File name:

advanced-systemcare-setup.exe

Full analysis: https://app.any.run/tasks/9bda7e1f-5fce-4a86-8f90-34a41658b790
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: August 23, 2024, 23:27:54
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3B685BF27639F62D06B7370677E50EFF

SHA1:

4B2C198A1747B36F551690009305A5FE3B71BBE6

SHA256:

448A0C53C5DC0DFB69BA17AA5579B85394ED392BA324B300477D81A1916EF989

SSDEEP:

393216:1GEJB1uHQV2aDBxeUkhFLLZT7BMegUxqE06zU2wi45g+GCkMwl6X:nfgHG2a9xeUYMe1xAIAZECHWi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • PPUninstaller.exe (PID: 4604)
      • smBootTimeBase.exe (PID: 3916)
      • ASCService.exe (PID: 6780)
    • Steals credentials from Web Browsers

      • PPUninstaller.exe (PID: 4604)
      • smBootTimeBase.exe (PID: 3916)
    • Registers / Runs the DLL via REGSVR32.EXE

      • ASCInit.exe (PID: 5244)
    • Application was injected by another process

      • explorer.exe (PID: 4552)
    • Changes the autorun value in the registry

      • ASCInit.exe (PID: 5244)
    • Runs injected code in another process

      • ICONPIN64.exe (PID: 4920)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • advanced-systemcare-setup.exe (PID: 7088)
      • advanced-systemcare-setup.exe (PID: 6492)
      • advanced-systemcare-setup.tmp (PID: 4692)
      • advanced-systemcare-setup.exe (PID: 1488)
      • advanced-systemcare-setup.tmp (PID: 6480)
      • ASCInit.exe (PID: 5244)
    • Executable content was dropped or overwritten

      • advanced-systemcare-setup.exe (PID: 7088)
      • advanced-systemcare-setup.exe (PID: 6492)
      • advanced-systemcare-setup.tmp (PID: 4692)
      • advanced-systemcare-setup.exe (PID: 1488)
      • advanced-systemcare-setup.tmp (PID: 6480)
      • ASCInit.exe (PID: 5244)
    • Reads the date of Windows installation

      • advanced-systemcare-setup.tmp (PID: 7108)
      • advanced-systemcare-setup.tmp (PID: 4692)
      • advanced-systemcare-setup.tmp (PID: 6480)
      • PPUninstaller.exe (PID: 4604)
      • ASCInit.exe (PID: 5244)
      • IObitLiveUpdate.exe (PID: 5104)
    • Reads security settings of Internet Explorer

      • advanced-systemcare-setup.tmp (PID: 7108)
      • advanced-systemcare-setup.tmp (PID: 6480)
      • ASCInit.exe (PID: 5244)
      • advanced-systemcare-setup.tmp (PID: 4692)
      • IObitLiveUpdate.exe (PID: 5104)
    • Process drops legitimate windows executable

      • advanced-systemcare-setup.tmp (PID: 4692)
      • advanced-systemcare-setup.tmp (PID: 6480)
    • Reads the Windows owner or organization settings

      • advanced-systemcare-setup.tmp (PID: 4692)
      • advanced-systemcare-setup.tmp (PID: 6480)
    • Process drops SQLite DLL files

      • advanced-systemcare-setup.tmp (PID: 6480)
    • Searches for installed software

      • advanced-systemcare-setup.tmp (PID: 6480)
      • PPUninstaller.exe (PID: 4604)
      • ASCInit.exe (PID: 5244)
      • RealTimeProtector.exe (PID: 2580)
      • Register.exe (PID: 6796)
      • ASCService.exe (PID: 6780)
      • smBootTimeBase.exe (PID: 3916)
      • BrowserCleaner.exe (PID: 6620)
      • UninstallInfo.exe (PID: 7084)
      • PrivacyShield.exe (PID: 7140)
      • smBootTime.exe (PID: 1440)
      • smBootTime.exe (PID: 3448)
      • Display.exe (PID: 488)
      • AutoCare.exe (PID: 5248)
      • RealTimeProtector.exe (PID: 2092)
      • IObitLiveUpdate.exe (PID: 5104)
      • StartupInfo.exe (PID: 3584)
      • Register.exe (PID: 3176)
      • AutoSweep.exe (PID: 5720)
    • Drops a system driver (possible attempt to evade defenses)

      • advanced-systemcare-setup.tmp (PID: 6480)
    • Application launched itself

      • RealTimeProtector.exe (PID: 32)
    • Executes as Windows Service

      • ASCService.exe (PID: 6780)
    • Starts CMD.EXE for commands execution

      • ASCInit.exe (PID: 5244)
    • Likely accesses (executes) a file from the Public directory

      • ICONPIN64.exe (PID: 4920)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 6636)
  • INFO

    • Checks supported languages

      • advanced-systemcare-setup.exe (PID: 7088)
      • advanced-systemcare-setup.tmp (PID: 7108)
      • advanced-systemcare-setup.tmp (PID: 4692)
      • advanced-systemcare-setup.exe (PID: 6492)
      • Setup.exe (PID: 6616)
      • advanced-systemcare-setup.exe (PID: 1488)
      • advanced-systemcare-setup.tmp (PID: 6480)
      • ASCUpgrade.exe (PID: 400)
      • LocalLang.exe (PID: 6444)
      • ASCUpgrade.exe (PID: 6160)
      • PPUninstaller.exe (PID: 4604)
      • RealTimeProtector.exe (PID: 32)
      • ASCInit.exe (PID: 5244)
      • DiskDefrag.exe (PID: 6716)
      • RealTimeProtector.exe (PID: 2580)
      • Register.exe (PID: 6796)
      • ASCService.exe (PID: 6780)
      • smBootTimeBase.exe (PID: 3916)
      • UninstallInfo.exe (PID: 7084)
      • ICONPIN64.exe (PID: 4920)
      • BrowserCleaner.exe (PID: 6620)
      • smBootTime.exe (PID: 1440)
      • smBootTime.exe (PID: 3448)
      • Display.exe (PID: 488)
      • AutoSweep.exe (PID: 5720)
      • RealTimeProtector.exe (PID: 2092)
      • AutoCare.exe (PID: 5248)
      • IObitLiveUpdate.exe (PID: 5104)
      • StartupInfo.exe (PID: 3584)
      • Register.exe (PID: 3176)
      • PrivacyShield.exe (PID: 7140)
    • Reads the computer name

      • advanced-systemcare-setup.tmp (PID: 7108)
      • advanced-systemcare-setup.tmp (PID: 4692)
      • Setup.exe (PID: 6616)
      • advanced-systemcare-setup.tmp (PID: 6480)
      • ASCUpgrade.exe (PID: 6160)
      • ASCUpgrade.exe (PID: 400)
      • ASCInit.exe (PID: 5244)
      • PPUninstaller.exe (PID: 4604)
      • RealTimeProtector.exe (PID: 32)
      • RealTimeProtector.exe (PID: 2580)
      • ASCService.exe (PID: 6780)
      • Register.exe (PID: 6796)
      • UninstallInfo.exe (PID: 7084)
      • smBootTime.exe (PID: 1440)
      • smBootTime.exe (PID: 3448)
      • RealTimeProtector.exe (PID: 2092)
      • AutoSweep.exe (PID: 5720)
      • AutoCare.exe (PID: 5248)
      • IObitLiveUpdate.exe (PID: 5104)
      • smBootTimeBase.exe (PID: 3916)
      • Register.exe (PID: 3176)
    • Process checks computer location settings

      • advanced-systemcare-setup.tmp (PID: 7108)
      • advanced-systemcare-setup.tmp (PID: 4692)
      • advanced-systemcare-setup.tmp (PID: 6480)
      • ASCInit.exe (PID: 5244)
      • IObitLiveUpdate.exe (PID: 5104)
    • Create files in a temporary directory

      • advanced-systemcare-setup.exe (PID: 6492)
      • advanced-systemcare-setup.exe (PID: 7088)
      • advanced-systemcare-setup.tmp (PID: 4692)
      • Setup.exe (PID: 6616)
      • advanced-systemcare-setup.tmp (PID: 6480)
      • advanced-systemcare-setup.exe (PID: 1488)
      • IObitLiveUpdate.exe (PID: 5104)
    • Creates files or folders in the user directory

      • advanced-systemcare-setup.tmp (PID: 4692)
      • Setup.exe (PID: 6616)
      • ASCUpgrade.exe (PID: 400)
      • advanced-systemcare-setup.tmp (PID: 6480)
      • PPUninstaller.exe (PID: 4604)
      • ASCService.exe (PID: 6780)
      • explorer.exe (PID: 4552)
      • UninstallInfo.exe (PID: 7084)
      • BrowserCleaner.exe (PID: 6620)
      • Display.exe (PID: 488)
      • ASCInit.exe (PID: 5244)
    • Creates files in the program directory

      • Setup.exe (PID: 6616)
      • advanced-systemcare-setup.tmp (PID: 6480)
      • ASCInit.exe (PID: 5244)
      • Register.exe (PID: 6796)
      • ASCService.exe (PID: 6780)
      • smBootTimeBase.exe (PID: 3916)
      • UninstallInfo.exe (PID: 7084)
      • PrivacyShield.exe (PID: 7140)
      • smBootTime.exe (PID: 1440)
      • Display.exe (PID: 488)
      • AutoCare.exe (PID: 5248)
      • IObitLiveUpdate.exe (PID: 5104)
      • AutoSweep.exe (PID: 5720)
      • StartupInfo.exe (PID: 3584)
    • Creates a software uninstall entry

      • advanced-systemcare-setup.tmp (PID: 6480)
    • Reads the machine GUID from the registry

      • PPUninstaller.exe (PID: 4604)
      • smBootTimeBase.exe (PID: 3916)
    • Reads Environment values

      • ASCInit.exe (PID: 5244)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (42.6)
.exe | Win16/32 Executable Delphi generic (19.5)
.exe | Generic Win/DOS Executable (18.9)
.exe | DOS Executable Generic (18.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:07:16 13:24:20+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 65024
InitializedDataSize: 71168
UninitializedDataSize: -
EntryPoint: 0x113bc
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 15.6.0.274
ProductVersionNumber: 15.6.0.274
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: IObit
FileDescription: Advanced SystemCare
FileVersion: 15.6.0.274
LegalCopyright: © IObit. All rights reserved.
ProductName: Advanced SystemCare
ProductVersion: 15.6.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
39
Malicious processes
11
Suspicious processes
3

Behavior graph

Click at the process to see the details
start advanced-systemcare-setup.exe advanced-systemcare-setup.tmp no specs advanced-systemcare-setup.exe advanced-systemcare-setup.tmp setup.exe advanced-systemcare-setup.exe advanced-systemcare-setup.tmp ascupgrade.exe no specs ascupgrade.exe locallang.exe no specs conhost.exe no specs ascinit.exe ppuninstaller.exe realtimeprotector.exe no specs diskdefrag.exe no specs realtimeprotector.exe register.exe ascservice.exe smboottimebase.exe cmd.exe no specs conhost.exe no specs sc.exe no specs uninstallinfo.exe iconpin64.exe conhost.exe no specs regsvr32.exe no specs browsercleaner.exe no specs privacyshield.exe no specs SPPSurrogate no specs smboottime.exe smboottime.exe no specs realtimeprotector.exe display.exe autosweep.exe autocare.exe iobitliveupdate.exe startupinfo.exe no specs register.exe explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
32"C:\Program Files (x86)\IObit\Advanced SystemCare\RealTimeProtector.exe" /installC:\Program Files (x86)\IObit\Advanced SystemCare\RealTimeProtector.exeadvanced-systemcare-setup.tmp
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Real-time Protector
Exit code:
0
Version:
15.0.0.272
Modules
Images
c:\program files (x86)\iobit\advanced systemcare\realtimeprotector.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
400"C:\Users\admin\AppData\Local\Temp\is-2TNJ0.tmp\ASCUpgrade.exe" /upgrade "c:\program files (x86)\iobit\advanced systemcare"C:\Users\admin\AppData\Local\Temp\is-2TNJ0.tmp\ASCUpgrade.exeadvanced-systemcare-setup.tmp
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Upgrader
Exit code:
0
Version:
14.2.0.39
Modules
Images
c:\users\admin\appdata\local\temp\is-2tnj0.tmp\ascupgrade.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
488"C:\Program Files (x86)\IObit\Advanced SystemCare\Display.exe" /serviceC:\Program Files (x86)\IObit\Advanced SystemCare\Display.exe
ASCService.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Display
Exit code:
0
Version:
15.0.0.159
Modules
Images
c:\program files (x86)\iobit\advanced systemcare\display.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1440"C:\Program Files (x86)\IObit\Advanced SystemCare\smBootTime.exe" /UpdateTaskschdC:\Program Files (x86)\IObit\Advanced SystemCare\smBootTime.exe
ASCService.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Startup Boot Time
Exit code:
0
Version:
15.0.0.32
Modules
Images
c:\program files (x86)\iobit\advanced systemcare\smboottime.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1488"C:\Users\admin\Desktop\advanced-systemcare-setup.exe" /VerySilent /DIR="C:\Program Files (x86)\IObit\Advanced SystemCare\" /UNINSTALL /INSTALLER /NORESTART /TASKS="desktopicon" /CreateTaskbarC:\Users\admin\Desktop\advanced-systemcare-setup.exe
Setup.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Advanced SystemCare
Exit code:
0
Version:
15.6.0.274
Modules
Images
c:\users\admin\desktop\advanced-systemcare-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1608\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2016C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
2092"C:\Program Files (x86)\IObit\Advanced SystemCare\RealTimeProtector.exe" /RunCurUsC:\Program Files (x86)\IObit\Advanced SystemCare\RealTimeProtector.exe
ASCService.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Real-time Protector
Exit code:
0
Version:
15.0.0.272
Modules
Images
c:\program files (x86)\iobit\advanced systemcare\realtimeprotector.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
2580"C:\Program Files (x86)\IObit\Advanced SystemCare\RealTimeProtector.exe" /RunC:\Program Files (x86)\IObit\Advanced SystemCare\RealTimeProtector.exe
RealTimeProtector.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Real-time Protector
Exit code:
0
Version:
15.0.0.272
Modules
Images
c:\program files (x86)\iobit\advanced systemcare\realtimeprotector.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3176"C:\Program Files (x86)\IObit\Advanced SystemCare\register.exe" /trailcheckC:\Program Files (x86)\IObit\Advanced SystemCare\Register.exe
ASCService.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
Register
Exit code:
0
Version:
15.0.0.1476
Modules
Images
c:\program files (x86)\iobit\advanced systemcare\register.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
Total events
34 575
Read events
34 456
Write events
110
Delete events
9

Modification events

(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000602E4
Operation:writeName:VirtualDesktop
Value:
1000000030304456033BCEE44DE41B4E8AEC331E84F566D2
(PID) Process:(4692) advanced-systemcare-setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4692) advanced-systemcare-setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4692) advanced-systemcare-setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4692) advanced-systemcare-setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000503A4
Operation:writeName:VirtualDesktop
Value:
1000000030304456033BCEE44DE41B4E8AEC331E84F566D2
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000008017C
Operation:writeName:VirtualDesktop
Value:
1000000030304456033BCEE44DE41B4E8AEC331E84F566D2
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000008017C
Operation:delete keyName:(default)
Value:
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000503A4
Operation:delete keyName:(default)
Value:
(PID) Process:(4552) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000602E4
Operation:delete keyName:(default)
Value:
Executable files
256
Suspicious files
61
Text files
419
Unknown types
10

Dropped files

PID
Process
Filename
Type
4692advanced-systemcare-setup.tmpC:\Users\admin\AppData\Local\Temp\Setup Log 2024-08-23 #001.txttext
MD5:B6BBC888572EC091B81D966E7FA83A46
SHA256:98020930C6AE27AFD1298018FC39FDB073A97B4013B9B3A1CDFFB7175B26AD53
4552explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.datbinary
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
6616Setup.exeC:\Users\admin\AppData\Local\Temp\ZLB2DCF.tmpbinary
MD5:8FB7288870AE2ACB5CDC3DB5A4062094
SHA256:7C5CF7BC56CFD6C333C503B80BC56CD12E370FF97559C1DA19C176A2E33391D3
4692advanced-systemcare-setup.tmpC:\Users\admin\AppData\Local\Temp\is-KORS1.tmp\Installer\Setup.exeexecutable
MD5:53F3C0DD002321F88A7962A683BE94D8
SHA256:2AEC783B0034007FEA160603710FF74BA7C871DBF199DF7B63DE02FEAD5701CC
4692advanced-systemcare-setup.tmpC:\Users\admin\AppData\Local\Temp\is-KORS1.tmp\Setup.exeexecutable
MD5:53F3C0DD002321F88A7962A683BE94D8
SHA256:2AEC783B0034007FEA160603710FF74BA7C871DBF199DF7B63DE02FEAD5701CC
6616Setup.exeC:\ProgramData\IObit\ASCDownloader\ASCInstaller_Downloader.logtext
MD5:C217F558C7AF8FA1B6EBE1F63B4E9CF2
SHA256:70316140673AD3C27731DA672CCBFE000BE8E1D294298C9A48BF0B47C4E4550B
4692advanced-systemcare-setup.tmpC:\Users\admin\AppData\Local\Temp\is-KORS1.tmp\Installer\Rinside.dattext
MD5:3115E02FD135942A8EB97EBFFE751BEB
SHA256:A9161FFE6690069E1267C6FDAD055FC0112144273B66A8BDC59862941279B21B
6616Setup.exeC:\ProgramData\IObit\iobitpromotion.initext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
7088advanced-systemcare-setup.exeC:\Users\admin\AppData\Local\Temp\is-EC8T0.tmp\advanced-systemcare-setup.tmpexecutable
MD5:4100108C68330E46BB48ACC5089E139F
SHA256:902757DCAB1AB2D599232478E2386B9AE1157E1BC2C677FBE879472863DAE3CD
1488advanced-systemcare-setup.exeC:\Users\admin\AppData\Local\Temp\is-A4EJ9.tmp\advanced-systemcare-setup.tmpexecutable
MD5:4100108C68330E46BB48ACC5089E139F
SHA256:902757DCAB1AB2D599232478E2386B9AE1157E1BC2C677FBE879472863DAE3CD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
23
DNS requests
6
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6616
Setup.exe
GET
206
152.199.20.140:80
http://update.iobit.com/infofiles/installer/asc/installer.zlb
unknown
whitelisted
6616
Setup.exe
GET
152.199.20.140:80
http://update.iobit.com/infofiles/installer/asc/installer.zlb
unknown
whitelisted
6616
Setup.exe
GET
206
152.199.20.140:80
http://update.iobit.com/infofiles/installer/asc/installer.zlb
unknown
whitelisted
6616
Setup.exe
GET
200
152.199.20.140:80
http://update.iobit.com/infofiles/ac/appver-ac.upt
unknown
whitelisted
6616
Setup.exe
GET
206
152.199.20.140:80
http://update.iobit.com/infofiles/installer/asc/installer.zlb
unknown
whitelisted
6616
Setup.exe
GET
206
152.199.20.140:80
http://update.iobit.com/infofiles/installer/asc/installer.zlb
unknown
whitelisted
5104
IObitLiveUpdate.exe
GET
206
152.199.20.140:80
http://update.iobit.com/infofiles/iobitliveupdate/update.ept
unknown
whitelisted
5104
IObitLiveUpdate.exe
GET
206
152.199.20.140:80
http://update.iobit.com/infofiles/iobitliveupdate/update.ept
unknown
whitelisted
7084
UninstallInfo.exe
GET
200
52.2.4.227:80
http://stats.iobit.com/install.php?operate=1&user=1&app=asc15&ver=15.6.0.274&pr=iobit&system=100&type=1&lang=en-US&geo=1033&insur=other
unknown
unknown
5104
IObitLiveUpdate.exe
GET
152.199.20.140:80
http://update.iobit.com/infofiles/iobitliveupdate/update.ept
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
239.255.255.250:1900
whitelisted
6616
Setup.exe
152.199.20.140:80
update.iobit.com
EDGECAST
US
unknown
6616
Setup.exe
52.2.70.45:80
ascstats.iobit.com
AMAZON-AES
US
unknown
4
System
192.168.100.255:137
whitelisted
7084
UninstallInfo.exe
52.2.4.227:80
stats.iobit.com
AMAZON-AES
US
unknown
5104
IObitLiveUpdate.exe
152.199.20.140:80
update.iobit.com
EDGECAST
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 142.250.184.206
whitelisted
update.iobit.com
  • 152.199.20.140
whitelisted
ascstats.iobit.com
  • 52.2.70.45
  • 52.86.31.74
  • 54.174.45.118
whitelisted
stats.iobit.com
  • 52.2.4.227
  • 52.86.185.198
  • 54.198.88.35
unknown

Threats

PID
Process
Class
Message
6616
Setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6616
Setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6616
Setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6616
Setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6616
Setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
6616
Setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
Process
Message
Setup.exe
C:\Users\admin\AppData\Roaming\IObit\Advanced SystemCare\
Setup.exe
********** FLanguageName: English
Setup.exe
GetDownloadPath: 2
Setup.exe
CheckDiskSpace: 1
Setup.exe
CheckDiskSpace: 2
Setup.exe
CheckDiskSpace: 3
Setup.exe
CheckDiskSpace: 4
Setup.exe
CheckDiskSpace: 5
Setup.exe
GetDownloadPath: 3
Setup.exe
CheckDiskSpace: 2