File name:

Resource Tuner 2.22 RePack (& Portable) by TryRooM.rar

Full analysis: https://app.any.run/tasks/5259a79b-db7d-45f9-957c-09253403234c
Verdict: Malicious activity
Analysis date: December 11, 2023, 08:35:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

A9CC3897CED061A37B10B55A18BB3148

SHA1:

1E3D60D6FE79AD4782AB65009C08207C145389C7

SHA256:

1380309D097498529873BFB6671A2E2EE1F0E803337989E14D7735F3B26C6EF0

SSDEEP:

98304:Cyvvhzdb/FOtPoBtdhxvTNjaKqvoXhvTOxJxGjOCqBZB30ToJZ5CsPJlCjmorgwg:dmX4npXdse6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • CCleaner.exe (PID: 1380)
    • Drops the executable file immediately after the start

      • CCleaner.exe (PID: 1380)
      • Resource.Tuner.2.22.tmp (PID: 2088)
      • Resource.Tuner.2.22.exe (PID: 3720)
    • Steals credentials from Web Browsers

      • CCleaner.exe (PID: 1380)
  • SUSPICIOUS

    • Reads the Internet Settings

      • CCleaner.exe (PID: 1936)
      • CCleaner.exe (PID: 1380)
      • cmd.exe (PID: 3620)
    • Application launched itself

      • CCleaner.exe (PID: 1936)
    • Reads security settings of Internet Explorer

      • CCleaner.exe (PID: 1380)
    • Checks Windows Trust Settings

      • CCleaner.exe (PID: 1380)
    • Reads Internet Explorer settings

      • CCleaner.exe (PID: 1380)
    • Reads settings of System Certificates

      • CCleaner.exe (PID: 1380)
    • Searches for installed software

      • CCleaner.exe (PID: 1380)
      • Resource.Tuner.2.22.tmp (PID: 2088)
    • Reads Microsoft Outlook installation path

      • CCleaner.exe (PID: 1380)
    • Process drops legitimate windows executable

      • Resource.Tuner.2.22.tmp (PID: 2088)
    • Reads the Windows owner or organization settings

      • Resource.Tuner.2.22.tmp (PID: 2088)
    • Starts CMD.EXE for commands execution

      • Resource.Tuner.2.22.tmp (PID: 2088)
  • INFO

    • Manual execution by a user

      • verclsid.exe (PID: 2336)
      • CCleaner.exe (PID: 1936)
      • wmpnscfg.exe (PID: 2972)
      • cmd.exe (PID: 3620)
      • restuner.exe (PID: 1664)
      • restuner.exe (PID: 3648)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 280)
    • Reads the computer name

      • CCleaner.exe (PID: 1936)
      • CCleaner.exe (PID: 1380)
      • wmpnscfg.exe (PID: 2972)
      • Resource.Tuner.2.22.tmp (PID: 2088)
      • restuner.exe (PID: 3648)
      • restuner.exe (PID: 1664)
    • Checks supported languages

      • CCleaner.exe (PID: 1936)
      • CCleaner.exe (PID: 1380)
      • Resource.Tuner.2.22.exe (PID: 3720)
      • wmpnscfg.exe (PID: 2972)
      • Resource.Tuner.2.22.tmp (PID: 2088)
      • restuner.exe (PID: 3648)
      • restuner.exe (PID: 1664)
    • Reads Environment values

      • CCleaner.exe (PID: 1936)
      • CCleaner.exe (PID: 1380)
      • Resource.Tuner.2.22.tmp (PID: 2088)
    • Reads the machine GUID from the registry

      • CCleaner.exe (PID: 1380)
    • Reads product name

      • CCleaner.exe (PID: 1380)
    • Creates files in the program directory

      • CCleaner.exe (PID: 1380)
      • Resource.Tuner.2.22.tmp (PID: 2088)
    • Reads CPU info

      • CCleaner.exe (PID: 1380)
    • Creates files or folders in the user directory

      • CCleaner.exe (PID: 1380)
      • restuner.exe (PID: 3648)
      • restuner.exe (PID: 1664)
    • Checks proxy server information

      • CCleaner.exe (PID: 1380)
    • Create files in a temporary directory

      • Resource.Tuner.2.22.tmp (PID: 2088)
      • Resource.Tuner.2.22.exe (PID: 3720)
    • Creates a software uninstall entry

      • Resource.Tuner.2.22.tmp (PID: 2088)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 4496060
UncompressedSize: 4523058
OperatingSystem: Win32
ModifyDate: 2022:05:13 14:56:44
PackingMethod: Normal
ArchivedFileName: Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource.Tuner.2.22.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
69
Monitored processes
16
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs verclsid.exe no specs ccleaner.exe no specs ccleaner.exe wmpnscfg.exe no specs cmd.exe no specs resource.tuner.2.22.exe no specs resource.tuner.2.22.exe no specs resource.tuner.2.22.exe resource.tuner.2.22.tmp no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs restuner.exe no specs restuner.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
904"cmd.exe" /c rd /S /Q "C:\Program Files\Resource Tuner"C:\Windows\System32\cmd.exeResource.Tuner.2.22.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1376"Resource.Tuner.2.22.exe" /VERYSILENT /I /RU C:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource.Tuner.2.22.execmd.exe
User:
admin
Company:
Heaventools Software
Integrity Level:
MEDIUM
Description:
Resource Tuner 2.22
Exit code:
3221226540
Version:
2.22
Modules
Images
c:\users\admin\appdata\local\temp\resource tuner 2.22 repack (& portable) by tryroom\resource tuner 2.22 repack (& portable) by tryroom\resource.tuner.2.22.exe
c:\windows\system32\ntdll.dll
1380"C:\Program Files\CCleaner\CCleaner.exe" /uacC:\Program Files\CCleaner\CCleaner.exe
CCleaner.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
6.14.0.10584
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
1664"C:\Program Files\Resource Tuner\restuner.exe" C:\Program Files\Resource Tuner\restuner.exeexplorer.exe
User:
admin
Company:
Heaventools Software
Integrity Level:
MEDIUM
Description:
Resource Tuner
Exit code:
0
Version:
2.22.0.442
Modules
Images
c:\program files\resource tuner\restuner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1936"C:\Program Files\CCleaner\CCleaner.exe" C:\Program Files\CCleaner\CCleaner.exeexplorer.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
CCleaner
Exit code:
0
Version:
6.14.0.10584
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
2088"C:\Users\admin\AppData\Local\Temp\is-G2Q6N.tmp\Resource.Tuner.2.22.tmp" /SL5="$E01A4,4111009,101376,C:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource.Tuner.2.22.exe" /VERYSILENT /I /RU C:\Users\admin\AppData\Local\Temp\is-G2Q6N.tmp\Resource.Tuner.2.22.tmpResource.Tuner.2.22.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-g2q6n.tmp\resource.tuner.2.22.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2260"cmd.exe" /c del /F /Q "C:\Program Files\Resource Tuner\*.*"C:\Windows\System32\cmd.exeResource.Tuner.2.22.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2336"C:\Windows\system32\verclsid.exe" /S /C {0B2C9183-C9FA-4C53-AE21-C900B0C39965} /I {0C733A8A-2A1C-11CE-ADE5-00AA0044773D} /X 0x401C:\Windows\System32\verclsid.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Extension CLSID Verification Host
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\verclsid.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2472"C:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource.Tuner.2.22.exe" /VERYSILENT /I /RU C:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource.Tuner.2.22.execmd.exe
User:
admin
Company:
Heaventools Software
Integrity Level:
MEDIUM
Description:
Resource Tuner 2.22
Exit code:
3221226540
Version:
2.22
Modules
Images
c:\users\admin\appdata\local\temp\resource tuner 2.22 repack (& portable) by tryroom\resource tuner 2.22 repack (& portable) by tryroom\resource.tuner.2.22.exe
c:\windows\system32\ntdll.dll
Total events
17 017
Read events
16 687
Write events
274
Delete events
56

Modification events

(PID) Process:(280) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(280) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(280) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(280) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(280) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(280) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(280) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(280) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(280) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(280) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM
Executable files
23
Suspicious files
33
Text files
26
Unknown types
7

Dropped files

PID
Process
Filename
Type
280WinRAR.exeC:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource.Tuner.2.22.exe
MD5:
SHA256:
280WinRAR.exeC:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Silent installation EN.cmdbinary
MD5:78D63C9FDEEBCF287FB27019BA808021
SHA256:86CFAC2AA5A4580B1C446CD4C6D6CD20828828BF35F1E1879009EBE3388E5DE7
280WinRAR.exeC:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Распаковка portable.cmdbinary
MD5:AC068F85B778E0C4673D219C51E5B164
SHA256:FC612D5B7A9EAD0BF8F15182979B532E8F61041345AC4723239AF269FDA72EF7
1380CCleaner.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E1012488CD9FFF2ACF3EB5078120F962_24BEA0882352FD0902DF40E54E74305Dder
MD5:6617C90D96E7D64A14DF95BF7667D2D8
SHA256:B5AE45F663D07BC415C32862B684277AF0137B92F3619165255EDFEEF0CE001E
280WinRAR.exeC:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Тихая установка RU без интеграции.cmdbinary
MD5:0A1B452A00D7DF9AEBF30377006C3DE8
SHA256:9A29153E0AEE0712426DA3644CAD5B9213D0D3D6608AB8769047D4E39BA516B2
1380CCleaner.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:465DD9C1BB4003778F710C89B0B09D4D
SHA256:8C7CB52A08DC8173379D96E15C26AD914EE3D977F0CC2AC34E23CE454CDDE9A6
1380CCleaner.exeC:\Program Files\CCleaner\gcapi_dll.dllexecutable
MD5:F637D5D3C3A60FDDB5DD397556FE9B1D
SHA256:641B843CB6EE7538EC267212694C9EF0616B9AC9AB14A0ABD7CF020678D50B02
280WinRAR.exeC:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Unpacking portable.cmdtext
MD5:E62EAFA5F43A27B657FF4E501C546B44
SHA256:FA2AE578A2664D85380F545EFEC5EF9FB6A9035EABE700CBD0FFDC3B45F1244B
1380CCleaner.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ed7a5cc3cca8d52a.customDestinations-ms~RF229053.TMPbinary
MD5:DA39F131D86385E1285BF5489BA6B6F9
SHA256:38C92C3B93D15CCF2E5E59D01D223366D60FF508037EF997C0CDCC11CEC8BAD0
280WinRAR.exeC:\Users\admin\AppData\Local\Temp\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Resource Tuner 2.22 RePack (& Portable) by TryRooM\Тихая установка RU.cmdbinary
MD5:E7117465F450D981823C6D720ECA12A1
SHA256:23586064A3247C6BDB34E6F83DB5AC0930D65C5A2B8194E595D3F83B5E359666
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
20
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1380
CCleaner.exe
GET
200
2.22.242.9:80
http://ncc.avast.com/ncc.txt
unknown
text
26 b
1380
CCleaner.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2d9c1ac75ff6ce2b
unknown
compressed
4.66 Kb
1380
CCleaner.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ac0c32e53b01da9e
unknown
compressed
4.66 Kb
1380
CCleaner.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?32164488e2f5c3c1
unknown
compressed
4.66 Kb
1380
CCleaner.exe
GET
200
142.250.74.195:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIAjrICMzZli2TN25s%3D
unknown
binary
724 b
1380
CCleaner.exe
GET
200
142.250.74.195:80
http://ocsp.pki.goog/s/gts1d4/VcE3oVK8Y7w/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQCazWGSsgPbSQnI0sPJ6DzW
unknown
binary
472 b
1380
CCleaner.exe
GET
200
142.250.74.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
1380
CCleaner.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
binary
471 b
1380
CCleaner.exe
GET
200
142.250.74.195:80
http://ocsp.pki.goog/s/gts1d4/ZyBjqPWqmvE/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEC2xaOeQk22TEA6Dd3CBkM0%3D
unknown
binary
471 b
1380
CCleaner.exe
GET
200
142.250.74.195:80
http://ocsp.pki.goog/s/gts1d4/fKYaaVX9oaM/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEFR%2BOO9BG%2B3VCUfYZJRDCnY%3D
unknown
binary
471 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
unknown
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1380
CCleaner.exe
2.22.242.9:80
ncc.avast.com
Akamai International B.V.
DE
unknown
1380
CCleaner.exe
34.117.223.223:443
analytics.ff.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
1380
CCleaner.exe
23.35.237.21:443
www.ccleaner.com
AKAMAI-AS
DE
unknown
1380
CCleaner.exe
34.111.24.1:443
ipm-provider.ff.avast.com
GOOGLE
US
unknown
1380
CCleaner.exe
34.160.176.28:443
shepherd.ff.avast.com
GOOGLE
US
unknown
1380
CCleaner.exe
34.149.149.62:443
ip-info.ff.avast.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
ncc.avast.com
  • 2.22.242.9
  • 2.22.242.105
unknown
analytics.ff.avast.com
  • 34.117.223.223
unknown
www.ccleaner.com
  • 23.35.237.21
unknown
ipm-provider.ff.avast.com
  • 34.111.24.1
unknown
ip-info.ff.avast.com
  • 34.149.149.62
unknown
shepherd.ff.avast.com
  • 34.160.176.28
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
unknown
ocsp.pki.goog
  • 142.250.74.195
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
ipmcdn.avast.com
  • 23.51.124.44
unknown

Threats

No threats detected
Process
Message
CCleaner.exe
[2023-12-11 08:37:01.025] [error ] [settings ] [ 1380: 2548] [6000C4: 356] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
Failed to open log file 'C:\Program Files\CCleaner'
CCleaner.exe
OnLanguage - en
CCleaner.exe
[2023-12-11 08:37:01.681] [error ] [settings ] [ 1380: 2608] [9434E9: 359] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
[2023-12-11 08:37:01.696] [error ] [Burger ] [ 1380: 2608] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
[2023-12-11 08:37:01.696] [error ] [Burger ] [ 1380: 2608] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
OnLanguage - en
CCleaner.exe
startCheckingLicense()
CCleaner.exe
OnLanguage - en
CCleaner.exe
OnLanguage - en