| URL: | https://cdn-129.anonfiles.com/Ldocj4I7u5/81daf590-1631971498/iobituninstaller.zip |
| Full analysis: | https://app.any.run/tasks/5c3c4161-e4fb-4a22-abc8-d8a4d1d1ab03 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | September 18, 2021, 13:15:08 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MD5: | CC66E8DD5E1A90CD05C83811EE5BEA7D |
| SHA1: | 0EB2FCA7169044E6F132787630F47FFD7E8AC944 |
| SHA256: | 43D06869FD25E3199100739E1E5E9FF960B67FCC4C19DB7AC1A84183F8D5390B |
| SSDEEP: | 3:N8cFX6iKk2/jeBEXIGcn6IzxlXLcn:2cFjKk2beBoIGcn6GxlXLc |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 276 | "C:\Program Files\IObit\IObit Uninstaller\IObitDownloader.exe" "/File=C:\Users\admin\AppData\Local\Temp\Freeware-iu.upt" /show /lang=English.lng /product=un "iTop In" | C:\Program Files\IObit\IObit Uninstaller\IObitDownloader.exe | — | iush.exe | |||||||||||
User: admin Company: IObit Integrity Level: HIGH Description: IObit Downloader Exit code: 0 Version: 11.0.0.17 Modules
| |||||||||||||||
| 312 | "C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe" /Set | C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe | IObitUninstaler.exe | ||||||||||||
User: admin Company: IObit Integrity Level: HIGH Description: UninstallMonitor Exit code: 0 Version: 11.0.1.15 Modules
| |||||||||||||||
| 328 | "C:\Users\admin\AppData\Local\Temp\is-A5BT0.tmp\iTopSetup.exe.tmp" /SL5="$102DE,12830154,204800,C:\ProgramData\IObit\IObit Uninstaller\Downloader\un\iTopSetup.exe.exe" /sp- /verysilent /suppressmsgboxes /NoRestart /insur=iu_in_b | C:\Users\admin\AppData\Local\Temp\is-A5BT0.tmp\iTopSetup.exe.tmp | — | iTopSetup.exe.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 756 | "C:\ProgramData\IObit\IObit Uninstaller\Downloader\un\isrSetup.exe.exe" /sp- /verysilent /suppressmsgboxes /insur=iu_in | C:\ProgramData\IObit\IObit Uninstaller\Downloader\un\isrSetup.exe.exe | — | IObitDownloader.exe | |||||||||||
User: admin Company: iTop Inc. Integrity Level: HIGH Description: iTop Screen Recorder Exit code: 0 Version: 1.3.0.331 Modules
| |||||||||||||||
| 816 | "C:\Users\admin\AppData\Local\Temp\is-EQ41N.tmp\iobituninstaller.tmp" /SL5="$201CE,25494495,139264,C:\Users\admin\AppData\Local\Temp\Rar$EXa4092.11628\iobituninstaller.exe" /verysilent /NORESTART /DIR="C:\Program Files\IObit\IObit Uninstaller\" /TASKS="desktopicon, " /do /dt "" | C:\Users\admin\AppData\Local\Temp\is-EQ41N.tmp\iobituninstaller.tmp | iobituninstaller.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 840 | "C:\Users\admin\AppData\Local\Temp\is-O04F0.tmp\iScrInit.exe" /KillProcess /installdir="C:\Program Files\iTop Screen Recorder" | C:\Users\admin\AppData\Local\Temp\is-O04F0.tmp\iScrInit.exe | isrSetup.exe.tmp | ||||||||||||
User: admin Company: iTop Inc. Integrity Level: HIGH Description: iTop Screen Recorderr Ini Exit code: 0 Version: 1.0.0.219 Modules
| |||||||||||||||
| 868 | "C:\Program Files\iTop Screen Recorder\LocalLang.exe" | C:\Program Files\iTop Screen Recorder\LocalLang.exe | — | isrSetup.exe.tmp | |||||||||||
User: admin Company: iTop Inc. Integrity Level: HIGH Description: Check Language Exit code: 0 Version: 1.0.0.20 Modules
| |||||||||||||||
| 880 | C:\Windows\system32\svchost.exe -k netsvcs | C:\Windows\system32\svchost.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 956 | "C:\ProgramData\IObit\IObit Uninstaller\Downloader\un\iTopSetup.exe.exe" /sp- /verysilent /suppressmsgboxes /NoRestart /insur=iu_in_b | C:\ProgramData\IObit\IObit Uninstaller\Downloader\un\iTopSetup.exe.exe | IObitDownloader.exe | ||||||||||||
User: admin Company: iTop Inc. Integrity Level: HIGH Description: iTop VPN Exit code: 0 Version: 2.2.0.1935 Modules
| |||||||||||||||
| 1132 | "C:\Users\admin\AppData\Local\Temp\is-8FU5K.tmp\iobituninstaller.tmp" /SL5="$301BA,25494495,139264,C:\Users\admin\AppData\Local\Temp\Rar$EXa4092.11628\iobituninstaller.exe" /SPAWNWND=$201BC /NOTIFYWND=$50170 | C:\Users\admin\AppData\Local\Temp\is-8FU5K.tmp\iobituninstaller.tmp | iobituninstaller.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2368) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 1 | |||
| (PID) Process: | (2368) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: | |||
| (PID) Process: | (2368) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30911631 | |||
| (PID) Process: | (2368) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: | |||
| (PID) Process: | (2368) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30911631 | |||
| (PID) Process: | (2368) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2368) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2368) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2368) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (2368) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3424 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:— | SHA256:— | |||
| 3424 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\iobituninstaller[1].zip | compressed | |
MD5:— | SHA256:— | |||
| 3424 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\644B8874112055B5E195ECB0E8F243A4 | binary | |
MD5:— | SHA256:— | |||
| 3424 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:— | SHA256:— | |||
| 3424 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\644B8874112055B5E195ECB0E8F243A4 | der | |
MD5:— | SHA256:— | |||
| 2368 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776 | binary | |
MD5:— | SHA256:— | |||
| 2368 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776 | der | |
MD5:— | SHA256:— | |||
| 3424 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\iobituninstaller.zip.dycxcuy.partial | compressed | |
MD5:— | SHA256:— | |||
| 2368 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DFD132043DD59DD2D6.TMP | gmc | |
MD5:— | SHA256:— | |||
| 2368 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{7BFE91DD-1882-11EC-B77D-12A9866C77DE}.dat | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2368 | iexplore.exe | GET | 304 | 8.253.207.120:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?377a063b31d5d8a8 | US | — | — | whitelisted |
2368 | iexplore.exe | GET | 304 | 8.253.207.120:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4aefdc36caaa7610 | US | — | — | whitelisted |
2368 | iexplore.exe | GET | 304 | 8.253.207.120:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b17ee077a706dad0 | US | — | — | whitelisted |
1080 | svchost.exe | GET | 304 | 8.253.207.120:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f0635202fa048553 | US | — | — | whitelisted |
3424 | iexplore.exe | GET | 200 | 92.123.224.83:80 | http://crl.identrust.com/DSTROOTCAX3CRL.crl | unknown | der | 1.16 Kb | whitelisted |
2368 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | der | 471 b | whitelisted |
3148 | Setup.exe | GET | 200 | 152.199.20.140:80 | http://update.iobit.com/infofiles/ac/appver-ac.upt | US | text | 600 b | whitelisted |
3148 | Setup.exe | GET | 206 | 152.199.20.140:80 | http://update.iobit.com/infofiles/iu11/Freeware-iu11.upt | US | text | 2.36 Kb | whitelisted |
3148 | Setup.exe | GET | 206 | 152.199.20.140:80 | http://update.iobit.com/infofiles/iu11/Freeware-iu11.upt | US | binary | 2.36 Kb | whitelisted |
3148 | Setup.exe | GET | 206 | 152.199.20.140:80 | http://update.iobit.com/infofiles/ac/appver-ac.upt | US | text | 600 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3424 | iexplore.exe | 45.154.253.58:443 | cdn-129.anonfiles.com | — | — | suspicious |
3424 | iexplore.exe | 8.253.207.120:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | malicious |
3424 | iexplore.exe | 92.123.224.83:80 | crl.identrust.com | Akamai International B.V. | — | suspicious |
3424 | iexplore.exe | 104.89.32.83:80 | x1.c.lencr.org | Akamai Technologies, Inc. | NL | suspicious |
2368 | iexplore.exe | 152.199.19.161:443 | iecvlist.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2368 | iexplore.exe | 8.253.207.120:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | malicious |
1080 | svchost.exe | 8.253.207.120:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | malicious |
2368 | iexplore.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
3148 | Setup.exe | 152.199.20.140:80 | update.iobit.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | malicious |
3148 | Setup.exe | 23.23.144.131:80 | ascstats.iobit.com | Amazon.com, Inc. | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
cdn-129.anonfiles.com |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
crl.identrust.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
update.iobit.com |
| whitelisted |
ascstats.iobit.com |
| whitelisted |
stats.iobit.com |
| suspicious |
PID | Process | Class | Message |
|---|---|---|---|
3148 | Setup.exe | Potentially Bad Traffic | ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3148 | Setup.exe | Potentially Bad Traffic | ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3148 | Setup.exe | Potentially Bad Traffic | ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3148 | Setup.exe | Potentially Bad Traffic | ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3148 | Setup.exe | Potentially Bad Traffic | ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3148 | Setup.exe | Potentially Bad Traffic | ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3148 | Setup.exe | Potentially Bad Traffic | ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3148 | Setup.exe | Potentially Bad Traffic | ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3148 | Setup.exe | Potentially Bad Traffic | ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
3992 | iush.exe | Potentially Bad Traffic | ET INFO Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) |
Process | Message |
|---|---|
Setup.exe | StartDownCfg |
Setup.exe | LanID=1033 |
Setup.exe | ALangID=1033 |
Setup.exe | doFinshedEvent_appver |
Setup.exe | doFinshedEvent |
Setup.exe | Isshowstring:1 |
Setup.exe | VRecommendFlag.FAll True |
Setup.exe | DetectionEx [??????????? ???????????]
DisplayName=('Kaspersky' & (not 'Password'))
[Kaspersky]
DisplayName=('Kaspersky' & (not 'Password'))
[??]
DisplayName=('Kaspersky' & (not 'Password'))
[McAfee]
DisplayName=(('McAfee' & ('AntiVirus' | 'Security' | 'Protection' | 'LiveSafe' | 'Firewall' | 'VPN')) | ('???') | ('BT NetProtect' | 'Firewall' | 'VPN'))
[Check Point]
DisplayName=('ZoneAlarm' & ('Security' | 'Antivirus' | 'Firewall' | 'VPN'))
[QuickHeal]
DisplayName=('Quick Heal' & ('Security' | 'Antivirus' | 'Firewall' | 'VPN' | 'PCTuner'))
[Adguard]
DisplayName=('AdGuard')
[F-Secure]
DisplayName=('Freedome' | 'F-Secure ID PROTECTION' | 'F-Secure SAFE')
|
Setup.exe | Itop promote Welcome |
Setup.exe | Itop check |