| File name: | Uninstall Tool 3.7.4.5725.exe |
| Full analysis: | https://app.any.run/tasks/49d86414-eb29-49ac-b9f1-e53543e635cf |
| Verdict: | Malicious activity |
| Threats: | Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns. |
| Analysis date: | February 13, 2025, 01:39:57 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections |
| MD5: | 5C6F4482AEB57F4DFB925BC1C819C3A8 |
| SHA1: | BFE3980341E448CCFDA4BB4B6F0E9B1D711D042F |
| SHA256: | FC8D4A384C0451C1C93401ABEB2EECF7D5D2016EF16B10EF228873FCC8CE443E |
| SSDEEP: | 98304:FZriRyXVUnqmtdRT5rjxI9T4X6N4EYeOMhnVGHijZXq6LruhELusURyycYOyadyY:mszZ2v+G68INOq |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 37888 |
| InitializedDataSize: | 25600 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9c14 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.7.4.5725 |
| ProductVersionNumber: | 3.7.4.5725 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | |
| FileDescription: | Uninstall Tool Setup |
| FileVersion: | 3.7.4.5725.0 |
| LegalCopyright: | Copyright 2023 LR |
| ProductName: | Uninstall Tool |
| ProductVersion: | 3.7.4.5725 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 648 | "C:\Program Files\Uninstall Tool\UninstallTool.exe" /init | C:\Program Files\Uninstall Tool\UninstallTool.exe | — | Uninstall Tool 3.7.4.5725.tmp | |||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: HIGH Description: Uninstall Tool Exit code: 0 Version: 3.7.4.5725 Modules
| |||||||||||||||
| 3560 | "C:\Program Files\Uninstall Tool\UninstallTool.exe" | C:\Program Files\Uninstall Tool\UninstallTool.exe | Uninstall Tool 3.7.4.5725.tmp | ||||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: HIGH Description: Uninstall Tool Version: 3.7.4.5725 Modules
| |||||||||||||||
| 6184 | "C:\Program Files\Uninstall Tool\UninstallTool.exe" /install_service_silent | C:\Program Files\Uninstall Tool\UninstallTool.exe | Uninstall Tool 3.7.4.5725.tmp | ||||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: HIGH Description: Uninstall Tool Exit code: 0 Version: 3.7.4.5725 Modules
| |||||||||||||||
| 6220 | "C:\Program Files\Uninstall Tool\UninstallTool.exe" /add_control_panel_icon | C:\Program Files\Uninstall Tool\UninstallTool.exe | — | Uninstall Tool 3.7.4.5725.tmp | |||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: HIGH Description: Uninstall Tool Exit code: 0 Version: 3.7.4.5725 Modules
| |||||||||||||||
| 6272 | "C:\Program Files\Uninstall Tool\UninstallTool.exe" /skip_uac | C:\Program Files\Uninstall Tool\UninstallTool.exe | — | Uninstall Tool 3.7.4.5725.tmp | |||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: HIGH Description: Uninstall Tool Exit code: 0 Version: 3.7.4.5725 Modules
| |||||||||||||||
| 6324 | "C:\Program Files\Uninstall Tool\UninstallToolHelper.exe" /pid:3560 | C:\Program Files\Uninstall Tool\UninstallToolHelper.exe | — | UninstallTool.exe | |||||||||||
User: admin Company: CrystalIDEA Software Integrity Level: HIGH Description: Uninstall Tool Helper Process Version: 1, 1, 17, 5 | |||||||||||||||
| 6456 | "C:\Users\admin\AppData\Local\Temp\Uninstall Tool 3.7.4.5725.exe" | C:\Users\admin\AppData\Local\Temp\Uninstall Tool 3.7.4.5725.exe | — | explorer.exe | |||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Uninstall Tool Setup Exit code: 3221226540 Version: 3.7.4.5725.0 Modules
| |||||||||||||||
| 6512 | "C:\Users\admin\AppData\Local\Temp\Uninstall Tool 3.7.4.5725.exe" | C:\Users\admin\AppData\Local\Temp\Uninstall Tool 3.7.4.5725.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Uninstall Tool Setup Exit code: 0 Version: 3.7.4.5725.0 Modules
| |||||||||||||||
| 6532 | "C:\Users\admin\AppData\Local\Temp\is-LFL5D.tmp\Uninstall Tool 3.7.4.5725.tmp" /SL5="$502F2,5130422,64512,C:\Users\admin\AppData\Local\Temp\Uninstall Tool 3.7.4.5725.exe" | C:\Users\admin\AppData\Local\Temp\is-LFL5D.tmp\Uninstall Tool 3.7.4.5725.tmp | Uninstall Tool 3.7.4.5725.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| (PID) Process: | (6532) Uninstall Tool 3.7.4.5725.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\CrystalIdea Software\Uninstall Tool |
| Operation: | write | Name: | RN |
Value: yon7ifCJ+on9ieiJ5YnAic2JzInIiamJ2onmie+J/Yn+ieiJ+4nsiQ== | |||
| (PID) Process: | (6532) Uninstall Tool 3.7.4.5725.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\CrystalIdea Software\Uninstall Tool |
| Operation: | write | Name: | RC |
Value: 3InnieCJ54n6if2J6InlieWJqYndieaJ5onliQ== | |||
| (PID) Process: | (6532) Uninstall Tool 3.7.4.5725.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall Tool_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.5.1.ee2 (a) | |||
| (PID) Process: | (6532) Uninstall Tool 3.7.4.5725.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall Tool_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\Uninstall Tool | |||
| (PID) Process: | (6532) Uninstall Tool 3.7.4.5725.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall Tool_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\Uninstall Tool\ | |||
| (PID) Process: | (6532) Uninstall Tool 3.7.4.5725.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall Tool_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: Uninstall Tool | |||
| (PID) Process: | (6532) Uninstall Tool 3.7.4.5725.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall Tool_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
| (PID) Process: | (6532) Uninstall Tool 3.7.4.5725.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall Tool_is1 |
| Operation: | write | Name: | Inno Setup: Selected Tasks |
Value: service,cpanel,skip_uac,addlng,stdstart | |||
| (PID) Process: | (6532) Uninstall Tool 3.7.4.5725.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall Tool_is1 |
| Operation: | write | Name: | Inno Setup: Deselected Tasks |
Value: service\context,desktopicon,openurl | |||
| (PID) Process: | (6532) Uninstall Tool 3.7.4.5725.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Uninstall Tool_is1 |
| Operation: | write | Name: | Inno Setup: Language |
Value: english | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6532 | Uninstall Tool 3.7.4.5725.tmp | C:\Users\admin\AppData\Local\Temp\is-SBTV6.tmp\VclStylesInno.dll | executable | |
MD5:B0CA93CEB050A2FEFF0B19E65072BBB5 | SHA256:0E93313F42084D804B9AC4BE53D844E549CFCAF19E6F276A3B0F82F01B9B2246 | |||
| 6512 | Uninstall Tool 3.7.4.5725.exe | C:\Users\admin\AppData\Local\Temp\is-LFL5D.tmp\Uninstall Tool 3.7.4.5725.tmp | executable | |
MD5:62C95101DD1E6B1533EA39EBEB99DC91 | SHA256:311826CEA6FF290275F47998747258E13F6220F99808766FEC8F791C6BD6646D | |||
| 6532 | Uninstall Tool 3.7.4.5725.tmp | C:\Users\admin\AppData\Local\Temp\is-SBTV6.tmp\WizardForm.BitmapImage1.bmp | image | |
MD5:48386BC24D46A3FAC0056AB765A597A1 | SHA256:55E4D15D42D4983C2D3A4E0ABD07EFF703929FAE4DD33115F008BE346D501036 | |||
| 6532 | Uninstall Tool 3.7.4.5725.tmp | C:\Users\admin\AppData\Local\Temp\is-SBTV6.tmp\_isetup\_setup64.tmp | executable | |
MD5:4FF75F505FDDCC6A9AE62216446205D9 | SHA256:A4C86FC4836AC728D7BD96E7915090FD59521A9E74F1D06EF8E5A47C8695FD81 | |||
| 6532 | Uninstall Tool 3.7.4.5725.tmp | C:\Program Files\Uninstall Tool\languages\is-P739J.tmp | xml | |
MD5:12D25248123BCCC24102105175579061 | SHA256:2324948D09B7DF17DBF753FBB50B02038942A0B93700CD65969F7798C6DD16EA | |||
| 6532 | Uninstall Tool 3.7.4.5725.tmp | C:\Program Files\Uninstall Tool\is-96GNE.tmp | executable | |
MD5:869BB6CDA4E209ED6341DED19EFFBF84 | SHA256:B8831AF2C048B0CBF80457B29AAF412617922F89E114449E801AF626DA5ED20C | |||
| 6532 | Uninstall Tool 3.7.4.5725.tmp | C:\Users\admin\AppData\Local\Temp\is-SBTV6.tmp\ISTask.dll | executable | |
MD5:86A1311D51C00B278CB7F27796EA442E | SHA256:E916BDF232744E00CBD8D608168A019C9F41A68A7E8390AA48CFB525276C483D | |||
| 6532 | Uninstall Tool 3.7.4.5725.tmp | C:\Users\admin\AppData\Local\Temp\is-SBTV6.tmp\MetroBlue.vsf | binary | |
MD5:295D085196B3DA13BFCD53373F82F8EE | SHA256:CBDC95EB9E7269E0C3E3BDDFD37B0918962795D80BDBA932E46EA16FF5E6CDBF | |||
| 6532 | Uninstall Tool 3.7.4.5725.tmp | C:\Program Files\Uninstall Tool\languages\is-7VJGR.tmp | xml | |
MD5:1ABA2350FFD13F93EDFFBA70C8B2DFE5 | SHA256:FD867D6043F7997A4A0254659C4D38C741A7DB2E9622AE92B177CA13F0E0CAE8 | |||
| 6532 | Uninstall Tool 3.7.4.5725.tmp | C:\Program Files\Uninstall Tool\languages\Russian.xml | xml | |
MD5:1ABA2350FFD13F93EDFFBA70C8B2DFE5 | SHA256:FD867D6043F7997A4A0254659C4D38C741A7DB2E9622AE92B177CA13F0E0CAE8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5064 | SearchApp.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
6844 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
3560 | UninstallTool.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEEj8k7RgVZSNNqfJionWlBY%3D | unknown | — | — | whitelisted |
3560 | UninstallTool.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEGIdbQxSAZ47kHkVIIkhHAo%3D | unknown | — | — | whitelisted |
3560 | UninstallTool.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQVD%2BnGf79Hpedv3mhy6uKMVZkPCQQUDyrLIIcouOxvSK4rVKYpqhekzQwCEQDfD%2FoApQz6Tjifa39Nky1P | unknown | — | — | whitelisted |
1328 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
1328 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4556 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5064 | SearchApp.exe | 2.19.96.120:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
5064 | SearchApp.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1176 | svchost.exe | 40.126.31.1:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1176 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1076 | svchost.exe | 2.19.106.8:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
3560 | UninstallTool.exe | 104.18.38.233:80 | ocsp.comodoca.com | CLOUDFLARENET | — | whitelisted |
3560 | UninstallTool.exe | 172.64.149.23:80 | ocsp.comodoca.com | CLOUDFLARENET | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
crystalidea.license-manage.com |
| unknown |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |