click.exe

The executable click.exe has been detected as malware by 25 anti-virus scanners. The file has been seen being downloaded from storage.googleapis.com.
Version:
1.1.22.00

MD5:
df8e2021d0ef0ff25d8bffd1a7c88555

SHA-1:
74df94b04058536ab8f436d1e507e4cacaa2cb14

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
4/26/2024 5:17:37 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.2592224
538

Agnitum Outpost
Trojan.DL.AutoHK
7.1.1

Avira AntiVirus
TR/Dldr.Agent.980992
8.3.1.6

Arcabit
Trojan.Generic.D278DE0
1.0.0.425

avast!
Win32:Evo-gen [Susp]
2014.9-150816

Baidu Antivirus
Trojan.Win32.AutoHK
4.0.3.15816

Bitdefender
Trojan.GenericKD.2592224
1.0.20.1140

Emsisoft Anti-Malware
Trojan.GenericKD.2592224
8.15.08.16.10

ESET NOD32
Win32/TrojanDownloader.AutoHK.AI
9.12013

Fortinet FortiGate
W32/AutoHK.AI!tr.dldr
8/16/2015

F-Secure
Trojan.GenericKD.2592224
11.2015-16-08_1

G Data
Trojan.GenericKD.2592224
15.8.25

IKARUS anti.virus
Trojan-Downloader.Win32.Autohk
t3scan.1.9.5.0

K7 AntiVirus
Trojan-Downloader
13.207.16720

McAfee
Artemis!DF8E2021D0EF
5600.6672

Microsoft Security Essentials
Trojan:Win32/Skeeyah.A!bit
1.1.11903.0

MicroWorld eScan
Trojan.GenericKD.2592224
16.0.0.684

NANO AntiVirus
Trojan.Win32.DownLoader13.dtalza
0.30.24.2668

nProtect
Trojan.GenericKD.2592224
15.07.29.01

Panda Antivirus
Generic Suspicious
15.08.16.10

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Trend Micro
TROJ_GEN.R0C1C0DGS15
10.465.16

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
42430

ViRobot
Trojan.Win32.S.Agent.980992.U[h]
2014.3.20.0

File size:
958 KB (980,992 bytes)

Product version:
1.1.22.00

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\click.exe

File PE Metadata
Compilation timestamp:
5/1/2015 12:42:24 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:Gj9LM+htZiehvOQlppULAxVUiINhoiUzUKIIBzy9Sbb:Gj9gsDROQlELAxVUPoiaUwBzcMb

Entry address:
0x92193

Entry point:
E8, 50, 5E, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, 56, 8B, 44, 24, 14, 0B, C0, 75, 28, 8B, 4C, 24, 10, 8B, 44, 24, 0C, 33, D2, F7, F1, 8B, D8, 8B, 44, 24, 08, F7, F1, 8B, F0, 8B, C3, F7, 64, 24, 10, 8B, C8, 8B, C6, F7, 64, 24, 10, 03, D1, EB, 47, 8B, C8, 8B, 5C, 24, 10, 8B, 54, 24, 0C, 8B, 44, 24, 08, D1, E9, D1, DB, D1, EA, D1, D8, 0B, C9, 75, F4, F7, F3, 8B, F0, F7, 64, 24, 14, 8B, C8, 8B, 44, 24, 10, F7, E6, 03, D1, 72, 0E, 3B, 54, 24, 0C, 77, 08, 72, 0F, 3B, 44, 24, 08, 76, 09, 4E, 2B, 44, 24, 10, 1B...
 
[+]

Entropy:
5.8215

Code size:
635.5 KB (650,752 bytes)

The file click.exe has been seen being distributed by the following URL.

Remove click.exe - Powered by Reason Core Security