URL:

http://download.piriform.com/ccsetup535.exe?_sm_byp=iVVqPnnTk5P6r2N6

Full analysis: https://app.any.run/tasks/93b7049d-8abf-4002-8727-4cc1f1131fe9
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: February 15, 2019, 09:57:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

18539BBC5FB610CDCF5E7BE7DFC1BF13

SHA1:

2824D57079E630C6B5B8F1BB76EFD330CE04FEE1

SHA256:

188426911DF0BA6DB12CE8A2C86D6CAD9BC593EB734699236FD313CB4A289B7A

SSDEEP:

3:N1KaKElgGRWARQ9QUq6b9IQ5H:Ca5lQaCTH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • ccsetup535.exe (PID: 3300)
      • CCleaner.exe (PID: 3160)
      • CCleaner.exe (PID: 4048)
      • CCleaner.exe (PID: 3724)
    • Downloads executable files from the Internet

      • chrome.exe (PID: 2972)
    • Application was dropped or rewritten from another process

      • ccsetup535.exe (PID: 4016)
      • CCleaner.exe (PID: 3160)
      • CCleaner.exe (PID: 4008)
      • CCleaner.exe (PID: 4048)
      • ccsetup535.exe (PID: 3300)
      • CCleaner.exe (PID: 756)
      • CCleaner.exe (PID: 3724)
    • Loads the Task Scheduler COM API

      • CCleaner.exe (PID: 4008)
      • CCleaner.exe (PID: 4048)
      • CCleaner.exe (PID: 756)
    • Changes the autorun value in the registry

      • CCleaner.exe (PID: 4048)
    • Loads dropped or rewritten executable

      • ccsetup535.exe (PID: 3300)
  • SUSPICIOUS

    • Searches for installed software

      • ccsetup535.exe (PID: 3300)
    • Reads Internet Cache Settings

      • ccsetup535.exe (PID: 3300)
    • Creates files in the user directory

      • ccsetup535.exe (PID: 3300)
      • CCleaner.exe (PID: 3160)
      • CCleaner.exe (PID: 3724)
    • Reads the cookies of Mozilla Firefox

      • ccsetup535.exe (PID: 3300)
      • CCleaner.exe (PID: 3160)
    • Creates a software uninstall entry

      • ccsetup535.exe (PID: 3300)
    • Reads the cookies of Google Chrome

      • ccsetup535.exe (PID: 3300)
      • CCleaner.exe (PID: 3160)
    • Modifies the open verb of a shell class

      • ccsetup535.exe (PID: 3300)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 2972)
      • ccsetup535.exe (PID: 3300)
    • Reads internet explorer settings

      • CCleaner.exe (PID: 3160)
      • CCleaner.exe (PID: 4048)
      • ccsetup535.exe (PID: 3300)
      • CCleaner.exe (PID: 3724)
    • Starts Internet Explorer

      • ccsetup535.exe (PID: 3300)
      • CCleaner.exe (PID: 3160)
    • Low-level read access rights to disk partition

      • CCleaner.exe (PID: 3160)
      • ccsetup535.exe (PID: 3300)
      • CCleaner.exe (PID: 3724)
    • Application launched itself

      • CCleaner.exe (PID: 3160)
    • Starts application with an unusual extension

      • ccsetup535.exe (PID: 3300)
  • INFO

    • Application launched itself

      • chrome.exe (PID: 2972)
      • iexplore.exe (PID: 2196)
    • Reads Internet Cache Settings

      • chrome.exe (PID: 2972)
      • iexplore.exe (PID: 3648)
      • iexplore.exe (PID: 2372)
    • Reads settings of System Certificates

      • chrome.exe (PID: 2972)
      • CCleaner.exe (PID: 3160)
      • CCleaner.exe (PID: 3724)
    • Changes internet zones settings

      • iexplore.exe (PID: 2196)
      • iexplore.exe (PID: 4040)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3648)
      • iexplore.exe (PID: 2372)
    • Creates files in the user directory

      • iexplore.exe (PID: 3648)
      • iexplore.exe (PID: 2372)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3648)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3648)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
63
Monitored processes
24
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs ccsetup535.exe no specs ccsetup535.exe ns9781.tmp no specs ping.exe no specs chrome.exe no specs nsb51c.tmp no specs ping.exe no specs ccleaner.exe no specs iexplore.exe iexplore.exe ccleaner.exe ccleaner.exe iexplore.exe iexplore.exe chrome.exe no specs chrome.exe no specs ccleaner.exe no specs ccleaner.exe

Process information

PID
CMD
Path
Indicators
Parent process
756"C:\Program Files\CCleaner\CCleaner.exe" C:\Program Files\CCleaner\CCleaner.exeexplorer.exe
User:
admin
Company:
Piriform Ltd
Integrity Level:
MEDIUM
Description:
CCleaner
Exit code:
0
Version:
5, 35, 0, 6210
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2196"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
ccsetup535.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2372"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4040 CREDAT:79873C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2388"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=880,1271383365220138652,16944992696421106841,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=BD67C2A42C990FE2FFDD192E32ADD34A --mojo-platform-channel-handle=1136 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
68.0.3440.106
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2428"C:\Users\admin\AppData\Local\Temp\nsw8FB0.tmp\ns9781.tmp" ping -n 1 -w 1000 www.piriform.comC:\Users\admin\AppData\Local\Temp\nsw8FB0.tmp\ns9781.tmpccsetup535.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsw8fb0.tmp\ns9781.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2628"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=880,1271383365220138652,16944992696421106841,131072 --enable-features=PasswordImport --disable-gpu-sandbox --gpu-preferences=KAAAAAAAAACAAwBAAQAAAAAAAAAAAGAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAKAAAAEAAAAAAAAAAAAAAACwAAABAAAAAAAAAAAQAAAAoAAAAQAAAAAAAAAAEAAAALAAAA --service-request-channel-token=A411DCEA7DE3D9608C4BFCE2093B9685 --mojo-platform-channel-handle=3760 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
68.0.3440.106
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2648"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=880,1271383365220138652,16944992696421106841,131072 --enable-features=PasswordImport --service-pipe-token=6594FA022F0CF9BA49D6BA57F21202F0 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=6594FA022F0CF9BA49D6BA57F21202F0 --renderer-client-id=4 --mojo-platform-channel-handle=1892 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
68.0.3440.106
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2912"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2976 --on-initialized-event-handle=304 --parent-handle=308 /prefetch:6C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
68.0.3440.106
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2972"C:\Program Files\Google\Chrome\Application\chrome.exe" http://download.piriform.com/ccsetup535.exe?_sm_byp=iVVqPnnTk5P6r2N6C:\Program Files\Google\Chrome\Application\chrome.exe
explorer.exe
User:
admin
Company:
Google Inc.
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
3221225547
Version:
68.0.3440.106
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\68.0.3440.106\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3000ping -n 1 -w 1000 www.piriform.comC:\Windows\system32\ping.exens9781.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
Total events
3 322
Read events
2 628
Write events
678
Delete events
16

Modification events

(PID) Process:(2972) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2972) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2972) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2912) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:writeName:2972-13194698263070625
Value:
259
(PID) Process:(2972) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:dr
Value:
1
(PID) Process:(2972) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome
Operation:writeName:UsageStatsInSample
Value:
0
(PID) Process:(2972) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:3516-13180984670829101
Value:
0
(PID) Process:(2972) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(2972) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
Operation:delete valueName:2972-13194698263070625
Value:
259
(PID) Process:(2972) chrome.exeKey:HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
Operation:writeName:metricsid
Value:
Executable files
130
Suspicious files
37
Text files
165
Unknown types
21

Dropped files

PID
Process
Filename
Type
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\613080d5-4450-41f3-9ca3-79e428738558.tmp
MD5:
SHA256:
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000016.dbtmp
MD5:
SHA256:
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\000016.dbtmp
MD5:
SHA256:
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\3c7c929e-300d-4230-b323-560f42cc0bcf.tmp
MD5:
SHA256:
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\in_progress_download_metadata_store
MD5:
SHA256:
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ca69c4cb-2147-4e2a-9c7f-e5aee55e1e8f.tmp
MD5:
SHA256:
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF246bf9.TMPtext
MD5:
SHA256:
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Versiontext
MD5:
SHA256:
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.oldtext
MD5:
SHA256:
2972chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.oldtext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
83
DNS requests
28
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3648
iexplore.exe
GET
301
151.101.0.64:80
http://www.piriform.com/go/app_releasenotes?p=1&v=5.35.6210&l=1033&b=1&a=0
US
whitelisted
3160
CCleaner.exe
GET
301
151.101.0.64:80
http://www.piriform.com/auto?a=0&p=cc&v=5.35.6210&l=1033&lk=&mk=IJR6-W5SV-5KYR-QBZD-6BY4-RN5Z-WAV9-RVK2-VJCA&o=6.1W3&au=1&mx=97B7721C4994E2556FF6A439510F665DB45337A341A47E15F4997584423BF714&gu=00000000-0000-4000-8000-d6f7f2be5127
US
whitelisted
3724
CCleaner.exe
GET
301
151.101.0.64:80
http://www.piriform.com/auto?a=0&p=cc&v=5.35.6210&l=1033&lk=&mk=IJR6-W5SV-5KYR-QBZD-6BY4-RN5Z-WAV9-RVK2-VJCA&o=6.1W3&au=1&mx=97B7721C4994E2556FF6A439510F665DB45337A341A47E15F4997584423BF714&gu=00000000-0000-4000-8000-d6f7f2be5127
US
whitelisted
2372
iexplore.exe
GET
301
151.101.0.64:80
http://www.piriform.com/ccleaner/update?a=0&v=5.35.6210&l=1033&o=6.1W3&t=4&au=1
US
whitelisted
2972
chrome.exe
GET
200
52.222.150.220:80
http://download.piriform.com/ccsetup535.exe?_sm_byp=iVVqPnnTk5P6r2N6
US
executable
9.36 Mb
whitelisted
4040
iexplore.exe
GET
200
13.107.21.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
2196
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3300
ccsetup535.exe
GET
200
151.101.0.64:80
http://service.piriform.com/installcheck.aspx?p=1&v=5.35.6210&vx=5.35.6210&l=1033&b=1&o=6.1W3&g=2&i=1&a=0&e=0&n=ccsetup535.exe&id=003&mk=IJR6-W5SV-5KYR-QBZD-6BY4-RN5Z-WAV9-RVK2-VJCA&mx=97B7721C4994E2556FF6A439510F665DB45337A341A47E15F4997584423BF714&gu=00000000-0000-4000-8000-d6f7f2be5127
US
text
4 b
whitelisted
3648
iexplore.exe
GET
200
151.139.237.73:80
http://s1.pir.fm/pf/logos--DA8LAgMPCAQ/ccleaner-logo--small.jpg
US
image
6.34 Kb
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2972
chrome.exe
52.222.150.220:80
download.piriform.com
Amazon.com, Inc.
US
suspicious
2972
chrome.exe
172.217.18.110:443
sb-ssl.google.com
Google Inc.
US
whitelisted
2972
chrome.exe
172.217.16.131:443
ssl.gstatic.com
Google Inc.
US
whitelisted
3300
ccsetup535.exe
151.101.0.64:443
www.piriform.com
Fastly
US
whitelisted
3300
ccsetup535.exe
151.101.0.64:80
www.piriform.com
Fastly
US
whitelisted
2196
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3648
iexplore.exe
151.101.0.64:80
www.piriform.com
Fastly
US
whitelisted
2972
chrome.exe
216.58.207.67:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
2972
chrome.exe
172.217.22.35:443
www.gstatic.com
Google Inc.
US
whitelisted
3160
CCleaner.exe
151.101.0.64:80
www.piriform.com
Fastly
US
whitelisted

DNS requests

Domain
IP
Reputation
clientservices.googleapis.com
  • 216.58.207.67
whitelisted
download.piriform.com
  • 52.222.150.220
  • 52.222.150.28
  • 52.222.150.146
  • 52.222.150.16
whitelisted
www.gstatic.com
  • 172.217.22.35
whitelisted
accounts.google.com
  • 216.58.206.13
shared
sb-ssl.google.com
  • 172.217.18.110
whitelisted
ssl.gstatic.com
  • 172.217.16.131
whitelisted
www.piriform.com
  • 151.101.0.64
  • 151.101.64.64
  • 151.101.128.64
  • 151.101.192.64
whitelisted
service.piriform.com
  • 151.101.0.64
  • 151.101.64.64
  • 151.101.128.64
  • 151.101.192.64
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.ccleaner.com
  • 151.101.2.202
  • 151.101.66.202
  • 151.101.130.202
  • 151.101.194.202
whitelisted

Threats

PID
Process
Class
Message
2972
chrome.exe
Potentially Bad Traffic
ET POLICY Executable served from Amazon S3
2972
chrome.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info