| File name: | PowerISO8-x64.exe |
| Full analysis: | https://app.any.run/tasks/3025df33-6f85-47c5-86e3-52f457d45035 |
| Verdict: | Malicious activity |
| Analysis date: | October 05, 2023, 14:07:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 7513A757A9B43CEDA8D7614DCC73957E |
| SHA1: | 26F283F8B0E4900974A629EC9B567DB989186D77 |
| SHA256: | 29A96E7B461B21FE4C2A037798AAA9ADCE3B047A1A81E486352A090E1DBA2656 |
| SSDEEP: | 98304:f4lC2jLjuDROkdZ+dfEt3zvhl9fLBYIucektZlTQiXlKauUu4rjwpszLubfY6qWy:hNu1QvHv |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:12:16 01:50:53+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26112 |
| InitializedDataSize: | 141824 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x350d |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 8.6.0.0 |
| ProductVersionNumber: | 8.6.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Power Software Ltd |
| FileDescription: | PowerISO Setup |
| FileVersion: | 8.6.0.0 |
| LegalCopyright: | Copyright(c) 2004-2023 |
| ProductName: | PowerISO Setup |
| ProductVersion: | 8.6.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 604 | "C:\Users\admin\AppData\Local\Temp\PowerISO8-x64.exe" | C:\Users\admin\AppData\Local\Temp\PowerISO8-x64.exe | explorer.exe | ||||||||||||
User: admin Company: Power Software Ltd Integrity Level: HIGH Description: PowerISO Setup Exit code: 2 Version: 8.6.0.0 Modules
| |||||||||||||||
| 2616 | dummy /ccupdate | C:\Program Files\CCleaner\CCleaner.exe | CCUpdate.exe | ||||||||||||
User: SYSTEM Company: Piriform Software Ltd Integrity Level: SYSTEM Description: CCleaner Exit code: 0 Version: 6.14.0.10584 Modules
| |||||||||||||||
| 3008 | "C:\Program Files\CCleaner\CCUpdate.exe" | C:\Program Files\CCleaner\CCUpdate.exe | taskeng.exe | ||||||||||||
User: SYSTEM Company: Piriform Software Ltd Integrity Level: SYSTEM Description: CCleaner CCleaner emergency updater Exit code: 0 Version: 23.3.12.0 Modules
| |||||||||||||||
| 3628 | "C:\Users\admin\AppData\Local\Temp\PowerISO8-x64.exe" | C:\Users\admin\AppData\Local\Temp\PowerISO8-x64.exe | — | explorer.exe | |||||||||||
User: admin Company: Power Software Ltd Integrity Level: MEDIUM Description: PowerISO Setup Exit code: 3221226540 Version: 8.6.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3008) CCUpdate.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2616) CCleaner.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3008 | CCUpdate.exe | C:\Program Files\CCleaner\Setup\0e9f8492-70a5-4861-b7b7-e73c61c353ed.xml | xml | |
MD5:F9326B00FBE652751CF4782BBDB76EB0 | SHA256:D1163FFADD89832040C2F9D2A39605CCD227A39CC80D72A2819FF3F8795BC639 | |||
| 3008 | CCUpdate.exe | C:\Program Files\CCleaner\Setup\d8799e43-7768-4b4c-97b8-effac9ce9fe0.ini | text | |
MD5:2AF9F69DF769F876F6E02DA18E966020 | SHA256:473D48A44A348F6C547AEFD2C60DD4B9DE0092E1FB94A7611BDD374783EF3B2C | |||
| 3008 | CCUpdate.exe | C:\Program Files\CCleaner\Setup\46c2098e-983d-4571-b28b-c624e82108fe\ccleaner_update_helper.exe | executable | |
MD5:A8972ED3F3B9C685FCE499DC5BF546C1 | SHA256:162FF9CA559E82B0F3FB081768695916F79650E60531CAC7167EC95E8163105C | |||
| 3008 | CCUpdate.exe | C:\Program Files\CCleaner\Setup\46c2098e-983d-4571-b28b-c624e82108fe\update.xml | xml | |
MD5:95AFA91E459D4E8EBE1E5CDABA96E621 | SHA256:2874AED0490885680F7911DE90B44CE956C8DE27476EFA047D142D1DEB546164 | |||
| 3008 | CCUpdate.exe | C:\Program Files\CCleaner\ccleaner_update_helper.exe | executable | |
MD5:A8972ED3F3B9C685FCE499DC5BF546C1 | SHA256:162FF9CA559E82B0F3FB081768695916F79650E60531CAC7167EC95E8163105C | |||
| 604 | PowerISO8-x64.exe | C:\Users\admin\AppData\Local\Temp\nsz1160.tmp | binary | |
MD5:77EE3D675799B1F219B066E0D24906BE | SHA256:90EE711CD575B4F1E62CA2A4659DAF5417E308C18DA9418FBBB397543B32F3BF | |||
| 604 | PowerISO8-x64.exe | C:\Users\admin\AppData\Local\Temp\nso1170.tmp\System.dll | executable | |
MD5:8CF2AC271D7679B1D68EEFC1AE0C5618 | SHA256:6950991102462D84FDC0E3B0AE30C95AF8C192F77CE3D78E8D54E6B22F7C09BA | |||
| 3008 | CCUpdate.exe | C:\Program Files\CCleaner\Setup\08cf39d4-488c-4b36-b01a-9a30e3323940.cab | compressed | |
MD5:604E84A6639CC605DB06ED57FD3C7F3D | SHA256:EA397887F59EE8B4C942A9BFF4CB045B96B0AC8BF323E64ABEB7D16C67B07EF1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3008 | CCUpdate.exe | HEAD | 200 | 23.48.23.40:80 | http://emupdate.avcdn.net/files/emupdate/pong.txt | unknown | — | — | unknown |
3008 | CCUpdate.exe | GET | 200 | 23.48.23.59:80 | http://ccleaner.tools.avcdn.net/tools/ccleaner/update/updates.xml | unknown | xml | 1.58 Kb | unknown |
3008 | CCUpdate.exe | GET | 200 | 23.48.23.59:80 | http://ccleaner.tools.avcdn.net/tools/ccleaner/update/ccupdate036.cab | unknown | compressed | 414 Kb | unknown |
3008 | CCUpdate.exe | GET | 200 | 23.48.23.59:80 | http://ccleaner.tools.avcdn.net/tools/ccleaner/update/patches.ini | unknown | text | 170 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3008 | CCUpdate.exe | 34.149.149.62:443 | ip-info.ff.avast.com | GOOGLE | US | unknown |
3008 | CCUpdate.exe | 23.48.23.40:80 | emupdate.avcdn.net | Akamai International B.V. | DE | unknown |
3008 | CCUpdate.exe | 23.48.23.59:80 | ccleaner.tools.avcdn.net | Akamai International B.V. | DE | unknown |
2616 | CCleaner.exe | 34.117.223.223:443 | analytics.ff.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
ip-info.ff.avast.com |
| whitelisted |
emupdate.avcdn.net |
| whitelisted |
ccleaner.tools.avcdn.net |
| whitelisted |
analytics.ff.avast.com |
| whitelisted |
Process | Message |
|---|---|
CCleaner.exe | [2023-10-05 14:07:35.431] [error ] [settings ] [ 2616: 948] [6000C4: 356] Failed to get program directory
Exception: Unable to determine program folder of product 'piriform-cc'!
Code: 0x000000c0 (192)
|
CCleaner.exe | Failed to open log file 'C:\Program Files\CCleaner' |
CCleaner.exe | [2023-10-05 14:07:35.509] [error ] [lil ] [ 2616: 948] [81E517: 189] ~rLEQYNz+MoTE+7IlsQUVha6xC2aMmy2SyO/mJa1LQsSzsB5nk8kzx9HqtC2zDlvAr95fM9ybaseBq+Zs/ksPhf30XzPcm2rHgavmbP5LD4X99F8z3Jtqx4Gr5mz+Sw+F/fRfM9ybaseBq+Zs/ksPhf30PHyY3nDHkfP2fO5bH5Xo4187xIxj
|
CCleaner.exe | [2023-10-05 14:07:35.509] [error ] [lil ] [ 2616: 948] [81E517: 189] ~radfVZ3SJpLT7uYoqxlGy7r0Fn2Vzw==
|
CCleaner.exe | [2023-10-05 14:07:35.509] [error ] [lif_utils ] [ 2616: 948] [226DB9: 571] ~ubhfYJnPP5eB7LMluktG1v25Hn2Y2j6I0/LmPL8ZTsi4oBph
|