| File name: | clink.1.6.10.d5dce0_setup.exe |
| Full analysis: | https://app.any.run/tasks/dc392306-494a-4c89-8d93-bdbcd358a9d5 |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2024, 12:03:08 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | F4199DC93F60A142C7D6A59DBE9A2C6C |
| SHA1: | 20E9128BB77C8F8F23845BC49A9A31D48FE6348F |
| SHA256: | 5347A59A53C4C1310E6C71D72A7A3CBBF1004F2AE9B82DE90A29EDA0AC36AD58 |
| SSDEEP: | 98304:4eFx34V4f5PQjcovUWCXXYhSDjHHDyP1Cr7t+0jFPcwhGFayIsAdo9V/UMXWT+Ng:RFNana |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:08:01 02:44:18+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26112 |
| InitializedDataSize: | 141824 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x35d8 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1836 | "C:\Users\admin\AppData\Local\Temp\clink.1.6.10.d5dce0_setup.exe" | C:\Users\admin\AppData\Local\Temp\clink.1.6.10.d5dce0_setup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1928 | "C:\Program Files\clink\clink_x86.exe" autorun --allusers uninstall | C:\Program Files\clink\clink_x86.exe | — | clink.1.6.10.d5dce0_setup.exe | |||||||||||
User: admin Company: Martin Ridgers, Christopher Antos Integrity Level: HIGH Description: Clink Exit code: 0 Version: 1.6.10.d5dce0 Modules
| |||||||||||||||
| 2756 | "C:\Users\admin\AppData\Local\Temp\clink.1.6.10.d5dce0_setup.exe" | C:\Users\admin\AppData\Local\Temp\clink.1.6.10.d5dce0_setup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3684 | "C:\Program Files\clink\clink_x86.exe" autorun install -- --profile "~\clink" | C:\Program Files\clink\clink_x86.exe | — | clink.1.6.10.d5dce0_setup.exe | |||||||||||
User: admin Company: Martin Ridgers, Christopher Antos Integrity Level: HIGH Description: Clink Exit code: 0 Version: 1.6.10.d5dce0 Modules
| |||||||||||||||
| (PID) Process: | (2756) clink.1.6.10.d5dce0_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\clink_chrisant996 |
| Operation: | write | Name: | DisplayName |
Value: Clink v1.6.10 | |||
| (PID) Process: | (2756) clink.1.6.10.d5dce0_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\clink_chrisant996 |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files\clink\clink_uninstall_1.6.10.d5dce0.exe | |||
| (PID) Process: | (2756) clink.1.6.10.d5dce0_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\clink_chrisant996 |
| Operation: | write | Name: | Publisher |
Value: Christopher Antos | |||
| (PID) Process: | (2756) clink.1.6.10.d5dce0_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\clink_chrisant996 |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Windows\system32\cmd.exe,0 | |||
| (PID) Process: | (2756) clink.1.6.10.d5dce0_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\clink_chrisant996 |
| Operation: | write | Name: | URLInfoAbout |
Value: http://chrisant996.github.io/clink | |||
| (PID) Process: | (2756) clink.1.6.10.d5dce0_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\clink_chrisant996 |
| Operation: | write | Name: | HelpLink |
Value: http://chrisant996.github.io/clink | |||
| (PID) Process: | (2756) clink.1.6.10.d5dce0_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\clink_chrisant996 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\clink | |||
| (PID) Process: | (2756) clink.1.6.10.d5dce0_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\clink_chrisant996 |
| Operation: | write | Name: | DisplayVersion |
Value: 1.6.10 | |||
| (PID) Process: | (2756) clink.1.6.10.d5dce0_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\clink_chrisant996 |
| Operation: | write | Name: | EstimatedSize |
Value: 7121 | |||
| (PID) Process: | (2756) clink.1.6.10.d5dce0_setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment |
| Operation: | write | Name: | CLINK_DIR |
Value: C:\Program Files\clink | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2756 | clink.1.6.10.d5dce0_setup.exe | C:\Program Files\clink\clink_dll_x86.dll | executable | |
MD5:7A50ADF03A0598C96C345B10DD455881 | SHA256:33ED1E5891FDC071AEE25DE3ADE67E6763E88697792A0AAA82E62790AEE86737 | |||
| 2756 | clink.1.6.10.d5dce0_setup.exe | C:\Program Files\clink\clink_dll_x64.dll | executable | |
MD5:7D4D8782004341C49564A6E7A9FC4DCC | SHA256:A89A76296F5E08BAC0AB114C5412AF8AECA4DAA076B5E6DA9DD3D394D6534E18 | |||
| 2756 | clink.1.6.10.d5dce0_setup.exe | C:\Program Files\clink\default_settings | text | |
MD5:99F761B42B3518CBE0066E83F3394946 | SHA256:6A7352FB89884A78BDB78F5327436C2DABD9438D39CC9E61C9ADB6340A497A45 | |||
| 2756 | clink.1.6.10.d5dce0_setup.exe | C:\Program Files\clink\default_inputrc | text | |
MD5:69F6152A31C1FCC2725B0F674EEDDFF6 | SHA256:3A6A067A73B90F82FA0CC268292DB1FC8DCB42F7375E0B01C91D24B9F6B75B77 | |||
| 2756 | clink.1.6.10.d5dce0_setup.exe | C:\Program Files\clink\clink_uninstall_1.6.10.d5dce0.exe | executable | |
MD5:269E133128425608913729FD061707A0 | SHA256:F6DD0C7D6A1F5897A41FE6D2DE2BBBBCFA8607068AE49C9B2AA72492EE791139 | |||
| 2756 | clink.1.6.10.d5dce0_setup.exe | C:\Users\admin\AppData\Local\Temp\nsz3ECA.tmp | — | |
MD5:— | SHA256:— | |||
| 2756 | clink.1.6.10.d5dce0_setup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clink\Clink Documentation.lnk | binary | |
MD5:76FEA9523411E16CC4D5A6695DB7DAE4 | SHA256:84C0D06C9CB17F1F2123989199B3B7AE020009B956A51C2DF697D6FFFBB82711 | |||
| 2756 | clink.1.6.10.d5dce0_setup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clink\Clink.lnk | binary | |
MD5:6E4349C6530413370D0D0AB8FEC394D1 | SHA256:5AAE6C90FCD34621586CE8CCDABDD36BB3361B8396C44D28F15498B54DEA25E1 | |||
| 2756 | clink.1.6.10.d5dce0_setup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Clink\Uninstall Clink.lnk | binary | |
MD5:ABA49AC312D592AFBFF8528DB73D30E4 | SHA256:88CA56EEB6213521AC73CE9254B9FE9A145AAF3C7A451736E9FDC91BB0D1F103 | |||
| 2756 | clink.1.6.10.d5dce0_setup.exe | C:\Program Files\clink\clink_red.ico | image | |
MD5:E53B97EEE5A8E9D5589B778ED2E42676 | SHA256:5A709C7B800E42577DBF0004C21E3D5C1A895C86B0FD9D81688D80A11BB5F1E8 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |