| File name: | ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe |
| Full analysis: | https://app.any.run/tasks/79bd58e4-37b6-4c57-a1ef-5fb02fa2fef6 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | August 01, 2025, 01:23:58 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections |
| MD5: | EF3807036F446CC58A66DC5869FA5F6F |
| SHA1: | 38F5070622D7AB47CC2C1DD7C1C8CFC496981B08 |
| SHA256: | ED8CEC11C59045B09945CF8B6369687D9ACAAACF6D00BA0C6F6D5870099C46D4 |
| SSDEEP: | 98304:V/2qKTxgCAsWpihIOOaa7UjA9hGqc5TNoSCDzbPLFTh2YEs0mx4MDkkwS2GfG0c9:jYDe61CPwDv3uF0jibjzLQDp |
| .exe | | | InstallShield setup (45.2) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (43.6) |
| .exe | | | Win32 Executable (generic) (4.7) |
| .exe | | | Win16/32 Executable Delphi generic (2.1) |
| .exe | | | Generic Win/DOS Executable (2.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:06:24 10:40:37+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 2902016 |
| InitializedDataSize: | 4161536 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2c55bc |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.0.0.63 |
| ProductVersionNumber: | 6.0.0.63 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Pre-release |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | iTop Inc |
| FileDescription: | iTop Screen Recorder |
| FileVersion: | 6.0.0.63 |
| InternalName: | - |
| LegalCopyright: | © iTop Inc. All rights reserved. |
| LegalTrademarks: | iTop Inc. |
| OriginalFileName: | - |
| ProductName: | iTop Screen Recorder |
| ProductVersion: | 6.0.0.0 |
| Comments: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 320 | "C:\ProgramData\iTop Screen Recorder\Downloader\ISR_Setup.exe" /VerySilent /DIR="C:\Program Files\iTop Screen Recorder\" /UNINSTALL /INSTALLER /NORESTART /TASKS="desktopicon" /CreateTaskbar /DoNotWirteInsur | C:\ProgramData\iTop Screen Recorder\Downloader\ISR_Setup.exe | ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | ||||||||||||
User: admin Company: iTop Inc. Integrity Level: HIGH Description: iTop Screen Recorder Version: 6.0.0.3395 Modules
| |||||||||||||||
| 1212 | "C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --wake --system | C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Exit code: 0 Version: 134.0.6985.0 Modules
| |||||||||||||||
| 1612 | "C:\Users\admin\Desktop\ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe" | C:\Users\admin\Desktop\ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | explorer.exe | ||||||||||||
User: admin Company: iTop Inc Integrity Level: HIGH Description: iTop Screen Recorder Version: 6.0.0.63 Modules
| |||||||||||||||
| 1728 | "C:\Users\admin\Desktop\ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe" | C:\Users\admin\Desktop\ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | — | explorer.exe | |||||||||||
User: admin Company: iTop Inc Integrity Level: MEDIUM Description: iTop Screen Recorder Exit code: 3221226540 Version: 6.0.0.63 Modules
| |||||||||||||||
| 1740 | "C:\Users\admin\AppData\Local\Temp\is-PU1Q4.tmp\iScrInit.exe" /CheckOldVer=0 /CopyOldConfig /installdir="" | C:\Users\admin\AppData\Local\Temp\is-PU1Q4.tmp\iScrInit.exe | ISR_Setup.tmp | ||||||||||||
User: admin Company: iTop Inc. Integrity Level: HIGH Description: iTop Screen Recorderr Ini Exit code: 0 Version: 6.0.0.484 Modules
| |||||||||||||||
| 2432 | "C:\Users\admin\AppData\Local\Temp\is-PU1Q4.tmp\iScrInit.exe" /KillProcess /installdir="C:\Program Files\iTop Screen Recorder" | C:\Users\admin\AppData\Local\Temp\is-PU1Q4.tmp\iScrInit.exe | ISR_Setup.tmp | ||||||||||||
User: admin Company: iTop Inc. Integrity Level: HIGH Description: iTop Screen Recorderr Ini Exit code: 0 Version: 6.0.0.484 Modules
| |||||||||||||||
| 3100 | "C:\Users\admin\AppData\Local\Temp\is-H83A2.tmp\ISR_Setup.tmp" /SL5="$E0326,135198810,230912,C:\ProgramData\iTop Screen Recorder\Downloader\ISR_Setup.exe" /VerySilent /DIR="C:\Program Files\iTop Screen Recorder\" /UNINSTALL /INSTALLER /NORESTART /TASKS="desktopicon" /CreateTaskbar /DoNotWirteInsur | C:\Users\admin\AppData\Local\Temp\is-H83A2.tmp\ISR_Setup.tmp | ISR_Setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Version: 51.1052.0.0 Modules
| |||||||||||||||
| 4688 | "C:\Users\admin\AppData\Local\Temp\is-PU1Q4.tmp\iScrInit.exe" /CleanReg | C:\Users\admin\AppData\Local\Temp\is-PU1Q4.tmp\iScrInit.exe | ISR_Setup.tmp | ||||||||||||
User: admin Company: iTop Inc. Integrity Level: HIGH Description: iTop Screen Recorderr Ini Exit code: 0 Version: 6.0.0.484 Modules
| |||||||||||||||
| 5764 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6392 | "C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=134.0.6985.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x298,0x29c,0x2a0,0x274,0x2a4,0x111c460,0x111c46c,0x111c478 | C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe | — | updater.exe | |||||||||||
User: SYSTEM Company: Google LLC Integrity Level: SYSTEM Description: Google Updater Exit code: 0 Version: 134.0.6985.0 Modules
| |||||||||||||||
| (PID) Process: | (1612) ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\iTop Screen Recorder |
| Operation: | write | Name: | insur |
Value: ency_techno360_isr | |||
| (PID) Process: | (3100) ISR_Setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\iTop Screen Recorder |
| Operation: | write | Name: | InstallFinished |
Value: 0 | |||
| (PID) Process: | (3100) ISR_Setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Wow6432Node\iTop Screen Recorder |
| Operation: | write | Name: | InstallFinished |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1612 | ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | C:\ProgramData\iTop Screen Recorder\Downloader\ISR_Setup.exe | — | |
MD5:— | SHA256:— | |||
| 1612 | ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | C:\Users\admin\AppData\Local\Temp\Installerupt45870.058469375.ini | text | |
MD5:495E10B9039E6496548342FF20EABC10 | SHA256:9B7F4FF6C3B456E0A3565C382612820CD865D2A9983221D4C1A5787A6599C106 | |||
| 1612 | ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | C:\Users\admin\AppData\Local\Temp\libcrypto-1_1.dll | executable | |
MD5:E9888362828D6B6F6E13E6CFA5A36419 | SHA256:37CC65DA464443F780BA555ED3C86F5F1003CCBE790F85F3A612C62741C9FA92 | |||
| 6392 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\updater.log | text | |
MD5:98F66BE540D4F02E5B66DEA116875A4A | SHA256:C72065150F138CCD1BD73120555493A88BDF3BC0B013F92C9C58E23C0E1A3B5C | |||
| 3100 | ISR_Setup.tmp | C:\Program Files\iTop Screen Recorder\is-88F2O.tmp | executable | |
MD5:E545698C713B3294EE33455CA045A935 | SHA256:E29C142D8CC92E8346AA8460D5A8E6AC1BE1CA435EDA2F5E452C707738597EEB | |||
| 3100 | ISR_Setup.tmp | C:\Program Files\iTop Screen Recorder\AudioCapture.dll | executable | |
MD5:BB3DDFBC98722E3AE56BD3F0CBA65CC6 | SHA256:5DD3B28AB7841F666FCAFBD73E3A81F0479F94F2FCAC92BE9C3E349429D46A5E | |||
| 1612 | ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | C:\Users\admin\AppData\Roaming\iTop Screen Recorder\Main.ini | text | |
MD5:FC9AF3BE206ADA4C02EE4D18D8021374 | SHA256:2C88DC7CE8C569C66A63823B0E75CDCE9DE6D93B874E75825D927605293788C0 | |||
| 3100 | ISR_Setup.tmp | C:\Program Files\iTop Screen Recorder\unins000.exe | executable | |
MD5:1282BAEB66816A6BC2480CA71A27080A | SHA256:086DDDF62B5B452C167C857A681E8E084F8FB45F5BBA7C0603CE05333376D322 | |||
| 3100 | ISR_Setup.tmp | C:\Users\admin\AppData\Local\Temp\is-PU1Q4.tmp\Inno_English.lng | text | |
MD5:524B7877C76E16D30FD0FE02C2944A28 | SHA256:5E11AE4DD2586E690E90B07F9A9FE40843837853DE0A27500DCFDD27945CDE53 | |||
| 1612 | ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | C:\Users\admin\AppData\Local\Temp\Installerupt45870.0584525579.zlb | skn | |
MD5:99861DB0005DD0A8D70B9AF39C164239 | SHA256:4D0DC83EFEFADE318C01F98661110898CFBD5008A6716A335A365EF604A8F5F7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 206 | 23.50.131.84:443 | https://update.itopupdate.com/infofiles/isr/rmd/installer.zlb | unknown | binary | 53.5 Kb | — |
— | — | POST | 200 | 20.190.160.66:443 | https://login.live.com/RST2.srf | unknown | xml | 1.24 Kb | whitelisted |
— | — | POST | 400 | 20.190.160.131:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | unknown | text | 203 b | whitelisted |
— | — | POST | 500 | 40.91.76.224:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | unknown | xml | 512 b | whitelisted |
— | — | GET | 200 | 2.16.241.14:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 2.16.241.14:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.241.14:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 52.206.118.116:443 | https://stats.reportcpanel.com/multi_app_new.php?action=get-token | unknown | text | 24 b | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 2.16.241.14:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 2.16.241.14:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5944 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1612 | ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | 23.32.238.89:443 | update.itopupdate.com | Akamai International B.V. | DE | suspicious |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
update.itopupdate.com |
| unknown |
update.iobit.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | 33333 |
ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | Win32MinorVersion: 0 |
ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | 6666 |
ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | 7777 |
ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | 8888 |
ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | ********** FLanguageName: English |
ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | FormCreate: 1 |
ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | GetDownloadPath: 1 |
ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | CheckDiskSpace: 1 |
ed8cec11c59045b09945cf8b6369687d9acaaacf6d00ba0c6f6d5870099c46d4.exe | CheckDiskSpace: 2 |