File name:

BANDIZIP-SETUP-STD-ALL.EXE

Full analysis: https://app.any.run/tasks/1a6d1bb6-715a-4e67-99c1-24c176b019f5
Verdict: Malicious activity
Analysis date: February 14, 2025, 13:31:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

48435058210B98CA076EDA9F0C143110

SHA1:

12DF08BD11E7F507E7F6B172C2238E445910B084

SHA256:

391768ACA0E962D0A717B0C8EE63037AF0A8DCB7F13FA9BE8C380CFF0436E4DD

SSDEEP:

98304:1IAvcmnZNJEp8iV8uCRilS3wssp1DNqa8ZU9f7eXHLQKtM0VY10wY79CDe+OQ1r4:n342tPShsvpF2juu/s

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 2548)
      • Bandizip.exe (PID: 7160)
    • Checks Windows Trust Settings

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 7160)
    • Executable content was dropped or overwritten

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Changes Internet Explorer settings (feature browser emulation)

      • RegDll.x86.exe (PID: 7124)
      • RegDll.x86.exe (PID: 7096)
      • RegDll.x86.exe (PID: 7152)
    • Creates/Modifies COM task schedule object

      • RegDll.x64.exe (PID: 132)
      • RegDll.x86.exe (PID: 6204)
    • Reads Microsoft Outlook installation path

      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
    • Reads Internet Explorer settings

      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
    • Reads the date of Windows installation

      • Bandizip.exe (PID: 5528)
      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 1580)
    • Application launched itself

      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 1580)
    • Creates a software uninstall entry

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
  • INFO

    • Reads the software policy settings

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 7160)
    • Checks supported languages

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Bandizip.exe (PID: 7032)
      • RegDll.x86.exe (PID: 7096)
      • RegDll.x86.exe (PID: 7124)
      • RegDll.x86.exe (PID: 7152)
      • RegDll.x86.exe (PID: 6204)
      • RegDll.x64.exe (PID: 132)
      • RegDll.x64.exe (PID: 3640)
      • RegDll.x64.exe (PID: 6456)
      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 4932)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 5528)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
      • RegPackage.x86.exe (PID: 6852)
      • Bandizip.exe (PID: 2548)
      • RegPackage.x86.exe (PID: 644)
      • Bandizip.exe (PID: 7160)
      • Bandizip.exe (PID: 6452)
    • Reads the computer name

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 5528)
      • Updater.exe (PID: 4544)
      • RegPackage.x86.exe (PID: 6852)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 2548)
      • RegPackage.x86.exe (PID: 644)
      • Bandizip.exe (PID: 7160)
    • The sample compiled with english language support

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Creates files or folders in the user directory

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • RegDll.x64.exe (PID: 6344)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
    • Reads the machine GUID from the registry

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 7160)
    • Checks proxy server information

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 2548)
      • Bandizip.exe (PID: 7160)
      • Bandizip.exe (PID: 6864)
    • Creates files in the program directory

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • The sample compiled with korean language support

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Manual execution by a user

      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 2548)
      • Bandizip.exe (PID: 7160)
      • Bandizip.exe (PID: 6452)
    • Process checks computer location settings

      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 1580)
    • UPX packer has been detected

      • Bandizip.exe (PID: 2548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:19 07:28:36+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 436224
InitializedDataSize: 115200
UninitializedDataSize: -
EntryPoint: 0x4c3d4
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 7.37.0.0
ProductVersionNumber: 7.37.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: Bandisoft
FileDescription: Bandizip 7.37 0 Setup
FileVersion: 7.37
LegalCopyright: Copyright(C) 2011-2025, Bandisoft International Inc. All rights reserved.
ProductVersion: 7.37
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
21
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bandizip-setup-std-all.exe.exe bandizip.exe no specs regdll.x86.exe no specs regdll.x86.exe no specs regdll.x86.exe no specs regdll.x86.exe no specs regdll.x64.exe no specs regdll.x64.exe no specs regdll.x64.exe no specs regdll.x64.exe no specs bandizip.exe no specs bandizip.exe no specs updater.exe bandizip.exe bandizip.exe regpackage.x86.exe no specs bandizip.exe no specs regpackage.x86.exe no specs bandizip.exe bandizip.exe no specs bandizip-setup-std-all.exe.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
132"C:\Program Files\Bandizip\data\RegDll.x64.exe" /calldll "C:\Program Files\Bandizip\bdzshl.x64.dll" RegSvrC:\Program Files\Bandizip\data\RegDll.x64.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bandizip\data\regdll.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
644"C:\Program Files\Bandizip\data\RegPackage.x86.exe" /check Bandisoft.com.15700C60EE320C:\Program Files\Bandizip\data\RegPackage.x86.exeBandizip.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
286326790
Modules
Images
c:\program files\bandizip\data\regpackage.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1580"C:\Program Files\Bandizip\Bandizip.exe" C:\Program Files\Bandizip\Bandizip.exe
Bandizip.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2548"C:\Program Files\Bandizip\Bandizip.exe" cd "C:\Users\admin\Desktop\presidentjob.zip" "C:\Users\admin\Desktop\presidentjob.rtf" C:\Program Files\Bandizip\Bandizip.exeexplorer.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3640"C:\Program Files\Bandizip\data\RegDll.x64.exe" /addpath "C:\Program Files\Bandizip\"C:\Program Files\Bandizip\data\RegDll.x64.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bandizip\data\regdll.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4544"C:\Program Files\Bandizip\updater.exe" /nosleepC:\Program Files\Bandizip\Updater.exe
Bandizip.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip Updater
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4932"C:\Program Files\Bandizip\Bandizip.exe" /setdefaultprogramC:\Program Files\Bandizip\Bandizip.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
HIGH
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5528"C:\Program Files\Bandizip\Bandizip.exe" /setupiffirstC:\Program Files\Bandizip\Bandizip.exeexplorer.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6204"C:\Program Files\Bandizip\data\RegDll.x86.exe" /calldll "C:\Program Files\Bandizip\bdzshl.x86.dll" RegSvrC:\Program Files\Bandizip\data\RegDll.x86.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bandizip\data\regdll.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6344"C:\Users\admin\AppData\Local\Temp\BANDIZIP-SETUP-STD-ALL.EXE.exe" C:\Users\admin\AppData\Local\Temp\BANDIZIP-SETUP-STD-ALL.EXE.exeexplorer.exe
User:
admin
Company:
Bandisoft
Integrity Level:
MEDIUM
Description:
Bandizip 7.37 0 Setup
Exit code:
3221226540
Version:
7.37
Modules
Images
c:\users\admin\appdata\local\temp\bandizip-setup-std-all.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
20 494
Read events
16 951
Write events
3 538
Delete events
5

Modification events

(PID) Process:(7032) Bandizip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Bandizip\l
Operation:writeName:c
Value:
(PID) Process:(7032) Bandizip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Bandizip\l
Operation:writeName:r
Value:
(PID) Process:(7032) Bandizip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Bandizip\l
Operation:writeName:u
Value:
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip
Operation:writeName:Bandizip_bak
Value:
WinRAR.ZIP
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.zip\Shell\Open
Operation:writeName:FriendlyAppName
Value:
Bandizip
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zipx
Operation:writeName:Bandizip_bak
Value:
WinRAR
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.zipx\Shell\Open
Operation:writeName:FriendlyAppName
Value:
Bandizip
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rar
Operation:writeName:Bandizip_bak
Value:
WinRAR
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.rar\Shell\Open
Operation:writeName:FriendlyAppName
Value:
Bandizip
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.7z
Operation:writeName:Bandizip_bak
Value:
WinRAR
Executable files
24
Suspicious files
57
Text files
45
Unknown types
1

Dropped files

PID
Process
Filename
Type
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dder
MD5:F0E1375F24FD5570424F09166B1C6E39
SHA256:253AF393B4817356A5035D87FA544C09B49E3C213148EE0AD5AEF754B6097762
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:90192DD5466D357E4C24AA3A9274AB43
SHA256:8056EA44B9E587275B2C2C03EEB662556E67048D0AE0754E95B44FB384B16814
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\035E52AEDA0CBD41F7A1EE1F14E33688binary
MD5:39BF69006FAF8E3A42B2D8BEFB7B23EC
SHA256:6336E533FB29A1876D54DEB050010436A463FDEAE22A4A77005AB67AE5404CD7
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\bdzshl.x86.dllexecutable
MD5:CCC94085B4D2E06C5EA9D66B42CC43E4
SHA256:F35A626F0DC64F39381218AC9CD0274366D4165E785A6CA7D66AE00C187E8570
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\ark.x86.lgpl.dllexecutable
MD5:6EC81D6A7D5221F08C5D2EF37D63292C
SHA256:F021D8B7AD25E0EFDAD45A3049DC9AB83B444668A10D6A971A7C004E508A4BB3
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\bdzshl.x64.dllexecutable
MD5:58087A0B26273CA6AF271B1FA6FCD29A
SHA256:4C699510C70968723A1E3BB0204954782D7B92D327A2D41D37D2023847A59D4A
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\ark.x64.lgpl.dllexecutable
MD5:05F28649AD6D7D01EC5748312F56913C
SHA256:E6DC5B399192B217997F33279154CE31B7045286033D3BBBC4450BA267D071F3
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\data\bzshell.x64.dllexecutable
MD5:797578F961005D4D0874EAED8B2A07F9
SHA256:0FC6846B3930D62BBF62D16C5D33A70CA64291E51721AAAD23FFEBF27008FD3E
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\ark.x86.dllexecutable
MD5:315673FB13B1831E893ED7C3121D6072
SHA256:411B58B20DADB7AAC609F58B63085896C6A46E5DDEF6D918A90DA133C5E74A56
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\data\skin.recovery.datacompressed
MD5:0D51FF93EAB045D764E7017E108E1C51
SHA256:74901635E51D4D7824EDBA4B06048356C968E3CC9A42885B318B5C172D7366B4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
52
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5004
svchost.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6500
BANDIZIP-SETUP-STD-ALL.EXE.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
whitelisted
5004
svchost.exe
GET
200
23.48.23.159:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.159:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3128
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.67.160.244:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6864
Bandizip.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6864
Bandizip.exe
GET
200
142.250.186.131:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
4544
Updater.exe
GET
200
142.250.186.131:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.212.110.137:443
www.bing.com
Akamai International B.V.
CZ
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.159:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5004
svchost.exe
23.48.23.159:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
2.19.217.218:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5004
svchost.exe
2.19.217.218:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
23.67.160.244:80
ocsp.digicert.com
AKAMAI-AS
JP
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.142
whitelisted
www.bing.com
  • 23.212.110.137
  • 23.212.110.136
  • 23.212.110.218
  • 23.212.110.209
  • 23.212.110.138
  • 23.212.110.208
  • 23.212.110.187
  • 23.212.110.200
  • 23.212.110.211
  • 23.212.110.203
  • 23.212.110.217
  • 23.15.178.203
  • 23.15.178.184
  • 23.15.178.234
  • 23.15.178.251
  • 23.15.178.233
  • 23.15.178.200
  • 23.15.178.147
  • 23.15.178.136
  • 23.15.178.179
whitelisted
crl.microsoft.com
  • 23.48.23.159
  • 23.48.23.147
  • 23.48.23.164
  • 23.48.23.145
  • 23.48.23.143
  • 23.48.23.193
  • 23.48.23.156
  • 23.48.23.180
  • 23.48.23.141
whitelisted
www.microsoft.com
  • 2.19.217.218
whitelisted
ocsp.digicert.com
  • 23.67.160.244
  • 2.23.77.188
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.73
  • 40.126.31.130
  • 40.126.31.73
  • 40.126.31.67
  • 20.190.159.75
  • 20.190.159.71
  • 20.190.159.68
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
ver.bandi.so
  • 52.78.169.250
unknown
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted

Threats

No threats detected
No debug info