автокликер.exe

AHTUxPK

Igor

This is a setup program which is used to install the application. The file has been seen being downloaded from artemmian.ru and multiple other hosts.
Publisher:
Igor

Product:
AHTUxPK

Version:
1.00.0001

MD5:
65cfec5011b9db230745dc8fa65e0c51

SHA-1:
7a589f22279d7d072cb568f4feea499ef116585c

SHA-256:
85b1e42bb775cbfc8e51dace5fbc8afe128f6eb4b15582f52078bbd3cd27f4c5

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/28/2024 12:14:33 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Application.Win32.Agent.~AWO
18113

Trend Micro House Call
HKTL_CLICKER
7.2.115

Trend Micro
HKTL_CLICKER
10.465.25

File size:
148 KB (151,552 bytes)

Product version:
1.00.0001

Original file name:
AHTUxPK.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
10/19/2012 6:46:47 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:HTXABqiVIEyIY8QRnaQ7oYQfTphAnAqppP+C+3F9958:H76arIYTnwthAnAcGC2FD

Entry address:
0x19FC

Entry point:
68, 88, 77, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 23, 43, 24, C9, 4C, 9E, 14, 4C, 8D, 36, 28, 4B, 92, 47, 7B, 6F, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 30, 32, 30, 34, 33, 30, 41, 48, 54, 55, 78, 50, 4B, 00, 00, 00, 00, 00, FF, CC, 31, 00, 07, 45, AF, C0, 25, AE, 64, 62, 4B, A2, A2, 02, B1, 33, 63, 68, 51, 9A, 5A, E2, 69, 61, B0, 57, 47, BD, C8, A7, 3D, A7, 51, 9D, AA, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00, AA, 00, 60, D3, 93, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
136 KB (139,264 bytes)

The file автокликер.exe has been seen being distributed by the following 2 URLs.

Scan автокликер.exe - Powered by Reason Core Security