| File name: | uiso9_cn_9.7.0.3476.exe |
| Full analysis: | https://app.any.run/tasks/fe64348c-1451-4c58-8b78-e88e0c77bcd9 |
| Verdict: | Malicious activity |
| Analysis date: | April 29, 2025, 01:52:56 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections |
| MD5: | E67B238FD307435CE05DD36ABB7BD681 |
| SHA1: | BA4D127BD4BD953544BF2949252578AE612FFAE7 |
| SHA256: | A46EF9291B3ACA45CCBD5A9FF7DCF1F9958A1033BF5B212C19D6D4D550C050D6 |
| SSDEEP: | 98304:Z4adL7Mfb5kBv2ro9m4yFO+2dXs0tgvue1/uW2PG5B0Uhxt1Kc8jrj6iPxZDR4H/:3P1VK |
| .exe | | | Inno Setup installer (81.5) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10.5) |
| .exe | | | Win32 Executable (generic) (3.3) |
| .exe | | | Win16/32 Executable Delphi generic (1.5) |
| .exe | | | Generic Win/DOS Executable (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 41472 |
| InitializedDataSize: | 85504 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xaa98 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 9.7.0.3476 |
| ProductVersionNumber: | 9.7.0.3476 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | EZB Systems, Inc. |
| FileDescription: | UltraISO Setup |
| FileVersion: | 9.7.0.3476 |
| LegalCopyright: | (c) EZB Systems, Inc. |
| ProductName: | UltraISO |
| ProductVersion: | 9.7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\UltraISO\isoshell.dll" | C:\Windows\System32\regsvr32.exe | — | uiso9_cn_9.7.0.3476.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1088 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=1400 --field-trial-handle=1324,i,17106362102874953354,3712258371237010397,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1336 | "C:\Users\admin\AppData\Local\Temp\is-R923N.tmp\uiso9_cn_9.7.0.3476.tmp" /SL5="$401B2,2148413,128000,C:\Users\admin\AppData\Local\Temp\uiso9_cn_9.7.0.3476.exe" /SPAWNWND=$301AA /NOTIFYWND=$401AE | C:\Users\admin\AppData\Local\Temp\is-R923N.tmp\uiso9_cn_9.7.0.3476.tmp | uiso9_cn_9.7.0.3476.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 1396 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1396 --field-trial-handle=1316,i,1726462158255183354,7345488161575829348,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2384 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6f3bf598,0x6f3bf5a8,0x6f3bf5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2392 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://cn.ezbsystems.com/ultraiso/order.htm | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | UltraISO.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2408 | "C:\Users\admin\AppData\Local\Temp\uiso9_cn_9.7.0.3476.exe" /SPAWNWND=$301AA /NOTIFYWND=$401AE | C:\Users\admin\AppData\Local\Temp\uiso9_cn_9.7.0.3476.exe | uiso9_cn_9.7.0.3476.tmp | ||||||||||||
User: admin Company: EZB Systems, Inc. Integrity Level: HIGH Description: UltraISO Setup Exit code: 0 Version: 9.7.0.3476 Modules
| |||||||||||||||
| 2480 | "C:\Users\admin\AppData\Local\Temp\uiso9_cn_9.7.0.3476.exe" | C:\Users\admin\AppData\Local\Temp\uiso9_cn_9.7.0.3476.exe | explorer.exe | ||||||||||||
User: admin Company: EZB Systems, Inc. Integrity Level: MEDIUM Description: UltraISO Setup Exit code: 0 Version: 9.7.0.3476 Modules
| |||||||||||||||
| 2612 | "C:\Program Files\UltraISO\drivers\isocmd.exe" -i | C:\Program Files\UltraISO\drivers\IsoCmd.exe | — | uiso9_cn_9.7.0.3476.tmp | |||||||||||
User: admin Company: EZB Systems, Inc. Integrity Level: HIGH Description: ISO Command Exit code: 0 Version: 3.12 built by: WinDDK Modules
| |||||||||||||||
| 2652 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6f3bf598,0x6f3bf5a8,0x6f3bf5b4 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (1336) uiso9_cn_9.7.0.3476.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\EasyBoot Systems\UltraISO\5.0 |
| Operation: | write | Name: | Shared |
Value: C:\Program Files\Common Files\EZB Systems | |||
| (PID) Process: | (1336) uiso9_cn_9.7.0.3476.tmp | Key: | HKEY_CURRENT_USER\Software\EasyBoot Systems\UltraISO\5.0 |
| Operation: | write | Name: | Shared |
Value: C:\Program Files\Common Files\EZB Systems | |||
| (PID) Process: | (1336) uiso9_cn_9.7.0.3476.tmp | Key: | HKEY_CURRENT_USER\Software\EasyBoot Systems\UltraISO\5.0 |
| Operation: | write | Name: | XPBurn |
Value: 0 | |||
| (PID) Process: | (1336) uiso9_cn_9.7.0.3476.tmp | Key: | HKEY_CURRENT_USER\Software\EasyBoot Systems\UltraISO\5.0 |
| Operation: | write | Name: | ISOFolder |
Value: C:\Users\admin\Documents\My ISO Files | |||
| (PID) Process: | (1336) uiso9_cn_9.7.0.3476.tmp | Key: | HKEY_CURRENT_USER\Software\EasyBoot Systems\UltraISO\5.0 |
| Operation: | write | Name: | UseSkins |
Value: 1 | |||
| (PID) Process: | (752) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9653DE66-C5E0-4AEE-ADE5-0197BA68CE2B}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (1336) uiso9_cn_9.7.0.3476.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UltraISO_is1 |
| Operation: | write | Name: | QuietUninstallString |
Value: "C:\Program Files\UltraISO\unins000.exe" /SILENT | |||
| (PID) Process: | (1336) uiso9_cn_9.7.0.3476.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UltraISO_is1 |
| Operation: | write | Name: | DisplayVersion |
Value: 9.7 | |||
| (PID) Process: | (1336) uiso9_cn_9.7.0.3476.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UltraISO_is1 |
| Operation: | write | Name: | Publisher |
Value: EZB Systems, Inc. | |||
| (PID) Process: | (1336) uiso9_cn_9.7.0.3476.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UltraISO_is1 |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2408 | uiso9_cn_9.7.0.3476.exe | C:\Users\admin\AppData\Local\Temp\is-R923N.tmp\uiso9_cn_9.7.0.3476.tmp | executable | |
MD5:0856978F29AE90DC02A700A33FE0302E | SHA256:E0E512BF5E39C44DB7EDA3A0BA2DBAF91C5B61E5FA233C9D293068F4FCD92E82 | |||
| 2480 | uiso9_cn_9.7.0.3476.exe | C:\Users\admin\AppData\Local\Temp\is-CKKFT.tmp\uiso9_cn_9.7.0.3476.tmp | executable | |
MD5:0856978F29AE90DC02A700A33FE0302E | SHA256:E0E512BF5E39C44DB7EDA3A0BA2DBAF91C5B61E5FA233C9D293068F4FCD92E82 | |||
| 1336 | uiso9_cn_9.7.0.3476.tmp | C:\Program Files\UltraISO\drivers\IsoCmd.exe | executable | |
MD5:C0618803912BEA2270FF7126772D8090 | SHA256:C1098C04A395EFCA09CF27951B51584450A8333555B92F4BAB6D961A85500DB5 | |||
| 1336 | uiso9_cn_9.7.0.3476.tmp | C:\Program Files\UltraISO\drivers\is-OR26V.tmp | executable | |
MD5:E89B724CD7CE6E0757B37713A4202927 | SHA256:1844214045018304E53FB56B795E994D8AC19F41E50D9872BD42A49F31625520 | |||
| 1336 | uiso9_cn_9.7.0.3476.tmp | C:\Program Files\UltraISO\drivers\bootpart.sys | executable | |
MD5:E89B724CD7CE6E0757B37713A4202927 | SHA256:1844214045018304E53FB56B795E994D8AC19F41E50D9872BD42A49F31625520 | |||
| 1336 | uiso9_cn_9.7.0.3476.tmp | C:\Program Files\UltraISO\drivers\is-CNVOQ.tmp | executable | |
MD5:28B2D49D7C5675BF3E290FFE5445C42D | SHA256:AD54206D9B2AA90157AB21B77F6ACC2885C9A1EABDA3D82DA100EF2718D02124 | |||
| 1336 | uiso9_cn_9.7.0.3476.tmp | C:\Program Files\UltraISO\drivers\bootpt64.sys | executable | |
MD5:28B2D49D7C5675BF3E290FFE5445C42D | SHA256:AD54206D9B2AA90157AB21B77F6ACC2885C9A1EABDA3D82DA100EF2718D02124 | |||
| 1336 | uiso9_cn_9.7.0.3476.tmp | C:\Program Files\UltraISO\drivers\bootpart.exe | executable | |
MD5:C77843C280A632F7897362D17D31C97F | SHA256:DF6B26CF4BB99523D3F57FFA033EB60E1C4B6CE0FF43676AE028C4F59E669D1C | |||
| 1336 | uiso9_cn_9.7.0.3476.tmp | C:\Program Files\UltraISO\drivers\is-U1AI8.tmp | executable | |
MD5:C77843C280A632F7897362D17D31C97F | SHA256:DF6B26CF4BB99523D3F57FFA033EB60E1C4B6CE0FF43676AE028C4F59E669D1C | |||
| 1336 | uiso9_cn_9.7.0.3476.tmp | C:\Program Files\UltraISO\drivers\is-40I5H.tmp | executable | |
MD5:E489D12FF435AEEF4A5474C47D329590 | SHA256:66A01F63EE4F66C0CD5BB9BF20E1722D57CC8252AC126780800806B536F4CEA9 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3696 | msedge.exe | GET | 200 | 101.32.241.20:80 | http://cn.ezbsystems.com/ultraiso/order.htm | unknown | — | — | whitelisted |
3696 | msedge.exe | GET | 200 | 101.32.241.20:80 | http://cn.ezbsystems.com/cimages/ezbsys.gif | unknown | — | — | whitelisted |
3696 | msedge.exe | GET | 200 | 101.32.241.20:80 | http://cn.ezbsystems.com/cimages/uiso-title.gif | unknown | — | — | whitelisted |
3696 | msedge.exe | GET | 200 | 101.32.241.20:80 | http://cn.ezbsystems.com/images/bg.gif | unknown | — | — | whitelisted |
3696 | msedge.exe | GET | 200 | 101.32.241.20:80 | http://cn.ezbsystems.com/images/top_1.jpg | unknown | — | — | whitelisted |
3696 | msedge.exe | GET | 200 | 101.32.241.20:80 | http://cn.ezbsystems.com/images/order-title.gif | unknown | — | — | whitelisted |
3696 | msedge.exe | GET | 200 | 101.32.241.20:80 | http://cn.ezbsystems.com/images/zf-logo.jpg | unknown | — | — | whitelisted |
3696 | msedge.exe | GET | 200 | 101.32.241.20:80 | http://cn.ezbsystems.com/images/gm.gif | unknown | — | — | whitelisted |
3696 | msedge.exe | GET | 200 | 101.32.241.20:80 | http://cn.ezbsystems.com/images/lozenge-topleft.gif | unknown | — | — | whitelisted |
3696 | msedge.exe | GET | 200 | 101.32.241.20:80 | http://cn.ezbsystems.com/images/left_6.jpg | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3696 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2952 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3696 | msedge.exe | 150.171.27.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3696 | msedge.exe | 101.32.241.20:80 | cn.ezbsystems.com | Tencent Building, Kejizhongyi Avenue | SG | whitelisted |
3696 | msedge.exe | 2.16.241.201:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
3696 | msedge.exe | 150.171.28.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
cn.ezbsystems.com |
| whitelisted |
www.ezbsystems.com |
| whitelisted |
www.regsky.com |
| unknown |
www.bing.com |
| whitelisted |