| File name: | file |
| Full analysis: | https://app.any.run/tasks/1b7069db-f0d4-4996-80e2-5a84641de69a |
| Verdict: | Malicious activity |
| Threats: | GCleaner is a type of malware loader that has the capability to deliver numerous malicious software programs, which differ based on the location of the targeted victim. This malware is commonly spread through fraudulent websites that advertise free PC optimization tools |
| Analysis date: | December 02, 2023, 14:45:51 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | B8BB79B499C399E6AAAD382A3B7B6122 |
| SHA1: | AA79D755536CC1598F523C15696C3B379A4F77BA |
| SHA256: | 90C705C231A5E9E61A41474B00D64B321E85DF7F814B398FE11BA16287D98864 |
| SSDEEP: | 49152:kb3RMQvYYiKp7P0ZZUKykFPSgXW2faB4BKBdl2w/gVptWuBKuazMgUvOS6TOW38N:9qYYHQcePSIW2fwBdlcVvWuBpagng5G |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:12:02 12:52:05+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 1924587 |
| InitializedDataSize: | 1534 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1d7de5 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | Material Design NET 4.0 |
| CompanyName: | - |
| FileDescription: | MaterialSkin |
| FileVersion: | 1.0.0.0 |
| InternalName: | MaterialSkin.exe |
| LegalCopyright: | Copyright © 2014 |
| LegalTrademarks: | - |
| OriginalFileName: | MaterialSkin.exe |
| ProductName: | MaterialSkin |
| ProductVersion: | 1.0.0.0 |
| AssemblyVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 688 | "C:\Users\admin\Pictures\s3SQ6Tq9tWHEUdc97kGxVAcc.exe" | C:\Users\admin\Pictures\s3SQ6Tq9tWHEUdc97kGxVAcc.exe | — | CasPol.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Cleaner installer Exit code: 3221226540 Version: 1.0.0.0 Modules
| |||||||||||||||
| 924 | "C:\Users\admin\Pictures\9sei8jiOVsoGbZ4UgNClMsDC.exe" | C:\Users\admin\Pictures\9sei8jiOVsoGbZ4UgNClMsDC.exe | — | CasPol.exe | |||||||||||
User: admin Company: Softdiv Software Sdn Bhd Integrity Level: MEDIUM Description: RoboOCR Setup Exit code: 0 Version: 1.1 Modules
| |||||||||||||||
| 1088 | "C:\Users\admin\AppData\Local\Temp\1791515874.exe" | C:\Users\admin\AppData\Local\Temp\1791515874.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1392 | "C:\Users\admin\Pictures\GHqiIYwEPN5QwKIIyzOh6mYy.exe" | C:\Users\admin\Pictures\GHqiIYwEPN5QwKIIyzOh6mYy.exe | CasPol.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
OnlyLogger(PID) Process(1392) GHqiIYwEPN5QwKIIyzOh6mYy.exe C285.209.11.204 | |||||||||||||||
| 1716 | C:\Users\admin\AppData\Local\Temp\Broom.exe | C:\Users\admin\AppData\Local\Temp\Broom.exe | — | s3SQ6Tq9tWHEUdc97kGxVAcc.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Broom Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1724 | "C:\Windows\System32\cmd.exe" /c start /I "" "C:\Users\admin\AppData\Local\Temp\1791515874.exe" | C:\Windows\SysWOW64\cmd.exe | — | GHqiIYwEPN5QwKIIyzOh6mYy.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2040 | "C:\Users\admin\Pictures\s3SQ6Tq9tWHEUdc97kGxVAcc.exe" | C:\Users\admin\Pictures\s3SQ6Tq9tWHEUdc97kGxVAcc.exe | CasPol.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Cleaner installer Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2208 | "C:\Users\admin\AppData\Local\Temp\file.exe" | C:\Users\admin\AppData\Local\Temp\file.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: MaterialSkin Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2228 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\admin\AppData\Local\Temp\file.exe" -Force | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | file.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 2408 | "C:\Users\admin\AppData\Local\Temp\is-J6D8M.tmp\9sei8jiOVsoGbZ4UgNClMsDC.tmp" /SL5="$F03CE,922170,832512,C:\Users\admin\Pictures\9sei8jiOVsoGbZ4UgNClMsDC.exe" /SPAWNWND=$B03DC /NOTIFYWND=$1403BC | C:\Users\admin\AppData\Local\Temp\is-J6D8M.tmp\9sei8jiOVsoGbZ4UgNClMsDC.tmp | 9sei8jiOVsoGbZ4UgNClMsDC.exe | ||||||||||||
User: admin Company: Softdiv Software Sdn Bhd Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2208) file.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2208) file.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2208) file.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2208) file.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2528) CasPol.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2528) CasPol.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2528) CasPol.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2528) CasPol.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2528) CasPol.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\15A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1392) GHqiIYwEPN5QwKIIyzOh6mYy.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2528 | CasPol.exe | C:\Users\admin\Pictures\WkoS1UFD2TtqKQnvY4A00J5X.exe | binary | |
MD5:963DA09532E9758ADEDF9745C76EC700 | SHA256:8720B9487CEE7DAE6DB3F8F73273BCBBC56377400B830CA0F089473EBC9603F2 | |||
| 2528 | CasPol.exe | C:\Users\admin\AppData\Local\kvnSFfjiUVM1JanBUfR1MA1i.exe | html | |
MD5:772C06F2E452F8578F8758E28AEB2AED | SHA256:30266356E136691D926971206FB9541AAACCE37AA332B263E664D3769D9419A5 | |||
| 2528 | CasPol.exe | C:\Users\admin\Pictures\BVLzzZDj3FhOMYfBA1g2Exn6.exe | html | |
MD5:772C06F2E452F8578F8758E28AEB2AED | SHA256:30266356E136691D926971206FB9541AAACCE37AA332B263E664D3769D9419A5 | |||
| 2528 | CasPol.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 2528 | CasPol.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\v0SKDSVUURVzXYVxd9p1FTde.bat | text | |
MD5:690C7B4755848F562DBFB11E6FC3C9EA | SHA256:BA8678A98CE42E12C2EA1D7B388F7C164BA542C5A3C63E3BA0E58C6DD5374310 | |||
| 2528 | CasPol.exe | C:\Users\admin\AppData\Local\KdYMUAdbXyIrGff5Nw6S0GkE.exe | binary | |
MD5:963DA09532E9758ADEDF9745C76EC700 | SHA256:8720B9487CEE7DAE6DB3F8F73273BCBBC56377400B830CA0F089473EBC9603F2 | |||
| 2528 | CasPol.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cFAUxEoNpQvxoUzreC8yZbyR.bat | text | |
MD5:ED4252424FCAE9B54D1565E20D481F59 | SHA256:0E226023CE4B6C36BA70D7A84780E78F5C12007B8BF8A905BE3C066AC76F0075 | |||
| 2228 | powershell.exe | C:\Users\admin\AppData\Local\Temp\xjharncm.ycb.ps1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 2528 | CasPol.exe | C:\Users\admin\Pictures\GHqiIYwEPN5QwKIIyzOh6mYy.exe | executable | |
MD5:D0E991A3F9537689CE98EECB69DA57CF | SHA256:7D1B712ECCF7F2C8B250487359E20B1276880C4B350EBD8A1AC4C39984F9500D | |||
| 2528 | CasPol.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JTHw3I5740d4BLYbXQ1brtQQ.bat | text | |
MD5:23B2074BA005D766151F5A3A4AEB96E8 | SHA256:E9A8A52C11896B23C8BBBED1F52D399805454CA9DB4234F72169E984484E0290 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2528 | CasPol.exe | GET | — | 91.92.241.91:80 | http://91.92.241.91/files/5.exe | unknown | — | — | unknown |
2528 | CasPol.exe | GET | 200 | 91.92.241.91:80 | http://91.92.241.91/files/InstallSetup24.exe | unknown | executable | 2.33 Mb | unknown |
2528 | CasPol.exe | GET | 200 | 184.24.77.202:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?c7f50232afa86f77 | unknown | compressed | 65.2 Kb | unknown |
2528 | CasPol.exe | GET | — | 188.114.96.3:80 | http://stim.graspalace.com/order/tuc4.exe | unknown | — | — | unknown |
2528 | CasPol.exe | GET | 301 | 185.26.182.111:80 | http://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 | unknown | html | 162 b | unknown |
2528 | CasPol.exe | GET | — | 188.114.96.3:80 | http://gobo30cl.top/build.exe | unknown | — | — | unknown |
2528 | CasPol.exe | GET | 200 | 184.24.77.202:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?a1798b332a918e01 | unknown | compressed | 65.2 Kb | unknown |
1392 | GHqiIYwEPN5QwKIIyzOh6mYy.exe | GET | 200 | 85.209.11.204:80 | http://85.209.11.204/ip.php | unknown | text | 13 b | unknown |
1392 | GHqiIYwEPN5QwKIIyzOh6mYy.exe | GET | 200 | 85.209.11.204:80 | http://85.209.11.204/api/files/client/s51 | unknown | text | 38 b | unknown |
1392 | GHqiIYwEPN5QwKIIyzOh6mYy.exe | GET | 200 | 194.5.249.115:80 | http://194.5.249.115/files/BIFPuKaW1X.exe | unknown | executable | 414 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2528 | CasPol.exe | 172.67.34.170:443 | pastebin.com | CLOUDFLARENET | US | unknown |
2528 | CasPol.exe | 91.92.241.91:80 | — | Natskovi & Sie Ltd. | BG | unknown |
2528 | CasPol.exe | 188.114.96.3:80 | gobo30cl.top | CLOUDFLARENET | NL | unknown |
2528 | CasPol.exe | 104.21.12.138:443 | iplogger.com | CLOUDFLARENET | — | unknown |
2528 | CasPol.exe | 104.21.93.225:443 | flyawayaero.net | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
pastebin.com |
| shared |
gobo30cl.top |
| malicious |
online22.site |
| unknown |
stim.graspalace.com |
| malicious |
flyawayaero.net |
| unknown |
redirector.pm |
| malicious |
net.geo.opera.com |
| whitelisted |
iplogger.com |
| shared |
yip.su |
| whitelisted |
potatogoose.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
324 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
324 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain (iplogger .com in DNS lookup) |
324 | svchost.exe | Potentially Bad Traffic | ET DNS Query for .su TLD (Soviet Union) Often Malware Related |
2528 | CasPol.exe | Potential Corporate Privacy Violation | AV POLICY HTTP request for .exe file with no User-Agent |
2528 | CasPol.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
2528 | CasPol.exe | Potential Corporate Privacy Violation | AV POLICY HTTP request for .exe file with no User-Agent |
2528 | CasPol.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
2528 | CasPol.exe | A Network Trojan was detected | ET MALWARE Single char EXE direct download likely trojan (multiple families) |
2528 | CasPol.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain (iplogger .com in TLS SNI) |
2528 | CasPol.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
file.exe | Could not load file or assembly '1318400 bytes loaded from Anonymously Hosted DynamicMethods Assembly, Version=0.0.0.0, Culture=neutral, PublicKeyToken=null' or one of its dependencies. An attempt was made to load a program with an incorrect format.
|