URL:

http://download.windowsupdate.com/phf/d/dod/ph/prod5/msdownload/update/software/defu/2024/02/1024/updateplatform.amd64fre_ba0ffb5bc09e6139e95cfdf23f5e55ef109e58cc.exe.json

Full analysis: https://app.any.run/tasks/cc5fc9f7-cf9d-40ce-b1da-1d5626405e37
Verdict: Malicious activity
Analysis date: February 24, 2024, 10:34:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

F96415FA5D7ADA156CFE3C2B1C8CF9B0

SHA1:

2609353D37BDAA1C4CF950556C8BE614BA7361B2

SHA256:

A1CD89F05C08744BE7BF89B2E6011AEF1749D9933BA2249393232BD8113AF462

SSDEEP:

3:N1KaKEld9r4ElNWfBKHmKrBFJkACANHtsVXPmDAyKmhlRD0D+f6cAcQGdgQAQVoC:Ca5d96BKdfN0M7D6+f6c5SQA6opQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • CCleaner.exe (PID: 2756)
    • Drops the executable file immediately after the start

      • CCleaner.exe (PID: 2756)
    • Steals credentials from Web Browsers

      • CCleaner.exe (PID: 2756)
  • SUSPICIOUS

    • Uses RUNDLL32.EXE to load library

      • iexplore.exe (PID: 3864)
    • The process executes via Task Scheduler

      • CCleaner.exe (PID: 2756)
    • Reads Internet Explorer settings

      • CCleaner.exe (PID: 2756)
    • Executable content was dropped or overwritten

      • CCleaner.exe (PID: 2756)
    • Searches for installed software

      • CCleaner.exe (PID: 2756)
    • Reads security settings of Internet Explorer

      • CCleaner.exe (PID: 2756)
    • Checks Windows Trust Settings

      • CCleaner.exe (PID: 2756)
    • Reads settings of System Certificates

      • CCleaner.exe (PID: 2756)
    • Reads the date of Windows installation

      • CCleaner.exe (PID: 2756)
    • Reads the Internet Settings

      • CCleaner.exe (PID: 2756)
    • Reads Microsoft Outlook installation path

      • CCleaner.exe (PID: 2756)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 3864)
    • Checks supported languages

      • CCleaner.exe (PID: 4004)
      • wmpnscfg.exe (PID: 3796)
      • CCleaner.exe (PID: 2756)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3796)
      • CCleaner.exe (PID: 4004)
      • CCleaner.exe (PID: 2756)
    • Reads Environment values

      • CCleaner.exe (PID: 2756)
      • CCleaner.exe (PID: 4004)
    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 3864)
    • Manual execution by a user

      • CCleaner.exe (PID: 4004)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3864)
    • Reads the machine GUID from the registry

      • CCleaner.exe (PID: 2756)
    • Reads CPU info

      • CCleaner.exe (PID: 2756)
    • Reads product name

      • CCleaner.exe (PID: 2756)
    • Creates files in the program directory

      • CCleaner.exe (PID: 2756)
    • Reads the software policy settings

      • CCleaner.exe (PID: 2756)
    • Checks proxy server information

      • CCleaner.exe (PID: 2756)
    • Creates files or folders in the user directory

      • CCleaner.exe (PID: 2756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe rundll32.exe no specs notepad.exe no specs ccleaner.exe no specs ccleaner.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2044"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3864 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2648"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\updateplatform.amd64fre_ba0ffb5bc09e6139e95cfdf23f5e55ef109e58cc.exe.jsonC:\Windows\System32\notepad.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2756"C:\Program Files\CCleaner\CCleaner.exe" /uacC:\Program Files\CCleaner\CCleaner.exe
taskeng.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
6.14.0.10584
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
3500"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\updateplatform.amd64fre_ba0ffb5bc09e6139e95cfdf23f5e55ef109e58cc.exe.jsonC:\Windows\System32\rundll32.exeiexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3796"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3864"C:\Program Files\Internet Explorer\iexplore.exe" "http://download.windowsupdate.com/phf/d/dod/ph/prod5/msdownload/update/software/defu/2024/02/1024/updateplatform.amd64fre_ba0ffb5bc09e6139e95cfdf23f5e55ef109e58cc.exe.json"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
4004"C:\Program Files\CCleaner\CCleaner.exe" C:\Program Files\CCleaner\CCleaner.exeexplorer.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
MEDIUM
Description:
CCleaner
Exit code:
0
Version:
6.14.0.10584
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
Total events
35 545
Read events
35 141
Write events
316
Delete events
88

Modification events

(PID) Process:(3864) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3864) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
328653280
(PID) Process:(3864) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31090445
(PID) Process:(3864) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
628815780
(PID) Process:(3864) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31090445
(PID) Process:(3864) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3864) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3864) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3864) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3864) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
3
Suspicious files
24
Text files
13
Unknown types
13

Dropped files

PID
Process
Filename
Type
3864iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFB1A22EA90E65D8EA.TMPbinary
MD5:FF96E756B288ADB85BAAFB45E823CD83
SHA256:194BB957EBDA95763BC353A7A2436639F3F505B2B8BAD1E4CC68C2A92FB4A1F3
2756CCleaner.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ed7a5cc3cca8d52a.customDestinations-msbinary
MD5:11165F79DD26A6BCCA40BB5926CA8153
SHA256:F84A0010EBA333A02EF2F8B23A9EDAC7C5A4440E22CED2F8E3D8D595C12D9EC7
2756CCleaner.exeC:\Program Files\CCleaner\gcapi_17087709002756.dllexecutable
MD5:F637D5D3C3A60FDDB5DD397556FE9B1D
SHA256:641B843CB6EE7538EC267212694C9EF0616B9AC9AB14A0ABD7CF020678D50B02
2756CCleaner.exeC:\Program Files\CCleaner\gcapi_dll.dllexecutable
MD5:F637D5D3C3A60FDDB5DD397556FE9B1D
SHA256:641B843CB6EE7538EC267212694C9EF0616B9AC9AB14A0ABD7CF020678D50B02
2756CCleaner.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\0BLDGNOI.txttext
MD5:326C45671DAE950D6501517D1E8B2683
SHA256:A547BF6BC70C69639FE9DDBF46C45B8D6223E283E384F35C3DE31FD07E8ED40F
2756CCleaner.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAder
MD5:EC595EEAD4C696D69CC7E54CF7427B8C
SHA256:C209F113AEB88E5BD96679CE477DF1D94D15BA8EEC514A0A2959448CB5491EA8
2044iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\updateplatform.amd64fre_ba0ffb5bc09e6139e95cfdf23f5e55ef109e58cc.exe[1].jsonbinary
MD5:427DCE2BD709C3D1F3962859C4A68523
SHA256:B0F5EF08EAA84608BD1A46543F539226FD546D010B4071490E0C3CAD28B7ACCD
2756CCleaner.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:037AE8164352CA91E80AD33054D1906D
SHA256:07C018EB07002663D5248DAA8A65EAF587955E3DB45735E7E3AC9CB13D7D664E
2756CCleaner.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ed7a5cc3cca8d52a.customDestinations-ms~RF183f36.TMPbinary
MD5:C180671859156085B9BD60310F93B9CC
SHA256:12D48AA1D1EB02FC085BEBD25CBDFC19D65B8B4059B5130BD2E74DCDE5394FFE
3864iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\updateplatform.amd64fre_ba0ffb5bc09e6139e95cfdf23f5e55ef109e58cc.exe.jsonbinary
MD5:427DCE2BD709C3D1F3962859C4A68523
SHA256:B0F5EF08EAA84608BD1A46543F539226FD546D010B4071490E0C3CAD28B7ACCD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
29
DNS requests
15
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2044
iexplore.exe
GET
200
178.79.208.1:80
http://download.windowsupdate.com/phf/d/dod/ph/prod5/msdownload/update/software/defu/2024/02/1024/updateplatform.amd64fre_ba0ffb5bc09e6139e95cfdf23f5e55ef109e58cc.exe.json
unknown
binary
785 b
unknown
2756
CCleaner.exe
GET
200
2.16.164.65:80
http://ncc.avast.com/ncc.txt
unknown
text
26 b
unknown
2756
CCleaner.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1beae6b9a62e5d4e
unknown
unknown
2756
CCleaner.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
2756
CCleaner.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIAjrICMzZli2TN25s%3D
unknown
binary
724 b
unknown
2756
CCleaner.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/s/gts1d4/dKa2DF3Ws7g/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQCirF%2F66XssownTCQRm1ZB%2F
unknown
binary
472 b
unknown
2756
CCleaner.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
binary
471 b
unknown
2756
CCleaner.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?87b176368543c388
unknown
unknown
2756
CCleaner.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6d8ba188502ee14a
unknown
unknown
2756
CCleaner.exe
GET
200
142.250.185.163:80
http://ocsp.pki.goog/s/gts1d4/t0jeL7ceLrY/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICEQDRSW2avX2yRQo3SfbomPuF
unknown
binary
472 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2044
iexplore.exe
178.79.208.1:80
download.windowsupdate.com
LLNW
NL
unknown
2756
CCleaner.exe
2.16.164.65:80
ncc.avast.com
Akamai International B.V.
NL
unknown
2756
CCleaner.exe
34.117.223.223:443
analytics.ff.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
2756
CCleaner.exe
34.111.24.1:443
ipm-provider.ff.avast.com
GOOGLE
US
unknown
2756
CCleaner.exe
2.16.97.131:443
www.ccleaner.com
Akamai International B.V.
NL
unknown
2756
CCleaner.exe
34.160.176.28:443
shepherd.ff.avast.com
GOOGLE
US
unknown
2756
CCleaner.exe
34.149.149.62:443
ip-info.ff.avast.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
download.windowsupdate.com
  • 178.79.208.1
  • 87.248.202.1
whitelisted
ncc.avast.com
  • 2.16.164.65
  • 2.16.164.40
whitelisted
analytics.ff.avast.com
  • 34.117.223.223
whitelisted
ipm-provider.ff.avast.com
  • 34.111.24.1
whitelisted
www.ccleaner.com
  • 2.16.97.131
whitelisted
shepherd.ff.avast.com
  • 34.160.176.28
whitelisted
ip-info.ff.avast.com
  • 34.149.149.62
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.pki.goog
  • 142.250.185.163
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
2756
CCleaner.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
Process
Message
CCleaner.exe
[2024-02-24 10:34:59.815] [error ] [settings ] [ 2756: 2672] [6000C4: 356] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
Failed to open log file 'C:\Program Files\CCleaner'
CCleaner.exe
OnLanguage - en
CCleaner.exe
[2024-02-24 10:35:00.487] [error ] [settings ] [ 2756: 796] [9434E9: 359] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
[2024-02-24 10:35:00.502] [error ] [Burger ] [ 2756: 796] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
[2024-02-24 10:35:00.502] [error ] [Burger ] [ 2756: 796] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
CCleaner.exe
startCheckingLicense()
CCleaner.exe
OnLanguage - en
CCleaner.exe
OnLanguage - en
CCleaner.exe
OnLanguage - en