URL:

bandicam.com

Full analysis: https://app.any.run/tasks/d0d1bab1-7f0a-49fe-93ed-e55f173c235c
Verdict: Malicious activity
Analysis date: November 06, 2025, 18:23:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
websocket
qrcode
Indicators:
MD5:

DB17BECD40EC9C48AC58FF70360F77EF

SHA1:

9468C2C26B2CE5F787920E69889D8ADECC8C2F54

SHA256:

04072C83B0EE21D63A48BF79B9B2DBE752E25CCF034EE9CE2D18EA26AB84722F

SSDEEP:

3:+EcI:75

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • BDMPEG1SETUP.EXE (PID: 332)
    • Registers / Runs the DLL via REGSVR32.EXE

      • BDMPEG1SETUP.EXE (PID: 332)
    • Changes settings of System certificates

      • bdcam.exe (PID: 3648)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • bdcamsetup.exe (PID: 1872)
      • BDMPEG1SETUP.EXE (PID: 332)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
    • Executable content was dropped or overwritten

      • bdcamsetup.exe (PID: 1872)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
      • BDMPEG1SETUP.EXE (PID: 332)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • bdcamsetup.exe (PID: 1872)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
      • BDMPEG1SETUP.EXE (PID: 332)
    • Reads the Internet Settings

      • bdcamsetup.exe (PID: 1872)
      • bdcam.exe (PID: 2460)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
      • bdcam.exe (PID: 3648)
    • Creates/Modifies COM task schedule object

      • BDMPEG1SETUP.EXE (PID: 332)
    • There is functionality for taking screenshot (YARA)

      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
    • Uses RUNDLL32.EXE to load library

      • bdcam.exe (PID: 2460)
    • Changes Internet Explorer settings (feature browser emulation)

      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
    • Reads settings of System Certificates

      • bdcam.exe (PID: 3648)
    • Reads security settings of Internet Explorer

      • bdcam.exe (PID: 2460)
      • bdcam.exe (PID: 3648)
    • Reads Microsoft Outlook installation path

      • bdcam.exe (PID: 3648)
    • Reads Internet Explorer settings

      • bdcam.exe (PID: 3648)
    • Adds/modifies Windows certificates

      • bdcam.exe (PID: 3648)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 2908)
      • msedge.exe (PID: 3044)
      • msedge.exe (PID: 3264)
      • msedge.exe (PID: 3036)
      • msedge.exe (PID: 3616)
    • The sample compiled with arabic language support

      • msedge.exe (PID: 2908)
      • msedge.exe (PID: 2788)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
    • Reads the computer name

      • bdcamsetup.exe (PID: 1872)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
      • BDMPEG1SETUP.EXE (PID: 332)
      • bdcam.exe (PID: 2460)
      • bdcam.exe (PID: 3648)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 2908)
    • Create files in a temporary directory

      • bdcamsetup.exe (PID: 1872)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
      • BDMPEG1SETUP.EXE (PID: 332)
    • Checks supported languages

      • bdcamsetup.exe (PID: 1872)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
      • BDMPEG1SETUP.EXE (PID: 332)
      • bdcam.exe (PID: 2460)
      • bdcam.exe (PID: 3648)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 2908)
      • msedge.exe (PID: 2788)
    • Reads Environment values

      • bdcamsetup.exe (PID: 1872)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
      • BDMPEG1SETUP.EXE (PID: 332)
    • Creates files in the program directory

      • BDMPEG1SETUP.EXE (PID: 332)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
    • Creates a software uninstall entry

      • BDMPEG1SETUP.EXE (PID: 332)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
    • The sample compiled with english language support

      • BDMPEG1SETUP.EXE (PID: 332)
      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
    • The sample compiled with korean language support

      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
      • BDMPEG1SETUP.EXE (PID: 332)
    • Checks proxy server information

      • BDCAMSETUP_ENG_5_1_1_1837.EXE (PID: 1888)
      • bdcam.exe (PID: 3648)
    • Creates files or folders in the user directory

      • bdcam.exe (PID: 3648)
    • Reads the software policy settings

      • bdcam.exe (PID: 3648)
    • Manual execution by a user

      • msedge.exe (PID: 3036)
      • wscript.exe (PID: 3228)
      • notepad++.exe (PID: 2812)
      • wscript.exe (PID: 2980)
      • wscript.exe (PID: 2376)
      • wscript.exe (PID: 2808)
      • wscript.exe (PID: 3064)
      • wscript.exe (PID: 688)
      • wscript.exe (PID: 2500)
      • wscript.exe (PID: 2852)
      • wscript.exe (PID: 2800)
      • wscript.exe (PID: 2648)
      • wscript.exe (PID: 1228)
      • wscript.exe (PID: 2216)
      • wscript.exe (PID: 2884)
      • wscript.exe (PID: 1820)
      • wscript.exe (PID: 2212)
      • wscript.exe (PID: 2108)
      • wscript.exe (PID: 3396)
      • wscript.exe (PID: 3328)
      • wscript.exe (PID: 1884)
      • wscript.exe (PID: 3248)
      • wscript.exe (PID: 3768)
      • wscript.exe (PID: 3052)
      • wscript.exe (PID: 972)
      • wscript.exe (PID: 3868)
      • wscript.exe (PID: 3876)
      • wscript.exe (PID: 3800)
      • wscript.exe (PID: 3908)
      • wscript.exe (PID: 2944)
      • wscript.exe (PID: 112)
      • wscript.exe (PID: 1988)
      • wscript.exe (PID: 2952)
      • wscript.exe (PID: 716)
      • wscript.exe (PID: 3756)
      • wscript.exe (PID: 4068)
      • wscript.exe (PID: 2028)
      • msedge.exe (PID: 3616)
      • wscript.exe (PID: 2900)
      • wscript.exe (PID: 2424)
      • wscript.exe (PID: 3128)
      • wscript.exe (PID: 2468)
      • wscript.exe (PID: 3112)
      • wscript.exe (PID: 1236)
      • wscript.exe (PID: 4060)
      • wscript.exe (PID: 2524)
      • wscript.exe (PID: 3896)
      • wscript.exe (PID: 3272)
      • wscript.exe (PID: 3436)
      • wscript.exe (PID: 4060)
      • wscript.exe (PID: 1676)
      • wscript.exe (PID: 3204)
      • wscript.exe (PID: 2004)
      • wscript.exe (PID: 4072)
      • wscript.exe (PID: 2540)
      • wscript.exe (PID: 3804)
      • wscript.exe (PID: 120)
      • wscript.exe (PID: 3788)
      • wscript.exe (PID: 3868)
      • wscript.exe (PID: 636)
      • wscript.exe (PID: 3968)
      • wscript.exe (PID: 3764)
      • wscript.exe (PID: 2848)
      • wscript.exe (PID: 1404)
      • wscript.exe (PID: 3060)
      • wscript.exe (PID: 3092)
      • wscript.exe (PID: 3780)
      • wscript.exe (PID: 1872)
      • wscript.exe (PID: 1812)
      • wscript.exe (PID: 3944)
      • wscript.exe (PID: 1756)
      • wscript.exe (PID: 2984)
      • wscript.exe (PID: 2064)
      • wscript.exe (PID: 2976)
      • wscript.exe (PID: 2420)
      • wscript.exe (PID: 3768)
      • wscript.exe (PID: 4008)
      • wscript.exe (PID: 3344)
      • wscript.exe (PID: 2124)
      • wscript.exe (PID: 1096)
      • wscript.exe (PID: 116)
      • wscript.exe (PID: 3708)
      • wscript.exe (PID: 3460)
      • wscript.exe (PID: 3812)
      • wscript.exe (PID: 3348)
      • wscript.exe (PID: 3832)
      • wscript.exe (PID: 924)
      • wscript.exe (PID: 3096)
      • wscript.exe (PID: 3484)
      • wscript.exe (PID: 2872)
      • wscript.exe (PID: 2832)
      • wscript.exe (PID: 2028)
      • wscript.exe (PID: 1580)
      • wscript.exe (PID: 2624)
      • wscript.exe (PID: 2756)
      • wscript.exe (PID: 1836)
      • wscript.exe (PID: 2296)
      • wscript.exe (PID: 2100)
      • wscript.exe (PID: 2796)
      • wscript.exe (PID: 2936)
      • wscript.exe (PID: 3132)
      • wscript.exe (PID: 1884)
      • wscript.exe (PID: 2456)
      • wscript.exe (PID: 4108)
      • wscript.exe (PID: 3560)
      • wscript.exe (PID: 2592)
      • wscript.exe (PID: 2304)
      • wscript.exe (PID: 2648)
      • wscript.exe (PID: 4148)
      • wscript.exe (PID: 2544)
      • wscript.exe (PID: 4228)
      • wscript.exe (PID: 4188)
    • Reads the machine GUID from the registry

      • bdcam.exe (PID: 3648)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
250
Monitored processes
189
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs bdcamsetup.exe no specs bdcamsetup.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs bdcamsetup_eng_5_1_1_1837.exe no specs bdcamsetup_eng_5_1_1_1837.exe bdmpeg1setup.exe regsvr32.exe no specs bdcam.exe no specs rundll32.exe no specs bdcam.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs notepad++.exe wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
112"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\errormessage.vbs" C:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
116"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\errormessage.vbs" C:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
120"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\errormessage.vbs" C:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
272"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=4580 --field-trial-handle=1348,i,12913004234388480063,14342951433837952451,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
292"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=1548 --field-trial-handle=1328,i,5939723797999592296,6763316624126139866,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
308"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=27 --mojo-platform-channel-handle=4668 --field-trial-handle=1328,i,5939723797999592296,6763316624126139866,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
332"C:\Users\admin\AppData\Local\Temp\BDMPEG1SETUP.EXE" /SC:\Users\admin\AppData\Local\Temp\BDMPEG1SETUP.EXE
BDCAMSETUP_ENG_5_1_1_1837.EXE
User:
admin
Company:
Bandicam Company
Integrity Level:
HIGH
Description:
Bandicam MPEG-1 Decoder Setup File
Exit code:
0
Version:
V1.0.5.17
Modules
Images
c:\users\admin\appdata\local\temp\bdmpeg1setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
456"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --mojo-platform-channel-handle=4928 --field-trial-handle=1348,i,12913004234388480063,14342951433837952451,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
636"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\errormessage.vbs" C:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
688"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\errormessage.vbs" C:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
19 060
Read events
17 950
Write events
1 091
Delete events
19

Modification events

(PID) Process:(332) BDMPEG1SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89C4B786-A490-4A3E-AA70-E6A8C61D3689}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(332) BDMPEG1SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A1C6833E-A3EC-4397-9FA9-151792F3408F}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(332) BDMPEG1SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2E7539A-CECF-4A6A-B187-939943ECEF05}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(332) BDMPEG1SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F4F5C9E9-CFCC-4C65-A8BD-0423A338F188}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(332) BDMPEG1SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{89C4B786-A490-4A3E-AA70-E6A8C61D3689}
Operation:writeName:FriendlyName
Value:
Bandicam MPEG-1 Video Decoder
(PID) Process:(332) BDMPEG1SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{89C4B786-A490-4A3E-AA70-E6A8C61D3689}
Operation:writeName:CLSID
Value:
{89C4B786-A490-4A3E-AA70-E6A8C61D3689}
(PID) Process:(332) BDMPEG1SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{89C4B786-A490-4A3E-AA70-E6A8C61D3689}
Operation:writeName:FilterData
Value:
02000000010080FF02000000000000003070693300000000000000000200000000000000000000003074793300000000700000008000000031747933000000007000000090000000317069330800000000000000010000000000000000000000307479330000000070000000A00000007669647300001000800000AA00389B714D50454700001000800000AA00389B714D50473100001000800000AA00389B7100000000000000000000000000000000
(PID) Process:(332) BDMPEG1SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{E2E7539A-CECF-4A6A-B187-939943ECEF05}
Operation:writeName:FriendlyName
Value:
Bandicam MPEG-1 Audio Decoder
(PID) Process:(332) BDMPEG1SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{E2E7539A-CECF-4A6A-B187-939943ECEF05}
Operation:writeName:CLSID
Value:
{E2E7539A-CECF-4A6A-B187-939943ECEF05}
(PID) Process:(332) BDMPEG1SETUP.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{E2E7539A-CECF-4A6A-B187-939943ECEF05}
Operation:writeName:FilterData
Value:
02000000010080FF020000000000000030706933000000000000000001000000000000000000000030747933000000006000000070000000317069330800000000000000010000000000000000000000307479330000000060000000800000006175647300001000800000AA00389B715000000000001000800000AA00389B710100000000001000800000AA00389B71
Executable files
71
Suspicious files
685
Text files
233
Unknown types
5

Dropped files

PID
Process
Filename
Type
2908msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF605af.TMP
MD5:
SHA256:
2908msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
2908msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF605ee.TMP
MD5:
SHA256:
2908msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
2908msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF60736.TMP
MD5:
SHA256:
2908msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
3032msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\CrashpadMetrics.pmabinary
MD5:C612E96CBFAC63232FC2062E15600FB1
SHA256:DB3C05D5EC0B6719A73E7F0BE84BCE9342772DA70567E7CE08CF6573480B38FF
2908msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.datbinary
MD5:C71FF4D3A6085C165C6A9C908C072A09
SHA256:3CA7B7E98B5CA1C1DC458415463D00ACD9DF8302F481B103C93177FD2642B37B
2908msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Local State~RF604f4.TMPbinary
MD5:500EC2708CB8AB54D1E3C15CF2FFC985
SHA256:6186BA586D16D5ABE77B04AA31468D91B0ACE1917F5F24BFCE83261982BA509C
2908msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Variationsbinary
MD5:961E3604F228B0D10541EBF921500C86
SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
105
DNS requests
157
Threats
17

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3648
bdcam.exe
GET
200
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a3250a75ab233b07
US
compressed
4.87 Kb
whitelisted
2788
msedge.exe
GET
301
18.198.249.84:80
http://bandicam.com/
DE
whitelisted
3648
bdcam.exe
GET
200
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?30ff3d89ea37ce69
US
compressed
4.87 Kb
whitelisted
3648
bdcam.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
DE
binary
471 b
whitelisted
3648
bdcam.exe
GET
200
142.250.186.99:80
http://c.pki.goog/r/gsr1.crl
US
binary
1.70 Kb
whitelisted
3648
bdcam.exe
GET
200
142.250.186.99:80
http://o.pki.goog/we2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEQDpBcoaAeOzIhB6H13WnQsM
US
binary
280 b
whitelisted
3648
bdcam.exe
GET
200
142.250.186.99:80
http://c.pki.goog/r/r4.crl
US
binary
530 b
whitelisted
3848
msedge.exe
GET
301
88.99.137.18:80
http://filebin.net/errormessage
DE
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1076
svchost.exe
224.0.0.252:5355
whitelisted
2908
msedge.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
2788
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2788
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2788
msedge.exe
18.198.249.84:80
bandicam.com
AMAZON-02
DE
unknown
2788
msedge.exe
151.101.66.132:443
www.bandicam.com
FASTLY
US
whitelisted
2788
msedge.exe
142.250.181.232:443
www.googletagmanager.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
bandicam.com
  • 18.198.249.84
whitelisted
www.bandicam.com
  • 151.101.66.132
  • 151.101.130.132
  • 151.101.2.132
  • 151.101.194.132
whitelisted
static.bandicam.com
  • 151.101.130.132
  • 151.101.2.132
  • 151.101.194.132
  • 151.101.66.132
whitelisted
www.googletagmanager.com
  • 142.250.181.232
  • 172.217.23.104
whitelisted
www.bing.com
  • 2.16.204.152
  • 2.16.204.153
  • 2.16.204.141
  • 2.16.204.143
  • 2.16.204.151
  • 2.16.204.134
  • 2.16.241.218
  • 2.16.241.207
  • 2.16.241.205
  • 2.16.204.160
  • 2.16.204.156
  • 2.16.204.150
  • 2.16.204.139
  • 2.16.204.138
  • 2.16.204.145
  • 2.16.204.149
  • 2.16.204.155
whitelisted
consent.cookiebot.com
  • 2.16.183.86
  • 2.16.183.103
whitelisted
pagead2.googlesyndication.com
  • 142.250.181.226
whitelisted

Threats

PID
Process
Class
Message
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
2788
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
2788
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
3848
msedge.exe
Misc activity
ET FILE_SHARING Observed DNS Query to Abused File Sharing Domain in DNS Lookup (filebin .net)
3848
msedge.exe
Misc activity
ET FILE_SHARING Observed DNS Query to Abused File Sharing Domain in DNS Lookup (filebin .net)
3848
msedge.exe
Misc activity
ET FILE_SHARING Observed DNS Query to Abused File Sharing Domain in DNS Lookup (filebin .net)
Process
Message
msedge.exe
[1106/182415.502:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe