File name:

bdcamsetup.exe

Full analysis: https://app.any.run/tasks/b1d861e1-f9a4-4d71-9d36-42d13053b33f
Verdict: Malicious activity
Analysis date: April 14, 2025, 13:31:35
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

138383944F7B2520ECFEB849344B3E58

SHA1:

2BF939665FABCAFEAABBF0A94094E0D1071CAB16

SHA256:

902CB70CAE6EF28569450E70D04B1AB1F4A845225E92CA05AAFB7CB1D5C065D9

SSDEEP:

196608:+UrvAacZkk3IXG7lH7qv8Jfuzgnfqg2Sp6:LrvAFb3IW74vcf1fVp6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • bdcamsetup.exe (PID: 1188)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • bdcamsetup.exe (PID: 1188)
    • There is functionality for taking screenshot (YARA)

      • bdcamsetup.exe (PID: 1188)
  • INFO

    • The sample compiled with arabic language support

      • bdcamsetup.exe (PID: 1188)
    • Checks supported languages

      • bdcamsetup.exe (PID: 1188)
    • Reads the computer name

      • bdcamsetup.exe (PID: 1188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:04:10 12:19:23+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 25600
InitializedDataSize: 431104
UninitializedDataSize: 16896
EntryPoint: 0x33e9
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 3.0.4.1035
ProductVersionNumber: 3.0.4.1035
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Arabic
CharacterSet: Windows, Arabic
Comments: Bandicam Setup File (2016-04-12 오후 2:33:04)
CompanyName: Bandisoft
FileDescription: Bandicam Setup File
FileVersion: 3.0.4.1035
LegalCopyright: Copyright(C) 2009-2016 Bandisoft.com, All rights reserved.
ProductName: Bandicam
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
2
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start bdcamsetup.exe bdcamsetup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1188"C:\Users\admin\Downloads\bdcamsetup.exe" C:\Users\admin\Downloads\bdcamsetup.exe
explorer.exe
User:
admin
Company:
Bandisoft
Integrity Level:
HIGH
Description:
Bandicam Setup File
Version:
3.0.4.1035
Modules
Images
c:\users\admin\downloads\bdcamsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
3176"C:\Users\admin\Downloads\bdcamsetup.exe" C:\Users\admin\Downloads\bdcamsetup.exeexplorer.exe
User:
admin
Company:
Bandisoft
Integrity Level:
MEDIUM
Description:
Bandicam Setup File
Exit code:
3221226540
Version:
3.0.4.1035
Modules
Images
c:\users\admin\downloads\bdcamsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
110
Read events
110
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1188bdcamsetup.exeC:\Users\admin\AppData\Local\Temp\nskDD91.tmp\LangDLL.dllexecutable
MD5:410A586735F45164C86BDA363AD8446F
SHA256:B15B1FC88D1B56088B2D3738D76772A91FA186A316A3E0A154358820D0FB9005
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
7
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.110
whitelisted

Threats

No threats detected
No debug info