File name:

Bandicam 4.1.4.1412 Multilingual Portable.7z

Full analysis: https://app.any.run/tasks/71367f49-fac3-4a77-9c97-101000a2200d
Verdict: Malicious activity
Analysis date: April 08, 2025, 03:53:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
advancedinstaller
arch-exec
arch-doc
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

9EE4E14DD8C078B0D9CAAE8D06AE1AF7

SHA1:

7FF5EF1EEF0FB6093C163C4F9429FA9C88B1580B

SHA256:

84AFB28E5C0D11093B2D32139567AA8161D317FEF31B00078269764A6749F24A

SSDEEP:

98304:qqdOlQgoZ0Y6jvLoAXuuYks1phnVFAnrGfbYBjUkrDdiByRFG9t2YavVZM3K/K0b:K8ROqeZJqcpTvsVGcBypfSc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2136)
      • Bandicam_Portable.exe (PID: 7620)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2136)
      • Bandicam_Portable.exe (PID: 7620)
    • ADVANCEDINSTALLER mutex has been found

      • Bandicam_Portable.exe (PID: 7620)
    • Executable content was dropped or overwritten

      • Bandicam_Portable.exe (PID: 7620)
    • Reads the Windows owner or organization settings

      • Bandicam_Portable.exe (PID: 7620)
    • There is functionality for taking screenshot (YARA)

      • Bandicam_Portable.exe (PID: 7620)
    • Detects AdvancedInstaller (YARA)

      • Bandicam_Portable.exe (PID: 7620)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2136)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 2136)
      • Bandicam_Portable.exe (PID: 7620)
    • Checks supported languages

      • Bandicam_Portable.exe (PID: 7620)
      • msiexec.exe (PID: 7680)
      • msiexec.exe (PID: 7764)
      • Bandicam_Portable.exe (PID: 7824)
    • Reads Environment values

      • Bandicam_Portable.exe (PID: 7620)
    • Create files in a temporary directory

      • Bandicam_Portable.exe (PID: 7620)
    • Creates files or folders in the user directory

      • Bandicam_Portable.exe (PID: 7620)
    • Reads the computer name

      • Bandicam_Portable.exe (PID: 7620)
      • msiexec.exe (PID: 7680)
      • msiexec.exe (PID: 7764)
      • Bandicam_Portable.exe (PID: 7824)
    • Process checks computer location settings

      • Bandicam_Portable.exe (PID: 7620)
    • Reads the software policy settings

      • slui.exe (PID: 7184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2018:10:19 10:48:42+00:00
ArchivedFileName: Bandicam 4.1.4.1412 Multilingual Portable
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe bandicam_portable.exe no specs bandicam_portable.exe msiexec.exe no specs msiexec.exe no specs bandicam_portable.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2136"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Bandicam 4.1.4.1412 Multilingual Portable.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2320C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7184"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7572"C:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\Bandicam_Portable.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\Bandicam_Portable.exeWinRAR.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
This installer database contains the logic and data required to install Adobe Flash Player.
Exit code:
3221226540
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2136.20842\bandicam 4.1.4.1412 multilingual portable\bandicam_portable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7620"C:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\Bandicam_Portable.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\Bandicam_Portable.exe
WinRAR.exe
User:
admin
Company:
Adobe
Integrity Level:
HIGH
Description:
This installer database contains the logic and data required to install Adobe Flash Player.
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2136.20842\bandicam 4.1.4.1412 multilingual portable\bandicam_portable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7680C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7764C:\Windows\syswow64\MsiExec.exe -Embedding FD8213944B77005FE9C410D5BD4EEDA4 CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7824"C:\Users\admin\AppData\Roaming\Adobe\Adobe Flash Player\prerequisites\Bandicam_Portable.exe" C:\Users\admin\AppData\Roaming\Adobe\Adobe Flash Player\prerequisites\Bandicam_Portable.exeBandicam_Portable.exe
User:
admin
Company:
CheshireCat
Integrity Level:
HIGH
Description:
Bandicam Portable
Version:
4.1.4.0
Modules
Images
c:\users\admin\appdata\roaming\adobe\adobe flash player\prerequisites\bandicam_portable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
3 035
Read events
3 027
Write events
8
Delete events
0

Modification events

(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Bandicam 4.1.4.1412 Multilingual Portable.7z
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
21
Suspicious files
24
Text files
41
Unknown types
0

Dropped files

PID
Process
Filename
Type
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\bandicam.initext
MD5:1DA652B83BC9E7506A55F286BFCABBF1
SHA256:667DF660B0561D2A717E4358DDD277315D4778651EF13ECD969CDBA73F84F134
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\bdcamvk32.jsonbinary
MD5:A57121E4D19A606946CCDE17F46E833D
SHA256:03975B3513B256E8AB6194634F0AAD0FAAC698581535908885EB07DCBCFA3E54
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\bdcamvk64.jsonbinary
MD5:ED3D0AC946F68746535893A8E2A43A6F
SHA256:6A9C91903B74385A816AA43A8316443287C827650342A42DFAD01A2947EDE636
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\lang\Bosnian.initext
MD5:94D123AD9F5060F687FA80C11E7D22C3
SHA256:A56EF839898416E6CE7C11F865AB26515C816BAA54B443FCFB86E3CCF9FEC804
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\lang\Arabic.initext
MD5:2E5DD09835488091B504A78E12408AF1
SHA256:80220CDC0C0AAB71CDEB326197F26A6BE8C65B51213B7ABF56300A32C242A605
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\lang\Azerbaijani.initext
MD5:DDE3C33EEF673BA4817368B6F4113D13
SHA256:7DA18DE8ED88885EA666CA3830B5171DAB160BA593703411E58C7865C9706FE9
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\lang\Croatian.initext
MD5:C4533DB41909F5A98EEE78234507872C
SHA256:18214178CE3FAB05AFAF4024C538337024D3C8310DE16B4CB9C31458DBA7B3F1
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\lang\Burmese.inibinary
MD5:38F3BE7B48C5BB12C898784BAE986EB6
SHA256:935F3DEDA48F36450F9D1D692AC244FA5A127523E10BAF809823D0B9AEA454B2
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\data\skin.datcompressed
MD5:7151783691CBC73C6D476740147A48DD
SHA256:E6B00C82A82DCD71360A269F9523705FB4D64CE21EF44939DA071FFFCFA3A0D4
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\data\rclick.wavbinary
MD5:302E0E3B92E3443F60BDBAD8D59EFED3
SHA256:81CAD36978281837C3BA3ABC26D782FE51591EA923BF31FBF3130FF86CD5F752
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
15
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7952
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7952
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7952
SIHClient.exe
20.12.23.50:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7952
SIHClient.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
7952
SIHClient.exe
13.85.23.206:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.49
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
No debug info