URL:

https://clubderestaurantescmr.resermap.com

Full analysis: https://app.any.run/tasks/3e8d9da1-112b-430c-aff6-8dcdeab6d2d3
Verdict: Malicious activity
Analysis date: August 24, 2023, 14:06:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

09BC4C712DCD53D8DC3A0417AFEA6DA6

SHA1:

A7D96C31C15B62DBC0D52F34ACD1E29B45FEE619

SHA256:

BCEA0862284F814C4A46254125C0EABC7C5FE81FF5E2F715E337BA487BED927D

SSDEEP:

3:N8UyazUBLmIEg:2UyazUj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Steals credentials from Web Browsers

      • CCleaner.exe (PID: 3972)
    • Actions looks like stealing of personal data

      • CCleaner.exe (PID: 3972)
  • SUSPICIOUS

    • The process executes via Task Scheduler

      • CCleanerBugReport.exe (PID: 3584)
      • CCUpdate.exe (PID: 348)
    • Reads settings of System Certificates

      • CCleanerBugReport.exe (PID: 3584)
    • Executable content was dropped or overwritten

      • CCUpdate.exe (PID: 348)
    • Searches for installed software

      • CCleaner.exe (PID: 3972)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 124)
    • Checks supported languages

      • CCleanerBugReport.exe (PID: 3584)
      • CCUpdate.exe (PID: 348)
      • CCleaner.exe (PID: 3972)
    • Reads the machine GUID from the registry

      • CCleanerBugReport.exe (PID: 3584)
      • CCUpdate.exe (PID: 348)
      • CCleaner.exe (PID: 3972)
    • Creates files in the program directory

      • CCleanerBugReport.exe (PID: 3584)
      • CCUpdate.exe (PID: 348)
    • Reads the computer name

      • CCleanerBugReport.exe (PID: 3584)
      • CCleaner.exe (PID: 3972)
      • CCUpdate.exe (PID: 348)
    • Reads CPU info

      • CCleanerBugReport.exe (PID: 3584)
      • CCleaner.exe (PID: 3972)
    • Reads Environment values

      • CCleaner.exe (PID: 3972)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe ccleanerbugreport.exe ccupdate.exe ccleaner.exe

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Program Files\Internet Explorer\iexplore.exe" "https://clubderestaurantescmr.resermap.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\version.dll
348"C:\Program Files\CCleaner\CCUpdate.exe" C:\Program Files\CCleaner\CCUpdate.exe
taskeng.exe
User:
SYSTEM
Company:
Piriform Software Ltd
Integrity Level:
SYSTEM
Description:
CCleaner CCleaner emergency updater
Exit code:
0
Version:
23.3.12.0
Modules
Images
c:\program files\ccleaner\ccupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
2388"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:124 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\iertutil.dll
3584"C:\Program Files\CCleaner\CCleanerBugReport.exe" --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "19ce970b-f6c0-4a09-bae4-274b971730e0" --version "6.14.10584" --silentC:\Program Files\CCleaner\CCleanerBugReport.exe
taskeng.exe
User:
admin
Company:
Piriform Software
Integrity Level:
HIGH
Description:
CCleaner Bug Report
Exit code:
2
Version:
1.0.0.1
Modules
Images
c:\program files\ccleaner\ccleanerbugreport.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
3972dummy /ccupdateC:\Program Files\CCleaner\CCleaner.exe
CCUpdate.exe
User:
SYSTEM
Company:
Piriform Software Ltd
Integrity Level:
SYSTEM
Description:
CCleaner
Exit code:
0
Version:
6.14.0.10584
Modules
Images
c:\program files\ccleaner\ccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
Total events
12 236
Read events
12 151
Write events
85
Delete events
0

Modification events

(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(124) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
2
Suspicious files
5
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
124iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:304811D7B957633DD225A7D694BFE9F9
SHA256:B983F388C416CEAA622B5281F22CDCD52F8D423BA1D47631A1088AAE92F66062
124iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:F72F23121EFA56CD917F15E8756FEE24
SHA256:EC72E322E0254067062D84B882A822365DFBD2DB33E0126FEDE2275DBC95A7A2
124iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776der
MD5:B2C81DC385D8027DFE5316AF20681390
SHA256:B487445E858A87D2A91424E02A843CE6A56E859760674C5C7666418130C63406
348CCUpdate.exeC:\Program Files\CCleaner\Setup\4de1b2ef-6727-4bd4-a5ea-3e3d974749e3.xmlxml
MD5:C3F530732A39B2EE497E16818503198E
SHA256:678127F81EBB1BF7969D64AACCE3BCAA28A27C046ECC4975A1F434053EFA4BD8
3584CCleanerBugReport.exeC:\Program Files\CCleaner\DATA\log\BugReport.logtext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
124iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:F7DCB24540769805E5BB30D193944DCE
SHA256:6B88C6AC55BBD6FEA0EBE5A760D1AD2CFCE251C59D0151A1400701CB927E36EA
3584CCleanerBugReport.exeC:\Program Files\CCleaner\Data\log\BugReport.statustext
MD5:94B95A77581EE9DC613D5682352FB0E7
SHA256:77D89468AF233D9DDFCD77647862CDA2D711B81993A069064547E8AFD967CBF2
348CCUpdate.exeC:\Program Files\CCleaner\Setup\9946455c-9d94-454c-bd3b-4f38e25feb13.iniini
MD5:2AF9F69DF769F876F6E02DA18E966020
SHA256:473D48A44A348F6C547AEFD2C60DD4B9DE0092E1FB94A7611BDD374783EF3B2C
348CCUpdate.exeC:\Program Files\CCleaner\Setup\6cc4d7f7-00c0-45bf-bb12-b56006f93a8a\update.xmlxml
MD5:5F0B282FF0D296F56B7A752C29F94BA8
SHA256:4C7A335CE5EA893E2A6A18FB862AC3A26355B7849A391BB9C6A4D89227ADC7F5
348CCUpdate.exeC:\Program Files\CCleaner\ccleaner_update_helper.exeexecutable
MD5:38BA21B056D1713E0B7BFE1D1D11B12A
SHA256:872CB81DE4DD02ACA60FB2FCEE956379CD74C3331D4A9D2B54E4AF5DFD3BFF5A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
34
DNS requests
25
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
348
CCUpdate.exe
HEAD
200
23.48.23.40:80
http://emupdate.avcdn.net/files/emupdate/pong.txt
US
whitelisted
1088
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4dc5b3e0f85b783d
US
whitelisted
348
CCUpdate.exe
GET
200
23.48.23.59:80
http://ccleaner.tools.avcdn.net/tools/ccleaner/update/ccupdate035.cab
US
compressed
414 Kb
whitelisted
348
CCUpdate.exe
GET
200
23.48.23.59:80
http://ccleaner.tools.avcdn.net/tools/ccleaner/update/patches.ini
US
ini
170 b
whitelisted
348
CCUpdate.exe
GET
200
23.48.23.59:80
http://ccleaner.tools.avcdn.net/tools/ccleaner/update/updates.xml
US
xml
1.58 Kb
whitelisted
124
iexplore.exe
GET
200
209.197.3.8:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7b4d5311b636771a
US
compressed
4.70 Kb
whitelisted
124
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2388
iexplore.exe
40.71.86.224:443
clubderestaurantescmr.resermap.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3284
svchost.exe
239.255.255.250:1900
whitelisted
124
iexplore.exe
184.86.251.10:443
www.bing.com
Akamai International B.V.
DE
suspicious
3584
CCleanerBugReport.exe
34.159.244.215:443
winqual.sb.avast.com
GOOGLE-CLOUD-PLATFORM
DE
unknown
348
CCUpdate.exe
34.149.149.62:443
ip-info.ff.avast.com
GOOGLE
US
suspicious
124
iexplore.exe
184.86.251.14:443
www.bing.com
Akamai International B.V.
DE
suspicious
124
iexplore.exe
152.199.19.161:443
EDGECAST
US
whitelisted
3584
CCleanerBugReport.exe
34.78.50.65:443
winqual.sb.avast.com
GOOGLE-CLOUD-PLATFORM
BE
unknown
124
iexplore.exe
184.86.251.13:443
www.bing.com
Akamai International B.V.
DE
suspicious
348
CCUpdate.exe
23.48.23.40:80
emupdate.avcdn.net
Akamai International B.V.
DE
suspicious

DNS requests

Domain
IP
Reputation
clubderestaurantescmr.resermap.com
  • 40.71.86.224
unknown
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 184.86.251.10
  • 184.86.251.14
  • 184.86.251.13
  • 184.86.251.12
  • 184.86.251.7
  • 184.86.251.11
  • 184.86.251.9
  • 184.86.251.16
  • 184.86.251.15
whitelisted
winqual.sb.avast.com
  • 34.159.244.215
  • 34.78.50.65
unknown
iecvlist.microsoft.com
whitelisted
r20swj13mr.microsoft.com
whitelisted
ip-info.ff.avast.com
  • 34.149.149.62
whitelisted
emupdate.avcdn.net
  • 23.48.23.4
  • 23.48.23.40
whitelisted
ccleaner.tools.avcdn.net
  • 23.48.23.59
  • 23.48.23.7
  • 2.16.164.64
  • 2.16.164.115
whitelisted
ctldl.windowsupdate.com
  • 209.197.3.8
  • 93.184.221.240
whitelisted

Threats

Found threats are available for the paid subscriptions
4 ETPRO signatures available at the full report
Process
Message
CCleaner.exe
Failed to open log file 'C:\Program Files\CCleaner'
CCleaner.exe
[2023-08-24 14:08:04.571] [error ] [settings ] [ 3972: 952] [6000C4: 356] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner.exe
[2023-08-24 14:08:04.586] [error ] [lif_utils ] [ 3972: 952] [226DB9: 571] ~/acaZ4nLaoDU4qJstxgPyLy6G3KI1DiegfunPr8GStG4pg==
CCleaner.exe
[2023-08-24 14:08:04.586] [error ] [lil ] [ 3972: 952] [81E517: 189] ~vLkMfNz+MoTE+7IlsQUVha6xC2aMmy2SyO/mJa1LQsSzsB5nk8kzx9HqtC2zDlvAr95fM9ybaseBq+Zs/ksPhf30XzPcm2rHgavmbP5LD4X99F8z3Jtqx4Gr5mz+Sw+F/fRfM9ybaseBq+Zs/ksPhf30PHyY3nDHkfP2fO5bH5Xo4187xIxj
CCleaner.exe
[2023-08-24 14:08:04.586] [error ] [lil ] [ 3972: 952] [81E517: 189] ~uqUPf9z9K47N/rQp/g9a17S6GDOV1SOT