File name:

Bandicam 4.1.4.1412 Multilingual Portable.7z

Full analysis: https://app.any.run/tasks/71367f49-fac3-4a77-9c97-101000a2200d
Verdict: Malicious activity
Analysis date: April 08, 2025, 03:53:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
advancedinstaller
arch-exec
arch-doc
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

9EE4E14DD8C078B0D9CAAE8D06AE1AF7

SHA1:

7FF5EF1EEF0FB6093C163C4F9429FA9C88B1580B

SHA256:

84AFB28E5C0D11093B2D32139567AA8161D317FEF31B00078269764A6749F24A

SSDEEP:

98304:qqdOlQgoZ0Y6jvLoAXuuYks1phnVFAnrGfbYBjUkrDdiByRFG9t2YavVZM3K/K0b:K8ROqeZJqcpTvsVGcBypfSc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 2136)
      • Bandicam_Portable.exe (PID: 7620)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2136)
      • Bandicam_Portable.exe (PID: 7620)
    • ADVANCEDINSTALLER mutex has been found

      • Bandicam_Portable.exe (PID: 7620)
    • Executable content was dropped or overwritten

      • Bandicam_Portable.exe (PID: 7620)
    • Reads the Windows owner or organization settings

      • Bandicam_Portable.exe (PID: 7620)
    • There is functionality for taking screenshot (YARA)

      • Bandicam_Portable.exe (PID: 7620)
    • Detects AdvancedInstaller (YARA)

      • Bandicam_Portable.exe (PID: 7620)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2136)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 2136)
      • Bandicam_Portable.exe (PID: 7620)
    • Checks supported languages

      • Bandicam_Portable.exe (PID: 7620)
      • msiexec.exe (PID: 7680)
      • msiexec.exe (PID: 7764)
      • Bandicam_Portable.exe (PID: 7824)
    • Reads Environment values

      • Bandicam_Portable.exe (PID: 7620)
    • Create files in a temporary directory

      • Bandicam_Portable.exe (PID: 7620)
    • Creates files or folders in the user directory

      • Bandicam_Portable.exe (PID: 7620)
    • Reads the computer name

      • Bandicam_Portable.exe (PID: 7620)
      • msiexec.exe (PID: 7680)
      • msiexec.exe (PID: 7764)
      • Bandicam_Portable.exe (PID: 7824)
    • Process checks computer location settings

      • Bandicam_Portable.exe (PID: 7620)
    • Reads the software policy settings

      • slui.exe (PID: 7184)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2018:10:19 10:48:42+00:00
ArchivedFileName: Bandicam 4.1.4.1412 Multilingual Portable
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe bandicam_portable.exe no specs bandicam_portable.exe msiexec.exe no specs msiexec.exe no specs bandicam_portable.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2136"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Bandicam 4.1.4.1412 Multilingual Portable.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2320C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7184"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7572"C:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\Bandicam_Portable.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\Bandicam_Portable.exeWinRAR.exe
User:
admin
Company:
Adobe
Integrity Level:
MEDIUM
Description:
This installer database contains the logic and data required to install Adobe Flash Player.
Exit code:
3221226540
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2136.20842\bandicam 4.1.4.1412 multilingual portable\bandicam_portable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7620"C:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\Bandicam_Portable.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\Bandicam_Portable.exe
WinRAR.exe
User:
admin
Company:
Adobe
Integrity Level:
HIGH
Description:
This installer database contains the logic and data required to install Adobe Flash Player.
Version:
1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2136.20842\bandicam 4.1.4.1412 multilingual portable\bandicam_portable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7680C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
7764C:\Windows\syswow64\MsiExec.exe -Embedding FD8213944B77005FE9C410D5BD4EEDA4 CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7824"C:\Users\admin\AppData\Roaming\Adobe\Adobe Flash Player\prerequisites\Bandicam_Portable.exe" C:\Users\admin\AppData\Roaming\Adobe\Adobe Flash Player\prerequisites\Bandicam_Portable.exeBandicam_Portable.exe
User:
admin
Company:
CheshireCat
Integrity Level:
HIGH
Description:
Bandicam Portable
Version:
4.1.4.0
Modules
Images
c:\users\admin\appdata\roaming\adobe\adobe flash player\prerequisites\bandicam_portable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
3 035
Read events
3 027
Write events
8
Delete events
0

Modification events

(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Bandicam 4.1.4.1412 Multilingual Portable.7z
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2136) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
21
Suspicious files
24
Text files
41
Unknown types
0

Dropped files

PID
Process
Filename
Type
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\lang\Arabic.initext
MD5:2E5DD09835488091B504A78E12408AF1
SHA256:80220CDC0C0AAB71CDEB326197F26A6BE8C65B51213B7ABF56300A32C242A605
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\bandicam.initext
MD5:1DA652B83BC9E7506A55F286BFCABBF1
SHA256:667DF660B0561D2A717E4358DDD277315D4778651EF13ECD969CDBA73F84F134
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\data\effects.datbinary
MD5:8125C864B0D52FF4B3230F7FC8C5D553
SHA256:6A94947827CF2D12B8CC203BFC38633AB2BB46CE6BCA3A365B5196F0CB922272
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\bdcamvk32.jsonbinary
MD5:A57121E4D19A606946CCDE17F46E833D
SHA256:03975B3513B256E8AB6194634F0AAD0FAAC698581535908885EB07DCBCFA3E54
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\bdcam64.binexecutable
MD5:6D59FCF0C27A25DFD42C8FF330DFFB9C
SHA256:34FAAF87DF2B28F8337315A0C835013DDAC9A09E0284341C5DE444B3D63BA40C
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\data\language.dattext
MD5:6DE795DAA4608A2822D53ED55CB6182E
SHA256:6F08B95B1AE4B27EA495B8A2CEF0C565A57CA830BFEE9D2E7029DB3E60408A80
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\lang\Armenian.initext
MD5:F1439D3FE7CD1526DFB3B63E504ACEBD
SHA256:599EBED7154D5EDC5B9C8BB797ABDCD0FA1236C739C040BC254548C972AAFF01
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\data\lclick.wavbinary
MD5:EDC287A54E68F13033DD06A688574CDE
SHA256:5C03D7D2366592D9E35264B957131DDEA2676FE505680DE70F5E0878F70CE0C5
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\bdcamvk64.jsonbinary
MD5:ED3D0AC946F68746535893A8E2A43A6F
SHA256:6A9C91903B74385A816AA43A8316443287C827650342A42DFAD01A2947EDE636
2136WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2136.20842\Bandicam 4.1.4.1412 Multilingual Portable\App\Bandicam\lang\Bosnian.initext
MD5:94D123AD9F5060F687FA80C11E7D22C3
SHA256:A56EF839898416E6CE7C11F865AB26515C816BAA54B443FCFB86E3CCF9FEC804
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
15
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
7952
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7952
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7952
SIHClient.exe
20.12.23.50:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7952
SIHClient.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
7952
SIHClient.exe
13.85.23.206:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.49
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
No debug info