Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

GCleaner

69
Global rank
58 infographic chevron month
Month rank
73 infographic chevron week
Week rank
0
IOCs

GCleaner is a type of malware loader that has the capability to deliver numerous malicious software programs, which differ based on the location of the targeted victim. This malware is commonly spread through fraudulent websites that advertise free PC optimization tools

Loader
Type
Unknown
Origin
19 September, 2019
First seen
13 September, 2026
Last seen

How to analyze GCleaner with ANY.RUN

Type
Unknown
Origin
19 September, 2019
First seen
13 September, 2026
Last seen

IOCs

IP addresses
155.102.51.14
163.181.131.226
92.123.104.62
192.178.183.132
150.171.27.11
23.52.181.141
172.66.171.73
149.154.166.110
204.79.197.203
150.171.28.12
212.56.41.77
142.251.110.139
48.209.138.168
150.171.28.11
23.52.181.212
172.67.203.222
162.159.142.9
18.244.18.27
150.171.109.105
142.251.151.119
Hashes
ceebae7b8927a3227e5303cf5e0f1f7b34bb542ad7250ac03fbcde36ec2f1508
226eec4486509917aa336afebd6ff65777b75b65f1fb06891d2a857a9421a974
e383b20484ee90c00054d52dd5af473b2ac9dc50c14d459a579ef5f44271d256
602c4c7482de6479dd2e9793cda275e5e63d773dacd1eca689232ab7008fb4fb
294c97175fd0894093b866e73548ae660aeed0c3cc1e73867eb66e52d34c0dd2
2d1bed2422e131a140087faf1b12b8a46f7de3b6413bae8bc395c06f0d70b9b0
88bdaf4b25b684b0320a2e11d3fe77dddd25e3b17141bd7ed1d63698c480e4ba
5ee3b25676e813d89ed866d03b5c3388567d8307a2a60d1c4a34d938cbadf710
6ac0f1845a56a1a537b9a6d9bcb724dddf3d3a5e61879ae925931b1c0534fbb7
39e13235f87a1b8621ada62c9ad2ebf8e17687c5533658e075efa70a04d5c78d
cb27007e138315b064576c17931280cfe6e6929efc3dafd7171713d204cfc3bf
a462f83ddb0ccc41ac10e0b5b98287b4d89da8bbbca869ccfb81979c70613c6c
d442e5bbb801c004a7903f6c217149fcda521088705ac9fecb0bc3b3058981bf
bc5ed164d15321404bbdcad0d647c322ffab1659462182dbd3945439d9ecbae7
847c14c297dbe4d8517debaa8ed555f3daedf843d6bad1f411598631a0bd3507
ae5d3df23f019455f3edfc3262aac2b00098881f09b9a934c0d26c0ab896700c
abf7d9d1e86de931096c21820bfa4fd70db1f55005d2db4aa674d86200867806
a43a5b58bfc57bd723b12bbdea9f6e1a921360b36d2d52c420f37299788442d3
c39595ddc0095eb4ae9e66db02ee175b31ac3da1f649eb88fa61b911f838f753
0cdb59e255ccd7dcf4af847c9b020aeaee78ce7fcf5f214ebcf123328acf9f24
Domains
client.wns.windows.com
ogads-pa.clients6.google.com
release-assets.githubusercontent.com
qqwwaa.tos-cn-hongkong.volces.com
www.bing.com
update.cg100iii.com
clientapi.aplus.pptv.com
neihite.cc
img-s-msn-com.akamaized.net
drive.usercontent.google.com
ecs.office.com
accounts.google.com
edge.microsoft.com
h.synacast.com
login.live.com
pay.aqiu6.com
crl.microsoft.com
systemformating.rest
config.edge.skype.com
activation-v2.sls.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://urlhaus.abuse.ch/downloads/text_online/
http://users.atw.hu/zoolatogato/xruhbmzvlaghfnqcerrv.exe
https://raw.githubusercontent.com/huuuuggga/aaaaa1/refs/heads/main/srtware.exe
https://www.blackhattoolz.com/licensing/updates/addmefast%20bot.exe
https://ossapp.suning.com/pcoss/dl/pptv(pplive)_forap_1084_9993.exe
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://139.198.15.223:8080/pinginfoview.exe
http://haeum.nfile.net/files/haeum.exe
http://ins.pplive.com/config/pptv/qd-all-slient-onelink-autostart/forqd1084/bind_en-us.ini
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://178.16.54.109/1.exe
http://clients2.google.com/time/1/current?cup2key=8:hkp2v16p3z5vxsxlmnunxakw3bzm2k1xceu5qa42qtq&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://github.com/vinhuptoday/testbn/raw/refs/heads/main/brbotnet.exe
http://62.60.226.140/files/unique2/file.exe
http://update.cg100iii.com/cgpro/update.exe
http://ocsp.usertrust.com/mfewtzbnmeswstajbgurdgmcgguabbsr83eyjy3njhjvpn5bepfc6mxawqquouejhttpgckwdnrjdtzgnczjy5ocebqer%2bxt6ogbxbkxqbankn0%3d
Last Seen at
Last Seen at

Recent blog posts

post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 1666
comments 0
post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 3504
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 6612
comments 0

What is the GCleaner loader malware?

The system optimizer market has for a long time been a breeding ground for all kinds of malicious software masking as legitimate to dupe users into downloading and installing it. G-Cleaner, also known as GCleaner, is a notable example of a fake PC optimization program, appearing to be genuine at first glance. In reality, it is a loader designed with one purpose: to get hold of victims’ sensitive data.

GCleaner is a loader, which was first spotted in early 2019. It is capable of a wide variety of malicious activities depending on the payload it is equipped with. Analysts have observed it to drop malware such as AZORult, the Raccoon info stealer, Smoke Loader, RedLine Stealer, and other popular families, depending on the victim’s geographic location.

The GCleaner malware is primarily known as one of the most widespread fake Windows utilities that is intended for targeting both organizations and individuals. It attempts to capitalize on the popularity of system cleaning tools by taking advantage of people’s negligence.

The identity of the individuals responsible for developing the G-Cleaner malware remains a mystery. Nonetheless, experts in the field of cybersecurity suspect that the creation of this malicious software was the work of a highly skilled and organized criminal organization.

Technical details of the GCleaner malicious software

Once G-Cleaner is installed on a computer, it extracts a malicious file in the system's temporary files folder and downloads a payload. For instance, GCleaner often drops AZORult and RedLine, stealers that scan the system for any type of personal information, which from now on becomes known to the attackers, including:

  • Passwords;
  • Credit card details;
  • Crypto addresses.

Although each malware family may exploit different types of vulnerabilities, in most cases, the process involves hijacking the victim’s web browser and then recording their keystrokes.

GCleaner makes use of different persistence mechanisms. For instance, after installation, it creates a number of new processes running in the background. The malware also writes data to a remote process, which is typically a legitimate Windows process. This makes it difficult for antivirus software to detect and remove the malware.

GCleaner attempts to stay hidden by using rootkit capabilities, which allow it to hide its presence from the operating system. As an extra layer of protection, it implements encryption to obfuscate its code, rendering it unreadable and harder for researchers to analyze.

Anti-debugging is also on the menu, which hinders reverse engineering efforts, making it challenging for analysts to debug the code and understand how it works.

Execution process of the GCleaner malware

By utilizing ANY.RUN, we can track the entire execution path of G-Cleaner and retrieve its config automatically. Here is a sample of the malware analyzed in our sandbox.

Gcleaner's configuration extracted by ANY.RUN Gcleaner's configuration extracted by ANY.RUN

Since GCleaner is a loader, its main purpose is to download other malware families. As a result, the execution flow varies from one version to another and can include the use of different tools. Overall, after it starts, the loader simply reruns itself under a different name from one of the "Program Files" directories. After that, it mostly attempts to download malware onto the infected system. In our case, GCleaner downloaded Redline.

Gcleaner’s network traffic Gcleaner's network traffic

Some samples of GCleaner may be detected by the malware’s network traffic. To do so, just look at the network stream. If you find "itsnotmalware/count.php" there, you can be pretty sure that it is GCleaner.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Distribution methods of the G-Cleaner malware

G-Cleaner has several channels for finding its way to users’ systems:

The most common one is through a website promoting a free optimizer. In fact, such was the first instance of this malware being discovered in 2019. The design of the page is reminiscent of those of CCleaner and other trusted providers, which is how criminals trick users into downloading malware.

Another widespread distribution method for G-Cleaner is through spam emails disguised as legitimate messages from international brands. In such cases, attackers utilize social engineering techniques to get users to install email attachments.

Alternatively, GCleaner can be masked as files not related to PC optimization. These may include game modes, patches, and other types of software.

Conclusion

G-Cleaner is a loader capable of introducing a range of malicious software onto the victim's computer. Generally, it is disseminated through fake websites advertising free PC performance optimization tools or via spam emails.

To prevent GCleaner and other malware from posing a risk to your organization’s infrastructure, you can conveniently scrutinize any questionable files using the ANY.RUN interactive malware analysis sandbox to quickly identify harmful code, study its behavior, and collect IOCs.

HAVE A LOOK AT

Maze screenshot
Maze
maze ransomware
Maze is ransomware — a malware type that encrypts the victim’s files and restores the data in exchange for a ransom payment. One of the most distinguishable features of Maze is that it is one of the first malware of the kind to publicly release stolen data.
Read More
Oblivion RAT screenshot
Oblivion RAT
oblivion
Oblivion RAT is a sophisticated Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on cybercrime forums for as little as $300 per month. It equips even novice attackers with a complete toolkit, including a web-based APK builder, dropper generator mimicking Google Play updates, and a real-time C2 panel. The RAT enables full device takeover, data theft, and financial fraud through deceptive social engineering and Accessibility Service abuse.
Read More
Bumblebee Loader screenshot
Bumblebee Loader
bumblebee
Bumblebee is a highly adaptable malware loader, often used by threat actors linked to the Conti and TrickBot cybercrime groups. Since its discovery in 2021, Bumblebee has been leveraged in phishing campaigns and email thread hijacking, primarily to distribute payloads like Cobalt Strike and ransomware. The malware employs obfuscation techniques, such as DLL injection and virtual environment detection, to avoid detection and sandbox analysis. Its command-and-control infrastructure and anti-analysis features allow it to persist on infected devices, where it enables further payload downloads and system compromise.
Read More
Sliver screenshot
Sliver
sliver
Sliver is an open-source command-and-control (C2) framework that has been increasingly adopted by threat actors as an alternative to tools like Cobalt Strike. Developed by security firm Bishop Fox, Sliver was initially intended for legitimate security testing and red teaming exercises. However, its robust features and open-source nature have made it attractive to malicious actors seeking to control compromised systems.
Read More
Virlock screenshot
Virlock
virlock
Virlock is a unique ransomware strain that combines encryption capabilities with file infection techniques. First observed in 2014, it stands out due to its polymorphic nature and ability to embed its code into compromised files, ensuring continued propagation. Once it infects a system, it encrypts files and locks the screen, demanding a ransom for file recovery and system access.
Read More
Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More