File name:

WebLaunchRecorder.exe

Full analysis: https://app.any.run/tasks/d83dc73d-80b3-4d09-a819-9443ffae2079
Verdict: Malicious activity
Analysis date: May 15, 2025, 07:04:58
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

C07737A69091D00DE3CF24E832294EFF

SHA1:

DAE3D15738F29556817030CF2BA2FE5B0DD43B3C

SHA256:

E1B70B55B4A37D2862B84688C849FE82B1D31A23804716ACBAAB66A133811BB6

SSDEEP:

6144:uS58v8WO7TcEsnhwuZAlSUKgRBbbhc331aGcDQ7swVixVI9:uS5q8WO7TcE9uZAlP5dc1b7swVixVI9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • somB7B9.tmp.exe (PID: 4000)
    • The process drops C-runtime libraries

      • somB7B9.tmp.exe (PID: 4000)
    • Process drops legitimate windows executable

      • somB7B9.tmp.exe (PID: 4000)
    • Creates a software uninstall entry

      • somB7B9.tmp.exe (PID: 4000)
    • The process creates files with name similar to system file names

      • somB7B9.tmp.exe (PID: 4000)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • somB7B9.tmp.exe (PID: 4000)
    • Reads security settings of Internet Explorer

      • WebLaunchRecorder.exe (PID: 6028)
  • INFO

    • Checks supported languages

      • WebLaunchRecorder.exe (PID: 6028)
      • somB7B9.tmp.exe (PID: 4000)
      • Screencast-O-Matic.exe (PID: 5548)
    • Create files in a temporary directory

      • WebLaunchRecorder.exe (PID: 6028)
      • somB7B9.tmp.exe (PID: 4000)
      • Screencast-O-Matic.exe (PID: 5548)
    • The sample compiled with english language support

      • WebLaunchRecorder.exe (PID: 6028)
      • somB7B9.tmp.exe (PID: 4000)
    • Reads the computer name

      • WebLaunchRecorder.exe (PID: 6028)
      • somB7B9.tmp.exe (PID: 4000)
      • Screencast-O-Matic.exe (PID: 5548)
    • Creates files or folders in the user directory

      • somB7B9.tmp.exe (PID: 4000)
      • Screencast-O-Matic.exe (PID: 5548)
    • Process checks computer location settings

      • WebLaunchRecorder.exe (PID: 6028)
      • Screencast-O-Matic.exe (PID: 5548)
    • Reads the machine GUID from the registry

      • Screencast-O-Matic.exe (PID: 5548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:04:29 18:49:39+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 251392
InitializedDataSize: 101888
UninitializedDataSize: -
EntryPoint: 0x28029
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Big Nerd Software, LLC
FileDescription: Web Launch Recorder
FileVersion: 2.0.0.0
InternalName: WebLaunchRecorder.exe
LegalCopyright: Copyright (C) 2016
OriginalFileName: WebLaunchRecorder.exe
ProductName: Screencast-O-Matic
ProductVersion: 2.0.0.0
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start weblaunchrecorder.exe sppextcomobj.exe no specs slui.exe no specs somb7b9.tmp.exe screencast-o-matic.exe reg.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
616C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
1324reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductNameC:\Windows\System32\reg.exeScreencast-O-Matic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3896"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4000"C:\Users\admin\AppData\Local\Temp\somB7B9.tmp.exe"C:\Users\admin\AppData\Local\Temp\somB7B9.tmp.exe
WebLaunchRecorder.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Screencast-O-Matic Web Launcher v2.21.1 (JRE14)
Exit code:
0
Version:
2.21.1.0
Modules
Images
c:\users\admin\appdata\local\temp\somb7b9.tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5548"C:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\Screencast-O-Matic.exe" "screen-recorder-launcher://s/screencast-o-matic.com/launcher/args?id=9daaa5b5-a955-4f8c-9f21-67330250ad78&al=true&exetime=1747292701"C:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\Screencast-O-Matic.exe
WebLaunchRecorder.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Screencast-O-Matic Launcher v2.0
Version:
2.0.0.1
Modules
Images
c:\users\admin\appdata\local\screencast-o-matic\v2_x64\screencast-o-matic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6028"C:\Users\admin\AppData\Local\Temp\WebLaunchRecorder.exe" C:\Users\admin\AppData\Local\Temp\WebLaunchRecorder.exe
explorer.exe
User:
admin
Company:
Big Nerd Software, LLC
Integrity Level:
MEDIUM
Description:
Web Launch Recorder
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\weblaunchrecorder.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7156\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exereg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
1 430
Read events
1 415
Write events
15
Delete events
0

Modification events

(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:DisplayName
Value:
Screencast-O-Matic Web Launcher v2.21.1 (JRE14)
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\som.ico
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:URLInfoAbout
Value:
https://screencast-o-matic.com
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:UninstallString
Value:
C:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\Uninstall.exe
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:Publisher
Value:
Screencast-O-Matic
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:NoModify
Value:
1
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:NoRepair
Value:
1
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CLASSES_ROOT\screen-recorder-launcher
Operation:writeName:URL Protocol
Value:
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
114
(PID) Process:(6028) WebLaunchRecorder.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
Executable files
93
Suspicious files
9
Text files
129
Unknown types
0

Dropped files

PID
Process
Filename
Type
6028WebLaunchRecorder.exeC:\Users\admin\AppData\Local\Temp\somB7B9.tmp.exe
MD5:
SHA256:
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:2C146BC8D73B8944F35506241B9953A9
SHA256:89384F8F64A9B7F67C8DECCAA721E2D76B8A17026D8083630859ED0CD1A9B58B
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:B5060343583E6BE3B3DE33CCD40398E0
SHA256:27878021C6D48FB669F1822821B5934F5A2904740BEBB340B6849E7635490CB7
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:02D669AFDABFE420598041B848B71158
SHA256:64A9AC181FD91B79270BF01759749394F57BE171436ED46F43D165325BB82067
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\releasetext
MD5:742CB5A10272D69B14CE84BD78E8BE84
SHA256:5F2692357FAE815ACC90F3A3D766C2AF4498535C745827CCCF268196321563F4
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:944A33D971704FF815A6C90733D0A72E
SHA256:44822AE123A3D6C3A8BDF9A4D65A4DC89EB31004C72FCFCEFA1DC3A53FF3EAB0
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:F0C9C56F56FFA3ADC548173569DBD793
SHA256:12D801992BBB09D43BB90330BB96E77BF12E669C325DDA4B5235942221C301C8
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-memory-l1-1-0.dllexecutable
MD5:E7B662FFA023B7F07A85AC3FB8910C11
SHA256:13AE84007249D532F326A00AD62E5C1F463581F30701E662BB1B3658C4C32A07
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-processthreads-l1-1-1.dllexecutable
MD5:D1B3CC23127884D9EFF1940F5B98E7AA
SHA256:51A73FBFA2AFE5E45962031618EC347AAA0857B11F3CF273F4C218354BFE70CB
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-libraryloader-l1-1-0.dllexecutable
MD5:2ACF6DB396A86E2BEF9D6DDF6919581F
SHA256:655BADE7FF61F01A803E7532082B14AE354442B0F65EF8164F824D0CFA033E6F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
26
DNS requests
18
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
756
lsass.exe
GET
200
18.245.38.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
unknown
whitelisted
756
lsass.exe
GET
200
18.245.65.219:80
http://ocsp.r2m02.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRmbQtwnInkvkvr7BNFR%2BS2lTYPjAQUwDFSzVpQw4J8dHHOy%2Bmc%2BXrrguICEATnj3kYTp8XdXqkAEUfnDY%3D
unknown
whitelisted
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
756
lsass.exe
GET
200
18.245.65.219:80
http://ocsp.r2m02.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRmbQtwnInkvkvr7BNFR%2BS2lTYPjAQUwDFSzVpQw4J8dHHOy%2Bmc%2BXrrguICEAEgzj0uEwz6KzhuXyWHhes%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5548
Screencast-O-Matic.exe
GET
200
54.164.66.30:80
http://screencast-o-matic.com/checkproxy
unknown
whitelisted
2772
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2772
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
4
System
192.168.100.255:138
whitelisted
6028
WebLaunchRecorder.exe
54.164.66.30:443
screencast-o-matic.com
AMAZON-AES
US
whitelisted
756
lsass.exe
18.245.38.41:80
ocsp.rootca1.amazontrust.com
US
whitelisted
756
lsass.exe
18.245.65.219:80
ocsp.r2m02.amazontrust.com
US
whitelisted
6028
WebLaunchRecorder.exe
35.170.87.67:443
screencast-o-matic.com
AMAZON-AES
US
whitelisted
6028
WebLaunchRecorder.exe
52.222.214.54:443
files2.screencast-o-matic.com
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 95.101.149.131
whitelisted
screencast-o-matic.com
  • 54.164.66.30
  • 35.170.87.67
  • 54.157.67.105
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.38.41
whitelisted
ocsp.r2m02.amazontrust.com
  • 18.245.65.219
whitelisted
screenpal.com
  • 35.170.87.67
  • 54.157.67.105
  • 54.164.66.30
unknown
files2.screencast-o-matic.com
  • 52.222.214.54
  • 52.222.214.74
  • 52.222.214.52
  • 52.222.214.47
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted

Threats

PID
Process
Class
Message
5548
Screencast-O-Matic.exe
Potentially Bad Traffic
ET INFO Vulnerable Java Version 14.0.x Detected
No debug info