| File name: | Mango Clicker.zip |
| Full analysis: | https://app.any.run/tasks/8e527864-6cba-4f3d-8dcc-deabd6f45981 |
| Verdict: | Malicious activity |
| Threats: | GCleaner is a type of malware loader that has the capability to deliver numerous malicious software programs, which differ based on the location of the targeted victim. This malware is commonly spread through fraudulent websites that advertise free PC optimization tools |
| Analysis date: | May 20, 2023, 10:22:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract |
| MD5: | FBDE49D059FDEF64949BD3963E475571 |
| SHA1: | 3B7EF38F8472FDB92F9B6BF70FB6E3599F4DDE2C |
| SHA256: | E4458564157889359396DBA6B60D37BDDCA978FBCF661A0D2846EEB7998E2703 |
| SSDEEP: | 24576:47FUDowAyrTVE3U5F/2HcKic6QL3E2vVsjECUAQT45deRV9Ri:4BuZrEUVKIy029s4C1eH9U |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipFileName: | Mango Clicker.exe |
|---|---|
| ZipUncompressedSize: | 1673165 |
| ZipCompressedSize: | 1673165 |
| ZipCRC: | 0xfa1042f9 |
| ZipModifyDate: | 2023:05:20 10:22:26 |
| ZipCompression: | None |
| ZipBitFlag: | - |
| ZipRequiredVersion: | 10 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 276 | "C:\Users\admin\Desktop\Mango Clicker.exe" | C:\Users\admin\Desktop\Mango Clicker.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Mango Clicker.exe Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 332 | "78dyrdmrh7.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX0\78dyrdmrh7.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 3221225477 Modules
| |||||||||||||||
| 548 | "C:\Users\admin\AppData\Local\Temp\is-QIFJT.tmp\Mango Clicker.tmp" /SL5="$100194,833547,832512,C:\Users\admin\Desktop\Mango Clicker.exe" | C:\Users\admin\AppData\Local\Temp\is-QIFJT.tmp\Mango Clicker.tmp | — | Mango Clicker.exe | |||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 656 | cmd.exe /d /c bbbhcqjpdq.bat 75265670 | C:\Windows\System32\cmd.exe | Kz9G.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 656 | "C:\Users\admin\AppData\Local\Temp\byTaS1OuBY86Y4DLaW3ylzN\Cleaner.exe" | C:\Users\admin\AppData\Local\Temp\byTaS1OuBY86Y4DLaW3ylzN\Cleaner.exe | — | cmd.exe | |||||||||||
User: admin Company: lrepacks.com Integrity Level: HIGH Description: Easy GIF Animator Setup Exit code: 2148734720 Version: 7.3.0.61.0 Modules
| |||||||||||||||
| 744 | conhost.exe ljxyvrnagm.dat 75265670 | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\conhost.exe | cmd.exe | ||||||||||||
User: admin Company: Joyent, Inc Integrity Level: HIGH Description: Evented I/O for V8 JavaScript Exit code: 0 Version: 0.10.43 Modules
| |||||||||||||||
| 744 | "C:\Users\admin\AppData\Roaming\cDHBv1sdfso\MB4XK4yIW.exe" | C:\Users\admin\AppData\Roaming\cDHBv1sdfso\MB4XK4yIW.exe | s0.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1228 | "clip64x.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX0\clip64x.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Description: FinalProject Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1364 | "C:\Users\admin\AppData\Local\Temp\is-QCMMQ.tmp\s0.exe" /eueleven SUB=2477 | C:\Users\admin\AppData\Local\Temp\is-QCMMQ.tmp\s0.exe | setup.tmp | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1416 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | 600m51no.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Services Installation Utility Exit code: 0 Version: 4.0.30319.34209 built by: FX452RTMGDR Modules
| |||||||||||||||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000 | |||
| (PID) Process: | (3936) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | LastFolder |
Value: C:\Users\admin\Desktop | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3936 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3936.15872\Mango Clicker.exe | executable | |
MD5:783CB4FA55B4CD542EDB30ED614DD388 | SHA256:F4BD41DBA5625E1AD0A861391CA4D811A35E341C14D6B2E8F43DC37CAADC1764 | |||
| 3536 | Mango Clicker.exe | C:\Users\admin\AppData\Local\Temp\is-J989O.tmp\Mango Clicker.tmp | executable | |
MD5:4E26055A6C0C70DEBA9C47658ED5B4D0 | SHA256:180CD3CA851B9AB60C992E62E91CB71CEB4B331CE9F512D971E512B6E628D47D | |||
| 276 | Mango Clicker.exe | C:\Users\admin\AppData\Local\Temp\is-QIFJT.tmp\Mango Clicker.tmp | executable | |
MD5:4E26055A6C0C70DEBA9C47658ED5B4D0 | SHA256:180CD3CA851B9AB60C992E62E91CB71CEB4B331CE9F512D971E512B6E628D47D | |||
| 3876 | Mango Clicker.tmp | C:\Users\admin\AppData\Local\Temp\is-LAO24.tmp\setup.dll | binary | |
MD5:393722A4F6BB3B9BFEC2FAEADF7C99D7 | SHA256:E4FCFCBB574C3079B99F07BF05E5B65B23E4185DC938E7D49536E7420E3FAD34 | |||
| 3876 | Mango Clicker.tmp | C:\Users\admin\AppData\Local\Temp\is-LAO24.tmp\state.log | text | |
MD5:444BCB3A3FCF8389296C49467F27E1D6 | SHA256:2689367B205C16CE32ED4200942B8B8B1E262DFC70D9BC9FBC77C49699A4F1DF | |||
| 3876 | Mango Clicker.tmp | C:\Users\admin\AppData\Local\Temp\is-LAO24.tmp\setup | text | |
MD5:E3872DAB0ED3EBD9A662120CDFE43AFE | SHA256:7FDEE77AD9220A2C4BF4465FAAE34AFDF1C684D8991926A580A3E7EDA46DABA9 | |||
| 3876 | Mango Clicker.tmp | C:\Users\admin\AppData\Local\Temp\is-LAO24.tmp\is-3311K.tmp | executable | |
MD5:B58ECEB68BEE975E9212E31B342B6165 | SHA256:4F214FBC5CB4A6860CF18D261D784A0C905B6DF0941D5185E1B95DF329EF2B89 | |||
| 4020 | Kz9G.exe | C:\Users\admin\AppData\Local\Temp\IXP000.TMP\elmxnpg.dat.3 | — | |
MD5:— | SHA256:— | |||
| 3876 | Mango Clicker.tmp | C:\Users\admin\AppData\Local\Temp\is-LAO24.tmp\setup.exe | executable | |
MD5:B58ECEB68BEE975E9212E31B342B6165 | SHA256:4F214FBC5CB4A6860CF18D261D784A0C905B6DF0941D5185E1B95DF329EF2B89 | |||
| 3876 | Mango Clicker.tmp | C:\Users\admin\AppData\Local\Temp\is-LAO24.tmp\is-8B3R0.tmp | text | |
MD5:E3872DAB0ED3EBD9A662120CDFE43AFE | SHA256:7FDEE77AD9220A2C4BF4465FAAE34AFDF1C684D8991926A580A3E7EDA46DABA9 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1680 | setup.tmp | HEAD | 200 | 45.12.253.74:80 | http://45.12.253.74/pineapple.php?pub=eueleven | BG | — | — | malicious |
1364 | s0.exe | GET | 200 | 45.12.253.75:80 | http://45.12.253.75/dll.php | BG | — | — | malicious |
1364 | s0.exe | GET | 200 | 45.12.253.72:80 | http://45.12.253.72/default/stuk.php | BG | text | 21 b | malicious |
3876 | Mango Clicker.tmp | GET | 200 | 188.114.97.3:80 | http://pricemarket.online/req.php?p=3811&t=46373734&title=TWFuZ28gQ2xpY2tlci5leGU=&sub=2477 | US | text | 106 b | malicious |
3876 | Mango Clicker.tmp | GET | 200 | 188.114.97.3:80 | http://pricemarket.online/reqs.php | US | text | 2 b | malicious |
2920 | auPz2Z7UG6.exe | GET | 200 | 192.124.249.23:80 | http://ocsp.godaddy.com//MEQwQjBAMD4wPDAJBgUrDgMCGgUABBTkIInKBAzXkF0Qh0pel3lfHJ9GPAQU0sSw0pHUTBFxs2HLPaH%2B3ahq1OMCAxvnFQ%3D%3D | US | binary | 1.66 Kb | whitelisted |
1680 | setup.tmp | GET | 200 | 45.12.253.74:80 | http://45.12.253.74/pineapple.php?pub=eueleven | BG | executable | 397 Kb | malicious |
1364 | s0.exe | GET | 200 | 45.12.253.72:80 | http://45.12.253.72/default/puk.php | BG | binary | 93.0 Kb | malicious |
3876 | Mango Clicker.tmp | GET | 200 | 188.114.96.3:80 | http://bridgecurrent.site/pe/buildIN.php?sub=2477&source=3811&s1=46373734&title=TWFuZ28gQ2xpY2tlci5leGU%3D | US | executable | 1.68 Mb | malicious |
1364 | s0.exe | GET | 200 | 45.12.253.75:80 | http://45.12.253.75/dll.php | BG | executable | 2.36 Mb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1416 | RegSvcs.exe | 135.181.7.171:81 | — | Hetzner Online GmbH | FI | malicious |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1076 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3412 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3876 | Mango Clicker.tmp | 188.114.97.3:80 | pricemarket.online | CLOUDFLARENET | NL | malicious |
3876 | Mango Clicker.tmp | 188.114.96.3:80 | pricemarket.online | CLOUDFLARENET | NL | malicious |
1680 | setup.tmp | 45.12.253.74:80 | — | VNET a.s. | BG | malicious |
1364 | s0.exe | 45.12.253.56:80 | — | VNET a.s. | BG | malicious |
1364 | s0.exe | 45.12.253.72:80 | — | VNET a.s. | BG | malicious |
Domain | IP | Reputation |
|---|---|---|
pricemarket.online |
| malicious |
bridgecurrent.site |
| malicious |
be81e3a6329916845781948380003611db11e14b53635001cce9e0221232f.reu.apho35.shop |
| unknown |
t.me |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.godaddy.com |
| whitelisted |
6ba117e349641684578199808.bag.sack54.net |
| unknown |
6ba117e349641684578199808.bag.sack55.net |
| unknown |
lodar2ben.top |
| malicious |
api.ip.sb |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3876 | Mango Clicker.tmp | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3876 | Mango Clicker.tmp | Misc activity | ET INFO EXE - Served Attached HTTP |
1680 | setup.tmp | Misc activity | ET INFO Packed Executable Download |
1680 | setup.tmp | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
1680 | setup.tmp | Potentially Bad Traffic | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response |
1680 | setup.tmp | Misc activity | ET INFO EXE - Served Attached HTTP |
1680 | setup.tmp | Generic Protocol Command Decode | SURICATA STREAM ESTABLISHED invalid ack |
1680 | setup.tmp | Generic Protocol Command Decode | SURICATA STREAM Packet with invalid ack |
1680 | setup.tmp | Generic Protocol Command Decode | SURICATA STREAM ESTABLISHED packet out of window |
1680 | setup.tmp | Generic Protocol Command Decode | SURICATA STREAM ESTABLISHED packet out of window |
Process | Message |
|---|---|
WebCompanionInstaller.exe | Detecting windows culture
|
WebCompanionInstaller.exe | 5/20/2023 11:23:36 AM :-> Starting installer 8.9.0.371 with: .\WebCompanionInstaller.exe --partner=IT210801 --version=8.9.0.371 --silent --partner=IT210801, Run as admin: True
|
WebCompanionInstaller.exe | Preparing for installing Web Companion
|
WebCompanionInstaller.exe | 5/20/2023 11:23:37 AM :-> Generating Machine and Install Id ...
|
WebCompanionInstaller.exe | 5/20/2023 11:23:37 AM :-> Machine Id and Install Id has been generated
|
WebCompanionInstaller.exe | 5/20/2023 11:23:37 AM :-> Checking prerequisites ...
|
WebCompanionInstaller.exe | 5/20/2023 11:23:37 AM :-> Antivirus not detected
|
WebCompanionInstaller.exe | 5/20/2023 11:23:38 AM :-> vm_check False
|
WebCompanionInstaller.exe | 5/20/2023 11:23:38 AM :-> reg_check :False
|
WebCompanionInstaller.exe | 5/20/2023 11:23:38 AM :-> Installed .Net framework is V40
|