Threat Database Trojans Trojan.Clicker.Small.A

Trojan.Clicker.Small.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,164
Threat Level: 80 % (High)
Infected Computers: 87
First Seen: May 2, 2017
Last Seen: August 7, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Clicker.Small.A
Signature status: No Signature

Known Samples

MD5: 4790bc293e0faf78964719bb2d385c44
SHA1: a4ca64a9bb5d3412f05dd1e19eb2adbb042079ac
SHA256: 2D9595B0E541D1854E0024DCAD8A43D981FC956C452BB52A8BF5DBC6A420A4E4
File Size: 32.77 KB, 32768 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Adobe Systems, Inc.
File Description Adobe? Flash? Player Installer/Uninstaller 10.1 r53
File Version 10,1,53,64
Internal Name Adobe? Flash? Player Installer/Uninstaller 10.1
Legal Copyright Copyright ? 1996-2010 Adobe, Inc.
Legal Trademarks Adobe? Flash? Player
Original Filename FlashUtil.exe
Product Name Flash? Player Installer/Uninstaller
Product Version 10,1,53,64

File Traits

  • HighEntropy
  • Installer Version
  • x86

Block Information

Total Blocks: 18
Potentially Malicious Blocks: 12
Whitelisted Blocks: 6
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x 0 0 0 0 1 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\dialogblockingservice.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\dialogblockingservice.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\dialogblockingservice.exe Synchronize,Write Data
c:\users\user\appdata\local\rcx2e3c.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\~da2e1c.tmp Synchronize,Write Data
c:\users\user\appdata\local\temp\~dfds3.reg Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\ad85b89389a00dfe9034f6cd719fd54f_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::dialogblockingservice C:\Users\Lhiaduui\AppData\Local\DialogBlockingService.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey

Windows API Usage

Category API
Service Control
  • OpenSCManager
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • WinExec

Shell Command Execution

regedit.exe /s C:\Users\Lhiaduui\AppData\Local\Temp\~dfds3.reg