| download: | /attachments/1386032122074103888/1386032196074209434/WinMemoryCleaner.exe |
| Full analysis: | https://app.any.run/tasks/4a3f0f9b-59b1-4061-a846-ff383d4d739b |
| Verdict: | Malicious activity |
| Analysis date: | June 21, 2025, 17:55:07 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections |
| MD5: | EBB6EAB585B6D62F4C3FF2AA3D30A9D0 |
| SHA1: | DD447FCB6AB02688F927438D2E520DDABB8E0DA0 |
| SHA256: | 5CF342A7237A0013FEB61B26A768C103E32C820A5E399818EEADF34DB039971E |
| SSDEEP: | 6144:5fFGDbP0o9hKm8JTxtrLLiIxAVbc6/QFsgjo/:5fuhX8JTxtmIxAmvFsgjo/ |
| .exe | | | Win64 Executable (generic) (49.4) |
|---|---|---|
| .scr | | | Windows screen saver (23.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (11.7) |
| .exe | | | Win32 Executable (generic) (8) |
| .exe | | | Generic Win/DOS Executable (3.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:12:24 10:34:38+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 212992 |
| InitializedDataSize: | 39424 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x35eda |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.8.0.0 |
| ProductVersionNumber: | 2.8.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | Windows Memory Cleaner |
| CompanyName: | Igor Mundstein |
| FileDescription: | Windows Memory Cleaner |
| FileVersion: | 2.8.0.0 |
| InternalName: | WinMemoryCleaner.exe |
| LegalCopyright: | GPL-3.0 |
| LegalTrademarks: | Igor Mundstein |
| OriginalFileName: | WinMemoryCleaner.exe |
| ProductName: | WinMemoryCleaner |
| ProductVersion: | 2.8.0.0 |
| AssemblyVersion: | 2.8.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1296 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1332 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2680 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | schtasks.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3956 | "C:\WINDOWS\system32\mmc.exe" "C:\WINDOWS\system32\taskschd.msc" /s | C:\Windows\System32\mmc.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Management Console Exit code: 3221226540 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4916 | "schtasks" /DELETE /F /TN "Windows Memory Cleaner" | C:\Windows\System32\schtasks.exe | — | WinMemoryCleaner.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5644 | "C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe" | C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Mundstein Integrity Level: HIGH Description: Windows Memory Cleaner Exit code: 0 Version: 2.8.0.0 Modules
| |||||||||||||||
| 6412 | "C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe" | C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe | — | explorer.exe | |||||||||||
User: admin Company: Igor Mundstein Integrity Level: MEDIUM Description: Windows Memory Cleaner Exit code: 3221226540 Version: 2.8.0.0 Modules
| |||||||||||||||
| 6896 | "C:\WINDOWS\system32\mmc.exe" "C:\WINDOWS\system32\taskschd.msc" /s | C:\Windows\System32\mmc.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Management Console Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5644) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AlwaysOnTop |
Value: 0 | |||
| (PID) Process: | (5644) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AutoOptimizationInterval |
Value: 0 | |||
| (PID) Process: | (5644) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AutoOptimizationMemoryUsage |
Value: 0 | |||
| (PID) Process: | (5644) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AutoUpdate |
Value: 1 | |||
| (PID) Process: | (5644) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | CloseAfterOptimization |
Value: 0 | |||
| (PID) Process: | (5644) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | CloseToTheNotificationArea |
Value: 0 | |||
| (PID) Process: | (5644) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | CompactMode |
Value: 0 | |||
| (PID) Process: | (5644) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | Language |
Value: en | |||
| (PID) Process: | (5644) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | MemoryAreas |
Value: 47 | |||
| (PID) Process: | (5644) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | OptimizationKey |
Value: 56 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6896 | mmc.exe | C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd | xml | |
MD5:45C6493682B2703A5040BCF6AA42DBF7 | SHA256:153F8A8B8E0BEBCC46CD9822A1B41F15B86AF5B05027C5870870BB005592A870 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5012 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 184.24.77.5:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5328 | SearchApp.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
3840 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5328 | SearchApp.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
3840 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
2940 | svchost.exe | GET | 200 | 23.209.209.135:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1268 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3924 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5644 | WinMemoryCleaner.exe | 185.199.109.133:443 | raw.githubusercontent.com | FASTLY | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5012 | svchost.exe | 40.126.32.140:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5012 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2336 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
1268 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
raw.githubusercontent.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
www.bing.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2200 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
Process | Message |
|---|---|
WinMemoryCleaner.exe | 2025-06-21 17:55:25.494 INFORMATION [Optimize] MEMORY AREAS (1.9 seconds)
Processes Working Set (Optimized) (0.3 seconds)
System Working Set (Optimized) (0.0 seconds)
Modified Page List (Optimized) (1.1 seconds)
Standby List (Optimized) (0.4 seconds)
Combined Page List (Optimized) (0.1 seconds)
|
WinMemoryCleaner.exe | WinMemoryCleaner.exe Information: 0 : |
mmc.exe | Constructor: Microsoft.TaskScheduler.SnapIn.TaskSchedulerSnapIn
|
mmc.exe | OnInitialize: Microsoft.TaskScheduler.SnapIn.TaskSchedulerSnapIn
|
mmc.exe | AddIcons: Microsoft.TaskScheduler.SnapIn.TaskSchedulerSnapIn
|
mmc.exe | ProcessCommandLineArguments: Microsoft.TaskScheduler.SnapIn.TaskSchedulerSnapIn
|