Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
AutoClick Smart cortesia de bb-fans.jimdo.com.exe

Overview

General Information

Sample name:AutoClick Smart cortesia de bb-fans.jimdo.com.exe
Analysis ID:1502469
MD5:e064db65f591ebb637aa2ca532b7ec35
SHA1:33fc69dce99767997a4ee0cc3398cdf82bbc6417
SHA256:ff4234e650d0ba4b296f099c3bb00995f64d43570da258906208e1e1681a45ad
Tags:exe
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Uses Windows timers to delay execution
Allocates memory with a write watch (potentially for evading sandboxes)
Detected potential crypto function
Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files

Classification

  • System is w10x64
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeReversingLabs: Detection: 18%
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeVirustotal: Detection: 34%Perma Link
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeFile opened: C:\Windows\WinSxS\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\MSVCR80.dllJump to behavior
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: C:\Users\AntHoniO\AppData\Local\Temporary Projects\22\obj\Debug\22.pdb source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeString found in binary or memory: http://www.bb-fans.jimdo.com
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.coml
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-user.html
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fonts.com
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.goodfont.co.kr
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.com
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sakkal.com
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sandoll.co.kr
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.com
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.typography.netD
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.deDPlease
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cn
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeCode function: 0_2_00007FFD9B8F170D0_2_00007FFD9B8F170D
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000000.1649312176.0000000000C30000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilename22.exe( vs AutoClick Smart cortesia de bb-fans.jimdo.com.exe
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeBinary or memory string: OriginalFilename22.exe( vs AutoClick Smart cortesia de bb-fans.jimdo.com.exe
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engineClassification label: mal52.evad.winEXE@1/0@0/0
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeMutant created: NULL
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.79%
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeReversingLabs: Detection: 18%
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeVirustotal: Detection: 34%
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SettingsJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dllJump to behavior
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeFile opened: C:\Windows\WinSxS\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\MSVCR80.dllJump to behavior
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: AutoClick Smart cortesia de bb-fans.jimdo.com.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\Users\AntHoniO\AppData\Local\Temporary Projects\22\obj\Debug\22.pdb source: AutoClick Smart cortesia de bb-fans.jimdo.com.exe
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 100msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 1msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 100msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 1msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 100msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 1msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 100msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 1msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 100msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 1msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 100msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 1msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 100msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 1msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 100msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 1msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 100msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 1msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 100msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeUser Timer Set: Timeout: 1msJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeMemory allocated: 1260000 memory reserve | memory write watchJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeMemory allocated: 3340000 memory reserve | memory write watchJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeMemory allocated: 1B340000 memory commit | memory reserve | memory write watchJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeMemory allocated: page read and write | page guardJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exeQueries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
DLL Side-Loading
11
Virtualization/Sandbox Evasion
OS Credential Dumping11
Virtualization/Sandbox Evasion
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Disable or Modify Tools
LSASS Memory12
System Information Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
AutoClick Smart cortesia de bb-fans.jimdo.com.exe18%ReversingLabsWin32.Infostealer.Tinba
AutoClick Smart cortesia de bb-fans.jimdo.com.exe34%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.fontbureau.com0%URL Reputationsafe
http://www.fontbureau.com0%URL Reputationsafe
http://www.fontbureau.com/designersG0%URL Reputationsafe
http://www.fontbureau.com/designers/?0%URL Reputationsafe
http://www.founder.com.cn/cn/bThe0%URL Reputationsafe
http://www.founder.com.cn/cn/bThe0%URL Reputationsafe
http://www.fontbureau.com/designers?0%URL Reputationsafe
http://www.fontbureau.com/designers?0%URL Reputationsafe
http://www.tiro.com0%URL Reputationsafe
http://www.fontbureau.com/designers0%URL Reputationsafe
http://www.goodfont.co.kr0%URL Reputationsafe
http://www.carterandcone.coml0%URL Reputationsafe
http://www.sajatypeworks.com0%URL Reputationsafe
http://www.sajatypeworks.com0%URL Reputationsafe
http://www.typography.netD0%URL Reputationsafe
http://www.fontbureau.com/designers/cabarga.htmlN0%URL Reputationsafe
http://www.founder.com.cn/cn/cThe0%URL Reputationsafe
http://www.galapagosdesign.com/staff/dennis.htm0%URL Reputationsafe
http://www.founder.com.cn/cn0%URL Reputationsafe
http://www.fontbureau.com/designers/frere-user.html0%URL Reputationsafe
http://www.jiyu-kobo.co.jp/0%URL Reputationsafe
http://www.galapagosdesign.com/DPlease0%URL Reputationsafe
http://www.fontbureau.com/designers80%URL Reputationsafe
http://www.fonts.com0%URL Reputationsafe
http://www.sandoll.co.kr0%URL Reputationsafe
http://www.urwpp.deDPlease0%URL Reputationsafe
http://www.zhongyicts.com.cn0%URL Reputationsafe
http://www.sakkal.com0%URL Reputationsafe
http://www.apache.org/licenses/LICENSE-2.00%Avira URL Cloudsafe
http://www.bb-fans.jimdo.com0%Avira URL Cloudsafe
http://www.bb-fans.jimdo.com2%VirustotalBrowse
http://www.apache.org/licenses/LICENSE-2.00%VirustotalBrowse
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.apache.org/licenses/LICENSE-2.0AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • 0%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://www.fontbureau.comAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
  • URL Reputation: safe
unknown
http://www.fontbureau.com/designersGAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.fontbureau.com/designers/?AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.founder.com.cn/cn/bTheAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
  • URL Reputation: safe
unknown
http://www.bb-fans.jimdo.comAutoClick Smart cortesia de bb-fans.jimdo.com.exefalse
  • 2%, Virustotal, Browse
  • Avira URL Cloud: safe
unknown
http://www.fontbureau.com/designers?AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
  • URL Reputation: safe
unknown
http://www.tiro.comAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.fontbureau.com/designersAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.goodfont.co.krAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.carterandcone.comlAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.sajatypeworks.comAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
  • URL Reputation: safe
unknown
http://www.typography.netDAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.fontbureau.com/designers/cabarga.htmlNAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.founder.com.cn/cn/cTheAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.galapagosdesign.com/staff/dennis.htmAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.founder.com.cn/cnAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.fontbureau.com/designers/frere-user.htmlAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.jiyu-kobo.co.jp/AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.galapagosdesign.com/DPleaseAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.fontbureau.com/designers8AutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.fonts.comAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.sandoll.co.krAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.urwpp.deDPleaseAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.zhongyicts.com.cnAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://www.sakkal.comAutoClick Smart cortesia de bb-fans.jimdo.com.exe, 00000000.00000002.2889507835.000000001D0C2000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1502469
Start date and time:2024-09-01 17:55:06 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 3m 41s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:6
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:AutoClick Smart cortesia de bb-fans.jimdo.com.exe
Detection:MAL
Classification:mal52.evad.winEXE@1/0@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 98%
  • Number of executed functions: 11
  • Number of non-executed functions: 0
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
  • Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Execution Graph export aborted for target AutoClick Smart cortesia de bb-fans.jimdo.com.exe, PID 7256 because it is empty
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtQueryValueKey calls found.
No simulations
No context
No context
No context
No context
No context
No created / dropped files found
File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Entropy (8bit):4.4023387390467965
TrID:
  • Win32 Executable (generic) Net Framework (10011505/4) 49.79%
  • Win32 Executable (generic) a (10002005/4) 49.75%
  • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
  • Windows Screen Saver (13104/52) 0.07%
  • Win16/32 Executable Delphi generic (2074/23) 0.01%
File name:AutoClick Smart cortesia de bb-fans.jimdo.com.exe
File size:126'976 bytes
MD5:e064db65f591ebb637aa2ca532b7ec35
SHA1:33fc69dce99767997a4ee0cc3398cdf82bbc6417
SHA256:ff4234e650d0ba4b296f099c3bb00995f64d43570da258906208e1e1681a45ad
SHA512:e0b2b4835ec0230562c3990fc40dc60c37e4eea8fe83f483fe77771a0cac8d5752d0c14f6e357d0d44331db15c455dd50246935ebab6a2bfec5838049f8fd5a9
SSDEEP:768:6k9e6e13yV2OWJfbneATpD4yp5Mte+Pb0xthHnJhJ1dOtdLQeKW81Y/sKlYsi:6k92ZLtThLmSWXQercc8
TLSH:8CC32F43E2B4F5BDD6E58678882A88AD86330D12422E91566CD7FF37BD72401E50F27E
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....$+O.....................0........... ........@.. .......................@............@................................
Icon Hash:498a80a2a2808241
Entrypoint:0x41cabe
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Time Stamp:0x4F2B240B [Fri Feb 3 00:02:19 2012 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:4
OS Version Minor:0
File Version Major:4
File Version Minor:0
Subsystem Version Major:4
Subsystem Version Minor:0
Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
Instruction
jmp dword ptr [00402000h]
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x1ca640x57.text
IMAGE_DIRECTORY_ENTRY_RESOURCE0x200000x7c0.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x220000xc.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x1e0000x1c.sdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x20000x1aac40x1b0002f4669a001312e0d536bbc79a4e06b15False0.21157045717592593data4.750413041323677IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.sdata0x1e0000x7b0x100030411a68b4198fb916acea70accdfeeaFalse0.036865234375data0.3025132428027854IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rsrc0x200000x7c00x10006d51ca95c315372fee2a525171bf1dddFalse0.136962890625data1.8755961838976858IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x220000xc0x1000a6b2e16bb149bd2d20cef5d1b6f25698False0.00830078125data0.015920183265625623IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_ICON0x203880x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 6400.15994623655913978
RT_ICON0x206700x128Device independent bitmap graphic, 16 x 32 x 4, image size 1920.3344594594594595
RT_GROUP_ICON0x207980x22data1.0294117647058822
RT_VERSION0x201180x26cdata0.45645161290322583
DLLImport
mscoree.dll_CorExeMain
TimestampSource PortDest PortSource IPDest IP
Sep 1, 2024 17:56:16.317195892 CEST53546721.1.1.1192.168.2.4

Click to jump to process

Click to jump to process

Click to dive into process behavior distribution

Target ID:0
Start time:11:55:55
Start date:01/09/2024
Path:C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\AutoClick Smart cortesia de bb-fans.jimdo.com.exe"
Imagebase:0xc10000
File size:126'976 bytes
MD5 hash:E064DB65F591EBB637AA2CA532B7EC35
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Reset < >
    Memory Dump Source
    • Source File: 00000000.00000002.2890249046.00007FFD9B8F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8F0000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ffd9b8f0000_AutoClick Smart cortesia de bb-fans.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 09d54928f36499eb6814787c45a518369594e6c6448073bcc969eacc24aee9f0
    • Instruction ID: 8fa4ccd56483b9301b9132ea66ef1c5a22be27d4b1f7e52e6b849cdacdc744dd
    • Opcode Fuzzy Hash: 09d54928f36499eb6814787c45a518369594e6c6448073bcc969eacc24aee9f0
    • Instruction Fuzzy Hash: 6DA39D7461DB888FD7B1EB18C8A4F9AB7E1FF99305F4509A9D08DC7261CB74A840CB52
    Memory Dump Source
    • Source File: 00000000.00000002.2890249046.00007FFD9B8F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8F0000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ffd9b8f0000_AutoClick Smart cortesia de bb-fans.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 045fdb39bc87929b84cb1666cfabd77dae8c28413be51ba2e705fa6ea11c7639
    • Instruction ID: 90e0203d40c260eb1c5dacfb98e4ff7d02151035354c7f8f4d6e4695dac3851a
    • Opcode Fuzzy Hash: 045fdb39bc87929b84cb1666cfabd77dae8c28413be51ba2e705fa6ea11c7639
    • Instruction Fuzzy Hash: E4B1B87561DB888FDBB1EB18C4A9BDAB7E1FFAD701F410969908DC3251DB34A841CB42
    Memory Dump Source
    • Source File: 00000000.00000002.2890249046.00007FFD9B8F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8F0000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ffd9b8f0000_AutoClick Smart cortesia de bb-fans.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 58fbb60521678787e3c9c96919d5b53418cbcd040ed77cdfc169461c57de3626
    • Instruction ID: bdadd858bf2cb393a8f80190cc8869d74d8ce1b0e75be66bd3caf2f7d0ef1122
    • Opcode Fuzzy Hash: 58fbb60521678787e3c9c96919d5b53418cbcd040ed77cdfc169461c57de3626
    • Instruction Fuzzy Hash: 71B19770619A8D8FDBA5DF68C854BE97FE1FF19340F45016AE84DCB2A2DB349940CB41
    Memory Dump Source
    • Source File: 00000000.00000002.2890249046.00007FFD9B8F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8F0000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ffd9b8f0000_AutoClick Smart cortesia de bb-fans.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: b90da8d09627d12a452e09ca09dd10148300aeff57c1b0c3728dd94bf43a396c
    • Instruction ID: b35dcfd16bfd29c805c0c054d0bd38074c27070314e0d80d28563e3a7085d869
    • Opcode Fuzzy Hash: b90da8d09627d12a452e09ca09dd10148300aeff57c1b0c3728dd94bf43a396c
    • Instruction Fuzzy Hash: B6B13574618B888FD7A0EF5CC489B5AB7E1FFAD311F45496AA08DD7221CB70E844CB12
    Memory Dump Source
    • Source File: 00000000.00000002.2890249046.00007FFD9B8F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8F0000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ffd9b8f0000_AutoClick Smart cortesia de bb-fans.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 7c74022a3e7ce36642a46bcf4435e0ce6ec3532820bc8b91733e54ee0544babd
    • Instruction ID: d53a5843eaec30bd101510cca463d9d4bf8e5dc2620da969f4672547c18be3ff
    • Opcode Fuzzy Hash: 7c74022a3e7ce36642a46bcf4435e0ce6ec3532820bc8b91733e54ee0544babd
    • Instruction Fuzzy Hash: BE91027061DBC98FD7A1DB68C455B5ABBE1FF99340F4448AEE08DC72A1DA74A844C702
    Memory Dump Source
    • Source File: 00000000.00000002.2890249046.00007FFD9B8F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8F0000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ffd9b8f0000_AutoClick Smart cortesia de bb-fans.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 91a0bf9596a0570973083a01e1676b106494f1aa4613aa62edfa53ba99a3d837
    • Instruction ID: e84d6b3070c5742c512e5ff7bc29b4ef4e45c8115bbeb7b36b9fc15be907926d
    • Opcode Fuzzy Hash: 91a0bf9596a0570973083a01e1676b106494f1aa4613aa62edfa53ba99a3d837
    • Instruction Fuzzy Hash: 6F51AB3061DB888FD790EF28C499B6ABBE0FF99351F44496DE489C7262DA34D944CB42
    Memory Dump Source
    • Source File: 00000000.00000002.2890249046.00007FFD9B8F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8F0000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ffd9b8f0000_AutoClick Smart cortesia de bb-fans.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: be6c35af01ea169dd9746aa899b5c913d8e1555853143b77cda7dcdfdf4f7834
    • Instruction ID: 52c2adfe6d59c31207daca681983ce19035816ba3829237aacf1eed4b0bd5ecc
    • Opcode Fuzzy Hash: be6c35af01ea169dd9746aa899b5c913d8e1555853143b77cda7dcdfdf4f7834
    • Instruction Fuzzy Hash: 9A411D62B2E7CA0FE392DB1888715647BF1FF99240F4605BAE48DC71B3EC286D418761
    Memory Dump Source
    • Source File: 00000000.00000002.2890249046.00007FFD9B8F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8F0000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ffd9b8f0000_AutoClick Smart cortesia de bb-fans.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: fba1f99729c86aef89bc63061bca645badc1d6cac7f4a0168a1ed08bda75e0a8
    • Instruction ID: 0c3249a2c8cd9165d2dc235a93df4a853337441dd885d1a1b0a735740a8835da
    • Opcode Fuzzy Hash: fba1f99729c86aef89bc63061bca645badc1d6cac7f4a0168a1ed08bda75e0a8
    • Instruction Fuzzy Hash: 3E318470A0DB894FE781DF58C890B59BBE1FF99304F8518A9F08DC7296CAA5EC01C702
    Memory Dump Source
    • Source File: 00000000.00000002.2890249046.00007FFD9B8F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8F0000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ffd9b8f0000_AutoClick Smart cortesia de bb-fans.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: cd444dd7eabfd179339e5bfcc4a8d7f3caa4e6236862b227ce7957b56a632cd0
    • Instruction ID: 956f2ff4350d843dd8541bcfeba2be9deeaa473a0e131eeb07671c411412308c
    • Opcode Fuzzy Hash: cd444dd7eabfd179339e5bfcc4a8d7f3caa4e6236862b227ce7957b56a632cd0
    • Instruction Fuzzy Hash: 7F11817160DB894FD781DB6CC890669BBE1FF9A300F4505BAE48DC72A3DA649940CB12
    Memory Dump Source
    • Source File: 00000000.00000002.2890249046.00007FFD9B8F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8F0000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ffd9b8f0000_AutoClick Smart cortesia de bb-fans.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 39cf0b1b0f086c627d8446619acefcc33eb374f35a3d1d6bac2255a72c9b236a
    • Instruction ID: 5303a5b90b0bb4c3bcd0d52cecab73830d7becba9f54757315d450f2960eb83c
    • Opcode Fuzzy Hash: 39cf0b1b0f086c627d8446619acefcc33eb374f35a3d1d6bac2255a72c9b236a
    • Instruction Fuzzy Hash: 4101C060E5DB8E5FDB029F2488616F93FB0EF0A200F4545B6F89DCB193DA34AA44C752
    Memory Dump Source
    • Source File: 00000000.00000002.2890249046.00007FFD9B8F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8F0000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ffd9b8f0000_AutoClick Smart cortesia de bb-fans.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: e866d20f9652ba4b83bcf04c4f46ce06395b69a7ac655e4eaac492bae17060f5
    • Instruction ID: e75fba1e255854dd75b304b4594359f998959d0f16625e40e4e65ed22d21ab34
    • Opcode Fuzzy Hash: e866d20f9652ba4b83bcf04c4f46ce06395b69a7ac655e4eaac492bae17060f5
    • Instruction Fuzzy Hash: D9018461A5DB8C5FD781DF1888507157FF0FF59244F8A06AAF4CCD72A2E7289944C712