File name:

ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe

Full analysis: https://app.any.run/tasks/c29c1bfb-0ea5-49b2-9591-46d47c63a71f
Verdict: Malicious activity
Analysis date: June 24, 2024, 15:57:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

B08DE8E90771D5E0149D9B522D566A66

SHA1:

B1EC8EE94DFEBD0470BF76DC1053C9426351224F

SHA256:

20E55E6959B429397836F763D32E760462B728EBA1B7B4723D0323C3B57764AD

SSDEEP:

98304:Io9h10ZX6NYzvk8jFd+Dj0y7TOhb9LiivkTQHvDvdNo93p1lGdtGjBPW9jv99kxw:MDwMtAA3lxeQf8WF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
      • ScnRecPortable.exe (PID: 3212)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
    • Reads the Internet Settings

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
    • Executable content was dropped or overwritten

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
      • ScnRecPortable.exe (PID: 3212)
    • Reads security settings of Internet Explorer

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
    • The process creates files with name similar to system file names

      • ScnRecPortable.exe (PID: 3212)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • ScnRecPortable.exe (PID: 3212)
    • Uses TASKKILL.EXE to kill process

      • ScnRecPortable.exe (PID: 3212)
    • Starts application with an unusual extension

      • ScnRecPortable.exe (PID: 3212)
  • INFO

    • Checks supported languages

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
      • ScnRecPortable.exe (PID: 3212)
      • ScnRec.exe (PID: 680)
      • ScnRec.exe (PID: 2080)
      • nsEF8F.tmp (PID: 3128)
    • Create files in a temporary directory

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
      • ScnRecPortable.exe (PID: 3212)
    • Reads the computer name

      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
      • ScnRecPortable.exe (PID: 3212)
      • ScnRec.exe (PID: 680)
      • ScnRec.exe (PID: 2080)
    • Reads product name

      • ScnRec.exe (PID: 680)
      • ScnRec.exe (PID: 2080)
    • Reads CPU info

      • ScnRec.exe (PID: 680)
      • ScnRec.exe (PID: 2080)
    • Process checks whether UAC notifications are on

      • ScnRec.exe (PID: 680)
      • ScnRec.exe (PID: 2080)
    • Reads Environment values

      • ScnRec.exe (PID: 680)
      • ScnRec.exe (PID: 2080)
    • UPX packer has been detected

      • ScnRec.exe (PID: 2080)
      • ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe (PID: 2248)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:12:31 00:38:51+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 65536
InitializedDataSize: 16384
UninitializedDataSize: 98304
EntryPoint: 0x28920
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 11.3.0.0
ProductVersionNumber: 11.3.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
Comments: 录制电脑屏幕画面和声音存为视频文件。
CompanyName: 紫迪软件
FileDescription: ZD屏幕录像机
FileVersion: 11.3.0.0
InternalName: ScnRec
LegalCopyright: 版权所有 (C) 2005-2020, 紫迪软件, 保留所有权利
LegalTrademarks: ZD屏幕录像机
OriginalFileName: ScnRec.exe
PrivateBuild: -
ProductName: ZD屏幕录像机
ProductVersion: 11.3
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT zd_soft_screen_recorder_v11.3.0_cn_portable.exe scnrecportable.exe scnrec.exe no specs taskkill.exe no specs nsef8f.tmp no specs reg.exe no specs THREAT scnrec.exe no specs zd_soft_screen_recorder_v11.3.0_cn_portable.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\ScnRec.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\ScnRec.exeScnRecPortable.exe
User:
admin
Company:
紫迪软件
Integrity Level:
HIGH
Description:
ZD屏幕录像机
Exit code:
1
Version:
11.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx.000\app\scnrec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42u.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2080C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\ScnRec.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\ScnRec.exe
ScnRecPortable.exe
User:
admin
Company:
紫迪软件
Integrity Level:
HIGH
Description:
ZD屏幕录像机
Version:
11.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx.000\app\scnrec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42u.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2248"C:\Users\admin\AppData\Local\Temp\ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe" C:\Users\admin\AppData\Local\Temp\ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe
explorer.exe
User:
admin
Company:
紫迪软件
Integrity Level:
HIGH
Description:
ZD屏幕录像机
Version:
11.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\zd_soft_screen_recorder_v11.3.0_cn_portable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2300taskkill /f /im "ScnRec.exe"C:\Windows\System32\taskkill.exeScnRecPortable.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
3128"C:\Users\admin\AppData\Local\Temp\nsmEE94.tmp\nsEF8F.tmp" reg query "HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder" /reg:32C:\Users\admin\AppData\Local\Temp\nsmEE94.tmp\nsEF8F.tmpScnRecPortable.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsmee94.tmp\nsef8f.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3160reg query "HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder" /reg:32C:\Windows\System32\reg.exensEF8F.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3212"C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\ScnRecPortable.exe" C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\ScnRecPortable.exe
ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe
User:
admin
Company:
CedarStudio
Integrity Level:
HIGH
Description:
Screen Recorder Portable
Version:
11.1.1.0
Modules
Images
c:\users\admin\appdata\local\temp\7zipsfx.000\scnrecportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3256"C:\Users\admin\AppData\Local\Temp\ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exe" C:\Users\admin\AppData\Local\Temp\ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeexplorer.exe
User:
admin
Company:
紫迪软件
Integrity Level:
MEDIUM
Description:
ZD屏幕录像机
Exit code:
3221226540
Version:
11.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\zd_soft_screen_recorder_v11.3.0_cn_portable.exe
c:\windows\system32\ntdll.dll
Total events
6 479
Read events
6 450
Write events
29
Delete events
0

Modification events

(PID) Process:(2248) ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2248) ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2248) ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2248) ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(680) ScnRec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
ScnRec.exe
(PID) Process:(680) ScnRec.exeKey:HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder\1C1E9FDF130E84323B2F9BF052B10F67
Operation:writeName:Setup
Value:
(PID) Process:(680) ScnRec.exeKey:HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder\1C1E9FDF130E84323B2F9BF052B10F67
Operation:writeName:Name
Value:
(PID) Process:(680) ScnRec.exeKey:HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder\1C1E9FDF130E84323B2F9BF052B10F67
Operation:writeName:Email
Value:
(PID) Process:(680) ScnRec.exeKey:HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder\1C1E9FDF130E84323B2F9BF052B10F67
Operation:writeName:Key
Value:
(PID) Process:(3212) ScnRecPortable.exeKey:HKEY_CURRENT_USER\Software\ZD Soft\Screen Recorder\1C1E9FDF130E84323B2F9BF052B10F67
Operation:writeName:Email
Value:
nemo@snd.org
Executable files
38
Suspicious files
2
Text files
58
Unknown types
0

Dropped files

PID
Process
Filename
Type
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\fonts\TRANA___.TTFbinary
MD5:3892A7332F80541AC7478D558A1D4112
SHA256:E0B07363AD8A0D477660CB7004C01996A3BEA033CD8FA4B7013A4B0290B3AE65
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\4.svgimage
MD5:86C20C5505247EEE01AB4B22108B5AD9
SHA256:4D793B75BE67508233D62B1ACFBC6B15144C3D0EAD2098373105687114A11DDE
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\6.svgimage
MD5:37FA3CF86190387121D3AEAF2868CDE1
SHA256:74EA4779A8FF9CEA672A8DCEF5ADDDBFE864EE77B0EB41102FE4E92E7F8A4CD0
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\3.svgimage
MD5:EFCDC88C366A63A25D94FCCED8F3192D
SHA256:2E32E6DCC2E3CAB24C5FE235F30659AC1FACB438757611C355F7EBC6F4D2E1A5
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\9.svgimage
MD5:696907ABE59C0B37146A7F49E6D89F92
SHA256:541732E3A2DCF52CD9C28E1D84865481AFA38559F4D3A7C901B8293850957157
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\arrow.svgimage
MD5:9090A0527A38C20E516EC75E0F2C1526
SHA256:5669AEA24AA008287E501C7F74BF41151AF98B98D92B2FAE829BDBB490024387
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\7.svgimage
MD5:91D0E99E731AC850D6661C5E45DA9076
SHA256:82BAE4541FEA0911C820D82991905D7A678CCC1B39E275F587F50915457D902E
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\8.svgimage
MD5:C9B8C0DD7056C05F2F29DE5369D305A4
SHA256:A69299868B7D753466AB6C5E2208B2BE147E616BEE0318DC191FEE6010141F69
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\about.svgimage
MD5:94576916AFA688C679F8A97F1ABB0CC6
SHA256:BE79E80C30F63BC34A30D7BF2AE447D1270AB596D7C7F09B1E9A4C002DB02EC9
2248ZD_Soft_Screen_Recorder_v11.3.0_CN_Portable.exeC:\Users\admin\AppData\Local\Temp\7ZipSfx.000\App\images\cancel.svgimage
MD5:7AA174323BB384E703F9816851ED2BDB
SHA256:20828FEC197129FD308CA491E799992E8D8EB6EE4B735CC1C9FEA4C10BE52213
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
10
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
1372
svchost.exe
GET
304
23.50.131.213:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
1372
svchost.exe
GET
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
239.255.255.250:3702
unknown
1372
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1060
svchost.exe
224.0.0.252:5355
unknown
1372
svchost.exe
23.50.131.213:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown
1372
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 23.50.131.213
  • 23.50.131.216
  • 23.50.131.200
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted

Threats

No threats detected
No debug info