File name:

SpeedAutoClicker-v1.6.2.zip

Full analysis: https://app.any.run/tasks/ba8b31ba-880b-43e5-af58-ee9942df5c32
Verdict: Malicious activity
Analysis date: May 22, 2021, 10:34:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

9192D35DE69F1DBD9DE0A36004C35CAF

SHA1:

0876EE1F6408005A754FFD34F52AB9185450B36D

SHA256:

B6014A35C04E9C13C6E97178F18B1597B0A7D8E1BBD3DB4CD843BB7D8B6993BB

SSDEEP:

49152:WgEDMGJzYrVU9EVwpTiwCeWYmO4faDsob3pAjMvgWJx9+:WgGJsUYoCX/O4esorp2MxM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • SpeedAutoClicker.exe (PID: 3620)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1952)
    • Reads internet explorer settings

      • SpeedAutoClicker.exe (PID: 3620)
    • Creates files in the program directory

      • SpeedAutoClicker.exe (PID: 3620)
  • INFO

    • Manual execution by user

      • explorer.exe (PID: 3528)
      • SpeedAutoClicker.exe (PID: 3620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: SpeedAutoClicker.exe
ZipUncompressedSize: 2232320
ZipCompressedSize: 2048652
ZipCRC: 0x53c6fb32
ZipModifyDate: 2019:07:05 09:17:25
ZipCompression: Deflated
ZipBitFlag: 0x0002
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe explorer.exe no specs speedautoclicker.exe

Process information

PID
CMD
Path
Indicators
Parent process
1952"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SpeedAutoClicker-v1.6.2.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
3528"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3620"C:\Users\admin\Desktop\SpeedAutoClicker.exe" C:\Users\admin\Desktop\SpeedAutoClicker.exe
explorer.exe
User:
admin
Company:
fabi.me
Integrity Level:
MEDIUM
Description:
Speed AutoClicker
Exit code:
0
Version:
1.6.2.0
Modules
Images
c:\users\admin\desktop\speedautoclicker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
547
Read events
499
Write events
48
Delete events
0

Modification events

(PID) Process:(1952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1952) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1952) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(1952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SpeedAutoClicker-v1.6.2.zip
(PID) Process:(1952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1952) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
1
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1952WinRAR.exeC:\Users\admin\Desktop\SpeedAutoClicker.exeexecutable
MD5:B3A2E60B9CF66A908FBC22FEC9A5F398
SHA256:6BC32E935A514DA31E6ED5559252C36D82FD64B1E6403748B0BA86598EF20071
3620SpeedAutoClicker.exeC:\Users\admin\AppData\Local\fabi.me\ac.configxml
MD5:D4A9C55E2EB5FA765D1BE883B19F5DF0
SHA256:69CCC597449CE2E3A24A0619E7F1E3C4D765B2AB84AC20B9FA54141446972E90
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3620
SpeedAutoClicker.exe
85.13.164.70:443
fabi.me
Neue Medien Muennich GmbH
DE
suspicious

DNS requests

Domain
IP
Reputation
fabi.me
  • 85.13.164.70
suspicious

Threats

No threats detected
No debug info