| File name: | WinMemoryCleaner.exe |
| Full analysis: | https://app.any.run/tasks/8e618b20-eb19-4a97-8695-e29efdaa41fa |
| Verdict: | Malicious activity |
| Analysis date: | February 04, 2025, 22:02:41 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections |
| MD5: | EBB6EAB585B6D62F4C3FF2AA3D30A9D0 |
| SHA1: | DD447FCB6AB02688F927438D2E520DDABB8E0DA0 |
| SHA256: | 5CF342A7237A0013FEB61B26A768C103E32C820A5E399818EEADF34DB039971E |
| SSDEEP: | 6144:5fFGDbP0o9hKm8JTxtrLLiIxAVbc6/QFsgjo/:5fuhX8JTxtmIxAmvFsgjo/ |
| .exe | | | Win64 Executable (generic) (49.4) |
|---|---|---|
| .scr | | | Windows screen saver (23.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (11.7) |
| .exe | | | Win32 Executable (generic) (8) |
| .exe | | | Generic Win/DOS Executable (3.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:12:24 10:34:38+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 212992 |
| InitializedDataSize: | 39424 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x35eda |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.8.0.0 |
| ProductVersionNumber: | 2.8.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | Windows Memory Cleaner |
| CompanyName: | Igor Mundstein |
| FileDescription: | Windows Memory Cleaner |
| FileVersion: | 2.8.0.0 |
| InternalName: | WinMemoryCleaner.exe |
| LegalCopyright: | GPL-3.0 |
| LegalTrademarks: | Igor Mundstein |
| OriginalFileName: | WinMemoryCleaner.exe |
| ProductName: | WinMemoryCleaner |
| ProductVersion: | 2.8.0.0 |
| AssemblyVersion: | 2.8.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4704 | "C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe" | C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe | — | explorer.exe | |||||||||||
User: admin Company: Igor Mundstein Integrity Level: MEDIUM Description: Windows Memory Cleaner Exit code: 3221226540 Version: 2.8.0.0 Modules
| |||||||||||||||
| 4716 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | schtasks.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5540 | "schtasks" /CREATE /F /RL HIGHEST /SC ONLOGON /TN "Windows Memory Cleaner" /TR """C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe""" | C:\Windows\System32\schtasks.exe | — | WinMemoryCleaner.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6212 | "C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe" | C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Mundstein Integrity Level: HIGH Description: Windows Memory Cleaner Version: 2.8.0.0 Modules
| |||||||||||||||
| 6296 | "schtasks" /DELETE /F /TN "Windows Memory Cleaner" | C:\Windows\System32\schtasks.exe | — | WinMemoryCleaner.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6304 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | schtasks.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6212) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AlwaysOnTop |
Value: 0 | |||
| (PID) Process: | (6212) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AutoOptimizationInterval |
Value: 0 | |||
| (PID) Process: | (6212) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AutoOptimizationMemoryUsage |
Value: 0 | |||
| (PID) Process: | (6212) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AutoUpdate |
Value: 1 | |||
| (PID) Process: | (6212) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | CloseAfterOptimization |
Value: 0 | |||
| (PID) Process: | (6212) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | CloseToTheNotificationArea |
Value: 0 | |||
| (PID) Process: | (6212) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | CompactMode |
Value: 0 | |||
| (PID) Process: | (6212) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | Language |
Value: en | |||
| (PID) Process: | (6212) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | MemoryAreas |
Value: 47 | |||
| (PID) Process: | (6212) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | OptimizationKey |
Value: 56 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1176 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
7100 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7100 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
3508 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
6404 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6212 | WinMemoryCleaner.exe | 185.199.109.133:443 | raw.githubusercontent.com | FASTLY | US | whitelisted |
5064 | SearchApp.exe | 2.16.204.161:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
1176 | svchost.exe | 20.190.160.130:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
640 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1076 | svchost.exe | 23.35.238.131:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 2.21.65.132:443 | www.bing.com | Akamai International B.V. | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
raw.githubusercontent.com |
| whitelisted |
www.bing.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2192 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
Process | Message |
|---|---|
WinMemoryCleaner.exe | 2025-02-04 22:03:17.748 INFORMATION [Optimize] MEMORY AREAS (5.3 seconds)
Processes Working Set (Optimized) (0.5 seconds)
System Working Set (Optimized) (0.1 seconds)
Modified Page List (Optimized) (2.8 seconds)
Standby List (Optimized) (1.0 seconds)
Combined Page List (Optimized) (0.9 seconds)
|
WinMemoryCleaner.exe | WinMemoryCleaner.exe Information: 0 : |
WinMemoryCleaner.exe | WinMemoryCleaner.exe Information: 0 : |
WinMemoryCleaner.exe | 2025-02-04 22:03:46.389 INFORMATION [Optimize] MEMORY AREAS (0.8 seconds)
Processes Working Set (Optimized) (0.1 seconds)
System Working Set (Optimized) (0.0 seconds)
Modified Page List (Optimized) (0.4 seconds)
Standby List (Optimized) (0.1 seconds)
Combined Page List (Optimized) (0.1 seconds)
|
WinMemoryCleaner.exe | WinMemoryCleaner.exe Information: 0 : |
WinMemoryCleaner.exe | 2025-02-04 22:03:57.373 INFORMATION [Optimize] MEMORY AREAS (0.5 seconds)
Processes Working Set (Optimized) (0.1 seconds)
System Working Set (Optimized) (0.0 seconds)
Modified Page List (Optimized) (0.2 seconds)
Standby List (Optimized) (0.1 seconds)
Combined Page List (Optimized) (0.1 seconds)
|