File name:

BANDIZIP-SETUP-STD-ALL.EXE

Full analysis: https://app.any.run/tasks/1a6d1bb6-715a-4e67-99c1-24c176b019f5
Verdict: Malicious activity
Analysis date: February 14, 2025, 13:31:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

48435058210B98CA076EDA9F0C143110

SHA1:

12DF08BD11E7F507E7F6B172C2238E445910B084

SHA256:

391768ACA0E962D0A717B0C8EE63037AF0A8DCB7F13FA9BE8C380CFF0436E4DD

SSDEEP:

98304:1IAvcmnZNJEp8iV8uCRilS3wssp1DNqa8ZU9f7eXHLQKtM0VY10wY79CDe+OQ1r4:n342tPShsvpF2juu/s

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Bandizip.exe (PID: 5528)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 2548)
      • Bandizip.exe (PID: 7160)
    • Checks Windows Trust Settings

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 7160)
    • Changes Internet Explorer settings (feature browser emulation)

      • RegDll.x86.exe (PID: 7096)
      • RegDll.x86.exe (PID: 7124)
      • RegDll.x86.exe (PID: 7152)
    • Executable content was dropped or overwritten

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Creates/Modifies COM task schedule object

      • RegDll.x86.exe (PID: 6204)
      • RegDll.x64.exe (PID: 132)
    • Creates a software uninstall entry

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Reads Microsoft Outlook installation path

      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
    • Reads the date of Windows installation

      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 1580)
      • RegDll.x64.exe (PID: 6344)
    • Reads Internet Explorer settings

      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
    • Application launched itself

      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 5528)
  • INFO

    • The sample compiled with english language support

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Creates files in the program directory

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Reads the computer name

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • RegDll.x64.exe (PID: 6344)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 1580)
      • RegPackage.x86.exe (PID: 6852)
      • Bandizip.exe (PID: 6864)
      • RegPackage.x86.exe (PID: 644)
      • Bandizip.exe (PID: 2548)
      • Bandizip.exe (PID: 7160)
      • Bandizip.exe (PID: 5528)
    • Reads the machine GUID from the registry

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 7160)
    • Checks supported languages

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • RegDll.x86.exe (PID: 7096)
      • RegDll.x86.exe (PID: 7152)
      • Bandizip.exe (PID: 7032)
      • RegDll.x86.exe (PID: 7124)
      • RegDll.x86.exe (PID: 6204)
      • RegDll.x64.exe (PID: 132)
      • RegDll.x64.exe (PID: 3640)
      • RegDll.x64.exe (PID: 6456)
      • Bandizip.exe (PID: 4932)
      • RegDll.x64.exe (PID: 6344)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 1580)
      • RegPackage.x86.exe (PID: 6852)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 2548)
      • RegPackage.x86.exe (PID: 644)
      • Bandizip.exe (PID: 7160)
      • Bandizip.exe (PID: 6452)
      • Bandizip.exe (PID: 5528)
    • Creates files or folders in the user directory

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
      • RegDll.x64.exe (PID: 6344)
    • Reads the software policy settings

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 7160)
    • Checks proxy server information

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Bandizip.exe (PID: 5528)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 2548)
      • Bandizip.exe (PID: 7160)
    • The sample compiled with korean language support

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Manual execution by a user

      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 2548)
      • Bandizip.exe (PID: 6452)
      • Bandizip.exe (PID: 7160)
    • Process checks computer location settings

      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 5528)
    • UPX packer has been detected

      • Bandizip.exe (PID: 2548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:19 07:28:36+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 436224
InitializedDataSize: 115200
UninitializedDataSize: -
EntryPoint: 0x4c3d4
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 7.37.0.0
ProductVersionNumber: 7.37.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: Bandisoft
FileDescription: Bandizip 7.37 0 Setup
FileVersion: 7.37
LegalCopyright: Copyright(C) 2011-2025, Bandisoft International Inc. All rights reserved.
ProductVersion: 7.37
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
21
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bandizip-setup-std-all.exe.exe bandizip.exe no specs regdll.x86.exe no specs regdll.x86.exe no specs regdll.x86.exe no specs regdll.x86.exe no specs regdll.x64.exe no specs regdll.x64.exe no specs regdll.x64.exe no specs regdll.x64.exe no specs bandizip.exe no specs bandizip.exe no specs updater.exe bandizip.exe bandizip.exe regpackage.x86.exe no specs bandizip.exe no specs regpackage.x86.exe no specs bandizip.exe bandizip.exe no specs bandizip-setup-std-all.exe.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
132"C:\Program Files\Bandizip\data\RegDll.x64.exe" /calldll "C:\Program Files\Bandizip\bdzshl.x64.dll" RegSvrC:\Program Files\Bandizip\data\RegDll.x64.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bandizip\data\regdll.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
644"C:\Program Files\Bandizip\data\RegPackage.x86.exe" /check Bandisoft.com.15700C60EE320C:\Program Files\Bandizip\data\RegPackage.x86.exeBandizip.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
286326790
Modules
Images
c:\program files\bandizip\data\regpackage.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1580"C:\Program Files\Bandizip\Bandizip.exe" C:\Program Files\Bandizip\Bandizip.exe
Bandizip.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2548"C:\Program Files\Bandizip\Bandizip.exe" cd "C:\Users\admin\Desktop\presidentjob.zip" "C:\Users\admin\Desktop\presidentjob.rtf" C:\Program Files\Bandizip\Bandizip.exeexplorer.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3640"C:\Program Files\Bandizip\data\RegDll.x64.exe" /addpath "C:\Program Files\Bandizip\"C:\Program Files\Bandizip\data\RegDll.x64.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bandizip\data\regdll.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4544"C:\Program Files\Bandizip\updater.exe" /nosleepC:\Program Files\Bandizip\Updater.exe
Bandizip.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip Updater
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4932"C:\Program Files\Bandizip\Bandizip.exe" /setdefaultprogramC:\Program Files\Bandizip\Bandizip.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
HIGH
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5528"C:\Program Files\Bandizip\Bandizip.exe" /setupiffirstC:\Program Files\Bandizip\Bandizip.exeexplorer.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6204"C:\Program Files\Bandizip\data\RegDll.x86.exe" /calldll "C:\Program Files\Bandizip\bdzshl.x86.dll" RegSvrC:\Program Files\Bandizip\data\RegDll.x86.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bandizip\data\regdll.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6344"C:\Users\admin\AppData\Local\Temp\BANDIZIP-SETUP-STD-ALL.EXE.exe" C:\Users\admin\AppData\Local\Temp\BANDIZIP-SETUP-STD-ALL.EXE.exeexplorer.exe
User:
admin
Company:
Bandisoft
Integrity Level:
MEDIUM
Description:
Bandizip 7.37 0 Setup
Exit code:
3221226540
Version:
7.37
Modules
Images
c:\users\admin\appdata\local\temp\bandizip-setup-std-all.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
20 494
Read events
16 951
Write events
3 538
Delete events
5

Modification events

(PID) Process:(7032) Bandizip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Bandizip\l
Operation:writeName:c
Value:
(PID) Process:(7032) Bandizip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Bandizip\l
Operation:writeName:r
Value:
(PID) Process:(7032) Bandizip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Bandizip\l
Operation:writeName:u
Value:
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip
Operation:writeName:Bandizip_bak
Value:
WinRAR.ZIP
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.zip\Shell\Open
Operation:writeName:FriendlyAppName
Value:
Bandizip
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zipx
Operation:writeName:Bandizip_bak
Value:
WinRAR
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.zipx\Shell\Open
Operation:writeName:FriendlyAppName
Value:
Bandizip
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rar
Operation:writeName:Bandizip_bak
Value:
WinRAR
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.rar\Shell\Open
Operation:writeName:FriendlyAppName
Value:
Bandizip
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.7z
Operation:writeName:Bandizip_bak
Value:
WinRAR
Executable files
24
Suspicious files
57
Text files
45
Unknown types
1

Dropped files

PID
Process
Filename
Type
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:90192DD5466D357E4C24AA3A9274AB43
SHA256:8056EA44B9E587275B2C2C03EEB662556E67048D0AE0754E95B44FB384B16814
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dder
MD5:F0E1375F24FD5570424F09166B1C6E39
SHA256:253AF393B4817356A5035D87FA544C09B49E3C213148EE0AD5AEF754B6097762
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\035E52AEDA0CBD41F7A1EE1F14E33688binary
MD5:39BF69006FAF8E3A42B2D8BEFB7B23EC
SHA256:6336E533FB29A1876D54DEB050010436A463FDEAE22A4A77005AB67AE5404CD7
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\ark.x64.dllexecutable
MD5:BE933DBC8F1FFCA97483D6B86B12E092
SHA256:3B064A3CD5AE78FAA18F5279DFA3419D31857924C626D170E6EFB7CB2B4ADC05
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:C357034A3247F5008403ACD50CD212F5
SHA256:1D3B56C4A3133AF11AED73F7D1620A98AAFBF38EE17EFF222340823771A17D8D
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\035E52AEDA0CBD41F7A1EE1F14E33688binary
MD5:96AA453AB28007169AD563BE36501DF7
SHA256:86B18919DAC078F7B5FDC31858B68BFFE4774558CADBBCD5807286DAC26C1FE7
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\data\lm.x64.dllexecutable
MD5:9A0C7D572ABC8B8D67920C60E284C8CB
SHA256:4B8B3355405CF71F6FB99B3A1B35824D008E9EE8ADE67F90CD7593ADBD31AD53
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\data\bzshell.x64.dllexecutable
MD5:797578F961005D4D0874EAED8B2A07F9
SHA256:0FC6846B3930D62BBF62D16C5D33A70CA64291E51721AAAD23FFEBF27008FD3E
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\ark.x64.lgpl.dllexecutable
MD5:05F28649AD6D7D01EC5748312F56913C
SHA256:E6DC5B399192B217997F33279154CE31B7045286033D3BBBC4450BA267D071F3
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\ark.x86.dllexecutable
MD5:315673FB13B1831E893ED7C3121D6072
SHA256:411B58B20DADB7AAC609F58B63085896C6A46E5DDEF6D918A90DA133C5E74A56
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
52
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.159:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5004
svchost.exe
GET
200
23.48.23.159:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.67.160.244:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5004
svchost.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
23.67.160.244:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6500
BANDIZIP-SETUP-STD-ALL.EXE.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
whitelisted
6500
BANDIZIP-SETUP-STD-ALL.EXE.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
whitelisted
6864
Bandizip.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6864
Bandizip.exe
GET
200
142.250.185.227:80
http://o.pki.goog/we2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEQCYp8FDbOKrChCXDiq8pD%2Bn
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.212.110.137:443
www.bing.com
Akamai International B.V.
CZ
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.159:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5004
svchost.exe
23.48.23.159:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
2.19.217.218:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5004
svchost.exe
2.19.217.218:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
23.67.160.244:80
ocsp.digicert.com
AKAMAI-AS
JP
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.142
whitelisted
www.bing.com
  • 23.212.110.137
  • 23.212.110.136
  • 23.212.110.218
  • 23.212.110.209
  • 23.212.110.138
  • 23.212.110.208
  • 23.212.110.187
  • 23.212.110.200
  • 23.212.110.211
  • 23.212.110.203
  • 23.212.110.217
  • 23.15.178.203
  • 23.15.178.184
  • 23.15.178.234
  • 23.15.178.251
  • 23.15.178.233
  • 23.15.178.200
  • 23.15.178.147
  • 23.15.178.136
  • 23.15.178.179
whitelisted
crl.microsoft.com
  • 23.48.23.159
  • 23.48.23.147
  • 23.48.23.164
  • 23.48.23.145
  • 23.48.23.143
  • 23.48.23.193
  • 23.48.23.156
  • 23.48.23.180
  • 23.48.23.141
whitelisted
www.microsoft.com
  • 2.19.217.218
whitelisted
ocsp.digicert.com
  • 23.67.160.244
  • 2.23.77.188
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.73
  • 40.126.31.130
  • 40.126.31.73
  • 40.126.31.67
  • 20.190.159.75
  • 20.190.159.71
  • 20.190.159.68
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
ver.bandi.so
  • 52.78.169.250
unknown
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted

Threats

No threats detected
No debug info