File name:

스마트 오토클릭_smart-autoclick.exe

Full analysis: https://app.any.run/tasks/aa63a973-c037-4690-b11a-7f2a8673ea0e
Verdict: Malicious activity
Analysis date: April 19, 2024, 05:39:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

AABCE2DCDDFE419BF16FAB6B6C86A3FE

SHA1:

57B235C77299E8748DBA5A2602BD50B47194C008

SHA256:

AC832C708EFD7AD4DF6BD81E889A162CBF2EFBE958973D4DAF6DAA4EB090DA75

SSDEEP:

49152:bwWN215LxTCXw+9lunXSa27h4amRCSG5iDoK9WZfH7XeyelBnFOwU3/aSPWRlueG:HNI5LEAK5OgAxgT3/a0p

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
      • WTPSetup.exe (PID: 1556)
      • WebToPdfEx.exe (PID: 2336)
      • new_WebToPdfEx.exe (PID: 3916)
  • SUSPICIOUS

    • Reads the Internet Settings

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
      • WebToPdfEx.exe (PID: 2336)
    • Checks Windows Trust Settings

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
    • Reads settings of System Certificates

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
      • WebToPdfEx.exe (PID: 2336)
    • Reads security settings of Internet Explorer

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
      • WebToPdfEx.exe (PID: 2336)
    • Adds/modifies Windows certificates

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
    • Executable content was dropped or overwritten

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
      • WTPSetup.exe (PID: 1556)
      • WebToPdfEx.exe (PID: 2336)
      • new_WebToPdfEx.exe (PID: 3916)
    • Executing commands from a ".bat" file

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
    • Starts CMD.EXE for commands execution

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
    • Process drops legitimate windows executable

      • WTPSetup.exe (PID: 1556)
    • Creates a software uninstall entry

      • WTPSetup.exe (PID: 1556)
  • INFO

    • Reads the computer name

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
      • WTPSetup.exe (PID: 1556)
      • WebToPdfEx.exe (PID: 2336)
      • new_WebToPdfEx.exe (PID: 3916)
    • Checks supported languages

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
      • WTPSetup.exe (PID: 1556)
      • WebToPdfEx.exe (PID: 2336)
      • new_WebToPdfEx.exe (PID: 3916)
    • Checks proxy server information

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
    • Reads the software policy settings

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
      • WebToPdfEx.exe (PID: 2336)
    • Reads the machine GUID from the registry

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
      • WebToPdfEx.exe (PID: 2336)
      • new_WebToPdfEx.exe (PID: 3916)
    • Creates files or folders in the user directory

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
      • WTPSetup.exe (PID: 1556)
      • WebToPdfEx.exe (PID: 2336)
    • Reads Environment values

      • WebToPdfEx.exe (PID: 2336)
    • Create files in a temporary directory

      • 스마트 오토클릭_smart-autoclick.exe (PID: 3988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:08:18 04:49:35+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 1930240
InitializedDataSize: 455680
UninitializedDataSize: -
EntryPoint: 0x1d8d20
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: (주)드림위즈인터넷
FileDescription: 소프트웨어 자료실 다운로더
FileVersion: 1.0.0.1
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 스마트 오토클릭_smart-autoclick.exe wtpsetup.exe cmd.exe no specs webtopdfex.exe new_webtopdfex.exe 스마트 오토클릭_smart-autoclick.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1556"C:\Users\admin\AppData\Roaming\WTPSetup.exe" /SC:\Users\admin\AppData\Roaming\WTPSetup.exe
스마트 오토클릭_smart-autoclick.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\wtpsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2336"C:\Users\admin\AppData\Roaming\WebToPdf\WebToPdfEx.exe" installC:\Users\admin\AppData\Roaming\WebToPdf\WebToPdfEx.exe
WTPSetup.exe
User:
admin
Company:
pal11
Integrity Level:
HIGH
Description:
WebToPdfEx
Exit code:
0
Version:
2023.07.20.1
Modules
Images
c:\users\admin\appdata\roaming\webtopdf\webtopdfex.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2780C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Roaming\del.bat" "C:\Windows\System32\cmd.exe스마트 오토클릭_smart-autoclick.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3828"C:\Users\admin\AppData\Local\Temp\스마트 오토클릭_smart-autoclick.exe" C:\Users\admin\AppData\Local\Temp\스마트 오토클릭_smart-autoclick.exeexplorer.exe
User:
admin
Company:
(주)드림위즈인터넷
Integrity Level:
MEDIUM
Description:
소프트웨어 자료실 다운로더
Exit code:
3221226540
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\스마트 오토클릭_smart-autoclick.exe
c:\windows\system32\ntdll.dll
3916"C:\Users\admin\AppData\Roaming\WebToPdf\new_WebToPdfEx.exe" WpeRC:\Users\admin\AppData\Roaming\WebToPdf\new_WebToPdfEx.exe
WebToPdfEx.exe
User:
admin
Company:
pal11
Integrity Level:
HIGH
Description:
WebToPdfEx
Version:
2024.03.13.1
Modules
Images
c:\users\admin\appdata\roaming\webtopdf\new_webtopdfex.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3988"C:\Users\admin\AppData\Local\Temp\스마트 오토클릭_smart-autoclick.exe" C:\Users\admin\AppData\Local\Temp\스마트 오토클릭_smart-autoclick.exe
explorer.exe
User:
admin
Company:
(주)드림위즈인터넷
Integrity Level:
HIGH
Description:
소프트웨어 자료실 다운로더
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\스마트 오토클릭_smart-autoclick.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
18 172
Read events
18 078
Write events
81
Delete events
13

Modification events

(PID) Process:(3988) 스마트 오토클릭_smart-autoclick.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3988) 스마트 오토클릭_smart-autoclick.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(3988) 스마트 오토클릭_smart-autoclick.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(3988) 스마트 오토클릭_smart-autoclick.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(3988) 스마트 오토클릭_smart-autoclick.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(3988) 스마트 오토클릭_smart-autoclick.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3988) 스마트 오토클릭_smart-autoclick.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3988) 스마트 오토클릭_smart-autoclick.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3988) 스마트 오토클릭_smart-autoclick.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3988) 스마트 오토클릭_smart-autoclick.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
14
Suspicious files
9
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3988스마트 오토클릭_smart-autoclick.exeC:\Users\admin\AppData\Roaming\del.battext
MD5:0B2EBF51CFD5067CD9F6DC36B10B38DE
SHA256:049AB5DB9B85D9F152C59226D95E921639B27743E6978C4430BA1EF1F2E80DA7
3988스마트 오토클릭_smart-autoclick.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Eder
MD5:B99EAC298DFA3B38B4A15EED0281A110
SHA256:CBD1DF8269DCFFCC61FC0ABC2D14CF4CD231A9246EED4A5C7E9CBBF553D1CC20
3988스마트 오토클릭_smart-autoclick.exeC:\Users\admin\Desktop\쿠팡 바로가기.urlurl
MD5:AB93495598BC3D498C98F9DE53E112BD
SHA256:07B9825F8CABB842AF6ECAE9335005DFECD640D340F284D2DDC8C78916B56C11
3988스마트 오토클릭_smart-autoclick.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\1AF4D4A2760C58799AA3B4BB8DC99F8Bbinary
MD5:F89720FCCA0773287AC0684A2C6F0527
SHA256:AE193F9186D628A8211BD8BA9A994F930AAD9F8DD4533167E5141E4F95594D63
3988스마트 오토클릭_smart-autoclick.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:C2343C94C98D9215DFB74A2F4C4D6D54
SHA256:993C2C67581141F3AEE902A4FED5B84DECE75DDFECB0E41B5113757165611E31
3988스마트 오토클릭_smart-autoclick.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dder
MD5:E98825E3B31CCAB21C702F47047399EE
SHA256:40D12408ADC32DF776D7D5BA3C8A41FE7E9126B2C4A743E317590B5E2E2B5E9E
2336WebToPdfEx.exeC:\Users\admin\AppData\Roaming\WebToPdf\new_WebToPdfEx.exe
MD5:
SHA256:
3988스마트 오토클릭_smart-autoclick.exeC:\Users\admin\AppData\Roaming\dreamwiz.icoimage
MD5:DCC596045E4DFF16954076A239DDF24E
SHA256:5C66507D13860CDE1060CC2021EAAFCDE3CDD2E1834BD7447C4ED9D061D78321
3988스마트 오토클릭_smart-autoclick.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\1AF4D4A2760C58799AA3B4BB8DC99F8Bder
MD5:164D692FA83D39090E5FDF4D22815486
SHA256:4D585422B8CE751949299E75C8D2A16408D092DBE45340524707F24ABE9B2ADD
3988스마트 오토클릭_smart-autoclick.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:480716C3C35C6341D9F44111C2330FC9
SHA256:E6CD31F2CEBBE6C24A5E849E4CD682FC1C2EC38BB1E492F0F04ABF823824BA9E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
20
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3988
스마트 오토클릭_smart-autoclick.exe
GET
200
183.110.214.137:80
http://downsoftware.dreamwiz.com/images/coupang.ico
unknown
unknown
3988
스마트 오토클릭_smart-autoclick.exe
GET
200
183.110.214.137:80
http://downsoftware.dreamwiz.com/images/dreamwiz.ico
unknown
unknown
3988
스마트 오토클릭_smart-autoclick.exe
GET
200
183.110.214.10:80
http://api.baroapp.net/create/coupang?media=downloader
unknown
unknown
3988
스마트 오토클릭_smart-autoclick.exe
GET
302
183.110.214.137:80
http://downsoftware.dreamwiz.com/api/icon/create/software?media=downloader
unknown
unknown
3988
스마트 오토클릭_smart-autoclick.exe
GET
200
183.110.214.10:80
http://api.baroapp.net/create/software?media=downloader
unknown
unknown
3988
스마트 오토클릭_smart-autoclick.exe
GET
304
23.32.238.203:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?91de79d2c5c5997c
unknown
unknown
3988
스마트 오토클릭_smart-autoclick.exe
GET
302
183.110.214.137:80
http://downsoftware.dreamwiz.com/api/icon/create/coupang?media=downloader
unknown
unknown
3988
스마트 오토클릭_smart-autoclick.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
unknown
3988
스마트 오토클릭_smart-autoclick.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
unknown
3988
스마트 오토클릭_smart-autoclick.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQDr81PRuOX5itJdq%2B7TX7B1
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3988
스마트 오토클릭_smart-autoclick.exe
183.110.214.137:80
downsoftware.dreamwiz.com
Korea Telecom
KR
unknown
3988
스마트 오토클릭_smart-autoclick.exe
183.110.214.10:80
api.baroapp.net
Korea Telecom
KR
unknown
3988
스마트 오토클릭_smart-autoclick.exe
183.110.214.137:443
downsoftware.dreamwiz.com
Korea Telecom
KR
unknown
3988
스마트 오토클릭_smart-autoclick.exe
23.32.238.203:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3988
스마트 오토클릭_smart-autoclick.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
3988
스마트 오토클릭_smart-autoclick.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
downsoftware.dreamwiz.com
  • 183.110.214.137
unknown
api.baroapp.net
  • 183.110.214.10
unknown
software.dreamwiz.com
  • 183.110.214.137
unknown
ctldl.windowsupdate.com
  • 23.32.238.203
  • 23.32.238.226
  • 23.32.238.235
  • 23.32.238.185
  • 23.32.238.232
  • 23.32.238.169
  • 23.32.238.192
  • 23.32.238.168
  • 23.32.238.241
  • 2.22.242.122
  • 2.22.242.105
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
www.networkbence.co.kr
  • 112.175.69.181
unknown
dl-cdn.bomul.com
  • 121.160.102.14
unknown
www.noform.co.kr
  • 112.175.69.174
unknown

Threats

No threats detected
No debug info