File name:

uninstalltool_setup.exe

Full analysis: https://app.any.run/tasks/85c12a07-ab3a-4fbe-bb7a-e1a41c814b4d
Verdict: Malicious activity
Analysis date: May 25, 2025, 08:38:31
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
delphi
inno
installer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

417161BEF8A9990D7D99CD660042608D

SHA1:

8B319C3EC6CFF5A598F7EE3BE643A1E13AC85A1B

SHA256:

66B696E76AF8E72272883E22E7F5E42E168195C2E42FDDF6D9E4E59C8A003EE4

SSDEEP:

98304:f+cD4dnWeMKkjdkBAuk9YJiPrBZ5di+yDumsoaU2O0t1B1U3gTie+zr68BFRHooH:Jc5PsqvZBph

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • uninstalltool_setup.tmp (PID: 7728)
    • Runs injected code in another process

      • PinToTaskbar.exe (PID: 7928)
    • Application was injected by another process

      • explorer.exe (PID: 5492)
    • Executing a file with an untrusted certificate

      • UninstallToolHelper.exe (PID: 7224)
      • UninstallToolHelper.exe (PID: 4628)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • uninstalltool_setup.exe (PID: 7440)
      • uninstalltool_setup.exe (PID: 7692)
      • uninstalltool_setup.tmp (PID: 7728)
      • UninstallTool.exe (PID: 7976)
      • dllhost.exe (PID: 6744)
    • Reads security settings of Internet Explorer

      • uninstalltool_setup.tmp (PID: 7500)
      • uninstalltool_setup.tmp (PID: 7728)
      • UninstallTool.exe (PID: 8120)
    • Reads the Windows owner or organization settings

      • uninstalltool_setup.tmp (PID: 7728)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 7856)
      • regsvr32.exe (PID: 7892)
    • Drops a system driver (possible attempt to evade defenses)

      • UninstallTool.exe (PID: 7976)
    • Creates files in the driver directory

      • UninstallTool.exe (PID: 7976)
    • Searches for installed software

      • UninstallTool.exe (PID: 8000)
      • UninstallTool.exe (PID: 8120)
    • The process executes via Task Scheduler

      • UninstallTool.exe (PID: 8120)
      • UninstallTool.exe (PID: 960)
    • Reads the date of Windows installation

      • UninstallTool.exe (PID: 8000)
      • UninstallTool.exe (PID: 8120)
    • Adds/modifies Windows certificates

      • UninstallTool.exe (PID: 8120)
  • INFO

    • Checks supported languages

      • uninstalltool_setup.exe (PID: 7440)
      • uninstalltool_setup.tmp (PID: 7500)
      • uninstalltool_setup.exe (PID: 7692)
      • uninstalltool_setup.tmp (PID: 7728)
      • PinToTaskbar.exe (PID: 7928)
      • UninstallTool.exe (PID: 8000)
      • UninstallTool.exe (PID: 7976)
      • UninstallTool.exe (PID: 8032)
      • UninstallTool.exe (PID: 8056)
      • UninstallTool.exe (PID: 8100)
      • UninstallTool.exe (PID: 8120)
      • UninstallToolHelper.exe (PID: 7224)
    • Create files in a temporary directory

      • uninstalltool_setup.exe (PID: 7440)
      • uninstalltool_setup.exe (PID: 7692)
      • uninstalltool_setup.tmp (PID: 7728)
      • UninstallTool.exe (PID: 7976)
    • Reads the computer name

      • uninstalltool_setup.tmp (PID: 7500)
      • uninstalltool_setup.tmp (PID: 7728)
      • PinToTaskbar.exe (PID: 7928)
      • UninstallTool.exe (PID: 7976)
      • UninstallTool.exe (PID: 8056)
      • UninstallTool.exe (PID: 8100)
      • UninstallTool.exe (PID: 8120)
      • UninstallTool.exe (PID: 8000)
    • Process checks computer location settings

      • uninstalltool_setup.tmp (PID: 7500)
      • uninstalltool_setup.tmp (PID: 7728)
      • UninstallTool.exe (PID: 8000)
      • UninstallTool.exe (PID: 8120)
    • Creates files in the program directory

      • uninstalltool_setup.tmp (PID: 7728)
    • The sample compiled with english language support

      • uninstalltool_setup.tmp (PID: 7728)
      • UninstallTool.exe (PID: 7976)
    • Detects InnoSetup installer (YARA)

      • uninstalltool_setup.exe (PID: 7440)
      • uninstalltool_setup.tmp (PID: 7500)
    • Compiled with Borland Delphi (YARA)

      • uninstalltool_setup.exe (PID: 7440)
      • uninstalltool_setup.tmp (PID: 7500)
    • Creates a software uninstall entry

      • uninstalltool_setup.tmp (PID: 7728)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 5492)
    • Creates files or folders in the user directory

      • explorer.exe (PID: 5492)
      • UninstallTool.exe (PID: 7976)
      • UninstallTool.exe (PID: 8000)
      • UninstallTool.exe (PID: 8120)
    • Reads the machine GUID from the registry

      • UninstallTool.exe (PID: 8120)
    • Checks proxy server information

      • UninstallTool.exe (PID: 8120)
    • Reads the software policy settings

      • UninstallTool.exe (PID: 8120)
    • Manual execution by a user

      • UninstallTool.exe (PID: 6112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 102912
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 3.7.4.0
ProductVersionNumber: 3.7.4.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: CrystalIDEA Software
FileDescription: Uninstall Tool Setup
FileVersion: Uninstall Tool
LegalCopyright: Copyright © CrystalIDEA Software
OriginalFileName: uninstalltool_setup.exe
ProductName: Uninstall Tool
ProductVersion: 3.7.4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
156
Monitored processes
23
Malicious processes
4
Suspicious processes
7

Behavior graph

Click at the process to see the details
start uninstalltool_setup.exe uninstalltool_setup.tmp no specs sppextcomobj.exe no specs slui.exe uninstalltool_setup.exe uninstalltool_setup.tmp regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs pintotaskbar.exe no specs uninstalltool.exe uninstalltool.exe no specs uninstalltool.exe no specs uninstalltool.exe no specs uninstalltool.exe no specs uninstalltool.exe uninstalltoolhelper.exe no specs rundll32.exe no specs Copy/Move/Rename/Delete/Link Object uninstalltool.exe no specs uninstalltool.exe uninstalltoolhelper.exe no specs explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
960"C:\Program Files\Uninstall Tool\UninstallTool.exe" /admin /taskschC:\Program Files\Uninstall Tool\UninstallTool.exe
svchost.exe
User:
admin
Company:
CrystalIDEA Software
Integrity Level:
HIGH
Description:
Uninstall Tool
Version:
3.7.4.5725
Modules
Images
c:\program files\uninstall tool\uninstalltool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3100C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
4628"C:\Program Files\Uninstall Tool\UninstallToolHelper.exe" /pid:960C:\Program Files\Uninstall Tool\UninstallToolHelper.exeUninstallTool.exe
User:
admin
Company:
CrystalIDEA Software
Integrity Level:
HIGH
Description:
Uninstall Tool Helper Process
Version:
1, 1, 17, 5
5492C:\WINDOWS\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shcore.dll
6112"C:\Program Files\Uninstall Tool\UninstallTool.exe" C:\Program Files\Uninstall Tool\UninstallTool.exeexplorer.exe
User:
admin
Company:
CrystalIDEA Software
Integrity Level:
MEDIUM
Description:
Uninstall Tool
Exit code:
0
Version:
3.7.4.5725
Modules
Images
c:\program files\uninstall tool\uninstalltool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6744C:\WINDOWS\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\System32\dllhost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
7224"C:\Program Files\Uninstall Tool\UninstallToolHelper.exe" /pid:8120C:\Program Files\Uninstall Tool\UninstallToolHelper.exeUninstallTool.exe
User:
admin
Company:
CrystalIDEA Software
Integrity Level:
HIGH
Description:
Uninstall Tool Helper Process
Exit code:
0
Version:
1, 1, 17, 5
Modules
Images
c:\program files\uninstall tool\uninstalltoolhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
7440"C:\Users\admin\AppData\Local\Temp\uninstalltool_setup.exe" C:\Users\admin\AppData\Local\Temp\uninstalltool_setup.exe
explorer.exe
User:
admin
Company:
CrystalIDEA Software
Integrity Level:
MEDIUM
Description:
Uninstall Tool Setup
Exit code:
0
Version:
Uninstall Tool
Modules
Images
c:\users\admin\appdata\local\temp\uninstalltool_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
7500"C:\Users\admin\AppData\Local\Temp\is-NICNJ.tmp\uninstalltool_setup.tmp" /SL5="$50270,4977297,845824,C:\Users\admin\AppData\Local\Temp\uninstalltool_setup.exe" C:\Users\admin\AppData\Local\Temp\is-NICNJ.tmp\uninstalltool_setup.tmpuninstalltool_setup.exe
User:
admin
Company:
CrystalIDEA Software
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-nicnj.tmp\uninstalltool_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
7524C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
31 070
Read events
30 901
Write events
155
Delete events
14

Modification events

(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:0000000000040352
Operation:writeName:VirtualDesktop
Value:
1000000030304456BFA0DB55E4278845B426357D5B5F97B3
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:000000000004028A
Operation:writeName:VirtualDesktop
Value:
1000000030304456BFA0DB55E4278845B426357D5B5F97B3
(PID) Process:(7728) uninstalltool_setup.tmpKey:HKEY_CURRENT_USER\SOFTWARE\CrystalIdea Software\Uninstall Tool
Operation:writeName:DriverVersionNum
Value:
262
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconLayouts
Value:
00000000000000000000000000000000030001000100010014000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C0000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C0000000D0000000000000053006B007900700065002E006C006E006B003E0020007C000000110000000000000069006E006400650078006200610063006B002E0070006E0067003E002000200000001400000000000000620072006F007700730065006D006500740068006F0064002E007200740066003E002000200000001700000000000000630061006C0065006E0064006100720077006800650074006800650072002E007200740066003E002000200000001300000000000000630061006C006C00740068006F0075006700680074002E0070006E0067003E002000200000001500000000000000650076006500720079006F006E0065006D006F006E00740068002E007200740066003E0020002000000012000000000000006A00610063006B006C0065006E006700740068002E006A00700067003E0020002000000014000000000000006C006F0077006500720077006800650074006800650072002E0070006E0067003E0020002000000015000000000000006F006E006C007900650071007500690070006D0065006E0074002E007200740066003E00200020000000160000000000000072006500730070006F006E00730065007300650072007600650072002E007200740066003E002000200000000F0000000000000073006F006E0067006C00650074002E0070006E0067003E002000200000000F0000000000000073007400650070006100630074002E006A00700067003E00200020000000160000000000000055006E0069006E007300740061006C006C00200054006F006F006C002E006C006E006B003E0020002000000001000000000000000200010000000000000000000100000000000000020001000000000000000000110000000600000001000000140000000000000000000000000000000000000040400000803F13000000803F0000404009000000803F000080400A000000803F0000A0400B0000000040000000000C00000000400000803F0D0000000040000000400E0000000040000040400F0000000040000080401000000000400000A040110000004040000000001200000000000000803F0100000000000000004002000000000000004040030000000000000080400400000000000000A04005000000803F0000000006000000803F0000803F07000000803F000000400800
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconNameVersion
Value:
1
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:000000000002022A
Operation:writeName:VirtualDesktop
Value:
1000000030304456BFA0DB55E4278845B426357D5B5F97B3
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts
Operation:writeName:LastUpdate
Value:
1AD7326800000000
(PID) Process:(7856) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE8E6AD6-DABE-45E1-88C2-48DC4578924C}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(7856) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
18
(PID) Process:(7856) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Operation:writeName:{FE8E6AD6-DABE-45E1-88C2-48DC4578924C}
Value:
UTShellExt
Executable files
22
Suspicious files
28
Text files
87
Unknown types
0

Dropped files

PID
Process
Filename
Type
7440uninstalltool_setup.exeC:\Users\admin\AppData\Local\Temp\is-NICNJ.tmp\uninstalltool_setup.tmpexecutable
MD5:8C1451188764F81954E6D4672100433A
SHA256:5FE7888A8A41638E457A1D52369701F33B2084AEEB32A3C4FC996B1487A8FADD
7728uninstalltool_setup.tmpC:\Users\admin\AppData\Local\Temp\is-KT0NK.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
5492explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.datbinary
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
7692uninstalltool_setup.exeC:\Users\admin\AppData\Local\Temp\is-MQ9J6.tmp\uninstalltool_setup.tmpexecutable
MD5:8C1451188764F81954E6D4672100433A
SHA256:5FE7888A8A41638E457A1D52369701F33B2084AEEB32A3C4FC996B1487A8FADD
7728uninstalltool_setup.tmpC:\Program Files\Uninstall Tool\is-3PHE1.tmpexecutable
MD5:4DE7220115FE537EAF6C5776E83F0064
SHA256:E87288744CC29C5AB81D9C3FA78653CACD87BC74BF5A3ABC4F38AFCD6A1A5C16
7728uninstalltool_setup.tmpC:\Program Files\Uninstall Tool\is-TKJUQ.tmpexecutable
MD5:8C1451188764F81954E6D4672100433A
SHA256:5FE7888A8A41638E457A1D52369701F33B2084AEEB32A3C4FC996B1487A8FADD
7728uninstalltool_setup.tmpC:\Program Files\Uninstall Tool\PinToTaskbar.exeexecutable
MD5:4DE7220115FE537EAF6C5776E83F0064
SHA256:E87288744CC29C5AB81D9C3FA78653CACD87BC74BF5A3ABC4F38AFCD6A1A5C16
7728uninstalltool_setup.tmpC:\Program Files\Uninstall Tool\is-3FVI9.tmpexecutable
MD5:4C415ADB0750FE1E1D2F52C3902274C0
SHA256:7D0A990C0B976FF4D99ABFA935EADEBCECE34E7D4E711ED86066AB7845D6A417
7728uninstalltool_setup.tmpC:\Program Files\Uninstall Tool\unins000.exeexecutable
MD5:8C1451188764F81954E6D4672100433A
SHA256:5FE7888A8A41638E457A1D52369701F33B2084AEEB32A3C4FC996B1487A8FADD
7728uninstalltool_setup.tmpC:\Program Files\Uninstall Tool\PinToTaskbarHelper.dllexecutable
MD5:4C415ADB0750FE1E1D2F52C3902274C0
SHA256:7D0A990C0B976FF4D99ABFA935EADEBCECE34E7D4E711ED86066AB7845D6A417
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
24
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8120
UninstallTool.exe
GET
200
2.19.105.127:80
http://x1.c.lencr.org/
unknown
whitelisted
8120
UninstallTool.exe
GET
200
2.22.242.225:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgb%2BxzVcNt%2FVHDBxJLsu%2FnGhiQ%3D%3D
unknown
whitelisted
7276
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8120
UninstallTool.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVD%2BnGf79Hpedv3mhy6uKMVZkPCQQUDyrLIIcouOxvSK4rVKYpqhekzQwCEQDfD%2FoApQz6Tjifa39Nky1P
unknown
whitelisted
8120
UninstallTool.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D
unknown
whitelisted
8120
UninstallTool.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7276
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2340
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
2.16.168.114:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
5496
MoUsoCoreWorker.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.64
  • 40.126.31.130
  • 40.126.31.131
  • 20.190.159.129
  • 20.190.159.73
  • 20.190.159.0
  • 20.190.159.71
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
crystalidea.com
  • 173.230.144.164
unknown
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted

Threats

No threats detected
No debug info