| File name: | WinMemoryCleaner.exe |
| Full analysis: | https://app.any.run/tasks/cfbd59ee-bb7d-4c04-a564-7f1cedc7580d |
| Verdict: | Malicious activity |
| Analysis date: | September 05, 2024, 14:14:39 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | EBB6EAB585B6D62F4C3FF2AA3D30A9D0 |
| SHA1: | DD447FCB6AB02688F927438D2E520DDABB8E0DA0 |
| SHA256: | 5CF342A7237A0013FEB61B26A768C103E32C820A5E399818EEADF34DB039971E |
| SSDEEP: | 6144:5fFGDbP0o9hKm8JTxtrLLiIxAVbc6/QFsgjo/:5fuhX8JTxtmIxAmvFsgjo/ |
| .exe | | | Win64 Executable (generic) (49.4) |
|---|---|---|
| .scr | | | Windows screen saver (23.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (11.7) |
| .exe | | | Win32 Executable (generic) (8) |
| .exe | | | Generic Win/DOS Executable (3.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:12:24 10:34:38+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 212992 |
| InitializedDataSize: | 39424 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x35eda |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.8.0.0 |
| ProductVersionNumber: | 2.8.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | Windows Memory Cleaner |
| CompanyName: | Igor Mundstein |
| FileDescription: | Windows Memory Cleaner |
| FileVersion: | 2.8.0.0 |
| InternalName: | WinMemoryCleaner.exe |
| LegalCopyright: | GPL-3.0 |
| LegalTrademarks: | Igor Mundstein |
| OriginalFileName: | WinMemoryCleaner.exe |
| ProductName: | WinMemoryCleaner |
| ProductVersion: | 2.8.0.0 |
| AssemblyVersion: | 2.8.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2612 | "C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe" | C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Mundstein Integrity Level: HIGH Description: Windows Memory Cleaner Exit code: 0 Version: 2.8.0.0 Modules
| |||||||||||||||
| 5760 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | schtasks.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6020 | "schtasks" /DELETE /F /TN "Windows Memory Cleaner" | C:\Windows\System32\schtasks.exe | — | WinMemoryCleaner.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6428 | "C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe" | C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe | — | explorer.exe | |||||||||||
User: admin Company: Igor Mundstein Integrity Level: MEDIUM Description: Windows Memory Cleaner Exit code: 3221226540 Version: 2.8.0.0 Modules
| |||||||||||||||
| 6716 | "schtasks" /CREATE /F /RL HIGHEST /SC ONLOGON /TN "Windows Memory Cleaner" /TR """C:\Users\admin\AppData\Local\Temp\WinMemoryCleaner.exe""" | C:\Windows\System32\schtasks.exe | — | WinMemoryCleaner.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7072 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | schtasks.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2612) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AlwaysOnTop |
Value: 0 | |||
| (PID) Process: | (2612) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AutoOptimizationInterval |
Value: 0 | |||
| (PID) Process: | (2612) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AutoOptimizationMemoryUsage |
Value: 0 | |||
| (PID) Process: | (2612) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | AutoUpdate |
Value: 1 | |||
| (PID) Process: | (2612) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | CloseAfterOptimization |
Value: 0 | |||
| (PID) Process: | (2612) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | CloseToTheNotificationArea |
Value: 0 | |||
| (PID) Process: | (2612) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | CompactMode |
Value: 0 | |||
| (PID) Process: | (2612) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | Language |
Value: en | |||
| (PID) Process: | (2612) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | MemoryAreas |
Value: 47 | |||
| (PID) Process: | (2612) WinMemoryCleaner.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinMemoryCleaner |
| Operation: | write | Name: | OptimizationKey |
Value: 56 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.32.185.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.32.185.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
3716 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6252 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6252 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6164 | svchost.exe | 52.191.219.104:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 52.191.219.104:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 23.32.185.131:80 | www.microsoft.com | AKAMAI-AS | BR | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3260 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2612 | WinMemoryCleaner.exe | 185.199.111.133:443 | raw.githubusercontent.com | FASTLY | US | shared |
3716 | svchost.exe | 40.126.32.72:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3716 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
6164 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
raw.githubusercontent.com |
| shared |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2256 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
Process | Message |
|---|---|
WinMemoryCleaner.exe | WinMemoryCleaner.exe Information: 0 : |
WinMemoryCleaner.exe | 2024-09-05 14:14:57.160 INFORMATION [Optimize] MEMORY AREAS (1.4 seconds)
Processes Working Set (Optimized) (0.2 seconds)
System Working Set (Optimized) (0.0 seconds)
Modified Page List (Optimized) (0.7 seconds)
Standby List (Optimized) (0.3 seconds)
Combined Page List (Optimized) (0.1 seconds)
|
WinMemoryCleaner.exe | WinMemoryCleaner.exe Information: 0 : |
WinMemoryCleaner.exe | 2024-09-05 14:15:14.545 INFORMATION [Optimize] ??????? ?????? (0,7 ???????)
Processes Working Set (??????????????) (0,1 ???????)
System Working Set (??????????????) (0,0 ???????)
Modified Page List (??????????????) (0,5 ???????)
Standby List (??????????????) (0,1 ???????)
Combined Page List (??????????????) (0,1 ???????)
|