File name:

iobit-uninstaller.exe

Full analysis: https://app.any.run/tasks/804816e9-9873-4915-a8d7-47ce1997ba63
Verdict: Malicious activity
Analysis date: April 11, 2025, 14:59:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
upx
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

EB732C43B23E848EBDA2E2C429C55516

SHA1:

1F75ABA505398957750EEAD0D97F9DE87772EF52

SHA256:

DC55D900E2564E0A78F2F1155A4FC58259E04C51D9ED67984ADB8BB04DB739E9

SSDEEP:

49152:4sYeT/c7RNza9ouc9LBCV1aD0JZ4BB0RsEef7DWDvyupqPLxLTX03zOJHTt6a30I:4sYerc7zaWuoKUCxsEeeDvyl16ih8aoA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • iobit-uninstaller.exe (PID: 896)
  • SUSPICIOUS

    • Searches for installed software

      • iobit-uninstaller.exe (PID: 896)
  • INFO

    • The sample compiled with english language support

      • iobit-uninstaller.exe (PID: 896)
    • Checks supported languages

      • iobit-uninstaller.exe (PID: 896)
    • Reads the computer name

      • iobit-uninstaller.exe (PID: 896)
    • Creates files or folders in the user directory

      • iobit-uninstaller.exe (PID: 896)
    • Compiled with Borland Delphi (YARA)

      • iobit-uninstaller.exe (PID: 896)
    • Create files in a temporary directory

      • iobit-uninstaller.exe (PID: 896)
    • UPX packer has been detected

      • iobit-uninstaller.exe (PID: 896)
    • Reads the software policy settings

      • slui.exe (PID: 5720)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (42.1)
.exe | Win32 EXE Yoda's Crypter (41.3)
.exe | Win32 Executable (generic) (7)
.exe | Win16/32 Executable Delphi generic (3.2)
.exe | Generic Win/DOS Executable (3.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:04:28 07:17:39+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 1384448
InitializedDataSize: 303104
UninitializedDataSize: 2289664
EntryPoint: 0x3813e0
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.2.0.127
ProductVersionNumber: 2.2.0.127
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: IObit
FileDescription: IObit Uninstaller
FileVersion: 2.2.0.127
InternalName: -
LegalCopyright: Copyright(c) 2005-2012
LegalTrademarks: IObit
OriginalFileName: -
ProductName: IObit Uninstaller
ProductVersion: 2.0.0.0
Comments: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
5
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start start iobit-uninstaller.exe no specs iobit-uninstaller.exe sppextcomobj.exe no specs slui.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
896"C:\Users\admin\AppData\Local\Temp\iobit-uninstaller.exe" C:\Users\admin\AppData\Local\Temp\iobit-uninstaller.exe
explorer.exe
User:
admin
Company:
IObit
Integrity Level:
HIGH
Description:
IObit Uninstaller
Version:
2.2.0.127
Modules
Images
c:\users\admin\appdata\local\temp\iobit-uninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
896"C:\Users\admin\AppData\Local\Temp\iobit-uninstaller.exe" C:\Users\admin\AppData\Local\Temp\iobit-uninstaller.exeexplorer.exe
User:
admin
Company:
IObit
Integrity Level:
MEDIUM
Description:
IObit Uninstaller
Exit code:
3221226540
Version:
2.2.0.127
Modules
Images
c:\users\admin\appdata\local\temp\iobit-uninstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1272C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
3676C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5720"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
2 580
Read events
2 580
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
43
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\ZLBB7F7.tmpbinary
MD5:6ADF3A51C835BA9D9A760447AD994EF2
SHA256:83458733E322FEB4D0D163ED2380DA649BE15B633E4A8C2AFAB9837F7B078023
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\ZLBB81A.tmpbinary
MD5:DB7BA7BB44A552E69CCFC875295361DE
SHA256:75D7526E76366E145F5FD79DAAC076C8885F82BE5D6487F6C62FBEEE2EB5F84D
896iobit-uninstaller.exeC:\Users\admin\AppData\Roaming\IObit\IObit Uninstaller\Language\BULGARIAN.LNGbinary
MD5:ADF2481FD89A6CAE14A19AF7D1D94761
SHA256:DE07C604EC778FB2818512A2DC44F6DBCE7CBE60B95F53E3CCEA511ADB3EC97D
896iobit-uninstaller.exeC:\Users\admin\AppData\Roaming\IObit\IObit Uninstaller\Language\CHINESETRAD.LNGbinary
MD5:329F3A35156BF0D1AFB35AEF9FB263C0
SHA256:B5EF6A9E77CF3F7D76837643CD2ABC5D51826A0EF392843144F10E3C096DDF7D
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\ZLBB82A.tmpbinary
MD5:77B7DC43A0E6FE59B7E0641193D69AFE
SHA256:64675040442EC9B8375CD369A50B943BCCC00E6F615762A0193ED83ACED4BF44
896iobit-uninstaller.exeC:\Users\admin\AppData\Roaming\IObit\IObit Uninstaller\Language\CHINESESIMP.LNGbinary
MD5:5D889F669B5AAA09D6061BCD6AC90AF9
SHA256:DDB3C52E6781ACBD2F961F3E8F1A22B8B64102B91E623E45C5DDA1551F5802CA
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\ZLBB809.tmpbinary
MD5:E9A6253C37ACAF761C77B875974554E4
SHA256:5121007EE932C8D7DAE634D0151D5C53D654A94C07CFB30EFFA371BADB701807
896iobit-uninstaller.exeC:\Users\admin\AppData\Roaming\IObit\IObit Uninstaller\Language\DANISH.LNGbinary
MD5:16333DB77FA29E1AF9163A69A5150E2C
SHA256:CC80E58B98B399F59654193F9C3A3F15BF9DD1C956B7370804EFB9AC5015C752
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\UnLan37.zlibbinary
MD5:62FBE4E3A0C1B1E4FDF4704A1737606E
SHA256:5987EE5466B84EBE8B0BF083818C8F4FCACE22D5A53BEAF727FC3952F7BA9D9E
896iobit-uninstaller.exeC:\Users\admin\AppData\Local\Temp\ZLBB808.tmpbinary
MD5:F1BDF61C1735A4D87D1A29C6E9DC21E1
SHA256:A965009D66DA0B32A70D6453C21A2A1CFC15097029FE9C55124E8694C3A11461
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
22
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6768
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2104
svchost.exe
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6768
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
896
iobit-uninstaller.exe
GET
200
23.48.23.25:80
http://update.iobit.com/infofiles/iu-update.upt
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.21:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
23.216.77.21:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.216.77.21:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
896
iobit-uninstaller.exe
23.48.23.25:80
update.iobit.com
Akamai International B.V.
DE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.181.238
whitelisted
crl.microsoft.com
  • 23.216.77.21
  • 23.216.77.38
  • 23.216.77.32
  • 23.216.77.36
  • 23.216.77.25
  • 23.216.77.6
  • 23.216.77.7
  • 23.216.77.39
  • 23.216.77.22
whitelisted
update.iobit.com
  • 23.48.23.25
  • 23.48.23.64
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.130
  • 40.126.32.74
  • 40.126.32.134
  • 20.190.160.5
  • 20.190.160.65
  • 20.190.160.131
  • 40.126.32.140
  • 40.126.32.68
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info