File name:

0bf26e46f3fbdf0f24e81882104b439e.jpg

Full analysis: https://app.any.run/tasks/ea4ff34d-0634-43ac-8095-2a0d4eb3f426
Verdict: Malicious activity
Analysis date: April 13, 2025, 12:50:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
evasion
Indicators:
MIME: image/jpeg
File info: JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=0], baseline, precision 8, 736x736, components 3
MD5:

4244348A2B4C539AF0F5BE0B368C4608

SHA1:

B1A4BF13804D14EC5E7FAD33AB46F7046B75C76D

SHA256:

63AD9E9D7D812A8D92BED3EFF626F5FD8600F45F8EA13CAF92AA73EB0BDE6D22

SSDEEP:

384:NpM/0HccLTi91bBMoBnbtN9E3AcmbLJOkQ9xrFsgk9Q4ZDIQl3TbYyqt:7M/ucakvB2mRO/riJ9fDfl3TpQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • CCleaner64.exe (PID: 7252)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • CCleaner64.exe (PID: 7956)
      • CCleaner64.exe (PID: 8040)
    • Application launched itself

      • CCleaner64.exe (PID: 7956)
      • CCleaner64.exe (PID: 8040)
    • Reads security settings of Internet Explorer

      • CCleaner64.exe (PID: 7956)
      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
    • Executable content was dropped or overwritten

      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
    • Reads Internet Explorer settings

      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
    • Checks for external IP

      • CCleaner64.exe (PID: 8040)
    • The process verifies whether the antivirus software is installed

      • CCleaner64.exe (PID: 7252)
    • Searches for installed software

      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
  • INFO

    • Manual execution by a user

      • CCleaner64.exe (PID: 7956)
      • Taskmgr.exe (PID: 3332)
      • Taskmgr.exe (PID: 1280)
      • mspaint.exe (PID: 6028)
    • Checks supported languages

      • CCleaner64.exe (PID: 7956)
      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
    • Process checks computer location settings

      • CCleaner64.exe (PID: 7956)
      • CCleaner64.exe (PID: 8040)
    • Reads Environment values

      • CCleaner64.exe (PID: 7956)
      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
    • Reads the computer name

      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7956)
      • CCleaner64.exe (PID: 7252)
    • Reads the machine GUID from the registry

      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
    • The sample compiled with english language support

      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
    • Reads product name

      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
    • Reads CPU info

      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
    • Reads the software policy settings

      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
      • slui.exe (PID: 7528)
    • Creates files or folders in the user directory

      • CCleaner64.exe (PID: 8040)
    • Checks proxy server information

      • CCleaner64.exe (PID: 8040)
    • Creates files in the program directory

      • CCleaner64.exe (PID: 8040)
      • CCleaner64.exe (PID: 7252)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 1280)
    • Detects AutoHotkey samples (YARA)

      • CCleaner64.exe (PID: 8040)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jpg | JFIF-EXIF JPEG Bitmap (55.5)
.jpg | JPEG bitmap (33.3)
.mp3 | MP3 audio (11.1)

EXIF

ICC_Profile

ProfileCMMType: -
ProfileVersion: 4.3.0
ProfileClass: Display Device Profile
ColorSpaceData: RGB
ProfileConnectionSpace: XYZ
ProfileDateTime: 2016:01:01 00:00:00
ProfileFileSignature: acsp
PrimaryPlatform: Unknown ()
CMMFlags: Not Embedded, Independent
DeviceManufacturer: -
DeviceModel: -
DeviceAttributes: Reflective, Glossy, Positive, Color
RenderingIntent: Media-Relative Colorimetric
ConnectionSpaceIlluminant: 0.9642 1 0.82491
ProfileCreator: -
ProfileID: -
ProfileDescription: sRGB
RedMatrixColumn: 0.43607 0.22249 0.01392
GreenMatrixColumn: 0.38515 0.71687 0.09708
BlueMatrixColumn: 0.14307 0.06061 0.7141
MediaWhitePoint: 0.9642 1 0.82491
RedTRC: (Binary data 40 bytes, use -b option to extract)
GreenTRC: (Binary data 40 bytes, use -b option to extract)
BlueTRC: (Binary data 40 bytes, use -b option to extract)
ProfileCopyright: Google Inc. 2016

Composite

ImageSize: 736x736
Megapixels: 0.542
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
10
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rundll32.exe no specs sppextcomobj.exe no specs slui.exe ccleaner64.exe no specs ccleaner64.exe ccleaner64.exe taskmgr.exe no specs taskmgr.exe slui.exe no specs mspaint.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1280"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
3332"C:\WINDOWS\system32\taskmgr.exe" /4C:\Windows\System32\Taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Manager
Exit code:
3221226540
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
4724C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6028"C:\WINDOWS\system32\mspaint.exe" "C:\Users\admin\Desktop\basisseen.jpg"C:\Windows\System32\mspaint.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Paint
Exit code:
0
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mspaint.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7252"C:\Program Files\CCleaner\CCleaner64.exe" /monitorC:\Program Files\CCleaner\CCleaner64.exe
CCleaner64.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
6.20.0.10897
Modules
Images
c:\program files\ccleaner\ccleaner64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
7380"C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen C:\Users\admin\Downloads\0bf26e46f3fbdf0f24e81882104b439e.jpgC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7496C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7528"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7956"C:\Program Files\CCleaner\CCleaner64.exe" C:\Program Files\CCleaner\CCleaner64.exeexplorer.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
CCleaner
Exit code:
0
Version:
6.20.0.10897
Modules
Images
c:\program files\ccleaner\ccleaner64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
8040"C:\Program Files\CCleaner\CCleaner64.exe" /uacC:\Program Files\CCleaner\CCleaner64.exe
CCleaner64.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
6.20.0.10897
Modules
Images
c:\program files\ccleaner\ccleaner64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
Total events
20 237
Read events
20 055
Write events
126
Delete events
56

Modification events

(PID) Process:(7380) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Photo Viewer\Viewer
Operation:writeName:MainWndPos
Value:
6000000033000000A00400007502000000000000
(PID) Process:(8040) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:writeName:DAST
Value:
04/13/2025 12:51:07
(PID) Process:(8040) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:writeName:T8062
Value:
0
(PID) Process:(8040) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:writeName:UpdateBackground
Value:
1
(PID) Process:(8040) CCleaner64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
Operation:writeName:SystemRestorePointCreationFrequency
Value:
0
(PID) Process:(8040) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:writeName:NumOfOutdatedDrivers
Value:
0
(PID) Process:(8040) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:CCleaner PostInstall
Value:
(PID) Process:(8040) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:writeName:FTU
Value:
06/02/2024|3|1
(PID) Process:(8040) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:delete valueName:GUID
Value:
(PID) Process:(8040) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:delete valueName:GD
Value:
Executable files
5
Suspicious files
14
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
8040CCleaner64.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ccc0fa1b9f86f7b3.customDestinations-ms~RF10d90c.TMPbinary
MD5:715D03F2C851242AE02F082C92170337
SHA256:52F9047E9A072554A68045FD0215B8484C2D6D758FEE82543FBAA7C7F7D163D9
8040CCleaner64.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\ccupdate634_free[1].exe
MD5:
SHA256:
8040CCleaner64.exeC:\Program Files\CCleaner\temp_ccupdate\ccupdate634_free.exe
MD5:
SHA256:
8040CCleaner64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:759916124352EBECD0F489EFBF1B5D86
SHA256:F18D63C8FA933E21922FA07826EE030CD5918F4EC9AC0890818104C6DBEBAFA5
8040CCleaner64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:B93ED24351603CFA646C302C5B6597FD
SHA256:9778C052A41081FC9C0201185BA09B0A7958458CDDE7CD17B38E646AE9F75964
8040CCleaner64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:6273A3F4D8F4FB5C71A2EAB23FD05AEC
SHA256:560576E084800AFFBDFBDDCB90524240E9930F1E746A1E874814DE6B17D59845
8040CCleaner64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E573CDF4C6D731D56A665145182FD759_AFB3BE9383420FBAFF24AD413EEA555Ebinary
MD5:560ED610CFB98C89AB292D768B0B5928
SHA256:2904FCAAACA2818EEFCA00D1376528AA70CEA3533886F67E1249C3A0DCF10239
8040CCleaner64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E573CDF4C6D731D56A665145182FD759_AFB3BE9383420FBAFF24AD413EEA555Ebinary
MD5:4CE508889EA401B1BDF076CEFBF7ABD7
SHA256:0A382B89C741711DE9E43C2FF9B5FE1B148D49D82B36C463FCE8E64413E52A98
8040CCleaner64.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:7C732CA2621D9F468FC64E735ED2D3DC
SHA256:EC4CF3D7E37BFA28932DF16FDC62EBE24D3651430E4B0551DD35A2BD4C826AD0
8040CCleaner64.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ccc0fa1b9f86f7b3.customDestinations-msbinary
MD5:73D4B1CCB7C78F5A0CA99D334AA9ABC1
SHA256:20F2D629971FC21B8811A54245A2307BAD1D8B00720951080FCFA72D426AB1A0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
30
DNS requests
25
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.35:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8040
CCleaner64.exe
GET
200
23.48.23.10:80
http://ncc.avast.com/ncc.txt
unknown
whitelisted
8040
CCleaner64.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
8040
CCleaner64.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAXfj0A2M0oL7zuU%2F%2F2jetU%3D
unknown
whitelisted
8040
CCleaner64.exe
GET
200
142.250.184.195:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
8040
CCleaner64.exe
GET
200
142.250.184.195:80
http://o.pki.goog/s/wr3/bBg/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQSq0i5t2Pafi2Gw9uzwnc7KTctWgQUx4H1%2FY6I2QA8TWOiUDEkoM4j%2FiMCEGwY1bOiaIYyCQBbxs0Wu5Q%3D
unknown
whitelisted
7252
CCleaner64.exe
GET
200
23.48.23.10:80
http://ncc.avast.com/ncc.txt
unknown
whitelisted
8040
CCleaner64.exe
GET
200
142.250.184.227:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
5892
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.35:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
8040
CCleaner64.exe
23.48.23.10:80
ncc.avast.com
Akamai International B.V.
DE
whitelisted
8040
CCleaner64.exe
34.117.223.223:443
analytics.avcdn.net
GOOGLE-CLOUD-PLATFORM
US
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.35
  • 23.216.77.6
  • 23.216.77.38
  • 23.216.77.30
  • 23.216.77.25
  • 23.216.77.28
  • 23.216.77.36
  • 23.216.77.19
  • 23.216.77.42
whitelisted
google.com
  • 142.250.181.238
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.64
  • 20.190.160.128
  • 20.190.160.3
  • 20.190.160.67
  • 20.190.160.5
  • 40.126.32.76
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
ncc.avast.com
  • 23.48.23.10
  • 23.48.23.31
  • 23.48.23.8
whitelisted
analytics.avcdn.net
  • 34.117.223.223
whitelisted
www.ccleaner.com
  • 2.19.225.128
whitelisted
ip-info.ff.avast.com
  • 34.111.175.102
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
8040
CCleaner64.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
No debug info