File name:

BANDIZIP-SETUP-STD-ALL.EXE

Full analysis: https://app.any.run/tasks/1a6d1bb6-715a-4e67-99c1-24c176b019f5
Verdict: Malicious activity
Analysis date: February 14, 2025, 13:31:46
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

48435058210B98CA076EDA9F0C143110

SHA1:

12DF08BD11E7F507E7F6B172C2238E445910B084

SHA256:

391768ACA0E962D0A717B0C8EE63037AF0A8DCB7F13FA9BE8C380CFF0436E4DD

SSDEEP:

98304:1IAvcmnZNJEp8iV8uCRilS3wssp1DNqa8ZU9f7eXHLQKtM0VY10wY79CDe+OQ1r4:n342tPShsvpF2juu/s

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Bandizip.exe (PID: 5528)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 7160)
      • Bandizip.exe (PID: 2548)
    • Checks Windows Trust Settings

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 7160)
    • Executable content was dropped or overwritten

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Changes Internet Explorer settings (feature browser emulation)

      • RegDll.x86.exe (PID: 7124)
      • RegDll.x86.exe (PID: 7096)
      • RegDll.x86.exe (PID: 7152)
    • Creates/Modifies COM task schedule object

      • RegDll.x86.exe (PID: 6204)
      • RegDll.x64.exe (PID: 132)
    • Reads the date of Windows installation

      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 1580)
    • Creates a software uninstall entry

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Reads Microsoft Outlook installation path

      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
    • Application launched itself

      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 1580)
    • Reads Internet Explorer settings

      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
  • INFO

    • The sample compiled with english language support

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Checks proxy server information

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Bandizip.exe (PID: 5528)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 2548)
      • Bandizip.exe (PID: 7160)
    • Reads the computer name

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 1580)
      • Updater.exe (PID: 4544)
      • RegPackage.x86.exe (PID: 6852)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 2548)
      • Bandizip.exe (PID: 7160)
      • RegPackage.x86.exe (PID: 644)
    • Reads the machine GUID from the registry

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 7160)
    • Checks supported languages

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Bandizip.exe (PID: 7032)
      • RegDll.x86.exe (PID: 7096)
      • RegDll.x86.exe (PID: 7124)
      • RegDll.x86.exe (PID: 7152)
      • RegDll.x86.exe (PID: 6204)
      • RegDll.x64.exe (PID: 132)
      • RegDll.x64.exe (PID: 3640)
      • Bandizip.exe (PID: 4932)
      • RegDll.x64.exe (PID: 6456)
      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 1580)
      • RegPackage.x86.exe (PID: 6852)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 2548)
      • Bandizip.exe (PID: 6864)
      • RegPackage.x86.exe (PID: 644)
      • Bandizip.exe (PID: 7160)
      • Bandizip.exe (PID: 6452)
    • Creates files or folders in the user directory

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • RegDll.x64.exe (PID: 6344)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
    • Reads the software policy settings

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
      • Updater.exe (PID: 4544)
      • Bandizip.exe (PID: 6864)
      • Bandizip.exe (PID: 1580)
      • Bandizip.exe (PID: 7160)
    • Creates files in the program directory

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • The sample compiled with korean language support

      • BANDIZIP-SETUP-STD-ALL.EXE.exe (PID: 6500)
    • Manual execution by a user

      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 2548)
      • Bandizip.exe (PID: 7160)
      • Bandizip.exe (PID: 6452)
    • Process checks computer location settings

      • RegDll.x64.exe (PID: 6344)
      • Bandizip.exe (PID: 5528)
      • Bandizip.exe (PID: 1580)
    • UPX packer has been detected

      • Bandizip.exe (PID: 2548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:19 07:28:36+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 436224
InitializedDataSize: 115200
UninitializedDataSize: -
EntryPoint: 0x4c3d4
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 7.37.0.0
ProductVersionNumber: 7.37.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
CompanyName: Bandisoft
FileDescription: Bandizip 7.37 0 Setup
FileVersion: 7.37
LegalCopyright: Copyright(C) 2011-2025, Bandisoft International Inc. All rights reserved.
ProductVersion: 7.37
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
21
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bandizip-setup-std-all.exe.exe bandizip.exe no specs regdll.x86.exe no specs regdll.x86.exe no specs regdll.x86.exe no specs regdll.x86.exe no specs regdll.x64.exe no specs regdll.x64.exe no specs regdll.x64.exe no specs regdll.x64.exe no specs bandizip.exe no specs bandizip.exe no specs updater.exe bandizip.exe bandizip.exe regpackage.x86.exe no specs bandizip.exe no specs regpackage.x86.exe no specs bandizip.exe bandizip.exe no specs bandizip-setup-std-all.exe.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
132"C:\Program Files\Bandizip\data\RegDll.x64.exe" /calldll "C:\Program Files\Bandizip\bdzshl.x64.dll" RegSvrC:\Program Files\Bandizip\data\RegDll.x64.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bandizip\data\regdll.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
644"C:\Program Files\Bandizip\data\RegPackage.x86.exe" /check Bandisoft.com.15700C60EE320C:\Program Files\Bandizip\data\RegPackage.x86.exeBandizip.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
286326790
Modules
Images
c:\program files\bandizip\data\regpackage.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1580"C:\Program Files\Bandizip\Bandizip.exe" C:\Program Files\Bandizip\Bandizip.exe
Bandizip.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2548"C:\Program Files\Bandizip\Bandizip.exe" cd "C:\Users\admin\Desktop\presidentjob.zip" "C:\Users\admin\Desktop\presidentjob.rtf" C:\Program Files\Bandizip\Bandizip.exeexplorer.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3640"C:\Program Files\Bandizip\data\RegDll.x64.exe" /addpath "C:\Program Files\Bandizip\"C:\Program Files\Bandizip\data\RegDll.x64.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bandizip\data\regdll.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4544"C:\Program Files\Bandizip\updater.exe" /nosleepC:\Program Files\Bandizip\Updater.exe
Bandizip.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip Updater
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4932"C:\Program Files\Bandizip\Bandizip.exe" /setdefaultprogramC:\Program Files\Bandizip\Bandizip.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
HIGH
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5528"C:\Program Files\Bandizip\Bandizip.exe" /setupiffirstC:\Program Files\Bandizip\Bandizip.exeexplorer.exe
User:
admin
Company:
Bandisoft International Inc.
Integrity Level:
MEDIUM
Description:
Bandizip
Exit code:
0
Version:
7.37.0.1
Modules
Images
c:\program files\bandizip\bandizip.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6204"C:\Program Files\Bandizip\data\RegDll.x86.exe" /calldll "C:\Program Files\Bandizip\bdzshl.x86.dll" RegSvrC:\Program Files\Bandizip\data\RegDll.x86.exeBANDIZIP-SETUP-STD-ALL.EXE.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bandizip\data\regdll.x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6344"C:\Users\admin\AppData\Local\Temp\BANDIZIP-SETUP-STD-ALL.EXE.exe" C:\Users\admin\AppData\Local\Temp\BANDIZIP-SETUP-STD-ALL.EXE.exeexplorer.exe
User:
admin
Company:
Bandisoft
Integrity Level:
MEDIUM
Description:
Bandizip 7.37 0 Setup
Exit code:
3221226540
Version:
7.37
Modules
Images
c:\users\admin\appdata\local\temp\bandizip-setup-std-all.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
20 494
Read events
16 951
Write events
3 538
Delete events
5

Modification events

(PID) Process:(7032) Bandizip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Bandizip\l
Operation:writeName:c
Value:
(PID) Process:(7032) Bandizip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Bandizip\l
Operation:writeName:r
Value:
(PID) Process:(7032) Bandizip.exeKey:HKEY_CURRENT_USER\SOFTWARE\Bandizip\l
Operation:writeName:u
Value:
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip
Operation:writeName:Bandizip_bak
Value:
WinRAR.ZIP
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.zip\Shell\Open
Operation:writeName:FriendlyAppName
Value:
Bandizip
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zipx
Operation:writeName:Bandizip_bak
Value:
WinRAR
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.zipx\Shell\Open
Operation:writeName:FriendlyAppName
Value:
Bandizip
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.rar
Operation:writeName:Bandizip_bak
Value:
WinRAR
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Bandizip.rar\Shell\Open
Operation:writeName:FriendlyAppName
Value:
Bandizip
(PID) Process:(7032) Bandizip.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.7z
Operation:writeName:Bandizip_bak
Value:
WinRAR
Executable files
24
Suspicious files
57
Text files
45
Unknown types
1

Dropped files

PID
Process
Filename
Type
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:C357034A3247F5008403ACD50CD212F5
SHA256:1D3B56C4A3133AF11AED73F7D1620A98AAFBF38EE17EFF222340823771A17D8D
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:2D99DAE3E1D2CD1F7DF0F07F4B080818
SHA256:186E7BC6FC830D00B75445562E358DDCC3124D3B6964316A9A16548666AE1D79
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dder
MD5:F0E1375F24FD5570424F09166B1C6E39
SHA256:253AF393B4817356A5035D87FA544C09B49E3C213148EE0AD5AEF754B6097762
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:90192DD5466D357E4C24AA3A9274AB43
SHA256:8056EA44B9E587275B2C2C03EEB662556E67048D0AE0754E95B44FB384B16814
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\data\lm.x64.dllexecutable
MD5:9A0C7D572ABC8B8D67920C60E284C8CB
SHA256:4B8B3355405CF71F6FB99B3A1B35824D008E9EE8ADE67F90CD7593ADBD31AD53
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\ark.x86.lgpl.dllexecutable
MD5:6EC81D6A7D5221F08C5D2EF37D63292C
SHA256:F021D8B7AD25E0EFDAD45A3049DC9AB83B444668A10D6A971A7C004E508A4BB3
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\data\Amsiman.a64.exeexecutable
MD5:22C4164F9B09D1060D21D164D72BD77C
SHA256:508FB442480EAD13357E9C0C2249CAC3DD62DBF2A0574CAF5B8D04927E13A46C
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\bdzshl.x64.dllexecutable
MD5:58087A0B26273CA6AF271B1FA6FCD29A
SHA256:4C699510C70968723A1E3BB0204954782D7B92D327A2D41D37D2023847A59D4A
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\data\webview.x86.dllexecutable
MD5:3E2830F38B646AD31A4010E816A69993
SHA256:8630E5D78CEFEC64E63B56BCEAD2407E0E83484E05174043BB3150725719665E
6500BANDIZIP-SETUP-STD-ALL.EXE.exeC:\Program Files\Bandizip\data\skin.recovery.datacompressed
MD5:0D51FF93EAB045D764E7017E108E1C51
SHA256:74901635E51D4D7824EDBA4B06048356C968E3CC9A42885B318B5C172D7366B4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
16
TCP/UDP connections
52
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5004
svchost.exe
GET
200
23.48.23.159:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.159:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.67.160.244:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5004
svchost.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6500
BANDIZIP-SETUP-STD-ALL.EXE.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
whitelisted
1176
svchost.exe
GET
200
23.67.160.244:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6500
BANDIZIP-SETUP-STD-ALL.EXE.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
whitelisted
6500
BANDIZIP-SETUP-STD-ALL.EXE.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEHby99qPBsQR44pGbdwfRPc%3D
unknown
whitelisted
2744
SIHClient.exe
GET
200
2.19.217.218:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.212.110.137:443
www.bing.com
Akamai International B.V.
CZ
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.159:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5004
svchost.exe
23.48.23.159:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
2.19.217.218:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5004
svchost.exe
2.19.217.218:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
23.67.160.244:80
ocsp.digicert.com
AKAMAI-AS
JP
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.142
whitelisted
www.bing.com
  • 23.212.110.137
  • 23.212.110.136
  • 23.212.110.218
  • 23.212.110.209
  • 23.212.110.138
  • 23.212.110.208
  • 23.212.110.187
  • 23.212.110.200
  • 23.212.110.211
  • 23.212.110.203
  • 23.212.110.217
  • 23.15.178.203
  • 23.15.178.184
  • 23.15.178.234
  • 23.15.178.251
  • 23.15.178.233
  • 23.15.178.200
  • 23.15.178.147
  • 23.15.178.136
  • 23.15.178.179
whitelisted
crl.microsoft.com
  • 23.48.23.159
  • 23.48.23.147
  • 23.48.23.164
  • 23.48.23.145
  • 23.48.23.143
  • 23.48.23.193
  • 23.48.23.156
  • 23.48.23.180
  • 23.48.23.141
whitelisted
www.microsoft.com
  • 2.19.217.218
whitelisted
ocsp.digicert.com
  • 23.67.160.244
  • 2.23.77.188
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.73
  • 40.126.31.130
  • 40.126.31.73
  • 40.126.31.67
  • 20.190.159.75
  • 20.190.159.71
  • 20.190.159.68
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
ver.bandi.so
  • 52.78.169.250
unknown
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted

Threats

No threats detected
No debug info