File name:

CCleaner Updater.exe

Full analysis: https://app.any.run/tasks/6c516cbf-752a-417f-b847-c9bf8a8dbae9
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: September 13, 2019, 05:33:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

0E4E2E94E5679BF5A87C2A72180B3F10

SHA1:

63FFE20F8510C5E2AE9F0DB98BEF2B516CFFADEC

SHA256:

7B9695408F194307BC07EFBFCFDC1D48F3433FB2B0684CAFF85A7B97DDECA97A

SSDEEP:

1536:rTD5+Z5L4vb8DQ+8B5u7dSmeOoUtqzKnRG3MseinBVL+ZzBs:cZp4Cr8qdloUsziGGsBVL+Zds

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ccupdate5.61.7392.exe (PID: 3900)
      • ccupdate5.61.7392.exe (PID: 2964)
      • CCleaner.exe (PID: 2964)
      • ccleaner.exe (PID: 3976)
      • ccleaner.exe (PID: 2900)
      • CCUpdate.exe (PID: 3356)
      • ccleaner.exe (PID: 2424)
      • CCUpdate.exe (PID: 2348)
    • Loads the Task Scheduler COM API

      • CCleaner.exe (PID: 2964)
      • CCUpdate.exe (PID: 3356)
      • ccleaner.exe (PID: 3976)
      • ccleaner.exe (PID: 2900)
      • ccleaner.exe (PID: 2424)
    • Changes settings of System certificates

      • CCleaner Updater.exe (PID: 3524)
    • Loads dropped or rewritten executable

      • ccupdate5.61.7392.exe (PID: 3900)
      • CCUpdate.exe (PID: 2348)
    • Downloads executable files from the Internet

      • CCUpdate.exe (PID: 3356)
    • Actions looks like stealing of personal data

      • ccleaner.exe (PID: 2900)
      • ccleaner.exe (PID: 2424)
    • Changes the autorun value in the registry

      • ccleaner.exe (PID: 2424)
  • SUSPICIOUS

    • Reads Environment values

      • CCleaner Updater.exe (PID: 3524)
      • ccupdate5.61.7392.exe (PID: 3900)
      • ccleaner.exe (PID: 2900)
      • ccleaner.exe (PID: 2424)
    • Creates files in the program directory

      • ccupdate5.61.7392.exe (PID: 3900)
      • CCUpdate.exe (PID: 3356)
    • Executable content was dropped or overwritten

      • CCleaner Updater.exe (PID: 3524)
      • ccupdate5.61.7392.exe (PID: 3900)
      • CCUpdate.exe (PID: 3356)
    • Creates a software uninstall entry

      • ccupdate5.61.7392.exe (PID: 3900)
    • Low-level read access rights to disk partition

      • ccupdate5.61.7392.exe (PID: 3900)
      • CCUpdate.exe (PID: 3356)
      • CCUpdate.exe (PID: 2348)
      • ccleaner.exe (PID: 2900)
      • ccleaner.exe (PID: 2424)
    • Reads CPU info

      • ccupdate5.61.7392.exe (PID: 3900)
      • ccleaner.exe (PID: 2900)
      • ccleaner.exe (PID: 2424)
    • Application launched itself

      • CCUpdate.exe (PID: 3356)
      • ccleaner.exe (PID: 2900)
      • ccleaner.exe (PID: 3976)
    • Creates files in the user directory

      • ccleaner.exe (PID: 2900)
      • ccleaner.exe (PID: 2424)
    • Searches for installed software

      • ccleaner.exe (PID: 2900)
      • ccleaner.exe (PID: 2424)
    • Reads the cookies of Mozilla Firefox

      • ccleaner.exe (PID: 2900)
    • Reads the cookies of Google Chrome

      • ccleaner.exe (PID: 2900)
    • Reads internet explorer settings

      • ccleaner.exe (PID: 2424)
      • ccleaner.exe (PID: 2900)
  • INFO

    • Reads settings of System Certificates

      • ccleaner.exe (PID: 2900)
      • ccleaner.exe (PID: 2424)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:08:23 02:38:53+02:00
PEType: PE32
LinkerVersion: 11
CodeSize: 88576
InitializedDataSize: 2560
UninitializedDataSize: -
EntryPoint: 0x1799e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows command line

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date: 23-Aug-2019 00:38:53
Comments: CCleaner Updater By ActVer®
CompanyName: ActVer®
FileDescription: CCleaner Updater
FileVersion: 1.0.0.0
InternalName: CCupdate.exe
LegalCopyright: ActVer®©
LegalTrademarks: ActVer®
OriginalFilename: CCupdate.exe
ProductName: CCleaner Updater
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000080

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 23-Aug-2019 00:38:53
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LARGE_ADDRESS_AWARE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
\x01
0x0001A000
0x0000000C
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
0.224019

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.00112
490
UNKNOWN
UNKNOWN
RT_MANIFEST

Imports

mscoree.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
10
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start ccleaner updater.exe ccupdate5.61.7392.exe no specs ccupdate5.61.7392.exe ccleaner.exe no specs ccupdate.exe ccupdate.exe ccleaner.exe no specs explorer.exe no specs ccleaner.exe ccleaner.exe

Process information

PID
CMD
Path
Indicators
Parent process
2348CCUpdate.exe /emupdater /applydll "C:\Program Files\CCleaner\Setup\5e72a930-59dc-4329-ac2e-e0d51ebc8c37.dll"C:\Program Files\CCleaner\CCUpdate.exe
CCUpdate.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner emergency updater
Exit code:
0
Version:
19.2.566.0
Modules
Images
c:\program files\ccleaner\ccupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2424"C:\Program Files\CCleaner\ccleaner.exe" /monitorC:\Program Files\CCleaner\ccleaner.exe
ccleaner.exe
User:
admin
Company:
Piriform Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
5.61.0.7392
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2900"C:\Program Files\CCleaner\ccleaner.exe" /uacC:\Program Files\CCleaner\ccleaner.exe
ccleaner.exe
User:
admin
Company:
Piriform Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
5.61.0.7392
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2964"C:\Users\admin\AppData\Local\Temp\temp_ccupdate\ccupdate5.61.7392.exe" /INSTDIR='C:\Program Files\CCleaner' /L=1033 /COMMANDLINE='/uac'C:\Users\admin\AppData\Local\Temp\temp_ccupdate\ccupdate5.61.7392.exeCCleaner Updater.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
CCleaner Installer
Exit code:
3221226540
Version:
5.61.0.7392
Modules
Images
c:\users\admin\appdata\local\temp\temp_ccupdate\ccupdate5.61.7392.exe
c:\systemroot\system32\ntdll.dll
2964"C:\Program Files\CCleaner\CCleaner.exe" /createSkipUAC 5.35.6210C:\Program Files\CCleaner\CCleaner.execcupdate5.61.7392.exe
User:
admin
Company:
Piriform Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
5.61.0.7392
Modules
Images
c:\users\admin\appdata\local\temp\temp_ccupdate\ccupdate5.61.7392.exe
c:\program files\ccleaner\ccleaner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
3356"C:\Program Files\CCleaner\CCUpdate.exe" /regC:\Program Files\CCleaner\CCUpdate.exe
ccupdate5.61.7392.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner emergency updater
Exit code:
0
Version:
19.2.566.0
Modules
Images
c:\program files\ccleaner\ccupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
3524"C:\Users\admin\AppData\Local\Temp\CCleaner Updater.exe" C:\Users\admin\AppData\Local\Temp\CCleaner Updater.exe
explorer.exe
User:
admin
Company:
ActVer®
Integrity Level:
MEDIUM
Description:
CCleaner Updater
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\ccleaner updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3900"C:\Users\admin\AppData\Local\Temp\temp_ccupdate\ccupdate5.61.7392.exe" /INSTDIR='C:\Program Files\CCleaner' /L=1033 /COMMANDLINE='/uac'C:\Users\admin\AppData\Local\Temp\temp_ccupdate\ccupdate5.61.7392.exe
CCleaner Updater.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner Installer
Exit code:
0
Version:
5.61.0.7392
Modules
Images
c:\users\admin\appdata\local\temp\temp_ccupdate\ccupdate5.61.7392.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3976"C:\Program Files\CCleaner\ccleaner.exe" /updateSuccess /uacC:\Program Files\CCleaner\ccleaner.execcupdate5.61.7392.exe
User:
admin
Company:
Piriform Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
5.61.0.7392
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
4084C:\Windows\explorer.exeC:\Windows\explorer.execcupdate5.61.7392.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
4 792
Read events
4 548
Write events
241
Delete events
3

Modification events

(PID) Process:(3524) CCleaner Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CCleaner Updater_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3524) CCleaner Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CCleaner Updater_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3524) CCleaner Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CCleaner Updater_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(3524) CCleaner Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CCleaner Updater_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(3524) CCleaner Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CCleaner Updater_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3524) CCleaner Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CCleaner Updater_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3524) CCleaner Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CCleaner Updater_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3524) CCleaner Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CCleaner Updater_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3524) CCleaner Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CCleaner Updater_RASMANCS
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(3524) CCleaner Updater.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CCleaner Updater_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
4294901760
Executable files
65
Suspicious files
17
Text files
18
Unknown types
5

Dropped files

PID
Process
Filename
Type
3524CCleaner Updater.exeC:\Users\admin\AppData\Local\Temp\CabC72D.tmp
MD5:
SHA256:
3524CCleaner Updater.exeC:\Users\admin\AppData\Local\Temp\TarC72E.tmp
MD5:
SHA256:
3524CCleaner Updater.exeC:\Users\admin\AppData\Local\Temp\CabC78D.tmp
MD5:
SHA256:
3524CCleaner Updater.exeC:\Users\admin\AppData\Local\Temp\TarC78E.tmp
MD5:
SHA256:
3524CCleaner Updater.exeC:\Users\admin\AppData\Local\Temp\CabC80C.tmp
MD5:
SHA256:
3524CCleaner Updater.exeC:\Users\admin\AppData\Local\Temp\TarC80D.tmp
MD5:
SHA256:
3524CCleaner Updater.exeC:\Users\admin\AppData\Local\Temp\temp_ccupdate\ccupdate5.61.7392.exeexecutable
MD5:
SHA256:
3524CCleaner Updater.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\63E85DEAD2F87112F3D990057BEFF0F6binary
MD5:
SHA256:
3524CCleaner Updater.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CA4458E7366E94A3C3A9C1FE548B6D21_69DD77FD70A66F46541613EB9E77AB6Fbinary
MD5:
SHA256:
3524CCleaner Updater.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CA4458E7366E94A3C3A9C1FE548B6D21_69DD77FD70A66F46541613EB9E77AB6Fder
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
28
DNS requests
23
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3356
CCUpdate.exe
HEAD
200
2.16.186.73:80
http://emupdate.avcdn.net/files/emupdate/pong.txt
unknown
whitelisted
3524
CCleaner Updater.exe
GET
200
151.101.2.202:80
http://www.ccleaner.com/auto?p=cc&v=5.35.6210
US
text
23 b
whitelisted
3524
CCleaner Updater.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA%2BoSQYV1wCgviF2%2FcXsbb0%3D
US
der
471 b
whitelisted
3356
CCUpdate.exe
GET
200
5.62.40.217:80
http://ip-info.ff.avast.com/v2/info
DE
text
376 b
whitelisted
2348
CCUpdate.exe
GET
200
5.62.40.217:80
http://ip-info.ff.avast.com/v2/info
DE
text
376 b
whitelisted
3524
CCleaner Updater.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSFDxAmS5JEAmWxO0Ue9OdQ9z7zPAQUFQASKxOYspkH7R7for5XDStnAs0CEAMBmgI6%2F1ixa9bV6uYX8GY%3D
US
der
471 b
whitelisted
3524
CCleaner Updater.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAb9%2BQOWA63qAArrPye7uhs%3D
US
der
471 b
whitelisted
3524
CCleaner Updater.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSYagvY3tfizDNoybzVSPFZmSEm0wQUe2jOKarAF75JeuHlP9an90WPNTICEAUjQJuftcO4wMRjoxhyP%2Fk%3D
US
der
471 b
whitelisted
2900
ccleaner.exe
GET
200
151.101.2.202:80
http://www.ccleaner.com/auto?a=0&p=cc&v=5.61.7392&l=1033&lk=&mk=IJR6-W5SV-5KYR-QBZD-6BY4-RN5Z-WAV9-RVK2-VJCA&o=6.1W3&au=1&mx=97B7721C4994E2556FF6A439510F665DB45337A341A47E15F4997584423BF714&gd=e6e88bb1-0796-4b9a-878b-1cb17aa39f88
US
text
23 b
whitelisted
2900
ccleaner.exe
GET
200
151.101.2.109:80
http://license.piriform.com/verify/?p=ccpro&c=cc&cv=5.61.7392&l=1033&lk=CJ9T-J7CU-SPNV-GWMB-WBEC&mk=IJR6-W5SV-5KYR-QBZD-6BY4-RN5Z-WAV9-RVK2-VJCA&mx=97B7721C4994E2556FF6A439510F665DB45337A341A47E15F4997584423BF714&gd=e6e88bb1-0796-4b9a-878b-1cb17aa39f88
US
html
5.58 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3524
CCleaner Updater.exe
13.32.218.201:443
download.ccleaner.com
Amazon.com, Inc.
US
unknown
13.107.4.50:80
www.download.windowsupdate.com
Microsoft Corporation
US
whitelisted
3356
CCUpdate.exe
2.16.186.73:80
emupdate.avcdn.net
Akamai International B.V.
whitelisted
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
151.101.2.202:80
www.ccleaner.com
Fastly
US
suspicious
3524
CCleaner Updater.exe
104.18.11.39:80
cacerts.digicert.com
Cloudflare Inc
US
shared
3356
CCUpdate.exe
5.62.40.217:80
ip-info.ff.avast.com
AVAST Software s.r.o.
DE
suspicious
3356
CCUpdate.exe
2.16.186.59:80
ccleaner.tools.avcdn.net
Akamai International B.V.
whitelisted
2348
CCUpdate.exe
5.62.40.217:80
ip-info.ff.avast.com
AVAST Software s.r.o.
DE
suspicious
216.58.207.78:80
www.google-analytics.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.ccleaner.com
  • 151.101.2.202
  • 151.101.66.202
  • 151.101.130.202
  • 151.101.194.202
whitelisted
download.ccleaner.com
  • 13.32.218.201
  • 13.32.218.99
  • 13.32.218.42
  • 13.32.218.128
shared
cacerts.digicert.com
  • 104.18.11.39
  • 104.18.10.39
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
www.download.windowsupdate.com
  • 13.107.4.50
whitelisted
ip-info.ff.avast.com
  • 5.62.40.221
  • 5.62.40.217
whitelisted
emupdate.avcdn.net
  • 2.16.186.49
  • 2.16.186.73
whitelisted
ccleaner.tools.avcdn.net
  • 2.16.186.56
  • 2.16.186.59
whitelisted
shepherd.ff.avast.com
  • 5.62.44.197
  • 69.94.69.152
whitelisted
www.google-analytics.com
  • 216.58.207.78
whitelisted

Threats

PID
Process
Class
Message
3356
CCUpdate.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info