File name:

bytefence-update.exe

Full analysis: https://app.any.run/tasks/a20c9c1d-e407-4531-ab32-2191f47ea72d
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 30, 2025, 17:25:53
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

B694A9AF3522899AEB42F13CEE12EF0B

SHA1:

5F17EF45E4AA0C159E6365E55768BFDBC4CD0392

SHA256:

433BA2FDC1F4B9E3C1067392E6E014155EA42C25C94D1251F396FAC6092D690F

SSDEEP:

98304:ci4hYPVKlerkn461FAbkOnUEEj54qpUVugoh8UcxqHU7ooj/j3b6r1cBT3Z1iTVU:PuNVbjruDpKoc8Ete3M66Z++ermTnzT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • ByteFence.exe (PID: 6388)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • bytefence-update.exe (PID: 1276)
      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • Drops 7-zip archiver for unpacking

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • Creates a software uninstall entry

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • Process drops legitimate windows executable

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • There is functionality for taking screenshot (YARA)

      • bytefence-update.exe (PID: 1276)
    • Reads security settings of Internet Explorer

      • ByteFence.exe (PID: 6388)
    • Reads the date of Windows installation

      • ByteFence.exe (PID: 6388)
    • Reads the BIOS version

      • ByteFence.exe (PID: 6388)
    • Executes as Windows Service

      • ByteFenceService.exe (PID: 5548)
      • WmiApSrv.exe (PID: 5960)
  • INFO

    • Checks supported languages

      • bytefence-update.exe (PID: 1276)
      • bytefence-installer-5.4.3.1.exe (PID: 4244)
      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 4268)
      • ByteFenceService.exe (PID: 5548)
    • The sample compiled with english language support

      • bytefence-update.exe (PID: 1276)
      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • Creates files in the program directory

      • bytefence-update.exe (PID: 1276)
      • bytefence-installer-5.4.3.1.exe (PID: 4244)
      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 4268)
      • ByteFenceService.exe (PID: 5548)
    • Create files in a temporary directory

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
      • ByteFence.exe (PID: 6388)
    • Reads the computer name

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 4268)
      • ByteFenceService.exe (PID: 5548)
    • SQLite executable

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • Checks proxy server information

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
      • ByteFence.exe (PID: 6388)
    • Reads Windows Product ID

      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 5548)
    • Reads Environment values

      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 5548)
    • Process checks whether UAC notifications are on

      • ByteFence.exe (PID: 6388)
    • Disables trace logs

      • ByteFence.exe (PID: 6388)
    • Reads the machine GUID from the registry

      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 4268)
      • ByteFenceService.exe (PID: 5548)
    • Reads product name

      • ByteFence.exe (PID: 6388)
    • Reads the software policy settings

      • ByteFence.exe (PID: 6388)
    • Reads the time zone

      • ByteFence.exe (PID: 6388)
    • Creates files or folders in the user directory

      • ByteFence.exe (PID: 6388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:01:30 03:57:31+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x31d6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.4.3.1
ProductVersionNumber: 5.4.3.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: ByteFence Anti-Malware
CompanyName: Byte Technologies LLC
FileDescription: ByteFence Anti-Malware Update
FileVersion: 5.4.3.1
LegalCopyright: Copyright © 2019 Byte Technologies LLC
LegalTrademarks: ByteFence Anti-Malware is a trademark of Byte Technologies LLC
ProductName: ByteFence Anti-Malware
ProductVersion: 5.4.3.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bytefence-update.exe bytefence-installer-5.4.3.1.exe bytefence.exe bytefenceservice.exe no specs bytefenceservice.exe no specs wmiapsrv.exe no specs slui.exe no specs bytefence-update.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
904"C:\Users\admin\AppData\Local\Temp\bytefence-update.exe" C:\Users\admin\AppData\Local\Temp\bytefence-update.exeexplorer.exe
User:
admin
Company:
Byte Technologies LLC
Integrity Level:
MEDIUM
Description:
ByteFence Anti-Malware Update
Exit code:
3221226540
Version:
5.4.3.1
Modules
Images
c:\users\admin\appdata\local\temp\bytefence-update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1276"C:\Users\admin\AppData\Local\Temp\bytefence-update.exe" C:\Users\admin\AppData\Local\Temp\bytefence-update.exe
explorer.exe
User:
admin
Company:
Byte Technologies LLC
Integrity Level:
HIGH
Description:
ByteFence Anti-Malware Update
Exit code:
0
Version:
5.4.3.1
Modules
Images
c:\users\admin\appdata\local\temp\bytefence-update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4244"C:\Program Files\ByteFence\bytefence-installer-5.4.3.1.exe" /SC:\Program Files\ByteFence\bytefence-installer-5.4.3.1.exe
bytefence-update.exe
User:
admin
Company:
Byte Technologies LLC
Integrity Level:
HIGH
Description:
ByteFence Anti-Malware
Exit code:
0
Version:
5.4.3.1
Modules
Images
c:\program files\bytefence\bytefence-installer-5.4.3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4268"c:\program files\bytefence\ByteFenceService.exe" /iC:\Program Files\ByteFence\ByteFenceService.exeByteFence.exe
User:
admin
Company:
Byte Technologies LLC
Integrity Level:
HIGH
Description:
ByteFence Anti-Malware
Exit code:
0
Version:
5.4.3.1
Modules
Images
c:\program files\bytefence\bytefenceservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4728C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5548"c:\program files\bytefence\ByteFenceService.exe"C:\Program Files\ByteFence\ByteFenceService.exeservices.exe
User:
SYSTEM
Company:
Byte Technologies LLC
Integrity Level:
SYSTEM
Description:
ByteFence Anti-Malware
Version:
5.4.3.1
Modules
Images
c:\program files\bytefence\bytefenceservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5960C:\WINDOWS\system32\wbem\WmiApSrv.exeC:\Windows\System32\wbem\WmiApSrv.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
WMI Performance Reverse Adapter
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\psapi.dll
6388"C:\Program Files\ByteFence\ByteFence.exe"C:\Program Files\ByteFence\ByteFence.exe
bytefence-installer-5.4.3.1.exe
User:
admin
Company:
Byte Technologies LLC
Integrity Level:
HIGH
Description:
ByteFence Anti-Malware
Version:
5.4.3.1
Modules
Images
c:\program files\bytefence\bytefence.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
21 326
Read events
21 237
Write events
89
Delete events
0

Modification events

(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ByteFence
Operation:writeName:WDDASBLD
Value:
1
(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ByteFence
Operation:writeName:WDDASD
Value:
0
(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ByteFence
Operation:writeName:ERTPSUP
Value:
1
(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ByteFence
Operation:writeName:WDDASBLD
Value:
1
(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ByteFence
Operation:writeName:WDDASD
Value:
0
(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ByteFence
Operation:writeName:ERTPSUP
Value:
1
(PID) Process:(4244) bytefence-installer-5.4.3.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:DisplayName
Value:
ByteFence Anti-Malware
(PID) Process:(4244) bytefence-installer-5.4.3.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:UninstallString
Value:
"C:\Program Files\ByteFence\uninstall.exe"
(PID) Process:(4244) bytefence-installer-5.4.3.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:Publisher
Value:
Byte Technologies LLC
(PID) Process:(4244) bytefence-installer-5.4.3.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:InstallSource
Value:
C:\Program Files\ByteFence\
Executable files
34
Suspicious files
737
Text files
17
Unknown types
3

Dropped files

PID
Process
Filename
Type
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\ByteFence.exeexecutable
MD5:08FEB10B85D8488B2E7319937959A3C1
SHA256:E501C18EE5B7D285D1BFAF563B392DF1AC3C8D2A859814567280EF74A4353309
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\ByteFenceService.exeexecutable
MD5:159C9595D0E84D2923FC3DB390C50B44
SHA256:E72F9B13AABFF344349C92291B3AA6464CD6E06C51DF2873651A56C95274B712
1276bytefence-update.exeC:\Program Files\ByteFence\bytefence-installer-5.4.3.1.exeexecutable
MD5:7609CCF52C0CE17ED7F380F187C5814F
SHA256:0E5D9D1FAEAB296C123C37313C2F3C23A3147F8F450078D605ACFD559EED3F5B
4244bytefence-installer-5.4.3.1.exeC:\Users\admin\AppData\Local\Temp\nsxBC00.tmp\nsExec.dllexecutable
MD5:50BA20CAD29399E2DB9FA75A1324BD1D
SHA256:E7B145ABC7C519E6BD91DC06B7B83D1E73735AC1AC37D30A7889840A6EED38FC
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\rsEngineHelper.exe.configxml
MD5:E3D5F62B7B28176A510484E465FA0F18
SHA256:827CDA24DF7876010D5239FE2B8AF49472442D899F9C0F6D9FF53B4FF6860946
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\ByteFence.exe.configxml
MD5:E3D5F62B7B28176A510484E465FA0F18
SHA256:827CDA24DF7876010D5239FE2B8AF49472442D899F9C0F6D9FF53B4FF6860946
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\ByteFenceScan.exeexecutable
MD5:E38C4823C0F2CC0AAF9CA3AF67A64BC5
SHA256:163703C9AE372A86C5EA842A500AE100F83B13952F16C1A44FD900176EF70B87
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\ByteFenceGUI.dllexecutable
MD5:B255457F6A83DDD5857D1D596D007665
SHA256:DCB12533629F0A34FD99D9906208301F93453B6EDBC22467B36813ECE82079F2
4244bytefence-installer-5.4.3.1.exeC:\Users\admin\AppData\Local\Temp\nsxBC00.tmp\nsisdl.dllexecutable
MD5:732B08D61117E442DF209D6E2E4165A4
SHA256:73A1D4339513125BE547A038321E26A3DE13593DF96ED715EFD8A1683CCC0665
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\EULA.txttext
MD5:E6E5EDE5509C3806949C67B0C9A3EF7F
SHA256:B01DBDCC34869E07C9A31A471CFEE23D82E03BB924165CFFD54540593558A692
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
34
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6388
ByteFence.exe
GET
200
2.23.79.3:80
http://ocsp.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQJ1TBLBrQ9OnPHXPVaWb87MxkNlgQUwu79F9f%2Btw%2FGciJ7fvbA4gIz7D4CEH6T6%2Ft8xk5Z6kuad9QG%2FDs%3D
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.17.189.192:80
http://crl.thawte.com/ThawteTimestampingCA.crl
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.17.189.192:80
http://ts-ocsp.ws.symantec.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRi82PVYYKWGJWdgVNyePy5kYTdqQQUX5r1blzMzHSa1N197z%2Fb7EyALt0CEA7P9DjI%2Fr81bgTYapgbGlA%3D
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.17.189.192:80
http://ts-crl.ws.symantec.com/tss-ca-g2.crl
unknown
whitelisted
2340
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.17.189.192:80
http://ts-ocsp.ws.symantec.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRi82PVYYKWGJWdgVNyePy5kYTdqQQUX5r1blzMzHSa1N197z%2Fb7EyALt0CEA7P9DjI%2Fr81bgTYapgbGlA%3D
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2340
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.17.189.192:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
23.216.77.8:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.31.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6388
ByteFence.exe
104.22.0.235:443
api.reasonsecurity.com
CLOUDFLARENET
unknown
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6388
ByteFence.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.8
  • 23.216.77.36
  • 23.216.77.6
  • 23.216.77.42
  • 23.216.77.20
  • 2.16.241.19
  • 2.16.241.12
whitelisted
google.com
  • 172.217.16.206
whitelisted
logs.bytefence.com
whitelisted
login.live.com
  • 40.126.31.129
  • 40.126.31.69
  • 40.126.31.131
  • 20.190.159.75
  • 20.190.159.128
  • 20.190.159.23
  • 40.126.31.73
  • 20.190.159.64
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
api.reason.technology
whitelisted
proxel.bytefence.com
whitelisted
api.reasonsecurity.com
  • 104.22.0.235
  • 104.22.1.235
  • 172.67.9.68
unknown
cdn.bytefence.com
shared

Threats

No threats detected
No debug info