IOC Report
https://download.ccleaner.com/portable/ccsetup629.zip

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\webappsstore.sqlite-shm
data
dropped
malicious
C:\Users\user\Downloads\2f4bfd42-2fd8-46c8-95e4-68502d31c004.tmp
Zip archive data, at least v2.0 to extract, compression method=deflate
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\000002.dbtmp
ASCII text
dropped
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\CURRENT (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\MANIFEST-000002
MPEG-4 LOAS
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\33CUD2J1\C0XLFJ0M.txt
Generic INItialization configuration [Common]
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\AN5UOLP8\info[1].json
JSON data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\V01.chk
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\V01.log
data
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
Extensible storage engine DataBase, version 0x620, checksum 0x78318f8e, page size 32768, Windows version 10.0
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.jfm
data
dropped
C:\Users\user\AppData\Local\Temp\6358C710-B89F-46B9-93F2-F6CAC44F5286
data
dropped
C:\Users\user\AppData\Local\Temp\D566D7D7-DCD6-471C-8109-BE0AD33199E3
data
dropped
C:\Users\user\AppData\Local\Temp\F07D8C6A-04B6-4025-869C-70A788D7B5C0
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\B249ZNM80TU3VQ2OKGVN.temp
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\cc3891bee323ecc0.customDestinations-ms (copy)
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:44:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:44:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:44:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:44:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:44:14 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\Downloads\ccsetup629.zip (copy)
Zip archive data, at least v2.0 to extract, compression method=deflate
dropped
C:\Users\user\Downloads\ccsetup629.zip.crdownload (copy)
Zip archive data, at least v2.0 to extract, compression method=deflate
dropped
C:\Users\user\Downloads\ccsetup629\Data\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417\44ED97C8-2D40-4A50-913D-673F6858B9AF
data
dropped
C:\Users\user\Downloads\ccsetup629\Data\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417\7d846b03-5697-42ad-987c-9d397e36e919
data
dropped
C:\Users\user\Downloads\ccsetup629\Data\usercfg.ini
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Users\user\Downloads\ccsetup629\LOG\DriverUpdEng.log
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Users\user\Downloads\ccsetup629\LOG\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417\44ED97C8-2D40-4A50-913D-673F6858B9AF
data
dropped
C:\Users\user\Downloads\ccsetup629\LOG\burger_client\8866F8A9-70C9-43A2-BFBE-EE00AA2DC417\78181805-65b0-48ec-b23e-bb9eea753fff
data
dropped
C:\Users\user\Downloads\ccsetup629\LOG\su_controller.log
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Users\user\Downloads\ccsetup629\Setup\config.def
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Downloads\ccsetup629\ccleaner.ini
Microsoft HTML Help Project
modified
C:\Users\user\Downloads\ccsetup629\gcapi_17297235455428.dll (copy)
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\Downloads\ccsetup629\gcapi_dll.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Users\user\Downloads\ccsetup629\lc.dat (copy)
data
dropped
C:\Windows\Tasks\CCleanerCrashReporting.job
data
dropped
C:\Windows\Temp\waapi-1729723784\db0796778834078181e5dc1f
ASCII text, with no line terminators
dropped
C:\Windows\Temp\waapi-1729723784\lc.dat
data
dropped
There are 32 hidden files, click here to show them.

Domains

Name
IP
Malicious
ipm-gcp-prod.ff.avast.com
34.111.24.1
shepherd-gcp.ff.avast.com
34.160.176.28
ip-info-gcp.ff.avast.com
34.111.175.102
www.google.com
142.250.186.68
analytics-prod-gcp.ff.avast.com
34.117.223.223
download.ccleaner.com
unknown
shepherd.ff.avast.com
unknown
www.ccleaner.com
unknown
analytics.avcdn.net
unknown
ip-info.ff.avast.com
unknown
ipm-provider.ff.avast.com
unknown
ipmcdn.avast.com
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
142.250.185.78
unknown
United States
34.111.24.1
ipm-gcp-prod.ff.avast.com
United States
34.111.175.102
ip-info-gcp.ff.avast.com
United States
2.19.225.128
unknown
European Union
1.1.1.1
unknown
Australia
108.177.15.84
unknown
United States
172.217.18.14
unknown
United States
192.168.2.16
unknown
unknown
192.168.2.7
unknown
unknown
23.212.89.211
unknown
United States
192.168.2.9
unknown
unknown
34.160.176.28
shepherd-gcp.ff.avast.com
United States
216.58.206.35
unknown
United States
142.250.181.227
unknown
United States
34.117.223.223
analytics-prod-gcp.ff.avast.com
United States
239.255.255.250
unknown
Reserved
There are 7 hidden IPs, click here to show them.