File name:

bf_updater_installer.exe

Full analysis: https://app.any.run/tasks/d06cc7f0-1824-489a-9bd3-065f8726a43a
Verdict: Malicious activity
Analysis date: March 30, 2025, 17:33:43
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
netreactor
crypto-regex
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

2D96E745C2F834D69608CBFC67EF883E

SHA1:

A5A521D9B37281C7F84A8CE509F30FD1EEA45714

SHA256:

1E25D0F4C05582228EB301043CADC3B4A316878382F600D12466EFAA72517B0C

SSDEEP:

98304:MAXWrynDZSEgf8K1qRGIu1XH2qy51xXWuknpumIGsHvAhZRi4iyLP044N/ZhUqoH:ky5XP0FkbwJPm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • rsLggr.exe (PID: 4696)
      • rsLggr.exe (PID: 3956)
      • rsLggr.exe (PID: 5596)
      • rsLggr.exe (PID: 2340)
      • rsLggr.exe (PID: 3300)
      • rsEngineHelper.exe (PID: 2984)
      • rsLggr.exe (PID: 4488)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • bf_updater_installer.exe (PID: 6700)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • bf_updater_installer.exe (PID: 6700)
    • Executable content was dropped or overwritten

      • bf_updater_installer.exe (PID: 6700)
    • Uses TASKKILL.EXE to kill process

      • bf_updater_installer.exe (PID: 6700)
    • There is functionality for taking screenshot (YARA)

      • bf_updater_installer.exe (PID: 6700)
      • ByteFence.exe (PID: 5728)
    • Creates a software uninstall entry

      • bf_updater_installer.exe (PID: 6700)
    • Reads the date of Windows installation

      • ByteFence.exe (PID: 5728)
    • Reads security settings of Internet Explorer

      • ByteFence.exe (PID: 5728)
    • Reads the BIOS version

      • ByteFence.exe (PID: 5728)
    • Found regular expressions for crypto-addresses (YARA)

      • ByteFence.exe (PID: 5728)
    • Executes as Windows Service

      • ByteFenceService.exe (PID: 1388)
    • Executes application which crashes

      • ByteFence.exe (PID: 5728)
    • Searches for installed software

      • ByteFence.exe (PID: 5728)
  • INFO

    • Reads the computer name

      • bf_updater_installer.exe (PID: 6700)
      • ByteFence.exe (PID: 5728)
      • rsLggr.exe (PID: 4696)
      • ByteFenceService.exe (PID: 4452)
      • ByteFenceService.exe (PID: 1388)
      • rsEngineHelper.exe (PID: 2984)
    • The sample compiled with english language support

      • bf_updater_installer.exe (PID: 6700)
    • Checks supported languages

      • bf_updater_installer.exe (PID: 6700)
      • ByteFence.exe (PID: 5728)
      • rsLggr.exe (PID: 4696)
      • rsLggr.exe (PID: 3300)
      • rsLggr.exe (PID: 5596)
      • rsLggr.exe (PID: 2340)
      • ByteFenceService.exe (PID: 4452)
      • rsLggr.exe (PID: 3956)
      • ByteFenceService.exe (PID: 1388)
      • rsEngineHelper.exe (PID: 2984)
      • rsLggr.exe (PID: 4488)
    • Checks proxy server information

      • bf_updater_installer.exe (PID: 6700)
      • ByteFence.exe (PID: 5728)
      • rsEngineHelper.exe (PID: 2984)
    • Create files in a temporary directory

      • bf_updater_installer.exe (PID: 6700)
      • ByteFence.exe (PID: 5728)
      • rsEngineHelper.exe (PID: 2984)
    • Creates files in the program directory

      • bf_updater_installer.exe (PID: 6700)
      • ByteFence.exe (PID: 5728)
      • rsLggr.exe (PID: 4696)
      • ByteFenceService.exe (PID: 4452)
    • SQLite executable

      • bf_updater_installer.exe (PID: 6700)
    • Reads the machine GUID from the registry

      • ByteFence.exe (PID: 5728)
      • ByteFenceService.exe (PID: 4452)
      • ByteFenceService.exe (PID: 1388)
      • rsEngineHelper.exe (PID: 2984)
    • Reads Environment values

      • ByteFence.exe (PID: 5728)
      • ByteFenceService.exe (PID: 1388)
      • rsEngineHelper.exe (PID: 2984)
    • Process checks computer location settings

      • ByteFence.exe (PID: 5728)
    • Reads product name

      • ByteFence.exe (PID: 5728)
    • Process checks whether UAC notifications are on

      • ByteFence.exe (PID: 5728)
    • .NET Reactor protector has been detected

      • ByteFence.exe (PID: 5728)
    • Reads the software policy settings

      • ByteFence.exe (PID: 5728)
    • Disables trace logs

      • ByteFence.exe (PID: 5728)
      • rsEngineHelper.exe (PID: 2984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:12:11 21:50:38+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24064
InitializedDataSize: 118272
UninitializedDataSize: 1024
EntryPoint: 0x316d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.14.0.10
ProductVersionNumber: 3.14.0.10
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: ByteFence Anti-Malware
CompanyName: Byte Technologies LLC
FileDescription: ByteFence Anti-Malware
FileVersion: 3.14.0.10
LegalCopyright: Copyright © 2017 Byte Technologies LLC
LegalTrademarks: ByteFence Anti-Malware is a trademark of Byte Technologies LLC
ProductName: ByteFence Anti-Malware
ProductVersion: 3.14.0.10
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
24
Malicious processes
4
Suspicious processes
7

Behavior graph

Click at the process to see the details
start bf_updater_installer.exe taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs bytefence.exe rslggr.exe no specs rslggr.exe no specs rslggr.exe no specs rslggr.exe no specs bytefenceservice.exe no specs rslggr.exe no specs bytefenceservice.exe no specs rsenginehelper.exe no specs conhost.exe no specs rslggr.exe no specs werfault.exe no specs bf_updater_installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
664\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
920taskkill /f /im rsLggr.exeC:\Windows\SysWOW64\taskkill.exebf_updater_installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
960C:\WINDOWS\system32\WerFault.exe -u -p 5728 -s 3528C:\Windows\System32\WerFault.exeByteFence.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\oleaut32.dll
1388"C:\Program Files\ByteFence\ByteFenceService.exe"C:\Program Files\ByteFence\ByteFenceService.exeservices.exe
User:
SYSTEM
Company:
Byte Technologies LLC
Integrity Level:
SYSTEM
Description:
ByteFence Anti-Malware
Version:
3.14.0.0
Modules
Images
c:\program files\bytefence\bytefenceservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2340"C:\Program Files\ByteFence\rsLggr.exe" C:\Program Files\ByteFence\rsLggr.exeByteFence.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bytefence\rslggr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
2984"C:\Program Files\ByteFence\rsEngineHelper.exe" dLDF url:http://cdn.bytefence.com/rtop_setup.exe filepath:"C:\Users\admin\AppData\Local\Temp\rtop_setup.exe" product:BFC:\Program Files\ByteFence\rsEngineHelper.exeByteFence.exe
User:
admin
Company:
Reason Software Company Inc.
Integrity Level:
HIGH
Description:
Reason Security Engine Helper
Exit code:
0
Version:
2.0.3.1
Modules
Images
c:\program files\bytefence\rsenginehelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3300"C:\Program Files\ByteFence\rsLggr.exe" C:\Program Files\ByteFence\rsLggr.exeByteFence.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bytefence\rslggr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
3956"C:\Program Files\ByteFence\rsLggr.exe" C:\Program Files\ByteFence\rsLggr.exeByteFence.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\bytefence\rslggr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
4268taskkill /f /im ByteFenceService.exeC:\Windows\SysWOW64\taskkill.exebf_updater_installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4452"C:\Program Files\ByteFence\ByteFenceService.exe" /iC:\Program Files\ByteFence\ByteFenceService.exeByteFence.exe
User:
admin
Company:
Byte Technologies LLC
Integrity Level:
HIGH
Description:
ByteFence Anti-Malware
Exit code:
0
Version:
3.14.0.0
Modules
Images
c:\program files\bytefence\bytefenceservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
23 903
Read events
23 805
Write events
98
Delete events
0

Modification events

(PID) Process:(6700) bf_updater_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:DisplayName
Value:
ByteFence Anti-Malware
(PID) Process:(6700) bf_updater_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:UninstallString
Value:
"C:\Program Files\ByteFence\uninstall.exe"
(PID) Process:(6700) bf_updater_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:Publisher
Value:
Byte Technologies LLC
(PID) Process:(6700) bf_updater_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:InstallSource
Value:
C:\Program Files\ByteFence\
(PID) Process:(6700) bf_updater_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:DisplayVersion
Value:
3.14.0.10
(PID) Process:(6700) bf_updater_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:DisplayIcon
Value:
C:\Program Files\ByteFence\Uninstall.exe
(PID) Process:(6700) bf_updater_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:URLInfoAbout
Value:
https://www.bytefence.com
(PID) Process:(6700) bf_updater_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:NoModify
Value:
1
(PID) Process:(6700) bf_updater_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:NoRepair
Value:
1
(PID) Process:(6700) bf_updater_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ByteFence
Operation:writeName:PINSTP
Value:
Executable files
21
Suspicious files
4
Text files
17
Unknown types
0

Dropped files

PID
Process
Filename
Type
6700bf_updater_installer.exeC:\Users\admin\AppData\Local\Temp\nsyBFF7.tmp\nsDialogs.dllexecutable
MD5:B3070CF20DB659FDFB3CB2ED38130E8D
SHA256:F2C1409FAF2952C1C91F4B5495158EF5C7D1A1DB6EEA4A18F163574BD52FCAD0
6700bf_updater_installer.exeC:\Program Files\ByteFence\ByteFenceService.exeexecutable
MD5:624E2BAB14C48D0C84EE265125811169
SHA256:3B6A1DC1E3777B10A650276AD53D7A9601BEF28180EFF2F724B15CF254DF4893
6700bf_updater_installer.exeC:\Program Files\ByteFence\ByteFence.exeexecutable
MD5:61330D8ACBB7800E49E63BD411EF20AB
SHA256:68C3BD98CA647E3C51DAAFDAC7DCD5F60230E9C65E1789C4DB06C0C6FCB1ED48
6700bf_updater_installer.exeC:\Users\admin\AppData\Local\Temp\nsyBFF7.tmp\nsExec.dllexecutable
MD5:B5A1F9DC73E2944A388A61411BDD8C70
SHA256:288100583F65A2B7ACFC0C7E231C0E268C58D3067675543F627C01E82F6FD884
6700bf_updater_installer.exeC:\Users\admin\AppData\Local\Temp\nsyBFF7.tmp\nsisdl.dllexecutable
MD5:41F557E065B405F94D0ECE8B5727233B
SHA256:9DE492995D2180635AA3194B88CE6DD94E0C2B001AF5952A73D4A84FBC32B6AB
6700bf_updater_installer.exeC:\Users\admin\AppData\Local\Temp\nsyBFF7.tmp\modern-wizard.bmpimage
MD5:0A3789BD73553A4E0F37022CF348653F
SHA256:282B94F02F605A667F0FC5C6DBDC6C9DDEB8048D811826FCF7E956ED263B7EE0
6700bf_updater_installer.exeC:\Users\admin\AppData\Local\Temp\nsyBFF7.tmp\modern-header.bmpimage
MD5:47C5CD0B09846144FBA0DA4C044E894F
SHA256:5604F656590451D28D1653AD5C5D385FBA1DCE76B39C14F917C6AAAD08F96B89
6700bf_updater_installer.exeC:\Program Files\ByteFence\Signatures.dattext
MD5:B90608A91C7ECE463529962407C886A9
SHA256:75FE2902AE5478AF45B2027B60B355DF1BD93ED52F396F361E41B9D8AEB66854
6700bf_updater_installer.exeC:\Program Files\ByteFence\rsEngine.dllexecutable
MD5:9A9D04211B81C88FBE36A3ADE45A7341
SHA256:05914E3E3E9F84E76F4E9827BBB1927D2465E0D36D51B15F404CE4590BC7DF19
6700bf_updater_installer.exeC:\Program Files\ByteFence\rsEngineHelper.exe.configxml
MD5:E3D5F62B7B28176A510484E465FA0F18
SHA256:827CDA24DF7876010D5239FE2B8AF49472442D899F9C0F6D9FF53B4FF6860946
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
19
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4220
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4220
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5728
ByteFence.exe
172.67.9.68:443
api.reasonsecurity.com
CLOUDFLARENET
US
unknown
4220
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4220
SIHClient.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4220
SIHClient.exe
13.85.23.206:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.36
whitelisted
google.com
  • 172.217.16.206
whitelisted
client.wns.windows.com
whitelisted
logs.bytefence.com
whitelisted
api.reasonsecurity.com
  • 172.67.9.68
  • 104.22.0.235
  • 104.22.1.235
unknown
cdn.bytefence.com
shared
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
No debug info