File name:

7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe

Full analysis: https://app.any.run/tasks/8fe9c0c8-a2cb-4292-a19e-7aeedddad653
Verdict: Malicious activity
Analysis date: October 22, 2024, 12:11:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B7B4656E0DB41DB4C677A324CC0F5DE5

SHA1:

788BA11B32EAD116136308D48ABA501827BE6E3E

SHA256:

7185E96993E8C74B553937B7EF0ED8CB6B1391BED47B89F788FB8BDBC6253E5D

SSDEEP:

98304:MhW5A/g/NmWUv+elfcFO7/ObMaelgda3lETfPQiofPLBJ3OspA4Dif4OKUP438DB:5wVv4ZD4bdzJelxDu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
    • Reads settings of System Certificates

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
    • The process creates files with name similar to system file names

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
    • Starts application with an unusual extension

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
    • Searches for installed software

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
  • INFO

    • Reads Environment values

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
    • Checks supported languages

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
      • nsCF15.tmp (PID: 2136)
    • Reads the computer name

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
    • Reads product name

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 924)
    • Reads the software policy settings

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
    • Create files in a temporary directory

      • 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe (PID: 3448)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:02:24 19:19:59+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 28672
InitializedDataSize: 445952
UninitializedDataSize: 16896
EntryPoint: 0x39e3
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Piriform Ltd
FileDescription: CCleaner Installer
FileVersion: 2.0.0.0
LegalCopyright: Copyright © 2005-2015 Piriform Ltd
ProductName: CCleaner
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe nscf15.tmp no specs ping.exe no specs wmpnscfg.exe no specs 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
924"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2136"C:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\nsCF15.tmp" ping -n 1 -w 1000 www.piriform.comC:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\nsCF15.tmp7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsicade.tmp\nscf15.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2720ping -n 1 -w 1000 www.piriform.comC:\Windows\System32\PING.EXEnsCF15.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
3448"C:\Users\admin\AppData\Local\Temp\7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe" C:\Users\admin\AppData\Local\Temp\7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe
explorer.exe
User:
admin
Company:
Piriform Ltd
Integrity Level:
HIGH
Description:
CCleaner Installer
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3744"C:\Users\admin\AppData\Local\Temp\7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe" C:\Users\admin\AppData\Local\Temp\7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeexplorer.exe
User:
admin
Company:
Piriform Ltd
Integrity Level:
MEDIUM
Description:
CCleaner Installer
Exit code:
3221226540
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe
c:\windows\system32\ntdll.dll
Total events
3 997
Read events
3 980
Write events
15
Delete events
2

Modification events

(PID) Process:(3448) 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar
Operation:writeName:test
Value:
test
(PID) Process:(3448) 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar
Operation:delete valueName:test
Value:
test
(PID) Process:(3448) 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar
Operation:delete keyName:(default)
Value:
(PID) Process:(3448) 7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
10
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
34487185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeC:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\System.dllexecutable
MD5:BF712F32249029466FA86756F5546950
SHA256:7851CB12FA4131F1FEE5DE390D650EF65CAC561279F1CFE70AD16CC9780210AF
34487185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeC:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\g\gcapi_dll.dllexecutable
MD5:D496480A00ABDE0655C0FDCE9530B43E
SHA256:DA10E8220D101C5EA98B4872879BD27884328C3794E08CF30492AF2C9343005B
34487185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeC:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\nsExec.dllexecutable
MD5:132E6153717A7F9710DCEA4536F364CD
SHA256:D29AFCE2588D8DD7BB94C00CA91CAC0E85B80FFA6B221F5FFCB83A2497228EB2
34487185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeC:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\g\gtapi_signed.dllexecutable
MD5:61BC40D1FAD9E0FAA9A07219B90BA0E4
SHA256:89E157A4F61D7D18180CB7F901C0095DA3B7A5CC5A9FD58D710099E5F0EE505A
34487185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeC:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\p\pfWWW.dllexecutable
MD5:CB1D8D51ABC47FCF036A8AAC36C5F4AA
SHA256:903EBBD07A9D551E41BA8CF581069E5E1C70894D2E6473C009B8CED94E8C0D2F
34487185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeC:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\p\syschk.dllexecutable
MD5:42FB0C5333071B1F4B04587B4E38353E
SHA256:D39C9C47075C0BD297AFFB3E5DC73B23EEE3A9E83B1E209359BDF64A620C8792
34487185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeC:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\nsCF15.tmpexecutable
MD5:132E6153717A7F9710DCEA4536F364CD
SHA256:D29AFCE2588D8DD7BB94C00CA91CAC0E85B80FFA6B221F5FFCB83A2497228EB2
34487185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeC:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\UserInfo.dllexecutable
MD5:C7CE0E47C83525983FD2C4C9566B4AAD
SHA256:6293408A5FA6D0F55F0A4D01528EB5B807EE9447A75A28B5986267475EBCD3AE
34487185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeC:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\modern-wizard.bmpimage
MD5:BF670074262A7E29DA8C0FF2D94C1438
SHA256:1EA1D0A8B0302840B2BA4743FDEF788C93517AC083B7A9DA7DD25640251CE061
34487185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exeC:\Users\admin\AppData\Local\Temp\nsiCADE.tmp\modern-header.bmpimage
MD5:6412E0B095DA5095B321D376EB912CA5
SHA256:F2D07A76AD7D89E64EE261C81039205E44CD0F496193A25DE08EAC488874E1E0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
8
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted
2564
svchost.exe
239.255.255.250:3702
whitelisted
4
System
192.168.100.255:138
whitelisted
3448
7185e96993e8c74b553937b7ef0ed8cb6b1391bed47b89f788fb8bdbc6253e5d.exe
184.30.215.216:443
www.piriform.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.212.174
whitelisted
www.piriform.com
  • 184.30.215.216
whitelisted

Threats

No threats detected
No debug info