IOC Report
AutoClicker-3.0.exe

loading gif

Files

File Path
Type
Category
Malicious
AutoClicker-3.0.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Temp\edityrv
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\Desktop\ACLib\playback.ico
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
dropped
C:\Users\user\Desktop\ACLib\record.ico
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
dropped
C:\Users\user\Desktop\ACLib\stop.ico
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
dropped

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\AutoClicker-3.0.exe
"C:\Users\user\Desktop\AutoClicker-3.0.exe"
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
31E0000
heap
page read and write
3FED000
heap
page read and write
4242000
heap
page read and write
3F8B000
heap
page read and write
3EDE000
heap
page read and write
3D64000
heap
page read and write
9DE000
stack
page read and write
4AB000
unkown
page readonly
A15000
heap
page read and write
2EC0000
heap
page read and write
2ED0000
heap
page read and write
4FDE000
stack
page read and write
426C000
heap
page read and write
401000
unkown
page execute read
3F67000
heap
page read and write
940000
heap
page read and write
541E000
stack
page read and write
4431000
heap
page read and write
302D000
heap
page read and write
392E000
stack
page read and write
89E000
stack
page read and write
405C000
heap
page read and write
3F0D000
heap
page read and write
429C000
heap
page read and write
B2E000
heap
page read and write
411D000
heap
page read and write
3F37000
heap
page read and write
B10000
heap
page read and write
4070000
heap
page read and write
41E6000
heap
page read and write
311E000
heap
page read and write
482000
unkown
page readonly
98000
stack
page read and write
42BE000
heap
page read and write
41BC000
heap
page read and write
3E58000
heap
page read and write
A5E000
stack
page read and write
3D30000
heap
page read and write
438F000
heap
page read and write
3E30000
heap
page read and write
490000
unkown
page read and write
B20000
heap
page read and write
3EFA000
heap
page read and write
40E8000
heap
page read and write
955000
heap
page read and write
1E0000
heap
page read and write
440E000
heap
page read and write
4013000
heap
page read and write
3D2F000
stack
page read and write
482000
unkown
page readonly
401F000
heap
page read and write
4066000
heap
page read and write
42FE000
heap
page read and write
400000
unkown
page readonly
B7D000
heap
page read and write
43CD000
heap
page read and write
40FA000
heap
page read and write
4399000
heap
page read and write
490000
unkown
page write copy
3FF7000
heap
page read and write
4375000
heap
page read and write
3015000
heap
page read and write
4AB000
unkown
page readonly
3D9B000
heap
page read and write
31E4000
heap
page read and write
53DF000
stack
page read and write
401000
unkown
page execute read
6AFF000
stack
page read and write
43B3000
heap
page read and write
3E92000
heap
page read and write
3F2D000
heap
page read and write
100000
heap
page read and write
43FD000
heap
page read and write
3DC8000
heap
page read and write
40B8000
heap
page read and write
B00000
heap
page read and write
43F3000
heap
page read and write
42E4000
heap
page read and write
3F81000
heap
page read and write
4A7000
unkown
page read and write
4220000
heap
page read and write
4130000
heap
page read and write
4030000
heap
page read and write
980000
heap
page read and write
3DE1000
heap
page read and write
4165000
heap
page read and write
B7A000
heap
page read and write
4310000
heap
page read and write
400000
unkown
page readonly
3F21000
heap
page read and write
B2A000
heap
page read and write
950000
heap
page read and write
B72000
heap
page read and write
3F9D000
heap
page read and write
426C000
heap
page read and write
47A0000
heap
page read and write
8AE000
stack
page read and write
A10000
heap
page read and write
3010000
heap
page read and write
40AE000
heap
page read and write
There are 90 hidden memdumps, click here to show them.