download:

/pchelpsoft/PC_Cleaner_setup.exe

Full analysis: https://app.any.run/tasks/0a56be94-7002-49b5-96d3-fca562683b6a
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: February 07, 2024, 09:53:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F004DA3D2F9F3FF3437089759BAE8CFD

SHA1:

F0106D7E51CCA3CFE35C4C6D6D53E9BDADDC7AD7

SHA256:

0CD53B38AFF244F57AFC12E7393B543D82E7EED2EECFC2FCDB034FCD1F3BD2EE

SSDEEP:

98304:N+QqZ8fFOesFEGi7IXaW4M7PpavOEMdnMfUz+/fHqIXF84F/sCSInHuP3Zpgvw7o:qUJjKguUU0Mq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PC_Cleaner_setup.exe (PID: 1632)
      • PC_Cleaner_setup.exe (PID: 3416)
      • PC_Cleaner_setup.tmp (PID: 2508)
    • Steals credentials from Web Browsers

      • PCCNotifications.exe (PID: 3020)
      • PCCleaner.exe (PID: 3012)
    • Actions looks like stealing of personal data

      • PCCNotifications.exe (PID: 3020)
      • PCCleaner.exe (PID: 3012)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • PC_Cleaner_setup.exe (PID: 3416)
      • PC_Cleaner_setup.exe (PID: 1632)
      • PC_Cleaner_setup.tmp (PID: 2508)
    • Reads the Windows owner or organization settings

      • PC_Cleaner_setup.tmp (PID: 2508)
    • Process drops SQLite DLL files

      • PC_Cleaner_setup.tmp (PID: 2508)
    • Reads the Internet Settings

      • PCCNotifications.exe (PID: 3020)
      • PCCleaner.exe (PID: 3012)
    • Reads settings of System Certificates

      • PCCNotifications.exe (PID: 3020)
      • PCCleaner.exe (PID: 3012)
    • Adds/modifies Windows certificates

      • PCCNotifications.exe (PID: 3020)
    • Checks for Java to be installed

      • PCCleaner.exe (PID: 3012)
    • Searches for installed software

      • PCCNotifications.exe (PID: 3020)
      • PCCleaner.exe (PID: 3012)
    • Reads browser cookies

      • PCCleaner.exe (PID: 3012)
    • Reads Mozilla Firefox installation path

      • PCCleaner.exe (PID: 3012)
  • INFO

    • Checks supported languages

      • PC_Cleaner_setup.tmp (PID: 3456)
      • PC_Cleaner_setup.exe (PID: 1632)
      • PC_Cleaner_setup.exe (PID: 3416)
      • PC_Cleaner_setup.tmp (PID: 2508)
      • PCCleaner.exe (PID: 3012)
      • PCCNotifications.exe (PID: 3020)
    • Reads the computer name

      • PC_Cleaner_setup.tmp (PID: 3456)
      • PC_Cleaner_setup.tmp (PID: 2508)
      • PCCleaner.exe (PID: 3012)
      • PCCNotifications.exe (PID: 3020)
    • Create files in a temporary directory

      • PC_Cleaner_setup.exe (PID: 3416)
      • PC_Cleaner_setup.exe (PID: 1632)
      • PC_Cleaner_setup.tmp (PID: 2508)
      • PCCleaner.exe (PID: 3012)
      • PCCNotifications.exe (PID: 3020)
    • Creates files in the program directory

      • PC_Cleaner_setup.tmp (PID: 2508)
      • PCCleaner.exe (PID: 3012)
    • Reads CPU info

      • PCCleaner.exe (PID: 3012)
    • Process checks computer location settings

      • PCCNotifications.exe (PID: 3020)
    • Checks proxy server information

      • PCCNotifications.exe (PID: 3020)
      • PCCleaner.exe (PID: 3012)
    • Creates files or folders in the user directory

      • PCCNotifications.exe (PID: 3020)
      • PCCleaner.exe (PID: 3012)
    • Reads the machine GUID from the registry

      • PCCNotifications.exe (PID: 3020)
      • PCCleaner.exe (PID: 3012)
    • Reads Windows Product ID

      • PCCleaner.exe (PID: 3012)
      • PCCNotifications.exe (PID: 3020)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 10:09:11+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 89088
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 9.5.1.2
ProductVersionNumber: 9.5.1.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: PC Helpsoft
FileDescription: PC Cleaner
FileVersion: 9.5.1.2
LegalCopyright: PC Helpsoft
OriginalFileName:
ProductName: PC Cleaner
ProductVersion: 9.5.1.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
6
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pc_cleaner_setup.exe pc_cleaner_setup.tmp no specs pc_cleaner_setup.exe pc_cleaner_setup.tmp pccnotifications.exe pccleaner.exe

Process information

PID
CMD
Path
Indicators
Parent process
1632"C:\Users\admin\Desktop\PC_Cleaner_setup.exe" C:\Users\admin\Desktop\PC_Cleaner_setup.exe
explorer.exe
User:
admin
Company:
PC Helpsoft
Integrity Level:
MEDIUM
Description:
PC Cleaner
Exit code:
0
Version:
9.5.1.2
Modules
Images
c:\users\admin\desktop\pc_cleaner_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2508"C:\Users\admin\AppData\Local\Temp\is-V8NKG.tmp\PC_Cleaner_setup.tmp" /SL5="$E0134,6942773,831488,C:\Users\admin\Desktop\PC_Cleaner_setup.exe" /SPAWNWND=$E0130 /NOTIFYWND=$F0184 C:\Users\admin\AppData\Local\Temp\is-V8NKG.tmp\PC_Cleaner_setup.tmp
PC_Cleaner_setup.exe
User:
admin
Company:
PC Helpsoft
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-v8nkg.tmp\pc_cleaner_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3012"C:\Program Files\PC Cleaner\PCCleaner" /STARTC:\Program Files\PC Cleaner\PCCleaner.exe
PC_Cleaner_setup.tmp
User:
admin
Company:
PC Helpsoft
Integrity Level:
HIGH
Description:
PC Cleaner
Exit code:
0
Version:
9.5.1.0
Modules
Images
c:\program files\pc cleaner\pccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
3020"C:\Program Files\PC Cleaner\PCCNotifications.exe"C:\Program Files\PC Cleaner\PCCNotifications.exe
PC_Cleaner_setup.tmp
User:
admin
Company:
PC Helpsoft
Integrity Level:
HIGH
Description:
PC Cleaner automatic scan and notifications
Exit code:
0
Version:
9.5.1.0
Modules
Images
c:\program files\pc cleaner\pccnotifications.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3416"C:\Users\admin\Desktop\PC_Cleaner_setup.exe" /SPAWNWND=$E0130 /NOTIFYWND=$F0184 C:\Users\admin\Desktop\PC_Cleaner_setup.exe
PC_Cleaner_setup.tmp
User:
admin
Company:
PC Helpsoft
Integrity Level:
HIGH
Description:
PC Cleaner
Exit code:
0
Version:
9.5.1.2
Modules
Images
c:\users\admin\desktop\pc_cleaner_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3456"C:\Users\admin\AppData\Local\Temp\is-B6AUN.tmp\PC_Cleaner_setup.tmp" /SL5="$F0184,6942773,831488,C:\Users\admin\Desktop\PC_Cleaner_setup.exe" C:\Users\admin\AppData\Local\Temp\is-B6AUN.tmp\PC_Cleaner_setup.tmpPC_Cleaner_setup.exe
User:
admin
Company:
PC Helpsoft
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-b6aun.tmp\pc_cleaner_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
15 265
Read events
15 212
Write events
44
Delete events
9

Modification events

(PID) Process:(2508) PC_Cleaner_setup.tmpKey:HKEY_CURRENT_USER\Software\PC Cleaner
Operation:delete valueName:IsUpgrade
Value:
1
(PID) Process:(2508) PC_Cleaner_setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
(PID) Process:(2508) PC_Cleaner_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
7AC1877D3030CFBC0147B481904A31C9ECB0DFF80327365AF6A69A75D1D31881
(PID) Process:(2508) PC_Cleaner_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Program Files\PC Cleaner\PCCleaner.exe
(PID) Process:(2508) PC_Cleaner_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(2508) PC_Cleaner_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
0E1CE8E23FF8E8240298233F4DA61417457360CF38BF2F9D9FFD2255E47EF7C3
(PID) Process:(2508) PC_Cleaner_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
CC090000BCD03F8EAB59DA01
(PID) Process:(2508) PC_Cleaner_setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete keyName:(default)
Value:
(PID) Process:(3020) PCCNotifications.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3020) PCCNotifications.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
14
Suspicious files
34
Text files
51
Unknown types
0

Dropped files

PID
Process
Filename
Type
2508PC_Cleaner_setup.tmpC:\Program Files\PC Cleaner\is-UJRI0.tmpexecutable
MD5:E1EFFFEABF739101E96D3A2CFECE74C0
SHA256:14096802B6957F548379C56FF9A48B39B988C03355132353230295B68C38E163
2508PC_Cleaner_setup.tmpC:\Program Files\PC Cleaner\unins000.exeexecutable
MD5:E1EFFFEABF739101E96D3A2CFECE74C0
SHA256:14096802B6957F548379C56FF9A48B39B988C03355132353230295B68C38E163
3416PC_Cleaner_setup.exeC:\Users\admin\AppData\Local\Temp\is-V8NKG.tmp\PC_Cleaner_setup.tmpexecutable
MD5:E1EFFFEABF739101E96D3A2CFECE74C0
SHA256:14096802B6957F548379C56FF9A48B39B988C03355132353230295B68C38E163
2508PC_Cleaner_setup.tmpC:\Program Files\PC Cleaner\is-5B4PR.tmpbinary
MD5:EFA73B8135E9046038538B20E93C9FA1
SHA256:129D94B7DD0166AB2AF827C53A4A065CC0AF2DE9812371084B46EC4F26CF3ED7
2508PC_Cleaner_setup.tmpC:\Program Files\PC Cleaner\is-9QRLV.tmptext
MD5:1723BE45104CDAC92B84F99255F66D11
SHA256:B176C4224DF8CCBC78AED40162DD7A86AE4F4C442F2DB7783C8BE977008D60EC
2508PC_Cleaner_setup.tmpC:\Program Files\PC Cleaner\is-22OTP.tmpbinary
MD5:C304408A360456B08D1FDF319166702D
SHA256:B6CCD92470726F0D35D0DC7A8F61DD0F17AC06C55550939351C49ACD2809E919
2508PC_Cleaner_setup.tmpC:\Program Files\PC Cleaner\Brazilian.inibinary
MD5:D6F95D407E81BB24A26CEFCA943E6A26
SHA256:6B70C646B90685E7396E64B22D16A6AF295B6F8984538D06DE4D32024C992A96
2508PC_Cleaner_setup.tmpC:\Program Files\PC Cleaner\Dutch.initext
MD5:1723BE45104CDAC92B84F99255F66D11
SHA256:B176C4224DF8CCBC78AED40162DD7A86AE4F4C442F2DB7783C8BE977008D60EC
2508PC_Cleaner_setup.tmpC:\Program Files\PC Cleaner\is-UC9D3.tmptext
MD5:32F8D94CF3326E223D0A3B572C22A069
SHA256:4B23102A29739E5A2A3B65A1AD1089FB5823B17ED97B4434CE33F576BB959FF6
2508PC_Cleaner_setup.tmpC:\Program Files\PC Cleaner\PCCleaner.exeexecutable
MD5:02B0A8F0F0172F093674DBF827B2B04C
SHA256:35B8B51D86C43EAA7AF96530C9E0348625FB10A376769DC457CB8B6D5419412F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
19
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3020
PCCNotifications.exe
GET
200
23.53.40.48:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2fef581d459c9b26
unknown
compressed
65.2 Kb
unknown
488
lsass.exe
GET
304
23.53.40.48:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fa455765e490287c
unknown
unknown
3012
PCCleaner.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
unknown
488
lsass.exe
GET
200
18.245.39.64:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
binary
1.49 Kb
unknown
488
lsass.exe
GET
200
108.138.2.173:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
binary
2.02 Kb
unknown
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
unknown
binary
1.37 Kb
unknown
3012
PCCleaner.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
unknown
3012
PCCleaner.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
unknown
3012
PCCleaner.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
unknown
3012
PCCleaner.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
3020
PCCNotifications.exe
116.203.251.147:443
collect.avqtools.com
Hetzner Online GmbH
DE
unknown
3020
PCCNotifications.exe
23.53.40.48:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3012
PCCleaner.exe
18.245.86.79:80
api.playanext.com
US
unknown
3012
PCCleaner.exe
99.86.4.23:443
offers.playanext.com
AMAZON-02
US
unknown
3012
PCCleaner.exe
216.239.38.21:443
cloud.pchelpsoft.com
GOOGLE
US
whitelisted
488
lsass.exe
23.53.40.48:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
488
lsass.exe
108.138.2.173:80
o.ss2.us
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
collect.avqtools.com
  • 116.203.251.147
unknown
ctldl.windowsupdate.com
  • 23.53.40.48
  • 23.53.40.35
  • 23.53.40.43
  • 23.53.40.19
  • 23.53.40.16
  • 23.53.40.26
  • 23.53.40.25
  • 23.53.40.40
  • 23.53.40.32
whitelisted
offers.playanext.com
  • 99.86.4.23
  • 99.86.4.92
  • 99.86.4.76
  • 99.86.4.112
unknown
api.playanext.com
  • 18.245.86.79
  • 18.245.86.84
  • 18.245.86.105
  • 18.245.86.26
whitelisted
cloud.pchelpsoft.com
  • 216.239.38.21
  • 216.239.32.21
  • 216.239.34.21
  • 216.239.36.21
unknown
o.ss2.us
  • 108.138.2.173
  • 108.138.2.107
  • 108.138.2.195
  • 108.138.2.10
whitelisted
ocsp.rootg2.amazontrust.com
  • 18.245.39.64
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.39.64
shared
files.playanext.com
  • 18.66.147.111
  • 18.66.147.113
  • 18.66.147.61
  • 18.66.147.52
unknown
www.pchelpsoft.com
  • 104.26.0.116
  • 172.67.73.195
  • 104.26.1.116
unknown

Threats

No threats detected
No debug info