File name:

HiBitUninstaller-Portable.exe

Full analysis: https://app.any.run/tasks/23a82131-d2b2-4c64-b253-53c44b5bb5a0
Verdict: Malicious activity
Analysis date: April 24, 2025, 07:04:29
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

F736A30FC6783E96912F40C024D1CD36

SHA1:

B2563A51224E5BD630C9BCDFC4ED9A672DCF4F76

SHA256:

71472EE7473C9BC0D02094DE53A5D295D54920517271298FB10A8E172C221E62

SSDEEP:

98304:MBN8rs6ZJKPN0PsP6N724NKlP7tZZ37bA5be77rh6QdRtQ0naQykD0Gz5XpMJ71P:lfdyOT88qyW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • HiBitUninstaller-Portable.exe (PID: 7776)
      • _iu14D2N.tmp (PID: 4488)
      • unins000.exe (PID: 7348)
    • Creates a software uninstall entry

      • HiBitUninstaller-Portable.exe (PID: 7776)
    • Searches for installed software

      • HiBitUninstaller-Portable.exe (PID: 7776)
    • Reads security settings of Internet Explorer

      • HiBitUninstaller-Portable.exe (PID: 7776)
      • _iu14D2N.tmp (PID: 4488)
    • Reads the Windows owner or organization settings

      • _iu14D2N.tmp (PID: 4488)
    • Uses TASKKILL.EXE to kill process

      • _iu14D2N.tmp (PID: 4488)
    • Starts application with an unusual extension

      • unins000.exe (PID: 7348)
    • Starts itself from another location

      • unins000.exe (PID: 7348)
  • INFO

    • The sample compiled with english language support

      • HiBitUninstaller-Portable.exe (PID: 7776)
    • Reads product name

      • HiBitUninstaller-Portable.exe (PID: 7776)
    • Reads CPU info

      • HiBitUninstaller-Portable.exe (PID: 7776)
    • Reads Environment values

      • HiBitUninstaller-Portable.exe (PID: 7776)
    • Compiled with Borland Delphi (YARA)

      • HiBitUninstaller-Portable.exe (PID: 7776)
    • Reads the computer name

      • HiBitUninstaller-Portable.exe (PID: 7776)
      • _iu14D2N.tmp (PID: 4488)
      • unins000.exe (PID: 7348)
    • Checks supported languages

      • HiBitUninstaller-Portable.exe (PID: 7776)
      • unins000.exe (PID: 7348)
      • _iu14D2N.tmp (PID: 4488)
    • Create files in a temporary directory

      • _iu14D2N.tmp (PID: 4488)
      • HiBitUninstaller-Portable.exe (PID: 7776)
      • unins000.exe (PID: 7348)
    • Process checks computer location settings

      • _iu14D2N.tmp (PID: 4488)
    • Checks proxy server information

      • slui.exe (PID: 7324)
    • Reads the software policy settings

      • slui.exe (PID: 7324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (42.6)
.exe | Win16/32 Executable Delphi generic (19.5)
.exe | Generic Win/DOS Executable (18.9)
.exe | DOS Executable Generic (18.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:02:18 18:58:32+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 6495232
InitializedDataSize: 7104512
UninitializedDataSize: -
EntryPoint: 0x630120
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.2.55.0
ProductVersionNumber: 3.2.55.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: HiBitSoftware
FileVersion: 3.2.55.0
InternalName: HiBitUninstaller
LegalCopyright: Copyright © 2017-2025 HiBitSoftware
LegalTrademarks: HiBitSoftware
OriginalFileName: HiBitUninstaller
ProductVersion: 3.2.55.0
Comments: https://www.hibitsoft.ir
ProgramID: com.embarcadero.UninstallManag
FileDescription: HiBit Uninstaller
ProductName: HiBit Uninstaller
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
7
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start hibituninstaller-portable.exe slui.exe unins000.exe _iu14d2n.tmp taskkill.exe no specs conhost.exe no specs hibituninstaller-portable.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4488"C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp" /SECONDPHASE="C:\Program Files (x86)\Microsoft\Skype for Desktop\unins000.exe" /FIRSTPHASEWND=$40350 /VERYSILENT /SUPPRESSMSGBOXES /NORESTARTC:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp
unins000.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\_iu14d2n.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
7324C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7348"C:\Program Files (x86)\Microsoft\Skype for Desktop\unins000.exe" /VERYSILENT /SUPPRESSMSGBOXES /NORESTARTC:\Program Files (x86)\Microsoft\Skype for Desktop\unins000.exe
HiBitUninstaller-Portable.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\program files (x86)\microsoft\skype for desktop\unins000.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
7436"C:\Windows\System32\taskkill.exe" /f /im Skype.exeC:\Windows\SysWOW64\taskkill.exe_iu14D2N.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7440\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7676"C:\Users\admin\AppData\Local\Temp\HiBitUninstaller-Portable.exe" C:\Users\admin\AppData\Local\Temp\HiBitUninstaller-Portable.exeexplorer.exe
User:
admin
Company:
HiBitSoftware
Integrity Level:
MEDIUM
Description:
HiBit Uninstaller
Exit code:
3221226540
Version:
3.2.55.0
Modules
Images
c:\users\admin\appdata\local\temp\hibituninstaller-portable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7776"C:\Users\admin\AppData\Local\Temp\HiBitUninstaller-Portable.exe" C:\Users\admin\AppData\Local\Temp\HiBitUninstaller-Portable.exe
explorer.exe
User:
admin
Company:
HiBitSoftware
Integrity Level:
HIGH
Description:
HiBit Uninstaller
Version:
3.2.55.0
Modules
Images
c:\users\admin\appdata\local\temp\hibituninstaller-portable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
Total events
7 924
Read events
7 850
Write events
55
Delete events
19

Modification events

(PID) Process:(7776) HiBitUninstaller-Portable.exeKey:HKEY_CURRENT_USER\SOFTWARE\HiBit Uninstaller Temp\Uninstaller
Operation:writeName:BuildNumber
Value:
3255
(PID) Process:(7776) HiBitUninstaller-Portable.exeKey:HKEY_CURRENT_USER\SOFTWARE\HiBit Uninstaller Temp\Uninstaller
Operation:writeName:PCName
Value:
DESKTOP-JGLLJLD
(PID) Process:(7776) HiBitUninstaller-Portable.exeKey:HKEY_CURRENT_USER\SOFTWARE\HiBit Uninstaller Temp\Uninstaller
Operation:writeName:Language
Value:
EnglishLang
(PID) Process:(7776) HiBitUninstaller-Portable.exeKey:HKEY_CURRENT_USER\SOFTWARE\HiBit Uninstaller Temp\Uninstaller
Operation:writeName:LanguageID
Value:
0
(PID) Process:(7776) HiBitUninstaller-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 123.0 (x64 en-US)
Operation:writeName:InstallDate
Value:
20240718
(PID) Process:(7776) HiBitUninstaller-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
Operation:writeName:InstallDate
Value:
20230209
(PID) Process:(7776) HiBitUninstaller-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Professional2019Retail - en-us
Operation:writeName:InstallDate
Value:
20230209
(PID) Process:(7776) HiBitUninstaller-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Professional2019Retail - en-us
Operation:writeName:EstimatedSize
Value:
209118
(PID) Process:(7776) HiBitUninstaller-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Professional2019Retail - es-es
Operation:writeName:InstallDate
Value:
20230209
(PID) Process:(7776) HiBitUninstaller-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Professional2019Retail - es-es
Operation:writeName:EstimatedSize
Value:
209118
Executable files
4
Suspicious files
8
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
4488_iu14D2N.tmpC:\Program Files (x86)\Microsoft\Skype for Desktop\unins000.dat
MD5:
SHA256:
7776HiBitUninstaller-Portable.exeC:\Users\admin\AppData\Local\Temp\OpenSSLLibrary\libeay32.dllexecutable
MD5:C1C57DB2A476833181E12E29E4CD1D3D
SHA256:2694EB8EA9B16B657E7BD6C4A933D77EBC0AA37D682960E3513A1AAE6600B5B9
7776HiBitUninstaller-Portable.exeC:\Users\admin\AppData\Local\Temp\HiBitUninstaller\Settings.initext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
7776HiBitUninstaller-Portable.exeC:\Users\admin\AppData\Local\Temp\HiBitUninstaller\Uninstaller\LocalDB.inibinary
MD5:A2DBC0FE3DC8BDE692F037646D3B41D0
SHA256:E461D15EF19E480C361BD37CCB22D648A906C49217A853445A03B47E796A9F2D
7776HiBitUninstaller-Portable.exeC:\Users\admin\AppData\Local\Temp\HiBitUninstaller\Uninstaller\UninstallList.inibinary
MD5:F0369E54DEF5ED8794A2A9B13FF28056
SHA256:1DB09E76C121752113249DABEB4CDA23BBCE69A1EAC463D14E9AB0425944489A
7776HiBitUninstaller-Portable.exeC:\Users\admin\AppData\Local\Temp\HiBitUninstaller\Uninstaller\EnglishLang.inibinary
MD5:E2E2BE94A644161DCD03E55D0CF7356B
SHA256:EE850402790F2B26B55B204EA1968C06C51FC214089AE8601544C3FC3B2949BA
7776HiBitUninstaller-Portable.exeC:\Users\admin\AppData\Local\Temp\OpenSSLLibrary\ssleay32.dllexecutable
MD5:DDD011C6710EC9039AD2585A04E79E93
SHA256:E38E353A823A54894077EF880E7159E274DFCE898A0B873DB3AD9332092581E8
7348unins000.exeC:\Users\admin\AppData\Local\Temp\_iu14D2N.tmpexecutable
MD5:E71F43141333C1BB06E2387F04AF46C8
SHA256:A6E4E687C3C56E96BCC7A4142F2BEBE123EEAC28BF1D1D0E7506038CDC39CD6A
7776HiBitUninstaller-Portable.exeC:\Users\admin\AppData\Local\Temp\HiBitUninstaller\Empty Folder Cleaner\Iglist.dbstext
MD5:B2F579921D740651177257F2C67AE631
SHA256:925EB5D26663ADF28151ACB75A89011442872604F6F4859A3618653C2164DC00
7776HiBitUninstaller-Portable.exeC:\Users\admin\AppData\Local\Temp\HiBitUninstaller\Uninstaller\Icon32.datbinary
MD5:6835E58077682385EA2C0B23D0726ADA
SHA256:15C46FDCBD8966D09587EC50345BCCC1B6DB2E1C305F8717F259BA574AFE5223
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
21
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8028
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8028
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7776
HiBitUninstaller-Portable.exe
GET
200
185.159.153.125:80
http://www.hibitsoft.ir/HiBitUninstaller/Ver.DBS
unknown
unknown
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
6404
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
8028
SIHClient.exe
172.202.163.200:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
8028
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.106
  • 2.16.164.9
whitelisted
google.com
  • 142.250.185.110
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 184.30.21.171
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
www.hibitsoft.ir
  • 185.159.153.125
unknown
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.19
whitelisted

Threats

No threats detected
No debug info