File name:

BitDefender.exe

Full analysis: https://app.any.run/tasks/83028a73-e61b-4ec2-95b4-bbd5be0775e9
Verdict: Malicious activity
Analysis date: November 18, 2024, 07:19:50
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
rust
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

D3AAE88F576F95DF9157E1FC1EE80726

SHA1:

EEFC47DFE0745CAEC97D11ABA570EEA2ACEB6BEB

SHA256:

809FD0248615F0DB51D7B01307A27D875E12F8D129035E77B3F34EB8EB227562

SSDEEP:

393216:HygBV9LVLGqMN9a+vDSOxwq459AyDXvxsYZ0IQlPc5JcRui7:3V9LMq0a+v6q4LPCVIQlPc5O

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • BitDefender.exe (PID: 7100)
    • Antivirus name has been found in the command line (generic signature)

      • BitDefender.exe (PID: 7100)
      • ProductAgentService.exe (PID: 700)
    • Registers / Runs the DLL via REGSVR32.EXE

      • DiscoverySrv.exe (PID: 3828)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BitDefender.exe (PID: 7100)
      • setuppackage.exe (PID: 2888)
      • installer.exe (PID: 4476)
    • Likely accesses (executes) a file from the Public directory

      • cmd.exe (PID: 5600)
      • chall.exe (PID: 2484)
    • Starts CMD.EXE for commands execution

      • BitDefender.exe (PID: 7100)
    • Reads security settings of Internet Explorer

      • BitDefender.exe (PID: 7100)
      • agent_launcher.exe (PID: 1952)
    • Checks Windows Trust Settings

      • agent_launcher.exe (PID: 1952)
    • Executes as Windows Service

      • bdredline.exe (PID: 6596)
      • ProductAgentService.exe (PID: 1500)
    • Application launched itself

      • ProductAgentService.exe (PID: 1500)
  • INFO

    • Checks supported languages

      • BitDefender.exe (PID: 7100)
      • chall.exe (PID: 2484)
      • agent_launcher.exe (PID: 1952)
    • Reads the computer name

      • chall.exe (PID: 2484)
      • BitDefender.exe (PID: 7100)
    • Create files in a temporary directory

      • BitDefender.exe (PID: 7100)
      • bddeploy.exe (PID: 4316)
      • setuppackage.exe (PID: 2888)
    • Process checks computer location settings

      • BitDefender.exe (PID: 7100)
    • The process uses the downloaded file

      • BitDefender.exe (PID: 7100)
      • agent_launcher.exe (PID: 1952)
    • Reads the machine GUID from the registry

      • agent_launcher.exe (PID: 1952)
    • Reads the software policy settings

      • agent_launcher.exe (PID: 1952)
    • Application based on Rust

      • bdredline.exe (PID: 6596)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:08:14 19:15:49+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 188416
InitializedDataSize: 265216
UninitializedDataSize: -
EntryPoint: 0xa6000
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
20
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bitdefender.exe cmd.exe no specs conhost.exe no specs chall.exe no specs agent_launcher.exe no specs bddeploy.exe setuppackage.exe installer.exe productagentservice.exe no specs bdredline.exe productagentservice.exe no specs productagentservice.exe no specs productagentservice.exe no specs productagentservice.exe discoverysrv.exe no specs regsvr32.exe no specs discoverysrv.exe no specs productagentservice.exe no specs productagentui.exe no specs watchdog.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
700"C:\Program Files\Bitdefender Agent\ProductAgentService.exe" start "C:\Users\admin\Desktop\BitDefender.exe"C:\Program Files\Bitdefender Agent\ProductAgentService.exeinstaller.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Bitdefender Agent
Exit code:
0
Version:
27.0.1.259
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1500"C:\Program Files\Bitdefender Agent\ProductAgentService.exe"C:\Program Files\Bitdefender Agent\ProductAgentService.exe
services.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
Bitdefender Agent
Version:
27.0.1.259
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1568"C:\Program Files\Bitdefender Agent\ProductAgentService.exe" protectC:\Program Files\Bitdefender Agent\ProductAgentService.exeinstaller.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Bitdefender Agent
Exit code:
31
Version:
27.0.1.259
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1744"C:\Program Files\Bitdefender Agent\ProductAgentService.exe" enableC:\Program Files\Bitdefender Agent\ProductAgentService.exeinstaller.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Bitdefender Agent
Exit code:
0
Version:
27.0.1.259
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1952"C:\Users\admin\AppData\Local\Temp\RarSFX0\agent_launcher.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\agent_launcher.exeBitDefender.exe
User:
admin
Company:
Bitdefender
Integrity Level:
MEDIUM
Description:
Bitdefender Agent Launcher
Exit code:
0
Version:
27.0.16.272
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\agent_launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2484c:\users\public\chall.exeC:\Users\Public\chall.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\public\chall.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
2888"C:\Users\admin\AppData\Local\Temp\RarSFX0\packages\setuppackage.exe"C:\Users\admin\AppData\Local\Temp\RarSFX0\packages\setuppackage.exe
bddeploy.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\packages\setuppackage.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3648"C:\Program Files\Bitdefender Agent\27.0.1.259\DiscoverySrv.exe"C:\Program Files\Bitdefender Agent\27.0.1.259\DiscoverySrv.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
DiscoverySrv
Version:
27.0.1.259
Modules
Images
c:\program files\bitdefender agent\27.0.1.259\discoverysrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\crypt32.dll
c:\windows\syswow64\ucrtbase.dll
3828"C:\Program Files\Bitdefender Agent\27.0.1.259\DiscoverySrv.exe" installC:\Program Files\Bitdefender Agent\27.0.1.259\DiscoverySrv.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
DiscoverySrv
Exit code:
0
Version:
27.0.1.259
Modules
Images
c:\program files\bitdefender agent\27.0.1.259\discoverysrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
4316"C:\Users\admin\AppData\Local\Temp\RarSFX0\bddeploy.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\bddeploy.exe
agent_launcher.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Installation File
Exit code:
0
Version:
27.0.16.272
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\bddeploy.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
32 116
Read events
32 034
Write events
79
Delete events
3

Modification events

(PID) Process:(4476) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:InstallerLauncher
Value:
(PID) Process:(4476) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:InstallerLauncher
Value:
(PID) Process:(4476) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Install
Operation:writeName:ShortInstallPath
Value:
C:\Program Files\Bitdefender Agent\
(PID) Process:(4476) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Install
Operation:writeName:InstallPath
Value:
C:\Program Files\Bitdefender Agent\
(PID) Process:(4476) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceFolder
Value:
C:\ProgramData\Bitdefender Agent
(PID) Process:(4476) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceLevel
Value:
1
(PID) Process:(4476) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceMode
Value:
0
(PID) Process:(4476) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Submission\Agent Submission Tool
Operation:writeName:AppPath
Value:
C:\Program Files\Bitdefender Agent\27.0.1.259\bdsubwiz.exe
(PID) Process:(4476) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bitdefender Agent
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Bitdefender Agent\27.0.1.259\bdicon.ico
(PID) Process:(4476) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bitdefender Agent
Operation:writeName:DisplayName
Value:
Bitdefender Agent
Executable files
55
Suspicious files
22
Text files
165
Unknown types
3

Dropped files

PID
Process
Filename
Type
7100BitDefender.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\agentpackage.exeexecutable
MD5:854954078FE09F22FCF2B0B0C22239F5
SHA256:46508A899A5593358CDC6FCE29C09B2E9FCE3D483EB45802B26FF68EF52A184A
7100BitDefender.exeC:\Users\Public\chall.exeexecutable
MD5:0CA65E5CA88B8B26C3273F455DF15847
SHA256:5CFD1D56585B5CD7EC58E0689953938E17BE6BAE32656CAEB10285DA2C7DB31A
7100BitDefender.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\deploy.dllexecutable
MD5:EDAC260CC2F94367601FBB0725B98893
SHA256:30D8D141F7AD4409A742CFC0A6D700607069D599CC4DD6E597953C9698B06956
7100BitDefender.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\bddeploy.exeexecutable
MD5:5A578F9EDEAA9DDBBE6E05026EC709BC
SHA256:E9C71131FE2A6D2AA7283542F2D0A30FA7B672FD34B134667E4BAFF1CFA6DB3E
7100BitDefender.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\agent_launcher.exe.md5text
MD5:9CD4A3E36F54AC331333E17523FBF774
SHA256:BA5C0034C21EB8A01E431EAB96B5BA0F197A37BC8B5EB3F4A94973046939B4F9
7100BitDefender.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\agent_launcher.exeexecutable
MD5:52197EE706B8AF5ED2431EED01AA0DB5
SHA256:A72B1882E289D5678931CD91C579810CD16CC30AC0453A77B166CD219402B097
7100BitDefender.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\deploy.dll.md5text
MD5:B7ABBCA1D2EAD41663C4CE3C317A6A46
SHA256:52AAF751B05DC5D3065C5D716118739075BEE31702D9C3D0D5012AFB174BF5B9
7100BitDefender.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\bddeploy.exe.md5text
MD5:0973E2965F7841151D7A53AB9F598B43
SHA256:22269CB67FB9F78AF1F580BC45326E953D710C17C3A2062CB4C574F188521308
7100BitDefender.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\setuppackage.exeexecutable
MD5:F6490A11A2CB2AAEE84021DACF2E2CCF
SHA256:EF640B738BBF96AA374EA8E488F768576EFCE2790CE039FADDA4CCBB0E2F4E3C
7100BitDefender.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\agentpackage.exe.md5text
MD5:665B937A18FDBBDB74D01B8761119BCD
SHA256:6C6D17CD3866C5850FC713E31EB4C325618642BE2CB3E953D45CFE96483A8D37
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
54
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6596
bdredline.exe
GET
403
104.18.168.222:80
http://upgrade.bitdefender.com/redline_com.bitdefender.agent/versions.id
unknown
whitelisted
6944
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
34.120.68.241:443
https://nimbus.bitdefender.net/bdnc/config
unknown
binary
237 b
whitelisted
GET
200
34.120.68.241:443
https://eu.nimbus.bitdefender.net/_ServerStatus
unknown
text
21 b
whitelisted
GET
200
34.149.211.227:443
https://mclb-gcp.nimbus.bitdefender.net/_ServerStatus
unknown
text
21 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
104.126.37.146:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5488
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5488
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
www.bing.com
  • 104.126.37.146
  • 104.126.37.137
  • 104.126.37.130
  • 104.126.37.153
  • 104.126.37.145
  • 104.126.37.136
  • 104.126.37.139
  • 104.126.37.128
  • 104.126.37.131
whitelisted
google.com
  • 142.250.181.238
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
upgrade.bitdefender.com
  • 104.18.168.222
  • 104.18.169.222
whitelisted
nimbus.bitdefender.net
  • 34.120.68.241
whitelisted
mclb-gcp.nimbus.bitdefender.net
  • 34.149.211.227
whitelisted
eu.nimbus.bitdefender.net
  • 34.120.68.241
whitelisted
elb-ned-gcp.nimbus.bitdefender.net
  • 34.54.215.149
whitelisted

Threats

No threats detected
No debug info