File name: | Recorder-devices-setup.exe |
Full analysis: | https://app.any.run/tasks/2d3affd7-7b0f-447f-987d-b49c9ae1ca38 |
Verdict: | Malicious activity |
Analysis date: | June 06, 2025, 12:30:54 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections |
MD5: | C04EA87A65BC213796D30FBA5042D86D |
SHA1: | 2286675F46E4650840BB020B8D61736ECA4DB482 |
SHA256: | 83010C58D5738A8DBF011C67FEDA1A3DF11943BDAA03F7EB9FAC5613A87FD377 |
SSDEEP: | 49152:+did6SjaviMUfHjT54GRpbI8+Qy5FST0Da1mW+Vbqdjs3xZMEK9TeudYWzpfDt6F:H6GavilX54GRpbINT4TALW+VbqVs3xZ5 |
.exe | | | Inno Setup installer (53.5) |
---|---|---|
.exe | | | InstallShield setup (21) |
.exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
.exe | | | Win32 Executable (generic) (2.1) |
.exe | | | Win16/32 Executable Delphi generic (1) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2025:01:08 15:36:35+00:00 |
ImageFileCharacteristics: | Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 684032 |
InitializedDataSize: | 159744 |
UninitializedDataSize: | - |
EntryPoint: | 0xa7f98 |
OSVersion: | 6.1 |
ImageVersion: | - |
SubsystemVersion: | 6.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 0.0.0.0 |
ProductVersionNumber: | 0.0.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | This installation was built with Inno Setup. |
CompanyName: | |
FileDescription: | Recorder Devices for ShareX Setup |
FileVersion: | |
LegalCopyright: | |
OriginalFileName: | |
ProductName: | Recorder Devices for ShareX |
ProductVersion: | 0.12.10 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
960 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Recorder Devices for ShareX\screen-capture-recorder-x64.dll" | C:\Windows\System32\regsvr32.exe | — | Recorder-devices-setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1040 | "C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" | C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Recorder Devices for ShareX Setup Exit code: 0 Version: Modules
| |||||||||||||||
1512 | "C:\Users\admin\AppData\Local\Temp\is-2E1L9.tmp\Recorder-devices-setup.tmp" /SL5="$C034E,912787,844800,C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" /SPAWNWND=$C00BE /NOTIFYWND=$90274 | C:\Users\admin\AppData\Local\Temp\is-2E1L9.tmp\Recorder-devices-setup.tmp | Recorder-devices-setup.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
1568 | "C:\Users\admin\AppData\Local\Temp\is-8UUB0.tmp\vcredist2010_x64.exe" /passive /norestart | C:\Users\admin\AppData\Local\Temp\is-8UUB0.tmp\vcredist2010_x64.exe | Recorder-devices-setup.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2010 x64 Redistributable Setup Exit code: 0 Version: 10.0.40219.325 Modules
| |||||||||||||||
1616 | "C:\Users\admin\AppData\Local\Temp\is-HAKKI.tmp\Recorder-devices-setup.tmp" /SL5="$60288,912787,844800,C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" | C:\Users\admin\AppData\Local\Temp\is-HAKKI.tmp\Recorder-devices-setup.tmp | — | Recorder-devices-setup.exe | |||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 2 Version: 51.1052.0.0 Modules
| |||||||||||||||
2656 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Recorder Devices for ShareX\virtual-audio-capturer-x64.dll" | C:\Windows\System32\regsvr32.exe | — | Recorder-devices-setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
3768 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Recorder Devices for ShareX\screen-capture-recorder-x64.dll" | C:\Windows\System32\regsvr32.exe | — | Recorder-devices-setup.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
3828 | "C:\Users\admin\AppData\Local\Temp\is-V11IM.tmp\Recorder-devices-setup.tmp" /SL5="$B02A0,912787,844800,C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" | C:\Users\admin\AppData\Local\Temp\is-V11IM.tmp\Recorder-devices-setup.tmp | — | Recorder-devices-setup.exe | |||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
4560 | "C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe" /SPAWNWND=$80348 /NOTIFYWND=$B02A0 | C:\Users\admin\AppData\Local\Temp\Recorder-devices-setup.exe | Recorder-devices-setup.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Recorder Devices for ShareX Setup Exit code: 0 Version: Modules
| |||||||||||||||
5024 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
|
(PID) Process: | (6820) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001 |
Operation: | write | Name: | Owner |
Value: A41A000079C4F7E4DED6DB01 | |||
(PID) Process: | (6820) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001 |
Operation: | write | Name: | SessionHash |
Value: 962E8F3548F6D6EC0479AA31165AE3E3671676C95C2D16DE7BE9CF3106272DD8 | |||
(PID) Process: | (6820) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0001 |
Operation: | write | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (6820) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders |
Operation: | write | Name: | c:\Config.Msi\ |
Value: | |||
(PID) Process: | (6820) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts |
Operation: | write | Name: | c:\Config.Msi\123311.rbs |
Value: 31184606 | |||
(PID) Process: | (6820) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts |
Operation: | write | Name: | c:\Config.Msi\123311.rbsLow |
Value: | |||
(PID) Process: | (6820) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0480DC222D01C4F37A2077C032048022 |
Operation: | write | Name: | 1926E8D15D0BCE53481466615F760A7F |
Value: 02:\SOFTWARE\Microsoft\VisualStudio\10.0\VC\VCRedist\x64\Version | |||
(PID) Process: | (6820) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C065BA555D648923380AAA2171113286 |
Operation: | write | Name: | 1926E8D15D0BCE53481466615F760A7F |
Value: 02:\SOFTWARE\Microsoft\DevDiv\vc\Servicing\10.0\red\amd64\1033\Install | |||
(PID) Process: | (6820) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
Operation: | write | Name: | c:\Program Files\Common Files\Microsoft Shared\VC\msdia100.dll |
Value: 1 | |||
(PID) Process: | (6820) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\94422102FB8324F41B3E7CD7B422BDC7 |
Operation: | write | Name: | 1926E8D15D0BCE53481466615F760A7F |
Value: c:\?Program Files\Common Files\Microsoft Shared\VC\msdia100.dll |
PID | Process | Filename | Type | |
---|---|---|---|---|
1512 | Recorder-devices-setup.tmp | C:\Users\admin\AppData\Local\Temp\is-8UUB0.tmp\is-04U5G.tmp | executable | |
MD5:02A945866CD1B13E2375C024F0E18301 | SHA256:F3B7A76D84D23F91957AA18456A14B4E90609E4CE8194C5653384ED38DADA6F3 | |||
6148 | Recorder-devices-setup.exe | C:\Users\admin\AppData\Local\Temp\is-2E1L9.tmp\Recorder-devices-setup.tmp | executable | |
MD5:998C1046FD9851A2CBE08E8432FBBCEB | SHA256:BB0ECB905EF428867C55899D577AEC1AAF822AE756063C754D3FDB245B9003BA | |||
1568 | vcredist2010_x64.exe | C:\78a395924524f76076\SetupUi.dll | executable | |
MD5:0D214CED87BF0B55883359160A68DACB | SHA256:29CF99D7E67B4C54BAFD109577A385387A39301BCDEC8AE4BA1A8A0044306713 | |||
1568 | vcredist2010_x64.exe | C:\78a395924524f76076\DisplayIcon.ico | image | |
MD5:F9657D290048E169FFABBBB9C7412BE0 | SHA256:B74AD253B9B8F9FCADE725336509143828EE739CC2B24782BE3ECFF26F229160 | |||
1512 | Recorder-devices-setup.tmp | C:\Users\admin\AppData\Local\Temp\is-8UUB0.tmp\vcredist2010_x64.exe | executable | |
MD5:02A945866CD1B13E2375C024F0E18301 | SHA256:F3B7A76D84D23F91957AA18456A14B4E90609E4CE8194C5653384ED38DADA6F3 | |||
1568 | vcredist2010_x64.exe | C:\78a395924524f76076\SetupEngine.dll | executable | |
MD5:63E7901D4FA7AC7766076720272060D0 | SHA256:A5116CCB17B242713E5645C2374ABF5827C0D2752B31553E3540C9123812E952 | |||
1568 | vcredist2010_x64.exe | C:\78a395924524f76076\Setup.exe | executable | |
MD5:2AF2C1A78542975B12282ACA4300D515 | SHA256:531EB45798728CB741043B28B8C1A4F75536DC75F92D100F55F9109D2D63F0D7 | |||
1568 | vcredist2010_x64.exe | C:\78a395924524f76076\SetupUi.xsd | xml | |
MD5:2FADD9E618EFF8175F2A6E8B95C0CACC | SHA256:222211E8F512EDF97D78BC93E1F271C922D5E91FA899E092B4A096776A704093 | |||
1568 | vcredist2010_x64.exe | C:\78a395924524f76076\SplashScreen.bmp | image | |
MD5:43B254D97B4FB6F9974AD3F935762C55 | SHA256:91A21EBA9F5E1674919EE3B36EFA99714CFB919491423D888CB56C0F25845969 | |||
1568 | vcredist2010_x64.exe | C:\78a395924524f76076\sqmapi.dll | executable | |
MD5:3F0363B40376047EFF6A9B97D633B750 | SHA256:BD6395A58F55A8B1F4063E813CE7438F695B9B086BB965D8AC44E7A97D35A93C |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.168.124:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6960 | svchost.exe | GET | 200 | 2.16.168.124:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6820 | msiexec.exe | GET | 200 | 2.16.168.124:80 | http://crl.microsoft.com/pki/crl/products/CSPCA.crl | unknown | — | — | whitelisted |
7424 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7424 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
2924 | SearchApp.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
2924 | SearchApp.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6960 | svchost.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5608 | RUXIMICS.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.168.124:80 | crl.microsoft.com | Akamai International B.V. | RU | whitelisted |
6960 | svchost.exe | 2.16.168.124:80 | crl.microsoft.com | Akamai International B.V. | RU | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
6960 | svchost.exe | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6960 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1512 | Recorder-devices-setup.tmp | 23.212.89.111:443 | download.microsoft.com | AKAMAI-AS | MX | whitelisted |
Domain | IP | Reputation |
---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
download.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |