| File name: | BANDIZIP-SETUP-STD-ALL.EXE |
| Full analysis: | https://app.any.run/tasks/1a6d1bb6-715a-4e67-99c1-24c176b019f5 |
| Verdict: | Malicious activity |
| Analysis date: | February 14, 2025, 13:31:46 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 48435058210B98CA076EDA9F0C143110 |
| SHA1: | 12DF08BD11E7F507E7F6B172C2238E445910B084 |
| SHA256: | 391768ACA0E962D0A717B0C8EE63037AF0A8DCB7F13FA9BE8C380CFF0436E4DD |
| SSDEEP: | 98304:1IAvcmnZNJEp8iV8uCRilS3wssp1DNqa8ZU9f7eXHLQKtM0VY10wY79CDe+OQ1r4:n342tPShsvpF2juu/s |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:19 07:28:36+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 436224 |
| InitializedDataSize: | 115200 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x4c3d4 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 7.37.0.0 |
| ProductVersionNumber: | 7.37.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | ASCII |
| CompanyName: | Bandisoft |
| FileDescription: | Bandizip 7.37 0 Setup |
| FileVersion: | 7.37 |
| LegalCopyright: | Copyright(C) 2011-2025, Bandisoft International Inc. All rights reserved. |
| ProductVersion: | 7.37 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 132 | "C:\Program Files\Bandizip\data\RegDll.x64.exe" /calldll "C:\Program Files\Bandizip\bdzshl.x64.dll" RegSvr | C:\Program Files\Bandizip\data\RegDll.x64.exe | — | BANDIZIP-SETUP-STD-ALL.EXE.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 644 | "C:\Program Files\Bandizip\data\RegPackage.x86.exe" /check Bandisoft.com.15700C60EE320 | C:\Program Files\Bandizip\data\RegPackage.x86.exe | — | Bandizip.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 286326790 Modules
| |||||||||||||||
| 1580 | "C:\Program Files\Bandizip\Bandizip.exe" | C:\Program Files\Bandizip\Bandizip.exe | Bandizip.exe | ||||||||||||
User: admin Company: Bandisoft International Inc. Integrity Level: MEDIUM Description: Bandizip Exit code: 0 Version: 7.37.0.1 Modules
| |||||||||||||||
| 2548 | "C:\Program Files\Bandizip\Bandizip.exe" cd "C:\Users\admin\Desktop\presidentjob.zip" "C:\Users\admin\Desktop\presidentjob.rtf" | C:\Program Files\Bandizip\Bandizip.exe | — | explorer.exe | |||||||||||
User: admin Company: Bandisoft International Inc. Integrity Level: MEDIUM Description: Bandizip Exit code: 0 Version: 7.37.0.1 Modules
| |||||||||||||||
| 3640 | "C:\Program Files\Bandizip\data\RegDll.x64.exe" /addpath "C:\Program Files\Bandizip\" | C:\Program Files\Bandizip\data\RegDll.x64.exe | — | BANDIZIP-SETUP-STD-ALL.EXE.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 4544 | "C:\Program Files\Bandizip\updater.exe" /nosleep | C:\Program Files\Bandizip\Updater.exe | Bandizip.exe | ||||||||||||
User: admin Company: Bandisoft International Inc. Integrity Level: MEDIUM Description: Bandizip Updater Exit code: 0 Version: 7.37.0.1 Modules
| |||||||||||||||
| 4932 | "C:\Program Files\Bandizip\Bandizip.exe" /setdefaultprogram | C:\Program Files\Bandizip\Bandizip.exe | — | BANDIZIP-SETUP-STD-ALL.EXE.exe | |||||||||||
User: admin Company: Bandisoft International Inc. Integrity Level: HIGH Description: Bandizip Exit code: 0 Version: 7.37.0.1 Modules
| |||||||||||||||
| 5528 | "C:\Program Files\Bandizip\Bandizip.exe" /setupiffirst | C:\Program Files\Bandizip\Bandizip.exe | — | explorer.exe | |||||||||||
User: admin Company: Bandisoft International Inc. Integrity Level: MEDIUM Description: Bandizip Exit code: 0 Version: 7.37.0.1 Modules
| |||||||||||||||
| 6204 | "C:\Program Files\Bandizip\data\RegDll.x86.exe" /calldll "C:\Program Files\Bandizip\bdzshl.x86.dll" RegSvr | C:\Program Files\Bandizip\data\RegDll.x86.exe | — | BANDIZIP-SETUP-STD-ALL.EXE.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 6344 | "C:\Users\admin\AppData\Local\Temp\BANDIZIP-SETUP-STD-ALL.EXE.exe" | C:\Users\admin\AppData\Local\Temp\BANDIZIP-SETUP-STD-ALL.EXE.exe | — | explorer.exe | |||||||||||
User: admin Company: Bandisoft Integrity Level: MEDIUM Description: Bandizip 7.37 0 Setup Exit code: 3221226540 Version: 7.37 Modules
| |||||||||||||||
| (PID) Process: | (7032) Bandizip.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Bandizip\l |
| Operation: | write | Name: | c |
Value: | |||
| (PID) Process: | (7032) Bandizip.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Bandizip\l |
| Operation: | write | Name: | r |
Value: | |||
| (PID) Process: | (7032) Bandizip.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Bandizip\l |
| Operation: | write | Name: | u |
Value: | |||
| (PID) Process: | (7032) Bandizip.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip |
| Operation: | write | Name: | Bandizip_bak |
Value: WinRAR.ZIP | |||
| (PID) Process: | (7032) Bandizip.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.zip\Shell\Open |
| Operation: | write | Name: | FriendlyAppName |
Value: Bandizip | |||
| (PID) Process: | (7032) Bandizip.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zipx |
| Operation: | write | Name: | Bandizip_bak |
Value: WinRAR | |||
| (PID) Process: | (7032) Bandizip.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.zipx\Shell\Open |
| Operation: | write | Name: | FriendlyAppName |
Value: Bandizip | |||
| (PID) Process: | (7032) Bandizip.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rar |
| Operation: | write | Name: | Bandizip_bak |
Value: WinRAR | |||
| (PID) Process: | (7032) Bandizip.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.rar\Shell\Open |
| Operation: | write | Name: | FriendlyAppName |
Value: Bandizip | |||
| (PID) Process: | (7032) Bandizip.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.7z |
| Operation: | write | Name: | Bandizip_bak |
Value: WinRAR | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | binary | |
MD5:C357034A3247F5008403ACD50CD212F5 | SHA256:1D3B56C4A3133AF11AED73F7D1620A98AAFBF38EE17EFF222340823771A17D8D | |||
| 6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | binary | |
MD5:2D99DAE3E1D2CD1F7DF0F07F4B080818 | SHA256:186E7BC6FC830D00B75445562E358DDCC3124D3B6964316A9A16548666AE1D79 | |||
| 6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850D | der | |
MD5:F0E1375F24FD5570424F09166B1C6E39 | SHA256:253AF393B4817356A5035D87FA544C09B49E3C213148EE0AD5AEF754B6097762 | |||
| 6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850D | binary | |
MD5:90192DD5466D357E4C24AA3A9274AB43 | SHA256:8056EA44B9E587275B2C2C03EEB662556E67048D0AE0754E95B44FB384B16814 | |||
| 6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | C:\Program Files\Bandizip\data\lm.x64.dll | executable | |
MD5:9A0C7D572ABC8B8D67920C60E284C8CB | SHA256:4B8B3355405CF71F6FB99B3A1B35824D008E9EE8ADE67F90CD7593ADBD31AD53 | |||
| 6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | C:\Program Files\Bandizip\ark.x86.lgpl.dll | executable | |
MD5:6EC81D6A7D5221F08C5D2EF37D63292C | SHA256:F021D8B7AD25E0EFDAD45A3049DC9AB83B444668A10D6A971A7C004E508A4BB3 | |||
| 6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | C:\Program Files\Bandizip\data\Amsiman.a64.exe | executable | |
MD5:22C4164F9B09D1060D21D164D72BD77C | SHA256:508FB442480EAD13357E9C0C2249CAC3DD62DBF2A0574CAF5B8D04927E13A46C | |||
| 6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | C:\Program Files\Bandizip\bdzshl.x64.dll | executable | |
MD5:58087A0B26273CA6AF271B1FA6FCD29A | SHA256:4C699510C70968723A1E3BB0204954782D7B92D327A2D41D37D2023847A59D4A | |||
| 6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | C:\Program Files\Bandizip\data\webview.x86.dll | executable | |
MD5:3E2830F38B646AD31A4010E816A69993 | SHA256:8630E5D78CEFEC64E63B56BCEAD2407E0E83484E05174043BB3150725719665E | |||
| 6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | C:\Program Files\Bandizip\data\skin.recovery.data | compressed | |
MD5:0D51FF93EAB045D764E7017E108E1C51 | SHA256:74901635E51D4D7824EDBA4B06048356C968E3CC9A42885B318B5C172D7366B4 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5004 | svchost.exe | GET | 200 | 23.48.23.159:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.159:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.19.217.218:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.67.160.244:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5004 | svchost.exe | GET | 200 | 2.19.217.218:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 23.67.160.244:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | unknown | — | — | whitelisted |
6500 | BANDIZIP-SETUP-STD-ALL.EXE.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEHby99qPBsQR44pGbdwfRPc%3D | unknown | — | — | whitelisted |
2744 | SIHClient.exe | GET | 200 | 2.19.217.218:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.212.110.137:443 | www.bing.com | Akamai International B.V. | CZ | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.48.23.159:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5004 | svchost.exe | 23.48.23.159:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.19.217.218:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
5004 | svchost.exe | 2.19.217.218:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 23.67.160.244:80 | ocsp.digicert.com | AKAMAI-AS | JP | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
ver.bandi.so |
| unknown |
ocsp.comodoca.com |
| whitelisted |