File name:

keymaker.exe

Full analysis: https://app.any.run/tasks/10466645-0af2-4b82-9302-98fd37b478c4
Verdict: Malicious activity
Analysis date: December 01, 2023, 14:28:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E2B75C862BB136D9A9168929A6C9A00A

SHA1:

CF200B6759A3429159FA6AAAFF239042CADC8BD7

SHA256:

E1D78799D1CD43DC5A9C3C7306439B04D6C5AC99FA9ADC3FD1FD5032676E1077

SSDEEP:

1536:9/IKEJRjZa7NdUYjolwbxrtoE2sTe07UII:SKEJRdkTNjKI6fg7E

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • bdcamsetup.exe (PID: 2532)
      • BDMPEG1SETUP.EXE (PID: 1988)
    • Registers / Runs the DLL via REGSVR32.EXE

      • BDMPEG1SETUP.EXE (PID: 1988)
    • Creates a writable file in the system directory

      • BDMPEG1SETUP.EXE (PID: 1988)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • bdcamsetup.exe (PID: 2532)
      • BDMPEG1SETUP.EXE (PID: 1988)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • bdcamsetup.exe (PID: 2532)
      • BDMPEG1SETUP.EXE (PID: 1988)
    • Uses RUNDLL32.EXE to load library

      • bdcam.exe (PID: 3144)
    • Reads the Internet Settings

      • bdcam.exe (PID: 3144)
      • bdcamsetup.exe (PID: 2532)
      • bdcam.exe (PID: 3232)
      • mmc.exe (PID: 1936)
      • bdcam.exe (PID: 1032)
      • bdcam.exe (PID: 3160)
    • Creates a software uninstall entry

      • bdcamsetup.exe (PID: 2532)
    • Reads settings of System Certificates

      • bdcam.exe (PID: 3232)
      • bdcam.exe (PID: 3160)
    • Reads security settings of Internet Explorer

      • bdcam.exe (PID: 3232)
      • bdcam.exe (PID: 3160)
    • Checks Windows Trust Settings

      • bdcam.exe (PID: 3232)
      • bdcam.exe (PID: 3160)
    • Adds/modifies Windows certificates

      • bdcam.exe (PID: 3232)
    • Reads Microsoft Outlook installation path

      • bdcam.exe (PID: 3232)
      • bdcam.exe (PID: 1032)
      • bdcam.exe (PID: 3160)
    • Reads Internet Explorer settings

      • bdcam.exe (PID: 3160)
  • INFO

    • Create files in a temporary directory

      • bdcamsetup.exe (PID: 2532)
      • BDMPEG1SETUP.EXE (PID: 1988)
    • Checks supported languages

      • bdcamsetup.exe (PID: 2532)
      • keymaker.exe (PID: 3476)
      • BDMPEG1SETUP.EXE (PID: 1988)
      • bdcam.exe (PID: 3144)
      • wmpnscfg.exe (PID: 3700)
      • bdcam.exe (PID: 1032)
      • keymaker.exe (PID: 3072)
      • keymaker.exe (PID: 2876)
      • bdcam.exe (PID: 3232)
      • keymaker.exe (PID: 3956)
      • bdcam.exe (PID: 3160)
    • Manual execution by a user

      • bdcamsetup.exe (PID: 2532)
      • bdcamsetup.exe (PID: 3592)
      • msedge.exe (PID: 3204)
      • wmpnscfg.exe (PID: 3700)
      • keymaker.exe (PID: 3072)
      • keymaker.exe (PID: 2876)
      • mmc.exe (PID: 2204)
      • mmc.exe (PID: 1936)
      • bdcam.exe (PID: 3872)
      • bdcam.exe (PID: 3232)
      • keymaker.exe (PID: 3956)
      • bdcam.exe (PID: 3412)
      • bdcam.exe (PID: 3160)
    • Reads Environment values

      • bdcamsetup.exe (PID: 2532)
      • BDMPEG1SETUP.EXE (PID: 1988)
    • Reads the computer name

      • bdcamsetup.exe (PID: 2532)
      • BDMPEG1SETUP.EXE (PID: 1988)
      • wmpnscfg.exe (PID: 3700)
      • bdcam.exe (PID: 3144)
      • bdcam.exe (PID: 3232)
      • bdcam.exe (PID: 3160)
      • bdcam.exe (PID: 1032)
    • Creates files in the program directory

      • BDMPEG1SETUP.EXE (PID: 1988)
      • bdcamsetup.exe (PID: 2532)
    • Checks proxy server information

      • bdcamsetup.exe (PID: 2532)
      • bdcam.exe (PID: 3232)
      • bdcam.exe (PID: 1032)
      • bdcam.exe (PID: 3160)
    • Application launched itself

      • msedge.exe (PID: 644)
      • msedge.exe (PID: 3204)
    • Reads the machine GUID from the registry

      • bdcam.exe (PID: 3232)
      • bdcam.exe (PID: 3160)
      • bdcam.exe (PID: 1032)
    • Creates files or folders in the user directory

      • bdcam.exe (PID: 3232)
      • bdcam.exe (PID: 3160)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: -
CodeSize: 6144
InitializedDataSize: 47104
UninitializedDataSize: -
EntryPoint: 0x100d4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
97
Monitored processes
34
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start keymaker.exe no specs bdcamsetup.exe no specs bdcamsetup.exe bdmpeg1setup.exe no specs regsvr32.exe no specs bdcam.exe no specs rundll32.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wmpnscfg.exe no specs msedge.exe no specs msedge.exe no specs keymaker.exe no specs keymaker.exe bdcam.exe no specs bdcam.exe mmc.exe no specs mmc.exe bdcam.exe keymaker.exe bdcam.exe no specs bdcam.exe

Process information

PID
CMD
Path
Indicators
Parent process
644"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.bandicam.com/f.php?id=eng_app_complete_install&v=2&lang=enC:\Program Files\Microsoft\Edge\Application\msedge.exebdcamsetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
900"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1508 --field-trial-handle=1264,i,9462568745769468768,15686940301888756478,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1032"C:\Program Files\Bandicam\bdcam.exe" "C:\Program Files\Bandicam\bdcam_safemode.lnk"C:\Program Files\Bandicam\bdcam.exe
mmc.exe
User:
admin
Company:
Bandicam Company
Integrity Level:
HIGH
Description:
Bandicam - bdcam.exe
Exit code:
2
Version:
4.5.3.1608
Modules
Images
c:\program files\bandicam\bdcam.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msimg32.dll
1784"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1624 --field-trial-handle=1284,i,1071331320307201576,10690616515901496197,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1936"C:\Windows\system32\mmc.exe" "C:\Windows\system32\WF.msc" C:\Windows\System32\mmc.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Management Console
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mmc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mfc42u.dll
1988C:\Users\admin\AppData\Local\Temp\BDMPEG1SETUP.EXE /SC:\Users\admin\AppData\Local\Temp\BDMPEG1SETUP.EXEbdcamsetup.exe
User:
admin
Company:
Bandicam Company
Integrity Level:
HIGH
Description:
Bandicam MPEG-1 Decoder Setup File
Exit code:
0
Version:
V1.0.5.17
Modules
Images
c:\users\admin\appdata\local\temp\bdmpeg1setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2004"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3808 --field-trial-handle=1284,i,1071331320307201576,10690616515901496197,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2064"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6a7af598,0x6a7af5a8,0x6a7af5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2204"C:\Windows\system32\mmc.exe" "C:\Windows\system32\WF.msc" C:\Windows\System32\mmc.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Management Console
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mmc.exe
c:\windows\system32\ntdll.dll
2328"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3792 --field-trial-handle=1284,i,1071331320307201576,10690616515901496197,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
17 044
Read events
15 727
Write events
1 307
Delete events
10

Modification events

(PID) Process:(3144) bdcam.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3144) bdcam.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3144) bdcam.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3144) bdcam.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3144) bdcam.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
(PID) Process:(2532) bdcamsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bandicam
Operation:writeName:DisplayVersion
Value:
4.5.3.1608
(PID) Process:(2532) bdcamsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bandicam
Operation:writeName:InstallLocation
Value:
"C:\Program Files\Bandicam"
(PID) Process:(2532) bdcamsetup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bandicam
Operation:writeName:Publisher
Value:
Bandicam.com
(PID) Process:(2532) bdcamsetup.exeKey:HKEY_CURRENT_USER\Software\BANDISOFT\BANDICAM
Operation:writeName:ProgramFolder
Value:
C:\Program Files\Bandicam
(PID) Process:(2532) bdcamsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
32
Suspicious files
97
Text files
106
Unknown types
0

Dropped files

PID
Process
Filename
Type
1988BDMPEG1SETUP.EXEC:\Users\admin\AppData\Local\Temp\nsq54D7.tmp
MD5:
SHA256:
2532bdcamsetup.exeC:\Users\admin\AppData\Local\Temp\nsn41BC.tmp\UserInfo.dllexecutable
MD5:1B446B36F5B4022D50FFDC0CF567B24A
SHA256:2862C7BC7F11715CEBDEA003564A0D70BF42B73451E2B672110E1392EC392922
2532bdcamsetup.exeC:\Users\admin\AppData\Local\Temp\nsn41BC.tmp\ioSpecial.initext
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
2532bdcamsetup.exeC:\Users\admin\AppData\Local\Temp\nsn41BC.tmp\modern-header.bmpimage
MD5:E76A5505A53440C94705BBD6B81EE9DA
SHA256:D35892F125FC5B7AF8EAB35C5D92A02E310DF2156F631A564598D04248F5D77F
2532bdcamsetup.exeC:\Users\admin\AppData\Local\Temp\nsn41BC.tmp\modern-wizard.bmpimage
MD5:DF49E245ECA7BB28691FAF396C32B934
SHA256:B751FA1A1A2291BA1282D49936CD641C4E4340794F475294ABD5E4817952A41E
1988BDMPEG1SETUP.EXEC:\Program Files\BandiMPEG1\bdfilters.dllexecutable
MD5:ED730387FDCD684B756601B863C47417
SHA256:9CBC29696AD2D582E251BF9C4BE5CCE618753FA43551D2474E1AE5CC5E1245E5
2532bdcamsetup.exeC:\Users\admin\AppData\Local\Temp\nsn41BC.tmp\System.dllexecutable
MD5:17ED1C86BD67E78ADE4712BE48A7D2BD
SHA256:BD046E6497B304E4EA4AB102CAB2B1F94CE09BDE0EEBBA4C59942A732679E4EB
2532bdcamsetup.exeC:\Users\admin\AppData\Local\Temp\nsn41BC.tmp\InstallOptions.dllexecutable
MD5:720304C57DCFA17751ED455B3BB9C10A
SHA256:6486029D3939231BD9F10457FD9A5AB2E44F30315AF443197A3347DF4E18C4E9
2532bdcamsetup.exeC:\Users\admin\AppData\Local\Temp\nsn41BC.tmp\LangDLL.dllexecutable
MD5:F1E9EED02DB3A822A7DDEF0C724E5F1F
SHA256:6DFF504C6759C418C6635C9B25B8C91D0D9EF7787A3A93610D7670BB563C09DF
2532bdcamsetup.exeC:\Program Files\Bandicam\bdcam.exeexecutable
MD5:31F47581CD57630D6D1338F0DB90D907
SHA256:5BF812947CC310CCA7FDB73EC1425E1FBBE393ACA40DC1975E138A6FCFCAE316
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
38
DNS requests
46
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3232
bdcam.exe
GET
200
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?61548cf8afa6a91e
unknown
compressed
4.66 Kb
unknown
3232
bdcam.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
binary
471 b
unknown
1080
svchost.exe
GET
200
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?5d0f3f151fb92950
unknown
compressed
65.2 Kb
unknown
3160
bdcam.exe
GET
200
172.217.18.3:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQChuVoVf7HVAxLxWCb2kXo7
unknown
binary
472 b
unknown
3160
bdcam.exe
GET
200
172.217.18.3:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
3160
bdcam.exe
GET
200
172.217.18.3:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
3204
msedge.exe
239.255.255.250:1900
whitelisted
2468
msedge.exe
151.101.2.132:443
www.bandicam.com
FASTLY
US
unknown
2468
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2468
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2468
msedge.exe
20.103.180.120:443
nav-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
2468
msedge.exe
20.31.251.109:443
data-edge.smartscreen.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
www.bandicam.com
  • 151.101.2.132
  • 151.101.66.132
  • 151.101.130.132
  • 151.101.194.132
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.31.251.109
whitelisted
static.bandicam.com
  • 151.101.2.132
  • 151.101.66.132
  • 151.101.130.132
  • 151.101.194.132
whitelisted
www.googletagmanager.com
  • 142.250.186.168
whitelisted
www.bing.com
  • 104.126.37.136
  • 104.126.37.186
  • 104.126.37.177
  • 104.126.37.179
  • 104.126.37.185
  • 104.126.37.131
  • 104.126.37.128
  • 104.126.37.129
  • 104.126.37.178
whitelisted
googleads.g.doubleclick.net
  • 142.250.185.194
whitelisted
region1.google-analytics.com
  • 216.239.34.36
  • 216.239.32.36
whitelisted

Threats

No threats detected
No debug info