File name:

BitDefender Update Handlers.zip

Full analysis: https://app.any.run/tasks/8af025f9-ddab-4b18-9978-a625eeff402b
Verdict: Malicious activity
Threats:

PlugX is a remote access trojan that is used extensively by Chinese APTs. The malware is primarily employed for spying on victims and can perform a variety of malicious activities, such as logging users’ keystrokes and exfiltrating information from browsers.

Analysis date: August 21, 2023, 11:54:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
plugx
trojan
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

28485116F9AA1EF2FFF9AAD86BDA9B59

SHA1:

6BA0E57B4774358715CD700B6FF387DBD63C63C4

SHA256:

09BFC423E4BC7A5EBB42808EB101EAA827B6FC9639B4BA313F307D0C9853D4AF

SSDEEP:

6144:T6XXkZaOOrBn4Gc/+EOxPX/hGL34/paXvJj7hPp:T6J/NnSv6qspgP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • bdreinit.exe (PID: 2732)
      • bdreinit.exe (PID: 2556)
      • bdreinit.exe (PID: 2104)
      • bdreinit.exe (PID: 1588)
    • Loads dropped or rewritten executable

      • bdreinit.exe (PID: 2732)
    • Connects to the CnC server

      • bdreinit.exe (PID: 2732)
    • PLUGX was detected

      • bdreinit.exe (PID: 2732)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • bdreinit.exe (PID: 2556)
    • Starts itself from another location

      • bdreinit.exe (PID: 2556)
    • Reads the Internet Settings

      • bdreinit.exe (PID: 2732)
    • Uses RUNDLL32.EXE to load library

      • WinRAR.exe (PID: 1872)
    • The process verifies whether the antivirus software is installed

      • bdreinit.exe (PID: 2732)
      • userinit.exe (PID: 2844)
  • INFO

    • Checks supported languages

      • bdreinit.exe (PID: 2556)
      • bdreinit.exe (PID: 2732)
      • bdreinit.exe (PID: 1588)
      • bdreinit.exe (PID: 2104)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1872)
    • Create files in a temporary directory

      • bdreinit.exe (PID: 2732)
      • bdreinit.exe (PID: 2556)
      • bdreinit.exe (PID: 2104)
      • bdreinit.exe (PID: 1588)
    • Reads the computer name

      • bdreinit.exe (PID: 2556)
      • bdreinit.exe (PID: 2732)
      • bdreinit.exe (PID: 2104)
      • bdreinit.exe (PID: 1588)
    • Checks proxy server information

      • bdreinit.exe (PID: 2732)
    • Loads dropped or rewritten executable

      • bdreinit.exe (PID: 2556)
      • bdreinit.exe (PID: 2104)
      • bdreinit.exe (PID: 1588)
    • Reads the machine GUID from the registry

      • bdreinit.exe (PID: 2732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipFileName: BitDefender Update Handlers/
ZipUncompressedSize: -
ZipCompressedSize: -
ZipCRC: 0x00000000
ZipModifyDate: 2023:08:21 18:38:10
ZipCompression: None
ZipBitFlag: -
ZipRequiredVersion: 20
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
11
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start start drop and start winrar.exe bdreinit.exe #PLUGX bdreinit.exe userinit.exe no specs rundll32.exe no specs notepad.exe no specs rundll32.exe no specs notepad.exe no specs bdreinit.exe no specs searchprotocolhost.exe no specs bdreinit.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
336"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa1872.37745\log.dllC:\Windows\System32\notepad.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
948"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIa1872.39329\log.datC:\Windows\System32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1588"C:\Users\admin\AppData\Local\Temp\Rar$EXa1872.43149\BitDefender Update Handlers\bdreinit.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1872.43149\BitDefender Update Handlers\bdreinit.exeWinRAR.exe
User:
admin
Company:
BitDefender
Integrity Level:
MEDIUM
Description:
BitDefender Crash Handler
Exit code:
1223
Version:
1.0.28.140
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1872.43149\bitdefender update handlers\bdreinit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dbghelp.dll
1872"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\BitDefender Update Handlers.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2032"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa1872.39329\log.datC:\Windows\System32\notepad.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\notepad.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2076"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIa1872.37745\log.dllC:\Windows\System32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
2104"C:\Users\admin\AppData\Local\Temp\Rar$EXa1872.42063\BitDefender Update Handlers\bdreinit.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1872.42063\BitDefender Update Handlers\bdreinit.exeWinRAR.exe
User:
admin
Company:
BitDefender
Integrity Level:
MEDIUM
Description:
BitDefender Crash Handler
Exit code:
1223
Version:
1.0.28.140
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1872.42063\bitdefender update handlers\bdreinit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dbghelp.dll
2556"C:\Users\admin\AppData\Local\Temp\Rar$EXa1872.36616\BitDefender Update Handlers\bdreinit.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa1872.36616\BitDefender Update Handlers\bdreinit.exe
WinRAR.exe
User:
admin
Company:
BitDefender
Integrity Level:
MEDIUM
Description:
BitDefender Crash Handler
Exit code:
1223
Version:
1.0.28.140
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa1872.36616\bitdefender update handlers\bdreinit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\gdi32.dll
2732"C:\Users\admin\BitDefender Update Handlers\bdreinit.exe" 601 0C:\Users\admin\BitDefender Update Handlers\bdreinit.exe
bdreinit.exe
User:
admin
Company:
BitDefender
Integrity Level:
MEDIUM
Description:
BitDefender Crash Handler
Exit code:
0
Version:
1.0.28.140
Modules
Images
c:\users\admin\bitdefender update handlers\bdreinit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shlwapi.dll
2844C:\Windows\system32\userinit.exe 609 2732C:\Windows\System32\userinit.exebdreinit.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Userinit Logon Application
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\userinit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
Total events
4 834
Read events
4 645
Write events
189
Delete events
0

Modification events

(PID) Process:(1872) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1872) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
9
Suspicious files
5
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1872.36616\BitDefender Update Handlers\bdreinit.exeexecutable
MD5:8A8DB1E20DC508AF5A81FC00B1929468
SHA256:386EB7AA33C76CE671D6685F79512597F1FAB28EA46C8EC7D89E58340081E2BD
1872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1872.36616\BitDefender Update Handlers\log.datbinary
MD5:F209540F8C39A9E6B07E176342757C9C
SHA256:0D8DDE6965AC26F5C779E1BFE168CB5F790DFEC3536468EFB6899794B5BA6B0C
2732bdreinit.exeC:\Users\admin\AppData\Local\Temp\tmp920790309.tmptext
MD5:84CB17743002B4CFB81B0153CEE648FC
SHA256:6604CE9C6B650A55C404DE5118D2FFA0B8CFA2FC714165AE02235066B92ADAF3
1872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa1872.37745\log.dllexecutable
MD5:E5FCF4118802E36EF6C6D5836B0460EE
SHA256:DA2AA74F43C446151761E78DC50EF1DE43084017070F409D9C04999C030FD1F6
2104bdreinit.exeC:\Users\admin\AppData\Local\Temp\tmp920790309.tmptext
MD5:84CB17743002B4CFB81B0153CEE648FC
SHA256:6604CE9C6B650A55C404DE5118D2FFA0B8CFA2FC714165AE02235066B92ADAF3
2556bdreinit.exeC:\Users\admin\BitDefender Update Handlers\bdreinit.exeexecutable
MD5:8A8DB1E20DC508AF5A81FC00B1929468
SHA256:386EB7AA33C76CE671D6685F79512597F1FAB28EA46C8EC7D89E58340081E2BD
1872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1872.42063\BitDefender Update Handlers\log.datbinary
MD5:F209540F8C39A9E6B07E176342757C9C
SHA256:0D8DDE6965AC26F5C779E1BFE168CB5F790DFEC3536468EFB6899794B5BA6B0C
1872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa1872.42063\BitDefender Update Handlers\log.dllexecutable
MD5:E5FCF4118802E36EF6C6D5836B0460EE
SHA256:DA2AA74F43C446151761E78DC50EF1DE43084017070F409D9C04999C030FD1F6
1588bdreinit.exeC:\Users\admin\AppData\Local\Temp\tmp920790309.tmptext
MD5:84CB17743002B4CFB81B0153CEE648FC
SHA256:6604CE9C6B650A55C404DE5118D2FFA0B8CFA2FC714165AE02235066B92ADAF3
1872WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa1872.39329\log.datbinary
MD5:F209540F8C39A9E6B07E176342757C9C
SHA256:0D8DDE6965AC26F5C779E1BFE168CB5F790DFEC3536468EFB6899794B5BA6B0C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
8
DNS requests
16
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2732
bdreinit.exe
POST
154.38.101.34:8080
http://www.apple-net.com:8080/AC8C222429A87DC4/FC654631
US
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2732
bdreinit.exe
58.158.177.102:80
www.wbemsystem.com
ARTERIA Networks Corporation
JP
malicious
2732
bdreinit.exe
154.38.101.34:8080
www.apple-net.com
CNSERVERS
US
malicious

DNS requests

Domain
IP
Reputation
www.wbemsystem.com
  • 58.158.177.102
malicious
dns.msftncsi.com
  • 131.107.255.255
shared
www.lionforcesystems.com
unknown
www.apple-net.com
  • 154.38.101.34
malicious

Threats

PID
Process
Class
Message
2732
bdreinit.exe
A Network Trojan was detected
ET MALWARE Possible PlugX Common Header Struct
2732
bdreinit.exe
A Network Trojan was detected
AV TROJAN PlugX Common Header Struct
2732
bdreinit.exe
A Network Trojan was detected
ET MALWARE Trojan.Win32.DLOADR.TIOIBEPQ CnC Traffic
4 ETPRO signatures available at the full report
Process
Message
bdreinit.exe
Protocol:[ TCP], Host: [www.wbemsystem.com:80], Proxy: [0::0::]
bdreinit.exe
Protocol:[HTTP], Host: [www.wbemsystem.com:80], Proxy: [0::0::]
bdreinit.exe
Protocol:[ UDP], Host: [www.wbemsystem.com:80], Proxy: [0::0::]
bdreinit.exe
Protocol:[ TCP], Host: [www.lionforcesystems.com:53], Proxy: [0::0::]
bdreinit.exe
Protocol:[HTTP], Host: [www.lionforcesystems.com:53], Proxy: [0::0::]
bdreinit.exe
Protocol:[ UDP], Host: [www.lionforcesystems.com:53], Proxy: [0::0::]
bdreinit.exe
Protocol:[ TCP], Host: [www.apple-net.com:8080], Proxy: [0::0::]
bdreinit.exe
Protocol:[HTTP], Host: [www.apple-net.com:8080], Proxy: [0::0::]
bdreinit.exe
Protocol:[ UDP], Host: [www.apple-net.com:8080], Proxy: [0::0::]