File name:

ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe

Full analysis: https://app.any.run/tasks/c29c1bfb-0ea5-49b2-9591-46d47c63a71f
Verdict: Malicious activity
Analysis date: June 24, 2024, 15:57:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

B08DE8E90771D5E0149D9B522D566A66

SHA1:

B1EC8EE94DFEBD0470BF76DC1053C9426351224F

SHA256:

20E55E6959B429397836F763D32E760462B728EBA1B7B4723D0323C3B57764AD

SSDEEP:

98304:Io9h10ZX6NYzvk8jFd+Dj0y7TOhb9LiivkTQHvDvdNo93p1lGdtGjBPW9jv99kxw:MDwMtAA3lxeQf8WF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
      • ScnRecPortable.exe (PID: 3212)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
    • Reads the Internet Settings

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
    • Executable content was dropped or overwritten

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
      • ScnRecPortable.exe (PID: 3212)
    • Reads security settings of Internet Explorer

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
    • The process creates files with name similar to system file names

      • ScnRecPortable.exe (PID: 3212)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • ScnRecPortable.exe (PID: 3212)
    • Uses TASKKILL.EXE to kill process

      • ScnRecPortable.exe (PID: 3212)
    • Starts application with an unusual extension

      • ScnRecPortable.exe (PID: 3212)
  • INFO

    • Checks supported languages

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
      • ScnRecPortable.exe (PID: 3212)
      • nsEF8F.tmp (PID: 3128)
      • ScnRec.exe (PID: 2080)
      • ScnRec.exe (PID: 680)
    • Create files in a temporary directory

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
      • ScnRecPortable.exe (PID: 3212)
    • Reads the computer name

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
      • ScnRecPortable.exe (PID: 3212)
      • ScnRec.exe (PID: 680)
      • ScnRec.exe (PID: 2080)
    • Reads CPU info

      • ScnRec.exe (PID: 680)
      • ScnRec.exe (PID: 2080)
    • Process checks whether UAC notifications are on

      • ScnRec.exe (PID: 680)
      • ScnRec.exe (PID: 2080)
    • Reads product name

      • ScnRec.exe (PID: 680)
      • ScnRec.exe (PID: 2080)
    • Reads Environment values

      • ScnRec.exe (PID: 680)
      • ScnRec.exe (PID: 2080)
    • UPX packer has been detected

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
      • ScnRec.exe (PID: 2080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:12:31 00:38:51+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 65536
InitializedDataSize: 16384
UninitializedDataSize: 98304
EntryPoint: 0x28920
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 11.3.0.0
ProductVersionNumber: 11.3.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
Comments: 录制电脑屏幕画面和声音存为视频文件。
CompanyName: 紫迪软件
FileDescription: ZD屏幕录像机
FileVersion: 11.3.0.0
InternalName: ScnRec
LegalCopyright: 版权所有 (C) 2005-2020, 紫迪软件, 保留所有权利
LegalTrademarks: ZD屏幕录像机
OriginalFileName: ScnRec.exe
PrivateBuild: -
ProductName: ZD屏幕录像机
ProductVersion: 11.3
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT zd_soft_screen_recorder_v11.3.0_cn_portable.exe scnrecportable.exe scnrec.exe no specs taskkill.exe no specs nsef8f.tmp no specs reg.exe no specs THREAT scnrec.exe no specs zd_soft_screen_recorder_v11.3.0_cn_portable.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\ScnRec.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\ScnRec.exeScnRecPortable.exe
User:
admin
Company:
紫迪软件
Integrity Level:
HIGH
Description:
ZD屏幕录像机
Exit code:
1
Version:
11.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx.000\app\scnrec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42u.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2080C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\ScnRec.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\ScnRec.exe
ScnRecPortable.exe
User:
admin
Company:
紫迪软件
Integrity Level:
HIGH
Description:
ZD屏幕录像机
Version:
11.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx.000\app\scnrec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42u.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2248"C:\Users\admin\AppData\Local\Temp\ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe" C:\Users\admin\AppData\Local\Temp\ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe
explorer.exe
User:
admin
Company:
紫迪软件
Integrity Level:
HIGH
Description:
ZD屏幕录像机
Version:
11.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\zd_soft_screen_recorder_v11.3.0_cn_portable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2300taskkill /f /im "ScnRec.exe"C:\Windows\System32\taskkill.exeScnRecPortable.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
3128"C:\Users\admin\AppData\Local\Temp\nsmEE94.tmp\nsEF8F.tmp" reg query "HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder" /reg:32C:\Users\admin\AppData\Local\Temp\nsmEE94.tmp\nsEF8F.tmpScnRecPortable.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsmee94.tmp\nsef8f.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3160reg query "HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder" /reg:32C:\Windows\System32\reg.exensEF8F.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3212"C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\ScnRecPortable.exe" C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\ScnRecPortable.exe
ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe
User:
admin
Company:
CedarStudio
Integrity Level:
HIGH
Description:
Screen Recorder Portable
Version:
11.1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx.000\scnrecportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3256"C:\Users\admin\AppData\Local\Temp\ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe" C:\Users\admin\AppData\Local\Temp\ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeexplorer.exe
User:
admin
Company:
紫迪软件
Integrity Level:
MEDIUM
Description:
ZD屏幕录像机
Exit code:
3221226540
Version:
11.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\zd_soft_screen_recorder_v11.3.0_cn_portable.exe
c:\windows\system32\ntdll.dll
Total events
6 479
Read events
6 450
Write events
29
Delete events
0

Modification events

(PID) Process:(2248) ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2248) ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2248) ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2248) ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(680) ScnRec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
ScnRec.exe
(PID) Process:(680) ScnRec.exeKey:HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder\1C1E9FDF130E84323B2F9BF052B10F67
Operation:writeName:Setup
Value:
(PID) Process:(680) ScnRec.exeKey:HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder\1C1E9FDF130E84323B2F9BF052B10F67
Operation:writeName:Name
Value:
(PID) Process:(680) ScnRec.exeKey:HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder\1C1E9FDF130E84323B2F9BF052B10F67
Operation:writeName:Email
Value:
(PID) Process:(680) ScnRec.exeKey:HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder\1C1E9FDF130E84323B2F9BF052B10F67
Operation:writeName:Key
Value:
(PID) Process:(3212) ScnRecPortable.exeKey:HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder\1C1E9FDF130E84323B2F9BF052B10F67
Operation:writeName:Email
Executable files
38
Suspicious files
2
Text files
58
Unknown types
0

Dropped files

PID
Process
Filename
Type
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\8.svgimage
MD5:C9B8C0DD7056C05F2F29DE5369D305A4
SHA256:A69299868B7D753466AB6C5E2208B2BE147E616BEE0318DC191FEE6010141F69
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\6.svgimage
MD5:37FA3CF86190387121D3AEAF2868CDE1
SHA256:74EA4779A8FF9CEA672A8DCEF5ADDDBFE864EE77B0EB41102FE4E92E7F8A4CD0
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\5.svgimage
MD5:BD8590EB91F41B9EFF4F196847D7C715
SHA256:5E0B552626DBA420AF5EAB1FD14810F9F719AB38917AA3190E5563ABC90211A6
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\close.svgimage
MD5:6AC4DB9D3FF80E8B942D726147D1D211
SHA256:892861CCC9F111AC68C8D2AA83CC2B2D9CAF8133306D32CBB0CFF2EFAF771A9F
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\9.svgimage
MD5:696907ABE59C0B37146A7F49E6D89F92
SHA256:541732E3A2DCF52CD9C28E1D84865481AFA38559F4D3A7C901B8293850957157
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\about.svgimage
MD5:94576916AFA688C679F8A97F1ABB0CC6
SHA256:BE79E80C30F63BC34A30D7BF2AE447D1270AB596D7C7F09B1E9A4C002DB02EC9
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\3.svgimage
MD5:EFCDC88C366A63A25D94FCCED8F3192D
SHA256:2E32E6DCC2E3CAB24C5FE235F30659AC1FACB438757611C355F7EBC6F4D2E1A5
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\2.svgimage
MD5:624608861572760AEC911F8EF5E390C9
SHA256:199C8F8E10DDE41517FD25D3651996BFD0EBEA73D1B757151B25A8AFC31060EB
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\1.svgimage
MD5:806605B7FF710F3E2B88503731F84B27
SHA256:4561528C03B38D4563703D233177C6123B4DBA7B4299819C805BAC214D9CACAC
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\arrow.svgimage
MD5:9090A0527A38C20E516EC75E0F2C1526
SHA256:5669AEA24AA008287E501C7F74BF41151AF98B98D92B2FAE829BDBB490024387
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
10
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
23.50.131.213:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
1372
svchost.exe
GET
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
1372
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
239.255.255.250:3702
unknown
1372
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1060
svchost.exe
224.0.0.252:5355
unknown
1372
svchost.exe
23.50.131.213:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown
1372
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 23.50.131.213
  • 23.50.131.216
  • 23.50.131.200
unknown
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
unknown
www.microsoft.com
  • 184.30.21.171
unknown
settings-win.data.microsoft.com
  • 51.104.136.2
unknown

Threats

No threats detected
No debug info