| File name: | BANDIVIEW-SETUP-X64 (1).EXE |
| Full analysis: | https://app.any.run/tasks/7499231b-b2a1-4882-b20b-ff6fe1b6b53b |
| Verdict: | Malicious activity |
| Analysis date: | August 07, 2024, 18:29:12 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | DAA2862FCD646457A93133DB31190541 |
| SHA1: | 59DA711AB7735174EBB1F28311B2618E29EA8A40 |
| SHA256: | 31000F870D5F0613A8E3DB5A979122C3E9EBF9B7AEFC6ADAEBE216145A620DCD |
| SSDEEP: | 98304:70lPkuZN4QLarfHfZn3TA13KVa1AZZEkjp+oiNZQ4ag0K14bK9dcD0s4k92q+oSY:Nc7XPpVFbzFGrDayUWKa8E |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:19 07:27:40+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 436224 |
| InitializedDataSize: | 115200 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x4c3b0 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 7.5.0.0 |
| ProductVersionNumber: | 7.5.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | ASCII |
| CompanyName: | Bandisoft |
| FileDescription: | BandiView 7.05 0 Setup |
| FileVersion: | 7.05 |
| LegalCopyright: | Copyright(C) 2023-2024, Bandisoft International Inc. All rights reserved. |
| ProductVersion: | 7.05 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 236 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --no-appcompat-clear --mojo-platform-channel-handle=5904 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 240 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6812 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 320 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=22 --mojo-platform-channel-handle=6108 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1128 | "C:\Program Files\BandiView\shell/RegPackage.x86.exe" /unreg BandiViewShellext | C:\Program Files\BandiView\shell\RegPackage.x86.exe | — | BANDIVIEW-SETUP-X64 (1).EXE.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1184 | "C:\Program Files\BandiView\data/RegDll.x64.exe" /regieemulation BandiView.exe | C:\Program Files\BandiView\data\RegDll.x64.exe | — | BANDIVIEW-SETUP-X64 (1).EXE.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1248 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --no-appcompat-clear --mojo-platform-channel-handle=6484 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1664 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4328 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2152 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7472 --field-trial-handle=2520,i,5333162555035401124,7302058882018615538,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2224 | "C:\Program Files\BandiView\BandiView.exe" /regdlg | C:\Program Files\BandiView\BandiView.exe | — | BANDIVIEW-SETUP-X64 (1).EXE.exe | |||||||||||
User: admin Company: Bandisoft International Inc. Integrity Level: HIGH Description: BandiView Image viewer Exit code: 0 Version: 7.5.0.1 Modules
| |||||||||||||||
| 2248 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x31c,0x320,0x324,0x318,0x32c,0x7fffd18a5fd8,0x7fffd18a5fe4,0x7fffd18a5ff0 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (6512) BANDIVIEW-SETUP-X64 (1).EXE.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6512) BANDIVIEW-SETUP-X64 (1).EXE.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6512) BANDIVIEW-SETUP-X64 (1).EXE.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6512) BANDIVIEW-SETUP-X64 (1).EXE.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1184) RegDll.x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION |
| Operation: | write | Name: | BandiView.exe |
Value: 11000 | |||
| (PID) Process: | (1184) RegDll.x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION |
| Operation: | write | Name: | BandiView.exe |
Value: 11000 | |||
| (PID) Process: | (6428) RegDll.x64.exe | Key: | HKEY_CLASSES_ROOT\*\shell\bvshell |
| Operation: | write | Name: | ExplorerCommandHandler |
Value: {0002DEAD-9BF7-4CFA-8A5C-DE8679340001} | |||
| (PID) Process: | (6428) RegDll.x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shell\bvshell |
| Operation: | write | Name: | ExplorerCommandHandler |
Value: {0002DEAD-9BF7-4CFA-8A5C-DE8679340001} | |||
| (PID) Process: | (6428) RegDll.x64.exe | Key: | HKEY_CLASSES_ROOT\*\shell\bvshell |
| Operation: | write | Name: | NeverDefault |
Value: | |||
| (PID) Process: | (6428) RegDll.x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shell\bvshell |
| Operation: | write | Name: | NeverDefault |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | der | |
MD5:E5C19C384CB144EDA9FB463F817A5BC4 | SHA256:45C2225A67A00E236DBFDA361A14D510A2362996E04A5B0E07CEF1D9CABDE10B | |||
| 6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | binary | |
MD5:794B875588E0EB5340779AE9C1D92C87 | SHA256:9246C555C7E4DFF77F93C76472AD3008A05EE1B3DE32C3722C53287B26F91BB1 | |||
| 6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | C:\Program Files\BandiView\shell\RegPackage.x86.exe | executable | |
MD5:25387FCE6D45E3190DD54400B3A67BC3 | SHA256:F48B5E9FAFCFE95DE1959AF56EB630F9D0527E440F08A9F8C39C2CE46DC837D7 | |||
| 6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850D | binary | |
MD5:9E7805A6B39BB529A72ECA0662F05161 | SHA256:620873F52A01DC157F7106ACE422AC106ED5B7DA96973A21C2FC4FCC816C67B2 | |||
| 6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | C:\Program Files\BandiView\data\icudtl.dat | binary | |
MD5:091A67C630F92F8316940180B787FBD2 | SHA256:63BB12EBACD1B93B01BE1A18F04EC0992AE7FB70CC3083825287261366A905CC | |||
| 6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | C:\Program Files\BandiView\data\resource.data | text | |
MD5:359F86BCA1F42E192109D1EAED70DEFB | SHA256:358966E59965A8549040D916DAEF2B77E193B70EF771EA47830F53D6B921F63E | |||
| 6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\55878D72B07DE680E267B610401D1AA2 | binary | |
MD5:7DF5D21C4BEBE7EEC318BABA51B7E8FA | SHA256:56336E646D90653F1892C931DBDCEDDE86A06A8F1BC7346305FA28AD03BFC208 | |||
| 6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | C:\Program Files\BandiView\data\lm.x64.dll | executable | |
MD5:C00768CFD4644F20E36091EB0D2BB71A | SHA256:73665EDE325E900E7ACF9C2DFEBFFA481A32505DC0DC915EF0A3EA9771680A87 | |||
| 6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | C:\Program Files\BandiView\data\RegDll.x64.exe | executable | |
MD5:B75CAEBA48754EA05DD3265E80917744 | SHA256:F81F269E9B259B827AC9046C396DAFBF8B13DE454762FDB32A2147CDA2174DF3 | |||
| 6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\55878D72B07DE680E267B610401D1AA2 | der | |
MD5:FEB8821B0BAFAE326E5EEF5EA44910FB | SHA256:9C5C996EA58C6FE6022521DF9C3B8BD83D01BCF520E29CB1753D602A95AAB918 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | unknown | — | — | whitelisted |
6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | unknown | — | — | whitelisted |
6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEBuRJhVl1EslGbwM0iynBP4%3D | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5244 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
3360 | BandiView.exe | GET | 200 | 216.58.206.35:80 | http://c.pki.goog/r/r1.crl | unknown | — | — | whitelisted |
3360 | BandiView.exe | GET | 200 | 172.217.18.3:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | — | — | whitelisted |
3360 | BandiView.exe | GET | 200 | 172.217.18.99:80 | http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEHvQOfnMl3BnEBjGqYCOwmQ%3D | unknown | — | — | whitelisted |
6432 | BandiView.exe | GET | 200 | 172.217.18.99:80 | http://o.pki.goog/wr2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEFISB6AKY0OzCbS%2BEJ1LbPY%3D | unknown | — | — | whitelisted |
6748 | msedge.exe | GET | 304 | 2.23.197.184:80 | http://x1.i.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5900 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3360 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | 52.78.169.250:443 | ver.bandi.so | AMAZON-02 | KR | unknown |
6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | 172.64.149.23:80 | ocsp.comodoca.com | CLOUDFLARENET | US | unknown |
6512 | BANDIVIEW-SETUP-X64 (1).EXE.exe | 104.18.38.233:80 | ocsp.comodoca.com | CLOUDFLARENET | — | shared |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5900 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
ver.bandi.so |
| unknown |
ocsp.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6748 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
6748 | msedge.exe | Misc activity | SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc) |
6748 | msedge.exe | Misc activity | SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc) |
6748 | msedge.exe | Potentially Bad Traffic | ET DNS Query for .cc TLD |
Process | Message |
|---|---|
msedge.exe | [0807/183240.155:WARNING:device_ticket.cc(151)] Timed out waiting for device ticket. Canceling async operation.
|
msedge.exe | [0807/183241.033:ERROR:filesystem_win.cc(128)] GetFileAttributes C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\attachments\86ec9f83-34d4-4264-aaea-0ecbe2f5e35e: The system cannot find the file specified. (0x2)
|
msedge.exe | [0807/183241.040:ERROR:filesystem_win.cc(128)] GetFileAttributes C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\attachments\86ec9f83-34d4-4264-aaea-0ecbe2f5e35e: The system cannot find the file specified. (0x2)
|
msedge.exe | [0807/183241.055:ERROR:filesystem_win.cc(128)] GetFileAttributes C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\attachments\86ec9f83-34d4-4264-aaea-0ecbe2f5e35e: The system cannot find the file specified. (0x2)
|
msedge.exe | [0807/183241.056:ERROR:filesystem_win.cc(128)] GetFileAttributes C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\attachments\86ec9f83-34d4-4264-aaea-0ecbe2f5e35e: The system cannot find the file specified. (0x2)
|