File name:

iobit-uninstaller.exe

Full analysis: https://app.any.run/tasks/804816e9-9873-4915-a8d7-47ce1997ba63
Verdict: Malicious activity
Analysis date: April 11, 2025, 14:59:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
upx
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

EB732C43B23E848EBDA2E2C429C55516

SHA1:

1F75ABA505398957750EEAD0D97F9DE87772EF52

SHA256:

DC55D900E2564E0A78F2F1155A4FC58259E04C51D9ED67984ADB8BB04DB739E9

SSDEEP:

49152:4sYeT/c7RNza9ouc9LBCV1aD0JZ4BB0RsEef7DWDvyupqPLxLTX03zOJHTt6a30I:4sYerc7zaWuoKUCxsEeeDvyl16ih8aoA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • iobit-uninstaller.exe (PID: 896)
  • SUSPICIOUS

    • Searches for installed software

      • iobit-uninstaller.exe (PID: 896)
  • INFO

    • The sample compiled with english language support

      • iobit-uninstaller.exe (PID: 896)
    • Compiled with Borland Delphi (YARA)

      • iobit-uninstaller.exe (PID: 896)
    • Reads the software policy settings

      • slui.exe (PID: 5720)
    • Creates files or folders in the user directory

      • iobit-uninstaller.exe (PID: 896)
    • Checks supported languages

      • iobit-uninstaller.exe (PID: 896)
    • UPX packer has been detected

      • iobit-uninstaller.exe (PID: 896)
    • Create files in a temporary directory

      • iobit-uninstaller.exe (PID: 896)
    • Reads the computer name

      • iobit-uninstaller.exe (PID: 896)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (42.1)
.exe | Win32 EXE Yoda's Crypter (41.3)
.exe | Win32 Executable (generic) (7)
.exe | Win16/32 Executable Delphi generic (3.2)
.exe | Generic Win/DOS Executable (3.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:04:28 07:17:39+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 1384448
InitializedDataSize: 303104
UninitializedDataSize: 2289664
EntryPoint: 0x3813e0
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.2.0.127
ProductVersionNumber: 2.2.0.127
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: IObit
FileDescription: IObit Uninstaller
FileVersion: 2.2.0.127
InternalName: -
LegalCopyright: Copyright(c) 2005-2012
LegalTrademarks: IObit
OriginalFileName: -
ProductName: IObit Uninstaller
ProductVersion: 2.0.0.0
Comments: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
5
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start start iobit-uninstaller.exe no specs iobit-uninstaller.exe sppextcomobj.exe no specs slui.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
896"C:\Users\admin\AppData\Local\Temp\iobit-uninstaller.exe" C:\Users\admin\AppData\Local\Temp\iobit-uninstaller.exe
explorer.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
IObit Uninstaller
Version:
2.2.0.127
Modules
Images
c:\users\admin\appdata\local\temp\iobit-uninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
896"C:\Users\admin\AppData\Local\Temp\iobit-uninstaller.exe" C:\Users\admin\AppData\Local\Temp\iobit-uninstaller.exeexplorer.exe
User:
admin
Company:
IObit
Integrity Level:
MEDIUM
Description:
IObit Uninstaller
Exit code:
3221226540
Version:
2.2.0.127
Modules
Images
c:\users\admin\appdata\local\temp\iobit-uninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1272C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
3676C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5720"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
2 580
Read events
2 580
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
43
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\UnLan56.zlibtext
MD5:D45812381412876C5E8C6CC8FB24F7B8
SHA256:C0540D70B99130DF552B6C9A277B5E6DBF9E395B7F3D0631F6A3AA1CE5060522
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\ZLBB85C.tmpbinary
MD5:21CC098DDCA151102F084EDECA1CA0F0
SHA256:A2EF090B0F99BF774DA7607E50E988EDEDF4EF2E9311F9F6F8DD362DDBFC3288
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\ZLBB809.tmpbinary
MD5:E9A6253C37ACAF761C77B875974554E4
SHA256:5121007EE932C8D7DAE634D0151D5C53D654A94C07CFB30EFFA371BADB701807
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\ZLBB7F7.tmpbinary
MD5:6ADF3A51C835BA9D9A760447AD994EF2
SHA256:83458733E322FEB4D0D163ED2380DA649BE15B633E4A8C2AFAB9837F7B078023
896iobit-uninstaller.exeC:\Users\admin\AppData\Roaming\IObit\IObit Uninstaller\Language\BULGARIAN.LNGbinary
MD5:ADF2481FD89A6CAE14A19AF7D1D94761
SHA256:DE07C604EC778FB2818512A2DC44F6DBCE7CBE60B95F53E3CCEA511ADB3EC97D
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\ZLBB81A.tmpbinary
MD5:DB7BA7BB44A552E69CCFC875295361DE
SHA256:75D7526E76366E145F5FD79DAAC076C8885F82BE5D6487F6C62FBEEE2EB5F84D
896iobit-uninstaller.exeC:\Users\admin\AppData\Roaming\IObit\IObit Uninstaller\Language\CHINESETRAD.LNGbinary
MD5:329F3A35156BF0D1AFB35AEF9FB263C0
SHA256:B5EF6A9E77CF3F7D76837643CD2ABC5D51826A0EF392843144F10E3C096DDF7D
896iobit-uninstaller.exeC:\Users\admin\AppData\Roaming\IObit\IObit Uninstaller\Language\ENGLISH.LNGbinary
MD5:4C6D71DA603680B1DCF293060A0140CC
SHA256:1A83C6320B43277AE97E9982202DC3788832BD0CF90B8B6A4E723FE02CD5B7F7
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\ZLBB82A.tmpbinary
MD5:77B7DC43A0E6FE59B7E0641193D69AFE
SHA256:64675040442EC9B8375CD369A50B943BCCC00E6F615762A0193ED83ACED4BF44
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\ZLBB83B.tmpbinary
MD5:3EBA0C283FED8689C05BD191704A3EBC
SHA256:C8D659011EC42303C3AC53080EF45E2C5DA863EF2485C240D3FE313FE587E511
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
22
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
896
iobit-uninstaller.exe
GET
200
23.48.23.25:80
http://update.iobit.com/infofiles/iu-update.upt
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6768
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6768
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.21:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
23.216.77.21:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.216.77.21:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
896
iobit-uninstaller.exe
23.48.23.25:80
update.iobit.com
Akamai International B.V.
DE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.181.238
whitelisted
crl.microsoft.com
  • 23.216.77.21
  • 23.216.77.38
  • 23.216.77.32
  • 23.216.77.36
  • 23.216.77.25
  • 23.216.77.6
  • 23.216.77.7
  • 23.216.77.39
  • 23.216.77.22
whitelisted
update.iobit.com
  • 23.48.23.25
  • 23.48.23.64
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.130
  • 40.126.32.74
  • 40.126.32.134
  • 20.190.160.5
  • 20.190.160.65
  • 20.190.160.131
  • 40.126.32.140
  • 40.126.32.68
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info