File name:

MadMan.exe

Full analysis: https://app.any.run/tasks/a8a5d8ea-f12b-40d8-aa14-31cb5492cb6c
Verdict: Malicious activity
Analysis date: December 19, 2025, 22:51:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: MS-DOS executable, MZ for MS-DOS
MD5:

A56D479405B23976F162F3A4A74E48AA

SHA1:

F4F433B3F56315E1D469148BDFD835469526262F

SHA256:

17D81134A5957FB758B9D69A90B033477A991C8B0F107D9864DC790CA37E6A23

SSDEEP:

24:k/l0Xq4Z0QXdgExX1kEIJAFC9tO7AAoeaUQiMl5W9Ui/wE1mAMMdXK:k/lL4Z0mdgoX1tFkPHJimW9tZMUK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates file in the systems drive root

      • ntvdm.exe (PID: 3748)
    • The process executes via Task Scheduler

      • CCleaner.exe (PID: 2736)
    • Executable content was dropped or overwritten

      • CCleaner.exe (PID: 2736)
    • Possible stealing of email data

      • CCleaner.exe (PID: 2736)
  • INFO

    • Manual execution by a user

      • explorer.exe (PID: 3920)
      • CCleaner.exe (PID: 776)
    • Checks supported languages

      • CCleaner.exe (PID: 776)
      • CCleaner.exe (PID: 2736)
    • Reads Environment values

      • CCleaner.exe (PID: 776)
      • CCleaner.exe (PID: 2736)
    • Reads the computer name

      • CCleaner.exe (PID: 776)
      • CCleaner.exe (PID: 2736)
    • Reads CPU info

      • CCleaner.exe (PID: 2736)
    • Reads the machine GUID from the registry

      • CCleaner.exe (PID: 2736)
    • Creates files in the program directory

      • CCleaner.exe (PID: 2736)
    • Reads product name

      • CCleaner.exe (PID: 2736)
    • The sample compiled with english language support

      • CCleaner.exe (PID: 2736)
    • Checks proxy server information

      • CCleaner.exe (PID: 2736)
    • Creates files or folders in the user directory

      • CCleaner.exe (PID: 2736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (49.6)
.exe | DOS Executable Generic (49.5)
.vxd | VXD Driver (0.7)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
5
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ntvdm.exe no specs explorer.exe no specs ccleaner.exe no specs ccleaner.exe PhotoViewer.dll no specs

Process information

PID
CMD
Path
Indicators
Parent process
776"C:\Program Files\CCleaner\CCleaner.exe" C:\Program Files\CCleaner\CCleaner.exeexplorer.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
CCleaner
Exit code:
0
Version:
6.14.0.10584
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
2736"C:\Program Files\CCleaner\CCleaner.exe" /uacC:\Program Files\CCleaner\CCleaner.exe
taskeng.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
6.14.0.10584
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
3412C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3748"C:\Windows\system32\ntvdm.exe" -i1 C:\Windows\System32\ntvdm.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
NTVDM.EXE
Exit code:
36
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3920"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
16 598
Read events
16 341
Write events
186
Delete events
71

Modification events

(PID) Process:(2736) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Piriform\CCleaner
Operation:writeName:DAST
Value:
12/19/2025 17:52:00
(PID) Process:(2736) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Piriform\CCleaner
Operation:writeName:T8062
Value:
0
(PID) Process:(2736) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Piriform\CCleaner
Operation:writeName:UpdateBackground
Value:
0
(PID) Process:(2736) CCleaner.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2736) CCleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
Operation:writeName:SystemRestorePointCreationFrequency
Value:
0
(PID) Process:(2736) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:CCleaner PostInstall
Value:
(PID) Process:(2736) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Piriform\CCleaner
Operation:writeName:FTU
Value:
02/11/2020|11|1
(PID) Process:(2736) CCleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner
Operation:delete valueName:GUID
Value:
(PID) Process:(2736) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Piriform\CCleaner
Operation:delete valueName:AutoUpdateNotificationExpiryTime
Value:
(PID) Process:(2736) CCleaner.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
3
Suspicious files
21
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
2736CCleaner.exeC:\Program Files\CCleaner\DATA\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417\44ED97C8-2D40-4A50-913D-673F6858B9AFbinary
MD5:F99B3F2534B0E2E65D6598339867C8BA
SHA256:7D72B7C374997D506DE28B8736578653F7DEE8217BD11172836A3C038A3D0122
2736CCleaner.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ed7a5cc3cca8d52a.customDestinations-ms~RF11855a.TMPbinary
MD5:C180671859156085B9BD60310F93B9CC
SHA256:12D48AA1D1EB02FC085BEBD25CBDFC19D65B8B4059B5130BD2E74DCDE5394FFE
3748ntvdm.exeC:\Users\admin\AppData\Local\Temp\scsED5F.tmptext
MD5:8CF6DDB5AA59B49F34B967CD46F013B6
SHA256:EE06792197C3E025B84860A72460EAF628C66637685F8C52C5A08A9CC35D376C
2736CCleaner.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ed7a5cc3cca8d52a.customDestinations-msbinary
MD5:B2D95465799F5CD4A5BF427484FE4A1B
SHA256:6AF65598BD00B84DDDA84F20EC468ECF08D3A807535B0309BD04D26230D1DBA7
2736CCleaner.exeC:\Program Files\CCleaner\DATA\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417\d4c3d316-384b-4149-b337-ba0c3299be0ebinary
MD5:101785425735EC98CC9B32FF7F745AB1
SHA256:69E5DC2D63391BF63128A891B71AB8C372CB510741F6BEB3F45000A15922FCB8
2736CCleaner.exeC:\Program Files\CCleaner\gcapi_dll.dllexecutable
MD5:F637D5D3C3A60FDDB5DD397556FE9B1D
SHA256:641B843CB6EE7538EC267212694C9EF0616B9AC9AB14A0ABD7CF020678D50B02
3748ntvdm.exeC:\Users\admin\AppData\Local\Temp\scsED70.tmptext
MD5:4C361DEA398F7AEEF49953BDC0AB4A9B
SHA256:06D61C23E6CA59B9DDAD1796ECCC42C032CD8F6F424AF6CFEE5D085D36FF7DFD
2736CCleaner.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:B0A279A76E8932B38A94E2832C6A9E45
SHA256:46477139951F4E8262D7E4E9A7BF3DBDA647AFC63D4975D91A4EB8061C4C668D
2736CCleaner.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F472B7FCD3A4C95ECA0730D9FE73D752_B6B3F8A76B67CB48DF975522878EF01Bbinary
MD5:C5B365746AA1075DB534512B53BB2C0A
SHA256:71BD142B295F01BA36DBE28A267EDB182472C1A281CD3F5E60FE372EFEE2C4F8
2736CCleaner.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\F472B7FCD3A4C95ECA0730D9FE73D752_B6B3F8A76B67CB48DF975522878EF01Bbinary
MD5:85D3A692E4927C4FD0E9E989EA1A4BD9
SHA256:99F326C7C8229FE7D22BEE9606BD8A866255B82E661A4188DCB18C0C5EC1B84C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
41
TCP/UDP connections
34
DNS requests
17
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2736
CCleaner.exe
GET
200
23.50.131.88:80
http://ncc.avast.com/ncc.txt
unknown
unknown
2736
CCleaner.exe
POST
200
34.117.223.223:443
https://analytics.ff.avast.com/receive3
unknown
24 b
unknown
2736
CCleaner.exe
POST
200
34.117.223.223:443
https://analytics.ff.avast.com/receive3
unknown
24 b
unknown
2736
CCleaner.exe
POST
200
34.117.223.223:443
https://analytics.ff.avast.com/receive3
unknown
24 b
unknown
2736
CCleaner.exe
POST
200
34.117.223.223:443
https://analytics.ff.avast.com/receive3
unknown
24 b
unknown
2736
CCleaner.exe
POST
200
34.117.223.223:443
https://analytics.ff.avast.com/receive3
unknown
24 b
unknown
2736
CCleaner.exe
POST
200
34.117.223.223:443
https://analytics.ff.avast.com/receive3
unknown
24 b
unknown
2736
CCleaner.exe
POST
200
34.117.223.223:443
https://analytics.ff.avast.com/receive3
unknown
24 b
unknown
2736
CCleaner.exe
POST
200
34.117.223.223:443
https://analytics.ff.avast.com/receive3
unknown
24 b
unknown
2736
CCleaner.exe
POST
200
34.117.223.223:443
https://analytics.ff.avast.com/receive3
unknown
24 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
1092
svchost.exe
224.0.0.252:5355
whitelisted
2736
CCleaner.exe
23.50.131.88:80
ncc.avast.com
AKAMAI-ASN1
NL
whitelisted
2736
CCleaner.exe
34.117.223.223:443
analytics.ff.avast.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
2736
CCleaner.exe
34.111.175.102:443
ip-info.ff.avast.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
2736
CCleaner.exe
34.160.176.28:443
shepherd.ff.avast.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
2736
CCleaner.exe
34.111.24.1:443
ipm-provider.ff.avast.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
2736
CCleaner.exe
23.213.161.200:443
www.ccleaner.com
AKAMAI-ASN1
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
ncc.avast.com
  • 23.50.131.88
  • 23.50.131.77
whitelisted
analytics.ff.avast.com
  • 34.117.223.223
whitelisted
www.ccleaner.com
  • 23.213.161.200
  • 23.213.161.201
whitelisted
ipm-provider.ff.avast.com
  • 34.111.24.1
whitelisted
ip-info.ff.avast.com
  • 34.111.175.102
whitelisted
shepherd.ff.avast.com
  • 34.160.176.28
whitelisted
ctldl.windowsupdate.com
  • 185.160.60.100
whitelisted
ocsp.pki.goog
  • 142.251.208.3
whitelisted
c.pki.goog
  • 142.250.185.195
whitelisted

Threats

PID
Process
Class
Message
1092
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
2736
CCleaner.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
Potential Corporate Privacy Violation
ET INFO External IP Lookup (avast .com)
Process
Message
CCleaner.exe
[2025-12-19 22:52:00.881] [error ] [settings ] [ 2736: 3132] [6000C4: 356] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
Failed to open log file 'C:\Program Files\CCleaner'
CCleaner.exe
OnLanguage - en
CCleaner.exe
[2025-12-19 22:52:01.678] [error ] [settings ] [ 2736: 1176] [9434E9: 359] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
[2025-12-19 22:52:01.725] [error ] [Burger ] [ 2736: 1176] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
[2025-12-19 22:52:01.725] [error ] [Burger ] [ 2736: 1176] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
startCheckingLicense()
CCleaner.exe
OnLanguage - en
CCleaner.exe
OnLanguage - en
CCleaner.exe
OnLanguage - en