clickme.exe

Rapid7 LLC

This is a setup program which is used to install the application. The file has been seen being downloaded from 192.168.1.106.
Publisher:
Rapid7 LLC  (signed and verified)

MD5:
4d2e8a1a9d33c318569662d1c6c7a324

SHA-1:
69da768600f0b4c436199bac7e773bbee27a48e6

SHA-256:
1239ce6a32a1a0189ab56d067ecb7c62884718112286cf2f733b6c282f46d8e3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/25/2024 9:44:22 PM UTC  (today)

File size:
21.1 KB (21,656 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\clickme.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
12/21/2011 5:07:24 PM

Valid to:
12/21/2012 5:03:50 PM

Subject:
CN=Rapid7 LLC, O=Rapid7 LLC, L=Austin, S=TX, C=US

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4EF02272FB2A40

File PE Metadata
Compilation timestamp:
12/29/2011 8:13:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
192:QXKcyowJL/RkmEPJUuJFuzf77yowJL/RkmEPJUuJFuzf72:MKcYJLRktRgHYJLRktRgS

Entry address:
0x10D0

Entry point:
55, 8B, EC, 83, EC, 08, 6A, 00, E8, 23, FF, FF, FF, 83, C4, 04, 89, 45, F8, 83, 7D, F8, 00, 75, 04, 33, C0, EB, 0E, 8B, 45, F8, 89, 45, FC, FF, 55, FC, B8, 01, 00, 00, 00, 8B, E5, 5D, C2, 10, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
512 Bytes (512 bytes)

The file clickme.exe has been seen being distributed by the following URL.

https://192.168.1.106:3790/.../1

Scan clickme.exe - Powered by Reason Core Security