File name:

WebLaunchRecorder.exe

Full analysis: https://app.any.run/tasks/d83dc73d-80b3-4d09-a819-9443ffae2079
Verdict: Malicious activity
Analysis date: May 15, 2025, 07:04:58
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

C07737A69091D00DE3CF24E832294EFF

SHA1:

DAE3D15738F29556817030CF2BA2FE5B0DD43B3C

SHA256:

E1B70B55B4A37D2862B84688C849FE82B1D31A23804716ACBAAB66A133811BB6

SSDEEP:

6144:uS58v8WO7TcEsnhwuZAlSUKgRBbbhc331aGcDQ7swVixVI9:uS5q8WO7TcE9uZAlP5dc1b7swVixVI9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • somB7B9.tmp.exe (PID: 4000)
    • Creates a software uninstall entry

      • somB7B9.tmp.exe (PID: 4000)
    • Process drops legitimate windows executable

      • somB7B9.tmp.exe (PID: 4000)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • somB7B9.tmp.exe (PID: 4000)
    • The process drops C-runtime libraries

      • somB7B9.tmp.exe (PID: 4000)
    • Reads security settings of Internet Explorer

      • WebLaunchRecorder.exe (PID: 6028)
    • The process creates files with name similar to system file names

      • somB7B9.tmp.exe (PID: 4000)
  • INFO

    • The sample compiled with english language support

      • WebLaunchRecorder.exe (PID: 6028)
      • somB7B9.tmp.exe (PID: 4000)
    • Reads the computer name

      • WebLaunchRecorder.exe (PID: 6028)
      • somB7B9.tmp.exe (PID: 4000)
      • Screencast-O-Matic.exe (PID: 5548)
    • Create files in a temporary directory

      • WebLaunchRecorder.exe (PID: 6028)
      • somB7B9.tmp.exe (PID: 4000)
      • Screencast-O-Matic.exe (PID: 5548)
    • Checks supported languages

      • WebLaunchRecorder.exe (PID: 6028)
      • somB7B9.tmp.exe (PID: 4000)
      • Screencast-O-Matic.exe (PID: 5548)
    • Creates files or folders in the user directory

      • somB7B9.tmp.exe (PID: 4000)
      • Screencast-O-Matic.exe (PID: 5548)
    • Process checks computer location settings

      • WebLaunchRecorder.exe (PID: 6028)
      • Screencast-O-Matic.exe (PID: 5548)
    • Reads the machine GUID from the registry

      • Screencast-O-Matic.exe (PID: 5548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:04:29 18:49:39+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 251392
InitializedDataSize: 101888
UninitializedDataSize: -
EntryPoint: 0x28029
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Big Nerd Software, LLC
FileDescription: Web Launch Recorder
FileVersion: 2.0.0.0
InternalName: WebLaunchRecorder.exe
LegalCopyright: Copyright (C) 2016
OriginalFileName: WebLaunchRecorder.exe
ProductName: Screencast-O-Matic
ProductVersion: 2.0.0.0
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start weblaunchrecorder.exe sppextcomobj.exe no specs slui.exe no specs somb7b9.tmp.exe screencast-o-matic.exe reg.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
616C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
1324reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductNameC:\Windows\System32\reg.exeScreencast-O-Matic.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3896"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4000"C:\Users\admin\AppData\Local\Temp\somB7B9.tmp.exe"C:\Users\admin\AppData\Local\Temp\somB7B9.tmp.exe
WebLaunchRecorder.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Screencast-O-Matic Web Launcher v2.21.1 (JRE14)
Exit code:
0
Version:
2.21.1.0
Modules
Images
c:\users\admin\appdata\local\temp\somb7b9.tmp.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5548"C:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\Screencast-O-Matic.exe" "screen-recorder-launcher://s/screencast-o-matic.com/launcher/args?id=9daaa5b5-a955-4f8c-9f21-67330250ad78&al=true&exetime=1747292701"C:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\Screencast-O-Matic.exe
WebLaunchRecorder.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Screencast-O-Matic Launcher v2.0
Version:
2.0.0.1
Modules
Images
c:\users\admin\appdata\local\screencast-o-matic\v2_x64\screencast-o-matic.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6028"C:\Users\admin\AppData\Local\Temp\WebLaunchRecorder.exe" C:\Users\admin\AppData\Local\Temp\WebLaunchRecorder.exe
explorer.exe
User:
admin
Company:
Big Nerd Software, LLC
Integrity Level:
MEDIUM
Description:
Web Launch Recorder
Exit code:
0
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\weblaunchrecorder.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7156\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exereg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
1 430
Read events
1 415
Write events
15
Delete events
0

Modification events

(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:DisplayName
Value:
Screencast-O-Matic Web Launcher v2.21.1 (JRE14)
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\som.ico
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:URLInfoAbout
Value:
https://screencast-o-matic.com
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:UninstallString
Value:
C:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\Uninstall.exe
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:Publisher
Value:
Screencast-O-Matic
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:NoModify
Value:
1
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Screencast-O-Matic v2 (WebLauncher-JRE14)
Operation:writeName:NoRepair
Value:
1
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CLASSES_ROOT\screen-recorder-launcher
Operation:writeName:URL Protocol
Value:
(PID) Process:(4000) somB7B9.tmp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
114
(PID) Process:(6028) WebLaunchRecorder.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
Executable files
93
Suspicious files
9
Text files
129
Unknown types
0

Dropped files

PID
Process
Filename
Type
6028WebLaunchRecorder.exeC:\Users\admin\AppData\Local\Temp\somB7B9.tmp.exe
MD5:
SHA256:
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\releasetext
MD5:742CB5A10272D69B14CE84BD78E8BE84
SHA256:5F2692357FAE815ACC90F3A3D766C2AF4498535C745827CCCF268196321563F4
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:944A33D971704FF815A6C90733D0A72E
SHA256:44822AE123A3D6C3A8BDF9A4D65A4DC89EB31004C72FCFCEFA1DC3A53FF3EAB0
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-handle-l1-1-0.dllexecutable
MD5:31FFFF2C6539B3D2F575500300B93D6B
SHA256:6DCBDAB7FA8CF66F4A05D1F5166BED33CD88BEE1D37AF6128F18184E6C301709
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-console-l1-2-0.dllexecutable
MD5:7A55E51D07E1F15221EB11479ADBC53F
SHA256:F901B0BC8C00B3AFC80E151E6F54B18F7672F932602C304FBFEEDD5AA3AD63C8
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-interlocked-l1-1-0.dllexecutable
MD5:1144CED0D8198C39F62FC71C1ECF6CB1
SHA256:D4D86E560A22D833FCDF0BA165D3BD3F6059E69830F4D2F9748AF08905B2D4C8
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-file-l2-1-0.dllexecutable
MD5:2E8995E2320E313545C3DDB5C71DC232
SHA256:C55EB043454AC2D460F86EA26F934ECB16BDB1D05294C168193A05090BF1C56C
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-heap-l1-1-0.dllexecutable
MD5:C7120579BB8F56F8CD4E0D329ECE3E9D
SHA256:2E00C0176952D7C009B93C40949F91F0AB367A1B274EE78B736BF563F0344DA3
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-file-l1-1-0.dllexecutable
MD5:FEC01082BCCDDADAD0814F30B43AB078
SHA256:C15DACEC228F40CE4C5B9D69BBA5E6627BC484C6E9D6550A76DB6F332E9F7734
4000somB7B9.tmp.exeC:\Users\admin\AppData\Local\Screencast-O-Matic\v2_x64\jre-14.0.1\bin\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:02D669AFDABFE420598041B848B71158
SHA256:64A9AC181FD91B79270BF01759749394F57BE171436ED46F43D165325BB82067
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
26
DNS requests
18
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
756
lsass.exe
GET
200
18.245.38.41:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
unknown
whitelisted
756
lsass.exe
GET
200
18.245.65.219:80
http://ocsp.r2m02.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRmbQtwnInkvkvr7BNFR%2BS2lTYPjAQUwDFSzVpQw4J8dHHOy%2Bmc%2BXrrguICEATnj3kYTp8XdXqkAEUfnDY%3D
unknown
whitelisted
756
lsass.exe
GET
200
18.245.65.219:80
http://ocsp.r2m02.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRmbQtwnInkvkvr7BNFR%2BS2lTYPjAQUwDFSzVpQw4J8dHHOy%2Bmc%2BXrrguICEAEgzj0uEwz6KzhuXyWHhes%3D
unknown
whitelisted
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5548
Screencast-O-Matic.exe
GET
200
54.164.66.30:80
http://screencast-o-matic.com/checkproxy
unknown
whitelisted
2772
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2772
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
4
System
192.168.100.255:138
whitelisted
6028
WebLaunchRecorder.exe
54.164.66.30:443
screencast-o-matic.com
AMAZON-AES
US
whitelisted
756
lsass.exe
18.245.38.41:80
ocsp.rootca1.amazontrust.com
US
whitelisted
756
lsass.exe
18.245.65.219:80
ocsp.r2m02.amazontrust.com
US
whitelisted
6028
WebLaunchRecorder.exe
35.170.87.67:443
screencast-o-matic.com
AMAZON-AES
US
whitelisted
6028
WebLaunchRecorder.exe
52.222.214.54:443
files2.screencast-o-matic.com
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 95.101.149.131
whitelisted
screencast-o-matic.com
  • 54.164.66.30
  • 35.170.87.67
  • 54.157.67.105
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.38.41
whitelisted
ocsp.r2m02.amazontrust.com
  • 18.245.65.219
whitelisted
screenpal.com
  • 35.170.87.67
  • 54.157.67.105
  • 54.164.66.30
unknown
files2.screencast-o-matic.com
  • 52.222.214.54
  • 52.222.214.74
  • 52.222.214.52
  • 52.222.214.47
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted

Threats

PID
Process
Class
Message
5548
Screencast-O-Matic.exe
Potentially Bad Traffic
ET INFO Vulnerable Java Version 14.0.x Detected
No debug info