File name:

bytefence-update.exe

Full analysis: https://app.any.run/tasks/a20c9c1d-e407-4531-ab32-2191f47ea72d
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 30, 2025, 17:25:53
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

B694A9AF3522899AEB42F13CEE12EF0B

SHA1:

5F17EF45E4AA0C159E6365E55768BFDBC4CD0392

SHA256:

433BA2FDC1F4B9E3C1067392E6E014155EA42C25C94D1251F396FAC6092D690F

SSDEEP:

98304:ci4hYPVKlerkn461FAbkOnUEEj54qpUVugoh8UcxqHU7ooj/j3b6r1cBT3Z1iTVU:PuNVbjruDpKoc8Ete3M66Z++ermTnzT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • ByteFence.exe (PID: 6388)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • bytefence-update.exe (PID: 1276)
      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • Drops 7-zip archiver for unpacking

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • Process drops legitimate windows executable

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • Creates a software uninstall entry

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • There is functionality for taking screenshot (YARA)

      • bytefence-update.exe (PID: 1276)
    • Reads the date of Windows installation

      • ByteFence.exe (PID: 6388)
    • Reads the BIOS version

      • ByteFence.exe (PID: 6388)
    • Executes as Windows Service

      • ByteFenceService.exe (PID: 5548)
      • WmiApSrv.exe (PID: 5960)
    • Reads security settings of Internet Explorer

      • ByteFence.exe (PID: 6388)
  • INFO

    • Checks supported languages

      • bytefence-update.exe (PID: 1276)
      • bytefence-installer-5.4.3.1.exe (PID: 4244)
      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 4268)
      • ByteFenceService.exe (PID: 5548)
    • Reads the computer name

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 5548)
      • ByteFenceService.exe (PID: 4268)
    • Creates files in the program directory

      • bytefence-update.exe (PID: 1276)
      • bytefence-installer-5.4.3.1.exe (PID: 4244)
      • ByteFenceService.exe (PID: 4268)
      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 5548)
    • The sample compiled with english language support

      • bytefence-update.exe (PID: 1276)
      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • Create files in a temporary directory

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
      • ByteFence.exe (PID: 6388)
    • SQLite executable

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
    • Checks proxy server information

      • bytefence-installer-5.4.3.1.exe (PID: 4244)
      • ByteFence.exe (PID: 6388)
    • Reads Environment values

      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 5548)
    • Process checks whether UAC notifications are on

      • ByteFence.exe (PID: 6388)
    • Reads Windows Product ID

      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 5548)
    • Reads the machine GUID from the registry

      • ByteFence.exe (PID: 6388)
      • ByteFenceService.exe (PID: 4268)
      • ByteFenceService.exe (PID: 5548)
    • Disables trace logs

      • ByteFence.exe (PID: 6388)
    • Reads product name

      • ByteFence.exe (PID: 6388)
    • Reads the software policy settings

      • ByteFence.exe (PID: 6388)
    • Reads the time zone

      • ByteFence.exe (PID: 6388)
    • Creates files or folders in the user directory

      • ByteFence.exe (PID: 6388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:01:30 03:57:31+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x31d6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.4.3.1
ProductVersionNumber: 5.4.3.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: ByteFence Anti-Malware
CompanyName: Byte Technologies LLC
FileDescription: ByteFence Anti-Malware Update
FileVersion: 5.4.3.1
LegalCopyright: Copyright © 2019 Byte Technologies LLC
LegalTrademarks: ByteFence Anti-Malware is a trademark of Byte Technologies LLC
ProductName: ByteFence Anti-Malware
ProductVersion: 5.4.3.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bytefence-update.exe bytefence-installer-5.4.3.1.exe bytefence.exe bytefenceservice.exe no specs bytefenceservice.exe no specs wmiapsrv.exe no specs slui.exe no specs bytefence-update.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
904"C:\Users\admin\AppData\Local\Temp\bytefence-update.exe" C:\Users\admin\AppData\Local\Temp\bytefence-update.exeexplorer.exe
User:
admin
Company:
Byte Technologies LLC
Integrity Level:
MEDIUM
Description:
ByteFence Anti-Malware Update
Exit code:
3221226540
Version:
5.4.3.1
Modules
Images
c:\users\admin\appdata\local\temp\bytefence-update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1276"C:\Users\admin\AppData\Local\Temp\bytefence-update.exe" C:\Users\admin\AppData\Local\Temp\bytefence-update.exe
explorer.exe
User:
admin
Company:
Byte Technologies LLC
Integrity Level:
HIGH
Description:
ByteFence Anti-Malware Update
Exit code:
0
Version:
5.4.3.1
Modules
Images
c:\users\admin\appdata\local\temp\bytefence-update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4244"C:\Program Files\ByteFence\bytefence-installer-5.4.3.1.exe" /SC:\Program Files\ByteFence\bytefence-installer-5.4.3.1.exe
bytefence-update.exe
User:
admin
Company:
Byte Technologies LLC
Integrity Level:
HIGH
Description:
ByteFence Anti-Malware
Exit code:
0
Version:
5.4.3.1
Modules
Images
c:\program files\bytefence\bytefence-installer-5.4.3.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4268"c:\program files\bytefence\ByteFenceService.exe" /iC:\Program Files\ByteFence\ByteFenceService.exeByteFence.exe
User:
admin
Company:
Byte Technologies LLC
Integrity Level:
HIGH
Description:
ByteFence Anti-Malware
Exit code:
0
Version:
5.4.3.1
Modules
Images
c:\program files\bytefence\bytefenceservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4728C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5548"c:\program files\bytefence\ByteFenceService.exe"C:\Program Files\ByteFence\ByteFenceService.exeservices.exe
User:
SYSTEM
Company:
Byte Technologies LLC
Integrity Level:
SYSTEM
Description:
ByteFence Anti-Malware
Version:
5.4.3.1
Modules
Images
c:\program files\bytefence\bytefenceservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5960C:\WINDOWS\system32\wbem\WmiApSrv.exeC:\Windows\System32\wbem\WmiApSrv.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
WMI Performance Reverse Adapter
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\psapi.dll
6388"C:\Program Files\ByteFence\ByteFence.exe"C:\Program Files\ByteFence\ByteFence.exe
bytefence-installer-5.4.3.1.exe
User:
admin
Company:
Byte Technologies LLC
Integrity Level:
HIGH
Description:
ByteFence Anti-Malware
Version:
5.4.3.1
Modules
Images
c:\program files\bytefence\bytefence.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
21 326
Read events
21 237
Write events
89
Delete events
0

Modification events

(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ByteFence
Operation:writeName:WDDASBLD
Value:
1
(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ByteFence
Operation:writeName:WDDASD
Value:
0
(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ByteFence
Operation:writeName:ERTPSUP
Value:
1
(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ByteFence
Operation:writeName:WDDASBLD
Value:
1
(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ByteFence
Operation:writeName:WDDASD
Value:
0
(PID) Process:(1276) bytefence-update.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ByteFence
Operation:writeName:ERTPSUP
Value:
1
(PID) Process:(4244) bytefence-installer-5.4.3.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:DisplayName
Value:
ByteFence Anti-Malware
(PID) Process:(4244) bytefence-installer-5.4.3.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:UninstallString
Value:
"C:\Program Files\ByteFence\uninstall.exe"
(PID) Process:(4244) bytefence-installer-5.4.3.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:Publisher
Value:
Byte Technologies LLC
(PID) Process:(4244) bytefence-installer-5.4.3.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Operation:writeName:InstallSource
Value:
C:\Program Files\ByteFence\
Executable files
34
Suspicious files
737
Text files
17
Unknown types
3

Dropped files

PID
Process
Filename
Type
4244bytefence-installer-5.4.3.1.exeC:\Users\admin\AppData\Local\Temp\nsxBC00.tmp\nsExec.dllexecutable
MD5:50BA20CAD29399E2DB9FA75A1324BD1D
SHA256:E7B145ABC7C519E6BD91DC06B7B83D1E73735AC1AC37D30A7889840A6EED38FC
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\ByteFenceGUI.dllexecutable
MD5:B255457F6A83DDD5857D1D596D007665
SHA256:DCB12533629F0A34FD99D9906208301F93453B6EDBC22467B36813ECE82079F2
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\Microsoft.Diagnostics.Tracing.TraceEvent.dllexecutable
MD5:D09B4A4509907F75F506B996A5FF7554
SHA256:6F8A2F1D045EFB952C1EA9988BB5DCC72555ECCAFE9B32C2C51B439EA1F28453
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\ByteFenceScan.exeexecutable
MD5:E38C4823C0F2CC0AAF9CA3AF67A64BC5
SHA256:163703C9AE372A86C5EA842A500AE100F83B13952F16C1A44FD900176EF70B87
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\rsUtils.dllexecutable
MD5:77E204240E1C8BCEF7C76FDAD68FBA4B
SHA256:A5E4C60D6900ABD3BADAF6103EE9F8D6656D0E47622CCD1CB7D5130924E3F8DD
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\rsEngineHelper.exe.configxml
MD5:E3D5F62B7B28176A510484E465FA0F18
SHA256:827CDA24DF7876010D5239FE2B8AF49472442D899F9C0F6D9FF53B4FF6860946
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\rsEngineHelper.exeexecutable
MD5:70FAEE8156584C778835643BDB8A783C
SHA256:E98AC8B609F98B692D3B149A84EE63432CC30724B86724A6B51795A66E8A83BD
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\rsEngine.dllexecutable
MD5:2C26A58F2711896ED930E8E806926CC3
SHA256:3C8543820B8841F216AD76B6FA8F18C30D355119703C32FF38DFB3309B0D1B97
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\WhiteList.dattext
MD5:F2DA96B01DFD8E829B60483F79007534
SHA256:78C96767E7F740BEFABFF1A55B4C485D50A4FB2A11D0B671E97421C94ADC0239
4244bytefence-installer-5.4.3.1.exeC:\Program Files\ByteFence\rsMessages.dllexecutable
MD5:0B6B9B54B403B53436810EEC277ED252
SHA256:F691C8E1DCC96EC7B9D1693D6FA60533DC2C700AB8FDD3195D937DE2DF46F827
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
34
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6388
ByteFence.exe
GET
200
2.17.189.192:80
http://ts-crl.ws.symantec.com/tss-ca-g2.crl
unknown
whitelisted
2340
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2340
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
GET
200
23.216.77.8:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl%20
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D
unknown
whitelisted
6388
ByteFence.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEApONbf5a7%2B%2BD8oIgcx970c%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
23.216.77.8:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.31.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6388
ByteFence.exe
104.22.0.235:443
api.reasonsecurity.com
CLOUDFLARENET
unknown
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6388
ByteFence.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.8
  • 23.216.77.36
  • 23.216.77.6
  • 23.216.77.42
  • 23.216.77.20
  • 2.16.241.19
  • 2.16.241.12
whitelisted
google.com
  • 172.217.16.206
whitelisted
logs.bytefence.com
whitelisted
login.live.com
  • 40.126.31.129
  • 40.126.31.69
  • 40.126.31.131
  • 20.190.159.75
  • 20.190.159.128
  • 20.190.159.23
  • 40.126.31.73
  • 20.190.159.64
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
api.reason.technology
whitelisted
proxel.bytefence.com
whitelisted
api.reasonsecurity.com
  • 104.22.0.235
  • 104.22.1.235
  • 172.67.9.68
unknown
cdn.bytefence.com
shared

Threats

No threats detected
No debug info