File name:

bitdefender_tsecurity.exe

Full analysis: https://app.any.run/tasks/ae84934e-894f-4894-a0a3-01c411ca2bc3
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: February 18, 2025, 01:19:37
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
installer
loader
rust
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

69EED25AB55A97300A124B163707CB0B

SHA1:

EB87F3B07C7E153F4A792F3B1C2875DBF534A243

SHA256:

3EB893E5478A744D8E11B74F13E6EC7054F4015A89CBDA4DFDBA391B4B352C4A

SSDEEP:

98304:DM5iwInfc50+bC24rKwWiCF7ek1Z6jcxIE6s6Qx4EwmpkZAZiqdKezzplTVs4qD3:U3HJdX8hR3cMAMSqJcX6vObRqZH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • DiscoverySrv.exe (PID: 3848)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • bitdefender_tsecurity.exe (PID: 6592)
      • ProductAgentService.exe (PID: 3840)
      • ydd156C.tmp (PID: 6528)
    • Reads security settings of Internet Explorer

      • agent_launcher.exe (PID: 6792)
      • bitdefender_tsecurity.exe (PID: 6592)
      • MicrosoftEdgeUpdate.exe (PID: 6540)
    • Checks Windows Trust Settings

      • agent_launcher.exe (PID: 6792)
      • DiscoverySrv.exe (PID: 3848)
      • ProductAgentService.exe (PID: 3840)
      • DiscoverySrv.exe (PID: 5560)
      • ProductAgentUI.exe (PID: 3836)
      • WatchDog.exe (PID: 6752)
    • There is functionality for taking screenshot (YARA)

      • bitdefender_tsecurity.exe (PID: 6592)
      • ProductAgentUI.exe (PID: 3836)
    • Executes as Windows Service

      • bdredline.exe (PID: 6336)
      • ProductAgentService.exe (PID: 3840)
    • The process verifies whether the antivirus software is installed

      • bdredline.exe (PID: 6336)
      • ProductAgentService.exe (PID: 3840)
      • DiscoverySrv.exe (PID: 3848)
      • DiscoverySrv.exe (PID: 5560)
      • regsvr32.exe (PID: 3524)
      • MicrosoftEdgeUpdate.exe (PID: 6540)
      • ProductAgentUI.exe (PID: 3836)
      • ydd156C.tmp (PID: 6528)
      • WatchDog.exe (PID: 6752)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3524)
    • Starts a Microsoft application from unusual location

      • ydd156C.tmp (PID: 6528)
      • MicrosoftEdgeUpdate.exe (PID: 6540)
    • Process drops legitimate windows executable

      • ProductAgentService.exe (PID: 3840)
      • ydd156C.tmp (PID: 6528)
      • MicrosoftEdgeUpdate.exe (PID: 6540)
    • Starts application with an unusual extension

      • ProductAgentService.exe (PID: 3840)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 6540)
  • INFO

    • Create files in a temporary directory

      • bitdefender_tsecurity.exe (PID: 6592)
    • Reads the computer name

      • bitdefender_tsecurity.exe (PID: 6592)
      • agent_launcher.exe (PID: 6792)
      • bdredline.exe (PID: 6336)
      • ProductAgentService.exe (PID: 3840)
      • DiscoverySrv.exe (PID: 5560)
      • ProductAgentUI.exe (PID: 3836)
      • MicrosoftEdgeUpdate.exe (PID: 6540)
      • WatchDog.exe (PID: 6752)
    • Checks supported languages

      • bitdefender_tsecurity.exe (PID: 6592)
      • agent_launcher.exe (PID: 6792)
      • bdredline.exe (PID: 6336)
      • ProductAgentService.exe (PID: 3840)
      • DiscoverySrv.exe (PID: 3848)
      • DiscoverySrv.exe (PID: 5560)
      • ProductAgentUI.exe (PID: 3836)
      • ydd156C.tmp (PID: 6528)
      • MicrosoftEdgeUpdate.exe (PID: 6540)
      • WatchDog.exe (PID: 6752)
    • Reads the machine GUID from the registry

      • agent_launcher.exe (PID: 6792)
      • DiscoverySrv.exe (PID: 5560)
      • DiscoverySrv.exe (PID: 3848)
      • ProductAgentService.exe (PID: 3840)
      • ProductAgentUI.exe (PID: 3836)
      • WatchDog.exe (PID: 6752)
    • Reads the software policy settings

      • agent_launcher.exe (PID: 6792)
      • DiscoverySrv.exe (PID: 3848)
      • DiscoverySrv.exe (PID: 5560)
      • ProductAgentUI.exe (PID: 3836)
      • ProductAgentService.exe (PID: 3840)
      • MicrosoftEdgeUpdate.exe (PID: 6540)
      • wermgr.exe (PID: 6556)
      • WatchDog.exe (PID: 6752)
    • Process checks computer location settings

      • agent_launcher.exe (PID: 6792)
      • bitdefender_tsecurity.exe (PID: 6592)
      • MicrosoftEdgeUpdate.exe (PID: 6540)
    • Reads Environment values

      • ProductAgentService.exe (PID: 3840)
      • MicrosoftEdgeUpdate.exe (PID: 6540)
    • Creates files in the program directory

      • ProductAgentService.exe (PID: 3840)
      • ydd156C.tmp (PID: 6528)
    • Reads CPU info

      • ProductAgentService.exe (PID: 3840)
    • Application based on Rust

      • bdredline.exe (PID: 6336)
    • The sample compiled with english language support

      • ProductAgentService.exe (PID: 3840)
      • ydd156C.tmp (PID: 6528)
      • MicrosoftEdgeUpdate.exe (PID: 6540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:08:14 19:15:49+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 188416
InitializedDataSize: 265216
UninitializedDataSize: -
EntryPoint: 0x1cab5
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
13
Malicious processes
8
Suspicious processes
3

Behavior graph

Click at the process to see the details
start bitdefender_tsecurity.exe agent_launcher.exe no specs bddeploy.exe bdredline.exe productagentservice.exe discoverysrv.exe no specs regsvr32.exe no specs discoverysrv.exe no specs productagentui.exe no specs ydd156c.tmp microsoftedgeupdate.exe wermgr.exe watchdog.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3524regsvr32 /s "C:\Program Files\Bitdefender Agent\27.1.1.11\DiscoveryComp.dll"C:\Windows\SysWOW64\regsvr32.exeDiscoverySrv.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3836"C:\Program Files\Bitdefender Agent\27.1.1.11\ProductAgentUI.exe" show=progress event_retry=Global\7295237F-E98C-4C46-A4A4-07F0D66278C2 app_name="Bitdefender Security"C:\Program Files\Bitdefender Agent\27.1.1.11\ProductAgentUI.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
Bitdefender Agent
Version:
27.1.1.11
Modules
Images
c:\program files\bitdefender agent\27.1.1.11\productagentui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
3840"C:\Program Files\Bitdefender Agent\ProductAgentService.exe"C:\Program Files\Bitdefender Agent\ProductAgentService.exe
services.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
Bitdefender Agent
Version:
27.1.1.11
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
3848"C:\Program Files\Bitdefender Agent\27.1.1.11\DiscoverySrv.exe" installC:\Program Files\Bitdefender Agent\27.1.1.11\DiscoverySrv.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
DiscoverySrv
Exit code:
0
Version:
27.1.1.11
Modules
Images
c:\program files\bitdefender agent\27.1.1.11\discoverysrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
5560"C:\Program Files\Bitdefender Agent\27.1.1.11\DiscoverySrv.exe"C:\Program Files\Bitdefender Agent\27.1.1.11\DiscoverySrv.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
DiscoverySrv
Version:
27.1.1.11
Modules
Images
c:\program files\bitdefender agent\27.1.1.11\discoverysrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\crypt32.dll
c:\windows\syswow64\ucrtbase.dll
6336"C:\Program Files\Bitdefender Agent\redline\bdredline.exe"C:\Program Files\Bitdefender Agent\redline\bdredline.exe
services.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
Bitdefender redline update
Version:
1.0.1.113
Modules
Images
c:\program files\bitdefender agent\redline\bdredline.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6528"C:\WINDOWS\TEMP\bd_156B.tmp\ydd156C.tmp" /silent /installC:\Windows\Temp\bd_156B.tmp\ydd156C.tmp
ProductAgentService.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Edge Update Setup
Exit code:
2147747592
Version:
1.3.195.43
Modules
Images
c:\windows\temp\bd_156b.tmp\ydd156c.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
6540"C:\Program Files (x86)\Microsoft\Temp\EU4F47.tmp\MicrosoftEdgeUpdate.exe" /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Program Files (x86)\Microsoft\Temp\EU4F47.tmp\MicrosoftEdgeUpdate.exe
ydd156C.tmp
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Edge Update
Exit code:
2147747592
Version:
1.3.195.43
Modules
Images
c:\program files (x86)\microsoft\temp\eu4f47.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
6556"C:\WINDOWS\system32\wermgr.exe" "-outproc" "0" "6540" "2368" "2356" "2372" "0" "0" "0" "0" "0" "0" "0" "0" C:\Windows\SysWOW64\wermgr.exe
MicrosoftEdgeUpdate.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wermgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
6592"C:\Users\admin\Desktop\bitdefender_tsecurity.exe" C:\Users\admin\Desktop\bitdefender_tsecurity.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\bitdefender_tsecurity.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
30 999
Read events
30 953
Write events
44
Delete events
2

Modification events

(PID) Process:(3840) ProductAgentService.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent
Operation:writeName:ServiceStages
Value:
0-1739841607
(PID) Process:(3840) ProductAgentService.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent
Operation:writeName:ServiceStages
Value:
0-1739841607 1-1739841607
(PID) Process:(3840) ProductAgentService.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent
Operation:writeName:ServiceStages
Value:
0-1739841607 1-1739841607 4-1739841607
(PID) Process:(3524) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CB23A858-ED47-425B-AAD2-D809C11E1DA6}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Free
(PID) Process:(3840) ProductAgentService.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent
Operation:writeName:ServiceStages
Value:
0-1739841607 1-1739841607 4-1739841607 8-1739841607
(PID) Process:(3524) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{753FDF26-44A2-47B5-B65E-2E207BD5BC0C}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3524) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{753FDF26-44A2-47B5-B65E-2E207BD5BC0C}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3840) ProductAgentService.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent
Operation:writeName:lang
Value:
{"dir":0,"name":"en_us"}
(PID) Process:(3840) ProductAgentService.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent
Operation:writeName:ServiceStages
Value:
0-1739841607 1-1739841607 4-1739841607 8-1739841607 9-1739841617-1
(PID) Process:(3840) ProductAgentService.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent
Operation:writeName:ServiceStages
Value:
0-1739841607 1-1739841607 4-1739841607 8-1739841607 9-1739841617-1 6-1739841617-0 13-1739841617 11-1739841617
Executable files
206
Suspicious files
11
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
6592bitdefender_tsecurity.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\bddeploy.exe.md5text
MD5:0B17F2039398AB492710D5372263986F
SHA256:7BDC3D1C981EE1A08F2CCFACC17665D1F360318E421D157CB943F632F00B442B
6592bitdefender_tsecurity.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\deploy.dllexecutable
MD5:B5803D9F71582E5DD94A9974B2AC5099
SHA256:7754503E4DD63DDA17D23CB0779349BAFDB917B9A8403228EE8BC9793AD4FFEF
6592bitdefender_tsecurity.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\agent_launcher.exe.md5text
MD5:98252F8092C40E8D165BA84FE4C3703D
SHA256:6E350745604EA36A42500A09ABCB9DD7384DEC17EFD56819229CA6A26CAEF853
3840ProductAgentService.exeC:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_8A3EB3B0E837053838683939C2047254binary
MD5:E043B0204A78DBCC9A3B1D0C4396996A
SHA256:6AB05B025ADBD8AE005392EB7C2F23E0145752041794BE9B31831FE1D4894988
3840ProductAgentService.exeC:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141binary
MD5:904A846E623A96632DCBB5A31FA697E9
SHA256:D9110EA697DB62DCD123FF2F33C4864656F84B47476FF386ACFFC5384D11B939
3840ProductAgentService.exeC:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEBbinary
MD5:334297BBBDC258BB66BF7DE7BBB11AE6
SHA256:71CCA8791B9156FABE97B9EA2291A87AFAAF94DCBB1A218ACE101DD837B873C7
3840ProductAgentService.exeC:\Program Files\Bitdefender Agent\27.1.1.11\apps_data\com.bitdefender.clbinary
MD5:E81EC9B0BC62549D6F8E25A19A453120
SHA256:883967E5E7F58B5F093AA314B72C090354AD631ED1F3017CF5338C1F950B510A
3840ProductAgentService.exeC:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_8A3EB3B0E837053838683939C2047254binary
MD5:F97F645EBB6BFE61CD8CD4D9498A79CC
SHA256:598FAE1AEE0183C391A3AA65220BC65DD6AC1E5C1FAEF0305FC84D4BEC4F7B95
3840ProductAgentService.exeC:\Program Files\Bitdefender Agent\27.1.1.11\storage\webview2_cache.jsonbinary
MD5:C4D723FB7CE0F08F4E544BF70BF97236
SHA256:F87D6E9C4FC203BB8D4285E616B95B3138F858E80BB78CED9F480A400337DA47
6592bitdefender_tsecurity.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\deploy.dll.md5text
MD5:FCF3219C0F424579777AAB81D43140B1
SHA256:095AC976D6DC8CF49AC795BE9CD57871CCCC6510C6CCF207B0B65AC6EEDCA0F5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
41
TCP/UDP connections
51
DNS requests
29
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
6336
bdredline.exe
GET
404
104.18.168.222:80
http://upgrade.bitdefender.com/redline_com.bitdefender.agent/versions.id
unknown
html
162 b
whitelisted
GET
200
34.149.211.227:443
https://mclb-gcp.nimbus.bitdefender.net/_ServerStatus
US
text
21 b
whitelisted
GET
200
35.190.56.82:443
https://elb-iow-gcp.nimbus.bitdefender.net/_ServerStatus
US
text
21 b
whitelisted
GET
200
34.120.68.241:443
https://nimbus.bitdefender.net/bdnc/config
US
binary
246 b
whitelisted
GET
200
34.149.211.227:443
https://mclb-gcp.nimbus.bitdefender.net/_ServerStatus
US
text
21 b
whitelisted
GET
200
34.120.85.253:443
https://elb-ore-gcp.nimbus.bitdefender.net/_ServerStatus
US
text
21 b
whitelisted
GET
200
34.120.68.241:443
https://nimbus.bitdefender.net/bdnc/config
US
binary
246 b
whitelisted
GET
200
34.120.85.253:443
https://elb-ore-gcp.nimbus.bitdefender.net/_ServerStatus
US
text
21 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.19.122.40:443
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.72:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6336
bdredline.exe
104.18.168.222:80
upgrade.bitdefender.com
CLOUDFLARENET
whitelisted
3840
ProductAgentService.exe
34.120.68.241:443
nimbus.bitdefender.net
GOOGLE-CLOUD-PLATFORM
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.238
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
upgrade.bitdefender.com
  • 104.18.168.222
  • 104.18.169.222
whitelisted
nimbus.bitdefender.net
  • 34.120.68.241
  • 2600:1901:0:69b7::
whitelisted
mclb-gcp.nimbus.bitdefender.net
  • 34.149.211.227
  • 2600:1901:0:c603::
whitelisted
elb-ore-gcp.nimbus.bitdefender.net
  • 34.120.85.253
  • 2600:1901:0:f8b::
whitelisted
elb-iow-gcp.nimbus.bitdefender.net
  • 35.190.56.82
  • 2600:1901:0:5723::
whitelisted
go.microsoft.com
  • 2.18.97.227
whitelisted

Threats

PID
Process
Class
Message
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
ET INFO Packed Executable Download
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Process
Message
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.