File name:

CCUpdate.exe

Full analysis: https://app.any.run/tasks/b4c15d35-a1dc-491e-8149-8f7defb81270
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: August 10, 2024, 15:33:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

943A4F169E9A3303ED6DEFC1AC3690BD

SHA1:

E0BD76B866624164C10B85D37EFB6474B84164DF

SHA256:

E531742A357907248DE84B99F68ED7E8EDD70E7CA918D21B24CC17EE4C128240

SSDEEP:

24576:q3mWRxLHNGoftow6ayTJGSeeWFwDQXTdVZ:q3mWRxLHNGoftow6ayGSeeWF2QXTdVZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • CCUpdate.exe (PID: 6472)
    • Actions looks like stealing of personal data

      • CCleaner64.exe (PID: 6532)
    • Steals credentials from Web Browsers

      • CCleaner64.exe (PID: 6532)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • CCUpdate.exe (PID: 6472)
    • Executable content was dropped or overwritten

      • CCUpdate.exe (PID: 6472)
    • Searches for installed software

      • CCleaner64.exe (PID: 6532)
    • Checks for external IP

      • CCUpdate.exe (PID: 6472)
  • INFO

    • Checks supported languages

      • CCUpdate.exe (PID: 6472)
      • CCleaner64.exe (PID: 6532)
    • Creates files in the program directory

      • CCUpdate.exe (PID: 6472)
    • Reads the computer name

      • CCUpdate.exe (PID: 6472)
      • CCleaner64.exe (PID: 6532)
    • Dropped object may contain TOR URL's

      • CCUpdate.exe (PID: 6472)
    • Reads the software policy settings

      • CCUpdate.exe (PID: 6472)
      • CCleaner64.exe (PID: 6532)
    • Reads Environment values

      • CCleaner64.exe (PID: 6532)
    • Reads CPU info

      • CCleaner64.exe (PID: 6532)
    • Reads the machine GUID from the registry

      • CCleaner64.exe (PID: 6532)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:03 07:16:09+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.38
CodeSize: 536576
InitializedDataSize: 283136
UninitializedDataSize: -
EntryPoint: 0x46df0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 24.8.15.0
ProductVersionNumber: 24.8.15.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Gen Digital Inc.
LegalCopyright: Copyright © 2005-2024 Gen Digital Inc. All rights reserved.
FileDescription: CCleaner CCleaner emergency updater
FileVersion: 24.8.15.0
InternalName: CCUpdate
OriginalFileName: CCUpdate.exe
ProductName: CCleaner CCleaner
ProductVersion: 24.8.15.0
ProductId: piriform-cc
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ccupdate.exe ccleaner64.exe ccupdate.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6424"C:\Users\admin\AppData\Local\Temp\CCUpdate.exe" C:\Users\admin\AppData\Local\Temp\CCUpdate.exeexplorer.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
MEDIUM
Description:
CCleaner CCleaner emergency updater
Exit code:
3221226540
Version:
24.8.15.0
Modules
Images
c:\users\admin\appdata\local\temp\ccupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6472"C:\Users\admin\AppData\Local\Temp\CCUpdate.exe" C:\Users\admin\AppData\Local\Temp\CCUpdate.exe
explorer.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
CCleaner CCleaner emergency updater
Exit code:
0
Version:
24.8.15.0
Modules
Images
c:\users\admin\appdata\local\temp\ccupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
6532dummy /ccupdateC:\Program Files\CCleaner\CCleaner64.exe
CCUpdate.exe
User:
admin
Company:
Piriform Software Ltd
Integrity Level:
HIGH
Description:
CCleaner
Exit code:
0
Version:
6.20.0.10897
Modules
Images
c:\program files\ccleaner\ccleaner64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
Total events
2 503
Read events
2 496
Write events
3
Delete events
4

Modification events

(PID) Process:(6472) CCUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:ccleaner_update_helper
Value:
C:\Program Files\CCleaner\ccleaner_update_helper.exe
(PID) Process:(6472) CCUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner
Operation:writeName:UpdateVersion
Value:
46
(PID) Process:(6472) CCUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Piriform\CCleaner
Operation:writeName:MicroUpdates
Value:
46=1723304000
(PID) Process:(6532) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:delete valueName:GUID
Value:
(PID) Process:(6532) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:delete valueName:GD
Value:
(PID) Process:(6532) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Piriform\CCleaner
Operation:delete valueName:SetupGD
Value:
(PID) Process:(6532) CCleaner64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:CCleaner Logging Type
Value:
Executable files
2
Suspicious files
1
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
6472CCUpdate.exeC:\Program Files\CCleaner\Setup\e09f8a9a-e03e-46aa-9a6d-0ba114d11935.xmlxml
MD5:AE6A8195071CA62513212CC891097046
SHA256:6670A81A48EA5C942C3617F0CFA026352ADFA1A9BCBB7848F4C41EA427585FF0
6472CCUpdate.exeC:\Program Files\CCleaner\Setup\ad4bf38b-e1a3-4b3c-87d8-e026aed8f434.cabcompressed
MD5:AA7D1C7FFA867757AE6F8C4DDF541A7C
SHA256:4D1E4C02610B3A26F801C122B2FA66532E5CC231D7DE8134E1CFF0EAEA1C5ACD
6472CCUpdate.exeC:\Program Files\CCleaner\Setup\b81aca84-73af-411a-9f86-4391eceebd78\update.xmlxml
MD5:31AE11ECE7D6DDEF5388AA54B9AF4831
SHA256:6798CD41AC2F9ED932AF01EFE92B34D0BAEF8A141212A8A8BE88B778BB75B208
6472CCUpdate.exeC:\Program Files\CCleaner\ccleaner_update_helper.exeexecutable
MD5:085836D33A93601B93FED6945B5888B7
SHA256:B35772D5854293EE72E324BA2AE49964D326EF56DC71D6C9D90133432B713AFA
6472CCUpdate.exeC:\Program Files\CCleaner\Setup\eb245c5a-2ce0-431a-b6ed-e0dccdaf9ed2.iniini
MD5:2AF9F69DF769F876F6E02DA18E966020
SHA256:473D48A44A348F6C547AEFD2C60DD4B9DE0092E1FB94A7611BDD374783EF3B2C
6472CCUpdate.exeC:\Program Files\CCleaner\Setup\b81aca84-73af-411a-9f86-4391eceebd78\ccleaner_update_helper.exeexecutable
MD5:085836D33A93601B93FED6945B5888B7
SHA256:B35772D5854293EE72E324BA2AE49964D326EF56DC71D6C9D90133432B713AFA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
49
DNS requests
24
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6472
CCUpdate.exe
HEAD
200
23.48.23.4:80
http://emupdate.avcdn.net/files/emupdate/pong.txt
unknown
whitelisted
6472
CCUpdate.exe
GET
200
23.48.23.59:80
http://ccleaner.tools.avcdn.net/tools/ccleaner/update/patches.ini
unknown
whitelisted
6472
CCUpdate.exe
GET
200
23.48.23.59:80
http://ccleaner.tools.avcdn.net/tools/ccleaner/update/ccupdate046.cab
unknown
whitelisted
6472
CCUpdate.exe
GET
200
23.48.23.59:80
http://ccleaner.tools.avcdn.net/tools/ccleaner/update/updates.xml
unknown
whitelisted
6380
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6532
CCleaner64.exe
GET
200
23.48.23.31:80
http://ncc.avast.com/ncc.txt
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3812
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3812
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1556
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
4016
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2876
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6472
CCUpdate.exe
34.149.149.62:443
ip-info.ff.avast.com
GOOGLE
US
unknown
6472
CCUpdate.exe
23.48.23.4:80
emupdate.avcdn.net
Akamai International B.V.
DE
unknown
6472
CCUpdate.exe
23.48.23.59:80
ccleaner.tools.avcdn.net
Akamai International B.V.
DE
unknown
6532
CCleaner64.exe
23.48.23.31:80
ncc.avast.com
Akamai International B.V.
DE
unknown
6532
CCleaner64.exe
34.117.223.223:443
analytics.avcdn.net
GOOGLE-CLOUD-PLATFORM
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.46
whitelisted
ip-info.ff.avast.com
  • 34.149.149.62
whitelisted
emupdate.avcdn.net
  • 23.48.23.4
  • 23.48.23.40
whitelisted
ccleaner.tools.avcdn.net
  • 23.48.23.59
  • 23.48.23.7
whitelisted
ncc.avast.com
  • 23.48.23.31
  • 23.48.23.10
whitelisted
analytics.avcdn.net
  • 34.117.223.223
whitelisted
www.bing.com
  • 184.86.251.22
  • 184.86.251.7
  • 184.86.251.9
  • 184.86.251.27
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.14
  • 20.190.160.20
  • 40.126.32.134
  • 40.126.32.76
  • 40.126.32.138
  • 20.190.160.22
  • 40.126.32.74
whitelisted

Threats

PID
Process
Class
Message
2256
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
2256
svchost.exe
Misc activity
ET INFO External IP Lookup Service in DNS Query (ip-info .ff .avast .com)
6472
CCUpdate.exe
Misc activity
ET INFO Observed External IP Lookup Domain (ip-info .ff .avast .com) in TLS SNI
4 ETPRO signatures available at the full report
Process
Message
CCleaner64.exe
[2024-08-10 15:33:21.873] [error ] [settings ] [ 6532: 6536] [000000: 0] Failed to get program directory Exception: Unable to determine program folder of product 'piriform-cc'! Code: 0x000000c0 (192)
CCleaner64.exe
[2024-08-10 15:33:21.873] [error ] [ini_access ] [ 6532: 6536] [000000: 0] Incorrect ini_accessor configuration! Fixing relative input path to avoid recursion. Input was: Setup
CCleaner64.exe
Failed to open log file 'C:\Program Files\CCleaner'