URL:

https://www.itopvpn.com/

Full analysis: https://app.any.run/tasks/f7928d8c-6d92-4764-a2d9-111467932d59
Verdict: Malicious activity
Analysis date: May 27, 2025, 17:20:20
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
evasion
delphi
inno
installer
rust
Indicators:
MD5:

F2A516C612001AFAB907AFCF1B053593

SHA1:

91CB8644CC97D6D55C4277E95364C51CF9D8E30B

SHA256:

FFE8DDD7CBB15DD7FE01802485233CE695F25A45023521F5A4BD9FAD4D5AD76B

SSDEEP:

3:N8DSLxVSK:2OLN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • iTopVPN_setup_Free.tmp (PID: 8056)
      • iTopVPN_setup_Free.tmp (PID: 4452)
      • iTopVPN_setup_Free.tmp (PID: 6652)
    • Executable content was dropped or overwritten

      • iTopVPN_setup_Free.exe (PID: 7808)
      • iTopVPN_setup_Free.exe (PID: 7864)
      • iTopVPN_setup_Free.tmp (PID: 4452)
      • iTopVPN_setup_Free.exe (PID: 3132)
      • iTopVPN_setup_Free.tmp (PID: 6652)
      • atud.exe (PID: 7512)
      • ugin.exe (PID: 2140)
      • ISRSetup.exe (PID: 2040)
      • ISRSetup.tmp (PID: 2332)
      • maymad2025.exe (PID: 8112)
      • 2711FDB859001D6EAC0BF0E328A77CC2.tmp (PID: 8496)
      • AutoUpdate.exe (PID: 8172)
      • itopmaymad25.exe (PID: 8600)
      • 2711FDB859001D6EAC0BF0E328A77CC2.exe (PID: 8476)
    • Checks for external IP

      • svchost.exe (PID: 2196)
      • ugin.exe (PID: 4944)
      • Setup.exe (PID: 7800)
      • unpr.exe (PID: 2852)
      • maymad2025.exe (PID: 8112)
    • Reads the Windows owner or organization settings

      • iTopVPN_setup_Free.tmp (PID: 4452)
      • iTopVPN_setup_Free.tmp (PID: 6652)
    • Process drops legitimate windows executable

      • iTopVPN_setup_Free.tmp (PID: 4452)
      • iTopVPN_setup_Free.tmp (PID: 6652)
      • ISRSetup.tmp (PID: 2332)
    • Uses TASKKILL.EXE to kill process

      • iTopVPN_setup_Free.tmp (PID: 6652)
      • ISRSetup.tmp (PID: 2332)
    • Drops a system driver (possible attempt to evade defenses)

      • iTopVPN_setup_Free.tmp (PID: 6652)
      • ugin.exe (PID: 2140)
    • Process drops SQLite DLL files

      • iTopVPN_setup_Free.tmp (PID: 6652)
      • ISRSetup.tmp (PID: 2332)
    • Windows service management via SC.EXE

      • sc.exe (PID: 2692)
      • sc.exe (PID: 8132)
      • sc.exe (PID: 8140)
      • sc.exe (PID: 7560)
      • sc.exe (PID: 2692)
    • Suspicious use of NETSH.EXE

      • cmd.exe (PID: 1472)
      • cmd.exe (PID: 4220)
    • Application launched itself

      • ugin.exe (PID: 2140)
    • Process uses IPCONFIG to clear DNS cache

      • cmd.exe (PID: 2552)
      • cmd.exe (PID: 7936)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 3760)
    • Starts CMD.EXE for commands execution

      • iTopVPN.exe (PID: 2240)
      • ugin.exe (PID: 2140)
    • Connects to unusual port

      • iTopVPN.exe (PID: 2240)
    • Stops a currently running service

      • sc.exe (PID: 8108)
      • sc.exe (PID: 7228)
    • The process drops C-runtime libraries

      • ISRSetup.tmp (PID: 2332)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 2340)
      • firefox.exe (PID: 456)
      • firefox.exe (PID: 1240)
      • firefox.exe (PID: 7360)
      • firefox.exe (PID: 5512)
      • firefox.exe (PID: 6988)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 456)
    • Launch of the file from Downloads directory

      • firefox.exe (PID: 456)
    • Create files in a temporary directory

      • iTopVPN_setup_Free.exe (PID: 7808)
      • iTopVPN_setup_Free.tmp (PID: 4452)
      • Setup.exe (PID: 7800)
      • iTopVPN_setup_Free.exe (PID: 7864)
      • iTopVPN_setup_Free.exe (PID: 3132)
      • iTopVPN_setup_Free.tmp (PID: 6652)
    • Checks supported languages

      • iTopVPN_setup_Free.exe (PID: 7808)
      • iTopVPN_setup_Free.tmp (PID: 8056)
      • iTopVPN_setup_Free.exe (PID: 7864)
      • iTopVPN_setup_Free.tmp (PID: 4452)
      • ugin.exe (PID: 4944)
      • Setup.exe (PID: 7800)
      • iTopVPN_setup_Free.exe (PID: 3132)
      • ugin.exe (PID: 7584)
      • iTopVPN_setup_Free.tmp (PID: 6652)
      • ugin.exe (PID: 8084)
      • ugin.exe (PID: 7500)
      • iTopVPN.exe (PID: 864)
      • ullc.exe (PID: 7824)
      • ugin.exe (PID: 2140)
    • Reads the computer name

      • iTopVPN_setup_Free.tmp (PID: 8056)
      • ugin.exe (PID: 4944)
      • iTopVPN_setup_Free.tmp (PID: 4452)
      • iTopVPN_setup_Free.tmp (PID: 6652)
      • ugin.exe (PID: 7584)
      • Setup.exe (PID: 7800)
      • ugin.exe (PID: 7500)
      • ugin.exe (PID: 8084)
      • iTopVPN.exe (PID: 864)
      • ugin.exe (PID: 2140)
    • Process checks computer location settings

      • iTopVPN_setup_Free.tmp (PID: 8056)
      • iTopVPN_setup_Free.tmp (PID: 4452)
      • iTopVPN_setup_Free.tmp (PID: 6652)
    • Creates files in the program directory

      • ugin.exe (PID: 4944)
      • Setup.exe (PID: 7800)
      • iTopVPN_setup_Free.tmp (PID: 6652)
      • iTopVPN.exe (PID: 864)
      • ugin.exe (PID: 2140)
    • Creates files or folders in the user directory

      • ugin.exe (PID: 4944)
      • iTopVPN_setup_Free.tmp (PID: 6652)
      • iTopVPN.exe (PID: 864)
    • Reads the machine GUID from the registry

      • ugin.exe (PID: 4944)
      • Setup.exe (PID: 7800)
    • The sample compiled with english language support

      • iTopVPN_setup_Free.tmp (PID: 4452)
      • iTopVPN_setup_Free.tmp (PID: 6652)
      • ugin.exe (PID: 2140)
      • atud.exe (PID: 7512)
      • ISRSetup.tmp (PID: 2332)
      • maymad2025.exe (PID: 8112)
      • AutoUpdate.exe (PID: 8172)
      • 2711FDB859001D6EAC0BF0E328A77CC2.tmp (PID: 8496)
      • itopmaymad25.exe (PID: 8600)
    • Compiled with Borland Delphi (YARA)

      • Setup.exe (PID: 7800)
      • iTopVPN_setup_Free.exe (PID: 3132)
      • iTopDownloader.exe (PID: 6324)
      • slui.exe (PID: 7884)
      • iTopVPN.exe (PID: 2240)
      • iTopVPNMini.exe (PID: 1120)
      • ISRSetup.tmp (PID: 2332)
      • ISRSetup.exe (PID: 2040)
      • wstr.exe (PID: 6372)
    • Creates a software uninstall entry

      • iTopVPN_setup_Free.tmp (PID: 6652)
    • Detects InnoSetup installer (YARA)

      • iTopVPN_setup_Free.exe (PID: 3132)
      • ISRSetup.exe (PID: 2040)
      • ISRSetup.tmp (PID: 2332)
    • Application based on Rust

      • iTopVPN.exe (PID: 2240)
    • Manual execution by a user

      • firefox.exe (PID: 7360)
      • firefox.exe (PID: 6988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
295
Monitored processes
158
Malicious processes
7
Suspicious processes
3

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs sppextcomobj.exe no specs slui.exe itopvpn_setup_free.exe itopvpn_setup_free.tmp no specs itopvpn_setup_free.exe itopvpn_setup_free.tmp ugin.exe setup.exe itopvpn_setup_free.exe itopvpn_setup_free.tmp ugin.exe no specs taskkill.exe no specs conhost.exe no specs ugin.exe no specs ugin.exe no specs ullc.exe no specs conhost.exe no specs itopvpn.exe no specs ugin.exe cmd.exe no specs conhost.exe no specs sc.exe no specs cmd.exe no specs conhost.exe no specs sc.exe no specs cmd.exe no specs conhost.exe no specs sc.exe no specs icop64.exe no specs conhost.exe no specs ugin.exe ugin.exe no specs unpr.exe ugin.exe no specs slui.exe itopdownloader.exe itopvpn.exe itopvpn.exe no specs atud.exe aud.exe aud.exe cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs itopvpnmini.exe isrsetup.exe isrsetup.tmp secedit.exe no specs conhost.exe no specs secedit.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs maymad2025.exe iscrinit.exe no specs iscrinit.exe no specs iscrinit.exe no specs iscrinit.exe no specs cmd.exe no specs conhost.exe no specs ipconfig.exe no specs wstr.exe no specs ugin.exe aud.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs locallang.exe no specs conhost.exe no specs iscrinit.exe no specs iscrinit.exe gpucheck.exe iscrmagnifier.exe no specs taskkill.exe no specs conhost.exe no specs iscrgpurecording.exe no specs iscrinit.exe no specs iconpin64.exe no specs conhost.exe no specs uninstallinfo.exe cmd.exe no specs conhost.exe no specs ipconfig.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs aud.exe no specs ipconfig.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs cmd.exe no specs conhost.exe no specs ping.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs cmd.exe no specs conhost.exe no specs ping.exe no specs firefox.exe no specs firefox.exe no specs iscrinit.exe iscrrec.exe autoupdate.exe iscrextdown.exe iscrinit.exe no specs autoupdate.exe no specs iscrextdown.exe no specs gpucheck.exe no specs graphics-check.exe no specs iscrrecext.exe no specs iscrvoicecapture.exe no specs autoupdate.exe no specs iscrinit.exe no specs aupdate.exe aupdate.exe 2711fdb859001d6eac0bf0e328a77cc2.exe 2711fdb859001d6eac0bf0e328a77cc2.tmp itopmaymad25.exe gpifcoll.exe svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
456"C:\Program Files\Mozilla Firefox\firefox.exe" https://www.itopvpn.com/C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
856"C:\Users\admin\AppData\Local\Temp\is-3IESN.tmp\iScrInit.exe" /DeleteAllFile /reinstall=1 /installdir="C:\Program Files\iTop Screen Recorder"C:\Users\admin\AppData\Local\Temp\is-3IESN.tmp\iScrInit.exeISRSetup.tmp
User:
admin
Company:
iTop Inc.
Integrity Level:
HIGH
Description:
iTop Screen Recorderr Ini
Exit code:
0
Version:
5.4.0.467
Modules
Images
c:\users\admin\appdata\local\temp\is-3iesn.tmp\iscrinit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
864"C:\Program Files (x86)\iTop VPN\iTopVPN.exe" /installinitC:\Program Files (x86)\iTop VPN\iTopVPN.exeiTopVPN_setup_Free.tmp
User:
admin
Company:
iTop Inc.
Integrity Level:
HIGH
Description:
iTop VPN
Exit code:
0
Version:
6.4.0.6113
Modules
Images
c:\program files (x86)\itop vpn\itopvpn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
872"C:\Program Files\iTop Screen Recorder\ICONPIN64.exe" pin "C:\Program Files\iTop Screen Recorder\iScrRec.exe"C:\Program Files\iTop Screen Recorder\ICONPIN64.exeiScrInit.exe
User:
admin
Company:
iTop Inc.
Integrity Level:
HIGH
Description:
Icon Pin
Exit code:
1
Version:
1.0.0.10
Modules
Images
c:\program files\itop screen recorder\iconpin64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
968"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5928 -childID 9 -isForBrowser -prefsHandle 5936 -prefMapHandle 4900 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1400 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {764617d5-56ad-4092-ba55-06b4ef6e9688} 5512 "\\.\pipe\gecko-crash-server-pipe.5512" 200c8c2cd90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcp140.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
1120"C:\Program Files (x86)\iTop VPN\iTopVPNMini.exe" /antrun /install /state 0C:\Program Files (x86)\iTop VPN\iTopVPNMini.exe
iTopVPN.exe
User:
admin
Company:
iTop Inc.
Integrity Level:
HIGH
Description:
iTop VPN Mini
Version:
6.0.0.6114
Modules
Images
c:\program files (x86)\itop vpn\itopvpnmini.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1180"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4308 -childID 6 -isForBrowser -prefsHandle 4316 -prefMapHandle 4312 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1444 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c81ad442-e446-40a4-bf09-1efb0db94132} 1240 "\\.\pipe\gecko-crash-server-pipe.1240" 1c85bebca10 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1240"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1240\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1472cmd.exe /c netsh interface ipv4 set interface "Connection" mtu=1500C:\Windows\SysWOW64\cmd.exeiTopVPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
99 494
Read events
99 341
Write events
139
Delete events
14

Modification events

(PID) Process:(456) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(456) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(2140) ugin.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\iTop VPN
Operation:writeName:insur
Value:
other
(PID) Process:(2140) ugin.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iTopVPN
Operation:writeName:URL Protocol
Value:
"C:\Program Files (x86)\iTop VPN\iTopVPN.exe"
(PID) Process:(2140) ugin.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iTopVPN\shell\open
Operation:writeName:FriendlyAppName
Value:
iTop VPN
(PID) Process:(6652) iTopVPN_setup_Free.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\iTop VPN
Operation:writeName:AppPath
Value:
C:\Program Files (x86)\iTop VPN\
(PID) Process:(6652) iTopVPN_setup_Free.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iTop VPN_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.6 (u)
(PID) Process:(6652) iTopVPN_setup_Free.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iTop VPN_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\iTop VPN
(PID) Process:(6652) iTopVPN_setup_Free.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iTop VPN_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\iTop VPN\
(PID) Process:(6652) iTopVPN_setup_Free.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\iTop VPN_is1
Operation:writeName:Inno Setup: Icon Group
Value:
iTop VPN
Executable files
577
Suspicious files
301
Text files
458
Unknown types
105

Dropped files

PID
Process
Filename
Type
456firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\protections.sqlite-journalbinary
MD5:376E902D1A5D39EECAB7B21F1FA7CB58
SHA256:1B7DB0463DC3DF15537BBDC329383FCEA9D0BC6604A0B2668B7A32EA83F32378
456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.db-journalbinary
MD5:C58104FAB82FD870B683F5A9299DB267
SHA256:273299D91F4EA585E8B5BC06929113301F71F960C5EC2F35B37F44DC199965F0
456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.binbinary
MD5:C7CD10C17735E1C517D4C2B47D38A231
SHA256:A34C4D45D8F2ECDA6E32506B5563324B7B5DAE291897DC26ADE4C27F6DA7053A
456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
456firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.binbinary
MD5:C95DDC2B1A525D1A243E4C294DA2F326
SHA256:3A5919E086BFB31E36110CF636D2D5109EB51F2C410B107F126126AB25D67363
456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
456firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
59
TCP/UDP connections
898
DNS requests
166
Threats
16

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
456
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
456
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
456
firefox.exe
POST
200
184.24.77.79:80
http://r11.o.lencr.org/
unknown
whitelisted
456
firefox.exe
POST
200
184.24.77.79:80
http://r11.o.lencr.org/
unknown
whitelisted
456
firefox.exe
POST
200
172.217.16.131:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
456
firefox.exe
POST
200
172.217.16.131:80
http://o.pki.goog/we2
unknown
whitelisted
456
firefox.exe
POST
200
18.245.65.219:80
http://ocsp.r2m03.amazontrust.com/
unknown
whitelisted
456
firefox.exe
POST
200
18.245.65.219:80
http://ocsp.r2m03.amazontrust.com/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5796
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7000
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
456
firefox.exe
44.221.113.86:443
www.itopvpn.com
AMAZON-AES
US
malicious
456
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.23.110
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
www.itopvpn.com
  • 44.221.113.86
  • 52.45.225.163
malicious
contile.services.mozilla.com
  • 34.36.137.203
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
spocs.getpocket.com
  • 34.36.137.203
whitelisted
mc.prod.ads.prod.webservices.mozgcp.net
  • 34.36.137.203
whitelisted
example.org
  • 23.215.0.133
  • 96.7.128.186
  • 96.7.128.192
  • 23.215.0.132
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
2196
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
4944
ugin.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
4944
ugin.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
2196
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
7800
Setup.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
7800
Setup.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
2852
unpr.exe
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
No debug info