File name:

dcsetup.exe

Full analysis: https://app.any.run/tasks/0f061125-23d0-4558-a42c-bd5a50869384
Verdict: Malicious activity
Analysis date: March 06, 2024, 21:40:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

392329D33605FA58B539EF7DA10FE715

SHA1:

950D2730ED07E989189C0E091C0654FF90C5304D

SHA256:

9419389E7E66580FE51816E3D5966F0BD656A9326EA5E8E942D634425AE38012

SSDEEP:

98304:8MhY18PMXktxZS3JcSqCX0r4brY56yZCne12/WuCoMXK1AM0XIbJQvoNtbHNBB8X:L3fGSNjsPT98yTr8FMWW5e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • dcsetup.exe (PID: 3848)
      • stalonestatisticsinfo.exe (PID: 2648)
    • Actions looks like stealing of personal data

      • MemfilesService.exe (PID: 2744)
      • GUAssistComSvc.exe (PID: 2624)
      • GUAssistComSvc.exe (PID: 480)
      • GUAssistComSvc.exe (PID: 3296)
      • GUAssistComSvc.exe (PID: 2168)
      • DiskCleaner.exe (PID: 2960)
    • Steals credentials from Web Browsers

      • DiskCleaner.exe (PID: 2960)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • dcsetup.exe (PID: 3848)
    • Process drops legitimate windows executable

      • dcsetup.exe (PID: 3848)
    • The process creates files with name similar to system file names

      • dcsetup.exe (PID: 3848)
    • The process drops C-runtime libraries

      • dcsetup.exe (PID: 3848)
    • Executable content was dropped or overwritten

      • dcsetup.exe (PID: 3848)
      • stalonestatisticsinfo.exe (PID: 2648)
    • Creates a software uninstall entry

      • dcsetup.exe (PID: 3848)
      • stalonestatisticsinfo.exe (PID: 2648)
    • Reads the Internet Settings

      • stalonestatisticsinfo.exe (PID: 2648)
      • dcsetup.exe (PID: 3848)
      • DiskCleaner.exe (PID: 2960)
    • Searches for installed software

      • stalonestatisticsinfo.exe (PID: 2648)
    • Reads security settings of Internet Explorer

      • stalonestatisticsinfo.exe (PID: 2648)
      • DiskCleaner.exe (PID: 2960)
  • INFO

    • Create files in a temporary directory

      • dcsetup.exe (PID: 3848)
      • stalonestatisticsinfo.exe (PID: 2648)
    • Reads the computer name

      • dcsetup.exe (PID: 3848)
      • GUAssistComSvc.exe (PID: 2328)
      • stalonestatisticsinfo.exe (PID: 2648)
      • DiskCleaner.exe (PID: 2960)
      • GUAssistComSvc.exe (PID: 2624)
      • MemfilesService.exe (PID: 2744)
      • GUAssistComSvc.exe (PID: 480)
      • GUAssistComSvc.exe (PID: 3296)
      • GUAssistComSvc.exe (PID: 2168)
    • Checks supported languages

      • dcsetup.exe (PID: 3848)
      • GUAssistComSvc.exe (PID: 2328)
      • stalonestatisticsinfo.exe (PID: 2648)
      • DiskCleaner.exe (PID: 2960)
      • MemfilesService.exe (PID: 2744)
      • GUAssistComSvc.exe (PID: 2624)
      • GUAssistComSvc.exe (PID: 2168)
      • GUAssistComSvc.exe (PID: 480)
      • GUAssistComSvc.exe (PID: 3296)
    • Creates files in the program directory

      • dcsetup.exe (PID: 3848)
      • DiskCleaner.exe (PID: 2960)
      • MemfilesService.exe (PID: 2744)
    • Reads Environment values

      • dcsetup.exe (PID: 3848)
      • stalonestatisticsinfo.exe (PID: 2648)
      • DiskCleaner.exe (PID: 2960)
    • Creates files or folders in the user directory

      • dcsetup.exe (PID: 3848)
      • DiskCleaner.exe (PID: 2960)
    • Checks proxy server information

      • stalonestatisticsinfo.exe (PID: 2648)
      • DiskCleaner.exe (PID: 2960)
    • Reads the machine GUID from the registry

      • stalonestatisticsinfo.exe (PID: 2648)
      • DiskCleaner.exe (PID: 2960)
      • GUAssistComSvc.exe (PID: 2624)
      • GUAssistComSvc.exe (PID: 480)
      • GUAssistComSvc.exe (PID: 3296)
      • GUAssistComSvc.exe (PID: 2168)
    • Manual execution by a user

      • msedge.exe (PID: 1900)
    • Application launched itself

      • msedge.exe (PID: 3164)
      • msedge.exe (PID: 1900)
    • Reads product name

      • DiskCleaner.exe (PID: 2960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:08:01 02:42:47+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25088
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x3312
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 6.0.1.9
ProductVersionNumber: 6.0.1.9
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Latvian
CharacterSet: Unknown (04E9)
CompanyName: Glarysoft Ltd
FileDescription: Glary Disk Cleaner Installer
LegalCopyright: Copyright (c) 2003 - 2024 Glarysoft Ltd
ProductName: Glary Disk Cleaner
ProductVersion: 6.0.1.9
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
25
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start dcsetup.exe guassistcomsvc.exe no specs stalonestatisticsinfo.exe diskcleaner.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe memfilesservice.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs guassistcomsvc.exe guassistcomsvc.exe guassistcomsvc.exe guassistcomsvc.exe dcsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
448"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1624 --field-trial-handle=1348,i,5644728729077019249,7926762764038394122,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
480"C:\Program Files\Glarysoft\Glary Disk Cleaner\GUAssistComSvc.exe" -EmbeddingC:\Program Files\Glarysoft\Glary Disk Cleaner\GUAssistComSvc.exe
svchost.exe
User:
admin
Company:
Glarysoft Ltd
Integrity Level:
HIGH
Exit code:
0
Version:
6.0.0.4
Modules
Images
c:\program files\glarysoft\glary disk cleaner\guassistcomsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1236"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1232 --field-trial-handle=1180,i,4742137073310764410,3394121780814328226,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1596"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1556 --field-trial-handle=1348,i,5644728729077019249,7926762764038394122,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1900"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate https://www.glarysoft.com/update/release-notes/?p=4&v=6.0.1.9C:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
2222
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2168"C:\Program Files\Glarysoft\Glary Disk Cleaner\GUAssistComSvc.exe" -EmbeddingC:\Program Files\Glarysoft\Glary Disk Cleaner\GUAssistComSvc.exe
svchost.exe
User:
admin
Company:
Glarysoft Ltd
Integrity Level:
HIGH
Exit code:
0
Version:
6.0.0.4
Modules
Images
c:\program files\glarysoft\glary disk cleaner\guassistcomsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2320"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xf0,0x6bb5f598,0x6bb5f5a8,0x6bb5f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
2222
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2328"C:\Program Files\Glarysoft\Glary Disk Cleaner\GUAssistComSvc.exe" /RegServerC:\Program Files\Glarysoft\Glary Disk Cleaner\GUAssistComSvc.exedcsetup.exe
User:
admin
Company:
Glarysoft Ltd
Integrity Level:
HIGH
Exit code:
0
Version:
6.0.0.4
Modules
Images
c:\program files\glarysoft\glary disk cleaner\guassistcomsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2376"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2204 --field-trial-handle=1348,i,5644728729077019249,7926762764038394122,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2624"C:\Program Files\Glarysoft\Glary Disk Cleaner\GUAssistComSvc.exe" -EmbeddingC:\Program Files\Glarysoft\Glary Disk Cleaner\GUAssistComSvc.exe
svchost.exe
User:
admin
Company:
Glarysoft Ltd
Integrity Level:
HIGH
Exit code:
0
Version:
6.0.0.4
Modules
Images
c:\program files\glarysoft\glary disk cleaner\guassistcomsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
16 919
Read events
16 497
Write events
405
Delete events
17

Modification events

(PID) Process:(2328) GUAssistComSvc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GUAssistComSvc.EXE
Operation:writeName:AppID
Value:
{0BCB705C-0F64-405B-8CB3-CDF41B796E19}
(PID) Process:(2328) GUAssistComSvc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{0BCB705C-0F64-405B-8CB3-CDF41B796E19}
Operation:delete valueName:LocalService
Value:
(PID) Process:(2328) GUAssistComSvc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F10E0193-E389-4E51-BDD8-D3DAF5F63851}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3848) dcsetup.exeKey:HKEY_CURRENT_USER\Software\Glarysoft\Disk Cleaner
Operation:writeName:Language
Value:
english.lng
(PID) Process:(3848) dcsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Glary Disk Cleaner
Operation:writeName:Channel
Value:
10000
(PID) Process:(3848) dcsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Glary Disk Cleaner
Operation:writeName:ProductID
Value:
6019021000
(PID) Process:(3848) dcsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Glary Disk Cleaner
Operation:writeName:Macaddress
Value:
C7AAA1DD69CBA06C012557A6B1D85510
(PID) Process:(3848) dcsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Glary Disk Cleaner
Operation:writeName:QuickLaunch
Value:
true
(PID) Process:(3848) dcsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Glary Disk Cleaner
Operation:writeName:DisplayName
Value:
Glary Disk Cleaner 6.0.1.9
(PID) Process:(3848) dcsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Glary Disk Cleaner
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Glarysoft\Glary Disk Cleaner\DiskCleaner.exe
Executable files
47
Suspicious files
25
Text files
275
Unknown types
11

Dropped files

PID
Process
Filename
Type
3848dcsetup.exeC:\Users\admin\AppData\Local\Temp\nsq1D1.tmp\DiskCleaner.inibinary
MD5:EA2800B1A32FF7EDD36DA40B8DD7FB2D
SHA256:DBBD443A907C7B5D773BF0BFCAB95BABB31BFB468B6D05662FF298AEB8433C3C
3848dcsetup.exeC:\Users\admin\AppData\Local\Temp\nsq1D1.tmp\modern-wizard.bmpimage
MD5:5DF1DBCB7959F4C7301BFC7A187BD40E
SHA256:195516D3A434664DFAF86A02E1B2228BC2FD8C6DF08870B96567AEC82101FD47
3848dcsetup.exeC:\Users\admin\AppData\Local\Temp\nsq1D1.tmp\nsDialogs.dllexecutable
MD5:1C8B2B40C642E8B5A5B3FF102796FB37
SHA256:8780095AA2F49725388CDDF00D79A74E85C9C4863B366F55C39C606A5FB8440C
3848dcsetup.exeC:\Program Files\Glarysoft\Glary Disk Cleaner\Config.dllexecutable
MD5:8CDACA868F1D8D4196888D0A93B64814
SHA256:847CC90E5948097508AF05AA07C36E3605A7A5A44F5D2446783942FE96982651
3848dcsetup.exeC:\Program Files\Glarysoft\Glary Disk Cleaner\CheckUpdate.dllexecutable
MD5:AEB198748F06DDB201CDAC1F44DEC915
SHA256:0B77138D76F952116B6FFC96D06EECD8F69B001940E02F078E4EFD8327CFCF97
3848dcsetup.exeC:\Users\admin\AppData\Local\Temp\nsq1D1.tmp\MachineCode.dllexecutable
MD5:A5BBEB050CE8BBE6A5233F0ED61EBA5B
SHA256:C4BEFE52ECF8CD85B7DCB81E466FB00477BCFC447B80AE0DC77513F9A485120A
3848dcsetup.exeC:\Users\admin\AppData\Local\Temp\nsq1D1.tmp\KillProcDLL.dllexecutable
MD5:2F8A43C3581AF1F31CE8D9DA0C03465B
SHA256:97B5B3985736CC0F49CEB2DA68B01CE51FA821B6DA3CEC69CFEEBFBA8D626845
3848dcsetup.exeC:\Users\admin\AppData\Local\Temp\nsq1D1.tmp\InstallOptions.dllexecutable
MD5:5F35212D7E90EE622B10BE39B09BD270
SHA256:31944B93E44301974D9C6F810D2DA792E34A53DCACD619A08CB0385AC59E513D
3848dcsetup.exeC:\Program Files\Glarysoft\Glary Disk Cleaner\AppMetrics.dllexecutable
MD5:A6BB2AEBEE188D1517EF7A91BE45F45E
SHA256:4D1BFF13965BF6EC1DBD9CF9E8589E43579308FFDE4AEBF12FC3F83214E34FDD
3848dcsetup.exeC:\Program Files\Glarysoft\Glary Disk Cleaner\Backup.dllexecutable
MD5:FE47E63AC392298D69B57FDBE3AD56AB
SHA256:E83BCF0CCBEB092B21B255206B2C114A83825EA6A9120919826BC5CF299D61EE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
16
DNS requests
17
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2960
DiskCleaner.exe
GET
188.114.97.0:80
http://go.glarysoft.com/g/t/modulecheckupdate/cn/10000/s/Glary%20Utilities/v/6.0.1.9/modulename/DiskCleaner.exe/uid/14E9569824631970D3B344703D62B4B7/urlrand/21307
unknown
unknown
2648
stalonestatisticsinfo.exe
POST
200
52.24.207.204:80
http://analytics.glarysoft.com/api/v1/install
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
2648
stalonestatisticsinfo.exe
52.24.207.204:80
analytics.glarysoft.com
AMAZON-02
US
unknown
1596
msedge.exe
188.114.97.0:443
www.glarysoft.com
CLOUDFLARENET
NL
unknown
1900
msedge.exe
239.255.255.250:1900
unknown
1596
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1596
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2960
DiskCleaner.exe
188.114.97.0:80
www.glarysoft.com
CLOUDFLARENET
NL
unknown
1596
msedge.exe
35.190.80.1:443
a.nel.cloudflare.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
analytics.glarysoft.com
  • 52.24.207.204
unknown
www.glarysoft.com
  • 188.114.97.0
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
whitelisted
go.glarysoft.com
  • 188.114.97.0
unknown
a.nel.cloudflare.com
  • 35.190.80.1
whitelisted
challenges.cloudflare.com
  • 104.17.2.184
whitelisted

Threats

PID
Process
Class
Message
2648
stalonestatisticsinfo.exe
Potentially Bad Traffic
ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla))
1596
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
1596
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
1596
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
No debug info