File name:

BANDIVIEW-SETUP-X64 (1).EXE

Full analysis: https://app.any.run/tasks/7499231b-b2a1-4882-b20b-ff6fe1b6b53b
Verdict: Malicious activity
Analysis date: August 07, 2024, 18:29:12
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

DAA2862FCD646457A93133DB31190541

SHA1:

59DA711AB7735174EBB1F28311B2618E29EA8A40

SHA256:

31000F870D5F0613A8E3DB5A979122C3E9EBF9B7AEFC6ADAEBE216145A620DCD

SSDEEP:

98304:70lPkuZN4QLarfHfZn3TA13KVa1AZZEkjp+oiNZQ4ag0K14bK9dcD0s4k92q+oSY:Nc7XPpVFbzFGrDayUWKa8E

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • BandiView.exe (PID: 6432)
      • BandiView.exe (PID: 3360)
    • Drops the executable file immediately after the start

      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
      • BandiView.exe (PID: 4920)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
      • BandiView.exe (PID: 2224)
      • BandiView.exe (PID: 6432)
      • BandiView.exe (PID: 3360)
      • BandiView.exe (PID: 4920)
    • Process drops legitimate windows executable

      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
    • Reads the date of Windows installation

      • RegDll.x64.exe (PID: 6432)
      • BandiView.exe (PID: 6432)
    • Creates a software uninstall entry

      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
    • Creates/Modifies COM task schedule object

      • BandiView.exe (PID: 2224)
      • BandiView.exe (PID: 6432)
    • Application launched itself

      • BandiView.exe (PID: 6432)
    • Checks Windows Trust Settings

      • BandiView.exe (PID: 3360)
      • BandiView.exe (PID: 6432)
      • BandiView.exe (PID: 4920)
      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
    • Executable content was dropped or overwritten

      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
      • BandiView.exe (PID: 4920)
    • Reads Microsoft Outlook installation path

      • BandiView.exe (PID: 6432)
      • BandiView.exe (PID: 3360)
    • Reads Internet Explorer settings

      • BandiView.exe (PID: 3360)
      • BandiView.exe (PID: 6432)
    • Changes Internet Explorer settings (feature browser emulation)

      • RegDll.x64.exe (PID: 1184)
  • INFO

    • Checks supported languages

      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
      • RegDll.x64.exe (PID: 1184)
      • RegDll.x64.exe (PID: 6432)
      • RegDll.x64.exe (PID: 6428)
      • RegPackage.x86.exe (PID: 1128)
      • BandiView.exe (PID: 2224)
      • BandiView.exe (PID: 6432)
      • BandiView.exe (PID: 3360)
      • identity_helper.exe (PID: 4060)
      • TextInputHost.exe (PID: 3552)
      • BandiView.exe (PID: 4920)
    • Creates files or folders in the user directory

      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
      • RegDll.x64.exe (PID: 6432)
      • BandiView.exe (PID: 3360)
      • BandiView.exe (PID: 6432)
      • BandiView.exe (PID: 4920)
    • Checks proxy server information

      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
      • BandiView.exe (PID: 3360)
      • BandiView.exe (PID: 6432)
      • BandiView.exe (PID: 4920)
    • Reads the machine GUID from the registry

      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
      • BandiView.exe (PID: 3360)
      • BandiView.exe (PID: 6432)
      • BandiView.exe (PID: 4920)
    • Creates files in the program directory

      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
    • Reads the computer name

      • RegDll.x64.exe (PID: 6432)
      • RegPackage.x86.exe (PID: 1128)
      • BandiView.exe (PID: 2224)
      • BandiView.exe (PID: 6432)
      • BandiView.exe (PID: 3360)
      • identity_helper.exe (PID: 4060)
      • TextInputHost.exe (PID: 3552)
      • BandiView.exe (PID: 4920)
      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
    • Process checks computer location settings

      • RegDll.x64.exe (PID: 6432)
      • BandiView.exe (PID: 2224)
      • BandiView.exe (PID: 6432)
    • Manual execution by a user

      • BandiView.exe (PID: 6432)
      • msedge.exe (PID: 6704)
      • RegDll.x64.exe (PID: 6432)
    • Reads the software policy settings

      • BandiView.exe (PID: 3360)
      • BANDIVIEW-SETUP-X64 (1).EXE.exe (PID: 6512)
      • BandiView.exe (PID: 6432)
      • BandiView.exe (PID: 4920)
    • Process checks Internet Explorer phishing filters

      • BandiView.exe (PID: 3360)
      • BandiView.exe (PID: 6432)
    • Application launched itself

      • msedge.exe (PID: 6704)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 6704)
    • Reads Environment values

      • identity_helper.exe (PID: 4060)
    • The process uses the downloaded file

      • msedge.exe (PID: 6704)
      • msedge.exe (PID: 6276)
    • Create files in a temporary directory

      • BandiView.exe (PID: 4920)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:19 07:27:40+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 436224
InitializedDataSize: 115200
UninitializedDataSize: -
EntryPoint: 0x4c3b0
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 7.5.0.0
ProductVersionNumber: 7.5.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: Bandisoft
FileDescription: BandiView 7.05 0 Setup
FileVersion: 7.05
LegalCopyright: Copyright(C) 2023-2024, Bandisoft International Inc. All rights reserved.
ProductVersion: 7.05
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
213
Monitored processes
68
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bandiview-setup-x64 (1).exe.exe regdll.x64.exe no specs regdll.x64.exe no specs regdll.x64.exe no specs regpackage.x86.exe no specs bandiview.exe no specs bandiview.exe bandiview.exe msedge.exe msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs textinputhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs bandiview.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs bandiview-setup-x64 (1).exe.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=5904 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
240"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6812 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
320"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=22 --mojo-platform-channel-handle=6108 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1128"C:\Program Files\BandiView\shell/RegPackage.x86.exe" /unreg BandiViewShellextC:\Program Files\BandiView\shell\RegPackage.x86.exeBANDIVIEW-SETUP-X64 (1).EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bandiview\shell\regpackage.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1184"C:\Program Files\BandiView\data/RegDll.x64.exe" /regieemulation BandiView.exeC:\Program Files\BandiView\data\RegDll.x64.exeBANDIVIEW-SETUP-X64 (1).EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bandiview\data\regdll.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1248"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=6484 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1664"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4328 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2152"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7472 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2224"C:\Program Files\BandiView\BandiView.exe" /regdlgC:\Program Files\BandiView\BandiView.exeBANDIVIEW-SETUP-X64 (1).EXE.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
HIGH
Description:
BandiView Image viewer
Exit code:
0
Version:
7.5.0.1
Modules
Images
c:\program files\bandiview\bandiview.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2248"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x31c,0x320,0x324,0x318,0x32c,0x7fffd18a5fd8,0x7fffd18a5fe4,0x7fffd18a5ff0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
71 414
Read events
70 308
Write events
1 102
Delete events
4

Modification events

(PID) Process:(6512) BANDIVIEW-SETUP-X64 (1).EXE.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6512) BANDIVIEW-SETUP-X64 (1).EXE.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6512) BANDIVIEW-SETUP-X64 (1).EXE.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6512) BANDIVIEW-SETUP-X64 (1).EXE.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1184) RegDll.x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:BandiView.exe
Value:
11000
(PID) Process:(1184) RegDll.x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:BandiView.exe
Value:
11000
(PID) Process:(6428) RegDll.x64.exeKey:HKEY_CLASSES_ROOT\*\shell\bvshell
Operation:writeName:ExplorerCommandHandler
Value:
{0002DEAD-9BF7-4CFA-8A5C-DE8679340001}
(PID) Process:(6428) RegDll.x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shell\bvshell
Operation:writeName:ExplorerCommandHandler
Value:
{0002DEAD-9BF7-4CFA-8A5C-DE8679340001}
(PID) Process:(6428) RegDll.x64.exeKey:HKEY_CLASSES_ROOT\*\shell\bvshell
Operation:writeName:NeverDefault
Value:
(PID) Process:(6428) RegDll.x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shell\bvshell
Operation:writeName:NeverDefault
Value:
Executable files
28
Suspicious files
654
Text files
192
Unknown types
20

Dropped files

PID
Process
Filename
Type
6512BANDIVIEW-SETUP-X64 (1).EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Eder
MD5:E5C19C384CB144EDA9FB463F817A5BC4
SHA256:45C2225A67A00E236DBFDA361A14D510A2362996E04A5B0E07CEF1D9CABDE10B
6512BANDIVIEW-SETUP-X64 (1).EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:794B875588E0EB5340779AE9C1D92C87
SHA256:9246C555C7E4DFF77F93C76472AD3008A05EE1B3DE32C3722C53287B26F91BB1
6512BANDIVIEW-SETUP-X64 (1).EXE.exeC:\Program Files\BandiView\shell\RegPackage.x86.exeexecutable
MD5:25387FCE6D45E3190DD54400B3A67BC3
SHA256:F48B5E9FAFCFE95DE1959AF56EB630F9D0527E440F08A9F8C39C2CE46DC837D7
6512BANDIVIEW-SETUP-X64 (1).EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:9E7805A6B39BB529A72ECA0662F05161
SHA256:620873F52A01DC157F7106ACE422AC106ED5B7DA96973A21C2FC4FCC816C67B2
6512BANDIVIEW-SETUP-X64 (1).EXE.exeC:\Program Files\BandiView\data\icudtl.datbinary
MD5:091A67C630F92F8316940180B787FBD2
SHA256:63BB12EBACD1B93B01BE1A18F04EC0992AE7FB70CC3083825287261366A905CC
6512BANDIVIEW-SETUP-X64 (1).EXE.exeC:\Program Files\BandiView\data\resource.datatext
MD5:359F86BCA1F42E192109D1EAED70DEFB
SHA256:358966E59965A8549040D916DAEF2B77E193B70EF771EA47830F53D6B921F63E
6512BANDIVIEW-SETUP-X64 (1).EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\55878D72B07DE680E267B610401D1AA2binary
MD5:7DF5D21C4BEBE7EEC318BABA51B7E8FA
SHA256:56336E646D90653F1892C931DBDCEDDE86A06A8F1BC7346305FA28AD03BFC208
6512BANDIVIEW-SETUP-X64 (1).EXE.exeC:\Program Files\BandiView\data\lm.x64.dllexecutable
MD5:C00768CFD4644F20E36091EB0D2BB71A
SHA256:73665EDE325E900E7ACF9C2DFEBFFA481A32505DC0DC915EF0A3EA9771680A87
6512BANDIVIEW-SETUP-X64 (1).EXE.exeC:\Program Files\BandiView\data\RegDll.x64.exeexecutable
MD5:B75CAEBA48754EA05DD3265E80917744
SHA256:F81F269E9B259B827AC9046C396DAFBF8B13DE454762FDB32A2147CDA2174DF3
6512BANDIVIEW-SETUP-X64 (1).EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\55878D72B07DE680E267B610401D1AA2der
MD5:FEB8821B0BAFAE326E5EEF5EA44910FB
SHA256:9C5C996EA58C6FE6022521DF9C3B8BD83D01BCF520E29CB1753D602A95AAB918
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
43
TCP/UDP connections
174
DNS requests
181
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6512
BANDIVIEW-SETUP-X64 (1).EXE.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
whitelisted
6512
BANDIVIEW-SETUP-X64 (1).EXE.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
whitelisted
6512
BANDIVIEW-SETUP-X64 (1).EXE.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEBuRJhVl1EslGbwM0iynBP4%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5244
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3360
BandiView.exe
GET
200
216.58.206.35:80
http://c.pki.goog/r/r1.crl
unknown
whitelisted
3360
BandiView.exe
GET
200
172.217.18.3:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
whitelisted
3360
BandiView.exe
GET
200
172.217.18.99:80
http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEHvQOfnMl3BnEBjGqYCOwmQ%3D
unknown
whitelisted
6432
BandiView.exe
GET
200
172.217.18.99:80
http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEFISB6AKY0OzCbS%2BEJ1LbPY%3D
unknown
whitelisted
6748
msedge.exe
GET
304
2.23.197.184:80
http://x1.i.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5900
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3360
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
6512
BANDIVIEW-SETUP-X64 (1).EXE.exe
52.78.169.250:443
ver.bandi.so
AMAZON-02
KR
unknown
6512
BANDIVIEW-SETUP-X64 (1).EXE.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
6512
BANDIVIEW-SETUP-X64 (1).EXE.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
4
System
192.168.100.255:137
whitelisted
5900
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 52.183.220.149
whitelisted
google.com
  • 142.250.186.46
whitelisted
ver.bandi.so
  • 52.78.169.250
unknown
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.sectigo.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
www.bing.com
  • 95.100.146.19
  • 95.100.146.35
  • 95.100.146.17
  • 95.100.146.34
  • 95.100.146.27
  • 95.100.146.25
  • 95.100.146.40
  • 95.100.146.10
  • 95.100.146.16
  • 2.23.209.133
  • 2.23.209.183
  • 2.23.209.176
  • 2.23.209.132
  • 2.23.209.135
  • 2.23.209.185
  • 2.23.209.182
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.193
  • 2.23.209.154
  • 2.23.209.140
  • 2.23.209.156
  • 2.23.209.143
  • 2.23.209.149
  • 13.107.21.200
  • 204.79.197.200
  • 95.100.146.18
  • 95.100.146.11
  • 95.100.146.32
  • 95.100.146.33
  • 95.100.146.26
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.68
  • 40.126.32.134
  • 40.126.32.74
  • 40.126.32.138
  • 20.190.160.22
  • 40.126.32.72
  • 20.190.160.14
  • 40.126.32.136
  • 40.126.32.133
  • 20.190.160.20
  • 40.126.32.76
whitelisted
client.wns.windows.com
  • 40.113.110.67
  • 40.113.103.199
whitelisted

Threats

PID
Process
Class
Message
6748
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
6748
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
6748
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
6748
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
Process
Message
msedge.exe
[0807/183240.155:WARNING:device_ticket.cc(151)] Timed out waiting for device ticket. Canceling async operation.
msedge.exe
[0807/183241.033:ERROR:filesystem_win.cc(128)] GetFileAttributes C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\attachments\86ec9f83-34d4-4264-aaea-0ecbe2f5e35e: The system cannot find the file specified. (0x2)
msedge.exe
[0807/183241.040:ERROR:filesystem_win.cc(128)] GetFileAttributes C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\attachments\86ec9f83-34d4-4264-aaea-0ecbe2f5e35e: The system cannot find the file specified. (0x2)
msedge.exe
[0807/183241.055:ERROR:filesystem_win.cc(128)] GetFileAttributes C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\attachments\86ec9f83-34d4-4264-aaea-0ecbe2f5e35e: The system cannot find the file specified. (0x2)
msedge.exe
[0807/183241.056:ERROR:filesystem_win.cc(128)] GetFileAttributes C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\attachments\86ec9f83-34d4-4264-aaea-0ecbe2f5e35e: The system cannot find the file specified. (0x2)