Bdcam.exe

bdcam

Bandisoft

This is a setup program which is used to install the application. The file has been seen being downloaded from s8878.chomikuj.pl and multiple other hosts.
Publisher:
www.Bandisoft.com  (signed by Bandisoft)

Product:
bdcam

Description:
Bandisoft - bdcam.exe

Version:
3.0.3.1025

MD5:
295f1cf32a45e7ed9a78752708edb9c7

SHA-1:
12715d500fbb06a48e170ecd0a2991e919c4010a

SHA-256:
85f1bea0f9bb3b0ba97ad95e94318546992c57a667a8e1f8e81bf14f2e2f6396

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 12:53:26 PM UTC  (today)

File size:
2.7 MB (2,847,664 bytes)

Product version:
3.0.3.1025

Copyright:
Copyright(c) 2009-2016 Bandisoft.com. All rights reserved.

Original file name:
Bdcam.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\bandicam\bdcam.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
1/14/2016 7:00:00 AM

Valid to:
12/27/2016 6:59:59 AM

Subject:
CN=Bandisoft, O=Bandisoft, L=Yeongdeungpogu, S=Seoul, C=KR

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
5F6408AB6AC97036B64990844CD70B9C

File PE Metadata
Compilation timestamp:
2/24/2016 1:09:16 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
49152:dny3MlWmxmxLbtj8g8bVu3lFGOQ4XYsSeHgnVwD4bLmJA6dtwkavAjd3ql:dnyqW0mxLObVWzQ4XYsS8sG4/owka4j2

Entry address:
0x6E3B35

Entry point:
60, C7, 44, 24, 1C, 70, 15, E6, 6A, 9C, 52, C7, 44, 24, 20, 97, 5C, 0E, 36, C6, 04, 24, 4A, 89, 4C, 24, 04, 8D, 64, 24, 20, E9, 6A, 19, 02, 00, E9, E5, F0, FF, FF, 00, 00, 47, 65, 74, 4B, 65, 79, 4E, 61, 6D, 65, 54, 65, 78, 74, 57, 00, C6, 44, 24, 04, D0, 8D, 64, 24, 24, 0F, 85, 81, C6, FF, FF, D0, E1, 8B, 0B, 38, F0, F9, 09, C9, E8, B0, E9, 01, 00, 9C, 8D, 64, 24, 04, E8, 18, BA, FF, FF, E9, 94, 9F, FF, FF, 00, 00, 55, 6E, 68, 6F, 6F, 6B, 57, 69, 6E, 64, 6F, 77, 73, 48, 6F, 6F, 6B, 45, 78, 00, 00, 00, 46...
 
[+]

Entropy:
7.9655  (probably packed)

Code size:
2.4 MB (2,548,224 bytes)

The file Bdcam.exe has been seen being distributed by the following 5 URLs.

http://s8878.chomikuj.pl/File.aspx?e=73-W7SCXFaGikjBELvcJnqyTVm0bOUFn1dHFJ3ksN7ddfiBGPEIhnnLsRHBByWIOHUQu00x4eixO_qIlCIH48TMXOhBZHk-Amz2hTWiyskypcvY2FuAZkCQ7CbVmpgsp7_VSPVm24CZC-uZ_WxQXFA&pv=2

http://s6540.chomikuj.pl/File.aspx?e=73-W7SCXFaGikjBELvcJnrPCNbms2_MDVQh1DulZ4z32dFMTCHEAZIDrq2QKMyxGoNLpfp-JIsNBw87RcAjB74p-P56fzVrcixhgpInRph4rrBjdGEioLsDjFyRN3QLFlh9xDoO1LHa1zqXDR9iubg&pv=2

http://s6540.chomikuj.pl/File.aspx?e=73-W7SCXFaGikjBELvcJnrPCNbms2_MDVQh1DulZ4z35237k5iIln9GQmhaXRo3t0T1RyurD3O7qKzrMYyYIdgCRZlreH_pNCkwEQZffmEZadX8FfkYLokeUvqoS5TqIogxK-WW34QZDJDFr7d1A-A&pv=2

http://s6540.chomikuj.pl/File.aspx?e=73-W7SCXFaGikjBELvcJnrPCNbms2_MDVQh1DulZ4z2m1SHDmcLSBC3_KwNiBY7YeekmylAULEh2iO7GRmS0i33zjttIldxWqjfOaJ3MY65IyP0DhVhv0Wfy3uAty6IuDET3CiNXuX9AfP-tDALEiA&pv=2

Scan Bdcam.exe - Powered by Reason Core Security