| download: | /ISetup5.exe |
| Full analysis: | https://app.any.run/tasks/56fccd7b-a049-4639-a132-db3bc23cf90d |
| Verdict: | Malicious activity |
| Threats: | GCleaner is a type of malware loader that has the capability to deliver numerous malicious software programs, which differ based on the location of the targeted victim. This malware is commonly spread through fraudulent websites that advertise free PC optimization tools |
| Analysis date: | April 15, 2024, 10:47:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 367655671A22A537CA614704F4B506C8 |
| SHA1: | B219FB346CA645501F9A0F202C928A781DC55462 |
| SHA256: | E4A4187057882D04B22D5FA1007DCEB599388F15547889965E888294C4DEAB85 |
| SSDEEP: | 12288:1xHPcXIacLpco6svFKqdu/d3iMqkez3F1MkfJHhdxVVVVVE4:L6u1FKq6d3iMqkW3FOYJhd44 |
| .exe | | | Win64 Executable (generic) (72.3) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (11.8) |
| .exe | | | Clipper DOS Executable (5.2) |
| .exe | | | Generic Win/DOS Executable (5.2) |
| .exe | | | DOS Executable Generic (5.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:04:21 02:50:09+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 108544 |
| InitializedDataSize: | 43203072 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x68f2 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 42.0.0.0 |
| ProductVersionNumber: | 83.0.0.0 |
| FileFlagsMask: | 0x950a |
| FileFlags: | (none) |
| FileOS: | Unknown (0x20823) |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Unknown (0479) |
| CharacterSet: | Unknown (24E2) |
| InternalName: | Hole |
| FileDescription: | Bill |
| OriginalFileName: | Fires |
| ProductName: | Selfie |
| ProductVersions: | 46.10.50.17 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 324 | "C:\Program Files\iolo technologies\System Mechanic\iolo.exe" | C:\Program Files\iolo technologies\System Mechanic\iolo.exe | SystemMechanic_5488CB36-BE62-4606-B07B-2EE938868BD1.exe | ||||||||||||
User: admin Company: RealDefense LLC Integrity Level: HIGH Description: System Mechanic Exit code: 4 Version: 24.3.0.57 Modules
| |||||||||||||||
| 784 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4212 --field-trial-handle=1152,i,13237446477805427599,8312076922104909723,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 848 | "C:\Users\admin\AppData\Local\Temp\u21k.1.exe" | C:\Users\admin\AppData\Local\Temp\u21k.1.exe | ISetup5.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1168 | "C:\Program Files\iolo technologies\System Mechanic\ioloTrayApp.exe" | C:\Program Files\iolo technologies\System Mechanic\ioloTrayApp.exe | iolo.exe | ||||||||||||
User: admin Company: RealDefense LLC Integrity Level: HIGH Description: ioloTrayApp Exit code: 0 Version: 24.3.0.57 Modules
| |||||||||||||||
| 1232 | "C:\Program Files\iolo technologies\System Mechanic\ioloTrayApp.exe" | C:\Program Files\iolo technologies\System Mechanic\ioloTrayApp.exe | iolo.exe | ||||||||||||
User: admin Company: RealDefense LLC Integrity Level: HIGH Description: ioloTrayApp Exit code: 0 Version: 24.3.0.57 Modules
| |||||||||||||||
| 1340 | "C:\Users\admin\AppData\Local\Temp\iolo\dm\SystemMechanic_5488CB36-BE62-4606-B07B-2EE938868BD1.exe" /eieci=11A12794-499E-4FA0-A281-A9A9AA8B2685 /eipi=5488CB36-BE62-4606-B07B-2EE938868BD1 | C:\Users\admin\AppData\Local\Temp\iolo\dm\SystemMechanic_5488CB36-BE62-4606-B07B-2EE938868BD1.exe | — | u21k.1.exe | |||||||||||
User: admin Company: RealDefense LLC Integrity Level: MEDIUM Description: System Mechanic Exit code: 3221226540 Version: 24.3.0.57 Modules
| |||||||||||||||
| 1384 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1424 --field-trial-handle=1152,i,13237446477805427599,8312076922104909723,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1628 | "C:\Program Files\iolo technologies\System Mechanic\WPF_Driver\release\win32\nfregdrv.exe" pgfilter | C:\Program Files\iolo technologies\System Mechanic\WPF_Driver\release\win32\nfregdrv.exe | — | SystemMechanic_5488CB36-BE62-4606-B07B-2EE938868BD1.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1864 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3548 --field-trial-handle=1152,i,13237446477805427599,8312076922104909723,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1928 | "C:\Program Files\iolo technologies\System Mechanic\iolo.exe" | C:\Program Files\iolo technologies\System Mechanic\iolo.exe | explorer.exe | ||||||||||||
User: admin Company: RealDefense LLC Integrity Level: HIGH Description: System Mechanic Exit code: 4 Version: 24.3.0.57 Modules
| |||||||||||||||
| (PID) Process: | (2648) ISetup5.exe | Key: | HKEY_CURRENT_USER\Software\BroomCleaner |
| Operation: | write | Name: | Installed |
Value: 1 | |||
| (PID) Process: | (2648) ISetup5.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2648) ISetup5.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2648) ISetup5.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2648) ISetup5.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (4044) u21k.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (4044) u21k.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (4044) u21k.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (4044) u21k.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (4044) u21k.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2648 | ISetup5.exe | C:\Users\admin\AppData\Local\Temp\u21k.0.exe | executable | |
MD5:— | SHA256:— | |||
| 2648 | ISetup5.exe | C:\Users\admin\AppData\Local\Temp\u21k.1.exe | executable | |
MD5:— | SHA256:— | |||
| 848 | u21k.1.exe | C:\Users\admin\AppData\Local\Temp\iolo\dm\ioloDMLog.txt | text | |
MD5:— | SHA256:— | |||
| 848 | u21k.1.exe | C:\ProgramData\iolo\logs\WSComm.log | text | |
MD5:— | SHA256:— | |||
| 2096 | SystemMechanic_5488CB36-BE62-4606-B07B-2EE938868BD1.exe | C:\ProgramData\iolo technologies\logs\bootstrap.log | text | |
MD5:— | SHA256:— | |||
| 2096 | SystemMechanic_5488CB36-BE62-4606-B07B-2EE938868BD1.exe | C:\Users\admin\AppData\Local\Microsoft\ApplicationInsights\47dcca04762a106e6b55dd88274558025456a143c2b1d8c4b4388b40b1f29722\2gsnt225.4ec | binary | |
MD5:— | SHA256:— | |||
| 2096 | SystemMechanic_5488CB36-BE62-4606-B07B-2EE938868BD1.exe | C:\Program Files\iolo technologies\System Mechanic\ACResources.dll | executable | |
MD5:— | SHA256:— | |||
| 2096 | SystemMechanic_5488CB36-BE62-4606-B07B-2EE938868BD1.exe | C:\Program Files\iolo technologies\System Mechanic\gpp.exe | executable | |
MD5:— | SHA256:— | |||
| 2096 | SystemMechanic_5488CB36-BE62-4606-B07B-2EE938868BD1.exe | C:\Program Files\iolo technologies\System Mechanic\defrag.dll | executable | |
MD5:— | SHA256:— | |||
| 2096 | SystemMechanic_5488CB36-BE62-4606-B07B-2EE938868BD1.exe | C:\Program Files\iolo technologies\System Mechanic\Incinerator.exe | executable | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2648 | ISetup5.exe | GET | 200 | 185.172.128.228:80 | http://185.172.128.228/ping.php?substr=five | unknown | — | — | unknown |
2648 | ISetup5.exe | GET | 200 | 185.172.128.90:80 | http://185.172.128.90/cpa/ping.php?substr=five&s=ab&sub=0 | unknown | — | — | unknown |
4044 | u21k.0.exe | POST | 200 | 185.172.128.209:80 | http://185.172.128.209/3cd2b41cbde8fc9c.php | unknown | — | — | unknown |
2648 | ISetup5.exe | GET | 200 | 185.172.128.59:80 | http://185.172.128.59/syncUpd.exe | unknown | — | — | unknown |
856 | svchost.exe | HEAD | 200 | 169.150.247.34:80 | http://download.iolo.net/sm/24/11A12794-499E-4FA0-A281-A9A9AA8B2685/24.3.0.57/SystemMechanic.exe | unknown | — | — | unknown |
856 | svchost.exe | GET | 200 | 169.150.247.34:80 | http://download.iolo.net/sm/24/11A12794-499E-4FA0-A281-A9A9AA8B2685/24.3.0.57/SystemMechanic.exe | unknown | — | — | unknown |
324 | iolo.exe | HEAD | 200 | 185.59.220.198:80 | http://download.iolo.net/sm/profiles/default/profiles.dat | unknown | — | — | unknown |
2648 | ISetup5.exe | GET | 200 | 185.172.128.228:80 | http://185.172.128.228/BroomSetup.exe | unknown | — | — | unknown |
324 | iolo.exe | HEAD | 200 | 185.59.220.198:80 | http://download.iolo.net/sm/supertuds/default/tud.dat | unknown | — | — | unknown |
848 | u21k.1.exe | POST | 200 | 20.157.87.45:80 | http://svc.iolo.com/__svc/sbv/DownloadManager.ashx | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2648 | ISetup5.exe | 185.172.128.90:80 | — | OOO Nadym Svyaz Service | RU | malicious |
2648 | ISetup5.exe | 185.172.128.228:80 | — | OOO Nadym Svyaz Service | RU | unknown |
2648 | ISetup5.exe | 185.172.128.59:80 | — | OOO Nadym Svyaz Service | RU | unknown |
4044 | u21k.0.exe | 185.172.128.209:80 | — | OOO Nadym Svyaz Service | RU | malicious |
848 | u21k.1.exe | 20.157.87.45:80 | svc.iolo.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
1888 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
856 | svchost.exe | 169.150.247.34:80 | download.iolo.net | — | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
svc.iolo.com |
| unknown |
download.iolo.net |
| whitelisted |
westus2-2.in.applicationinsights.azure.com |
| unknown |
iolo.azure-api.net |
| unknown |
www.iolo.com |
| unknown |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
assets.iolo.com |
| unknown |
fonts.googleapis.com |
| whitelisted |
fonts.gstatic.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2648 | ISetup5.exe | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 32 |
2648 | ISetup5.exe | A Network Trojan was detected | LOADER [ANY.RUN] GCleaner URI Pattern M2 |
2648 | ISetup5.exe | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 32 |
2648 | ISetup5.exe | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 32 |
2648 | ISetup5.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
2648 | ISetup5.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2648 | ISetup5.exe | Potentially Bad Traffic | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response |
2648 | ISetup5.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
2648 | ISetup5.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2648 | ISetup5.exe | Potentially Bad Traffic | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response |
Process | Message |
|---|---|
u21k.1.exe | PerformGetOrPost : Attempting a POST on http://svc.iolo.com/__svc/sbv/DownloadManager.ashx. |
u21k.1.exe | -> No proxy. Direct connection |
u21k.1.exe | HandleCommunicationFailure : Service Communication failed (attempt # 1 of 3). |
u21k.1.exe | PeformServiceCommunication : Error in Class EIdSocketError. Socket Error # 10060
Connection timed out.. |
u21k.1.exe | PerformGetOrPost : Attempting a POST on http://svc.iolo.com/__svc/sbv/DownloadManager.ashx. |
u21k.1.exe | HandleCommunicationFailure : CanRetry = True. |
u21k.1.exe | -> No proxy. Direct connection |
u21k.1.exe | IsValidCommunication : Result := True. |
u21k.1.exe | -> No proxy. Direct connection |
u21k.1.exe | PerformGetOrPost : Attempting a POST on http://svc.iolo.com/__svc/sbv/DownloadManager.ashx. |