223.223:443
analytics.ff.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2508
CCleaner.exe
34.149.149.62:443
ip-info.ff.avast.com
GOOGLE
US
unknown
2508
CCleaner.exe
34.160.176.28:443
shepherd.ff.avast.com
GOOGLE
US
unknown
2508
CCleaner.exe
2.19.225.128:443
www.ccleaner.com
AKAMAI-AS
FR
unknown
2508
CCleaner.exe
34.111.24.1:443
ipm-provider.ff.avast.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
ncc.avast.com
  • 104.124.11.43
  • 104.124.11.16
whitelisted
analytics.ff.avast.com
  • 34.117.223.223
whitelisted
www.ccleaner.com
  • 2.19.225.128
whitelisted
ipm-provider.ff.avast.com
  • 34.111.24.1
whitelisted
ip-info.ff.avast.com
  • 34.149.149.62
whitelisted
shepherd.ff.avast.com
  • 34.160.176.28
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.pki.goog
  • 142.250.186.67
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ipmcdn.avast.com
  • 104.102.46.251
whitelisted

Threats

No threats detected
Process
Message
CCleaner.exe
[2023-11-27 11:57:00.161] [error ] [settings ] [ 2508: 1788] [6000C4: 356] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
Failed to open log file 'C:\Program Files\CCleaner'
CCleaner.exe
OnLanguage - en
CCleaner.exe
[2023-11-27 11:57:00.708] [error ] [settings ] [ 2508: 580] [9434E9: 359] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
[2023-11-27 11:57:00.724] [error ] [Burger ] [ 2508: 580] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
[2023-11-27 11:57:00.724] [error ] [Burger ] [ 2508: 580] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
startCheckingLicense()
CCleaner.exe
OnLanguage - en
CCleaner.exe
OnLanguage - en
CCleaner.exe
OnLanguage - en