File name:

Bitwarden-Installer-2025.2.1.exe

Full analysis: https://app.any.run/tasks/bd48e9ce-62d9-416c-a3c4-87c84392da14
Verdict: Malicious activity
Analysis date: May 15, 2025, 14:52:13
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

24B74B3DCF7B95C5C99C9AFBFADD0BD8

SHA1:

72DC356F9328B77F24ACEAAE7AE24224C18D252F

SHA256:

8556A195A0A7D456716D22A879AFE7F4006B4DE2CDD1322FDD7D75F80BEC9F96

SSDEEP:

24576:SBLifzIMulZSRF4HyNt85nq2O6vhCmSxbv0kFgQ0Qh1lhUqXaM4DEA+AD:SB+fzIMulZSRF4HyNt85q2O6ZCmSxbvU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • Bitwarden-Installer-2025.2.1.exe (PID: 1812)
      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Bitwarden-Installer-2025.2.1.exe (PID: 1812)
      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
    • Executable content was dropped or overwritten

      • Bitwarden-Installer-2025.2.1.exe (PID: 1812)
      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
    • Reads security settings of Internet Explorer

      • Bitwarden-Installer-2025.2.1.exe (PID: 1812)
      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
    • Application launched itself

      • Bitwarden-Installer-2025.2.1.exe (PID: 1812)
    • There is functionality for taking screenshot (YARA)

      • Bitwarden-Installer-2025.2.1.exe (PID: 1812)
      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
  • INFO

    • Checks supported languages

      • Bitwarden-Installer-2025.2.1.exe (PID: 1812)
      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
    • The sample compiled with english language support

      • Bitwarden-Installer-2025.2.1.exe (PID: 1812)
      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
    • Process checks computer location settings

      • Bitwarden-Installer-2025.2.1.exe (PID: 1812)
    • Reads the computer name

      • Bitwarden-Installer-2025.2.1.exe (PID: 1812)
    • Create files in a temporary directory

      • Bitwarden-Installer-2025.2.1.exe (PID: 1812)
      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
    • Creates files in the program directory

      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
    • Checks proxy server information

      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
    • Reads the machine GUID from the registry

      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
    • Reads the software policy settings

      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
    • Creates files or folders in the user directory

      • Bitwarden-Installer-2025.2.1.exe (PID: 5244)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:26:14+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 473088
UninitializedDataSize: 16384
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2025.2.1.0
ProductVersionNumber: 2025.2.1.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Bitwarden Inc.
FileDescription: A secure and free password manager for all of your devices.
FileVersion: 2025.2.1
LegalCopyright: Copyright © 2015-2024 Bitwarden Inc.
ProductName: Bitwarden
ProductVersion: 2025.2.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start bitwarden-installer-2025.2.1.exe bitwarden-installer-2025.2.1.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1812"C:\Users\admin\AppData\Local\Temp\Bitwarden-Installer-2025.2.1.exe" C:\Users\admin\AppData\Local\Temp\Bitwarden-Installer-2025.2.1.exe
explorer.exe
User:
admin
Company:
Bitwarden Inc.
Integrity Level:
MEDIUM
Description:
A secure and free password manager for all of your devices.
Version:
2025.2.1
Modules
Images
c:\users\admin\appdata\local\temp\bitwarden-installer-2025.2.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2108C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5244"C:\Users\admin\AppData\Local\Temp\Bitwarden-Installer-2025.2.1.exe" /UAC:8014C /NCRC C:\Users\admin\AppData\Local\Temp\Bitwarden-Installer-2025.2.1.exe
Bitwarden-Installer-2025.2.1.exe
User:
admin
Company:
Bitwarden Inc.
Integrity Level:
HIGH
Description:
A secure and free password manager for all of your devices.
Version:
2025.2.1
Modules
Images
c:\users\admin\appdata\local\temp\bitwarden-installer-2025.2.1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
1 000
Read events
997
Write events
3
Delete events
0

Modification events

(PID) Process:(5244) Bitwarden-Installer-2025.2.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5244) Bitwarden-Installer-2025.2.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5244) Bitwarden-Installer-2025.2.1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
8
Suspicious files
2
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1812Bitwarden-Installer-2025.2.1.exeC:\Users\admin\AppData\Local\Temp\nsmC789.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
1812Bitwarden-Installer-2025.2.1.exeC:\Users\admin\AppData\Local\Temp\nsmC789.tmp\modern-wizard.bmpimage
MD5:0073DF1BFECFC543F9457843CC02B4A5
SHA256:35176DD40612D7542AF49B10E7ED927F25B4AB4A935BB4597909BEED8D1CACF8
5244Bitwarden-Installer-2025.2.1.exeC:\Users\admin\AppData\Local\Temp\nsg2C5D.tmp\StdUtils.dllexecutable
MD5:C6A6E03F77C313B267498515488C5740
SHA256:B72E9013A6204E9F01076DC38DABBF30870D44DFC66962ADBF73619D4331601E
1812Bitwarden-Installer-2025.2.1.exeC:\Users\admin\AppData\Local\Temp\nsmC789.tmp\nsDialogs.dllexecutable
MD5:466179E1C8EE8A1FF5E4427DBB6C4A01
SHA256:1E40211AF65923C2F4FD02CE021458A7745D28E2F383835E3015E96575632172
5244Bitwarden-Installer-2025.2.1.exeC:\Users\admin\AppData\Local\Temp\nsg2C5D.tmp\UAC.dllexecutable
MD5:ADB29E6B186DAA765DC750128649B63D
SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08
5244Bitwarden-Installer-2025.2.1.exeC:\Users\admin\AppData\Local\Temp\nsg2C5D.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
5244Bitwarden-Installer-2025.2.1.exeC:\Users\admin\AppData\Local\Temp\nsg2C5D.tmp\modern-wizard.bmpimage
MD5:0073DF1BFECFC543F9457843CC02B4A5
SHA256:35176DD40612D7542AF49B10E7ED927F25B4AB4A935BB4597909BEED8D1CACF8
5244Bitwarden-Installer-2025.2.1.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751binary
MD5:E192462F281446B5D1500D474FBACC4B
SHA256:F1BA9F1B63C447682EBF9DE956D0DA2A027B1B779ABEF9522D347D3479139A60
1812Bitwarden-Installer-2025.2.1.exeC:\Users\admin\AppData\Local\Temp\nsmC789.tmp\UAC.dllexecutable
MD5:ADB29E6B186DAA765DC750128649B63D
SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08
1812Bitwarden-Installer-2025.2.1.exeC:\Users\admin\AppData\Local\Temp\nsmC789.tmp\StdUtils.dllexecutable
MD5:C6A6E03F77C313B267498515488C5740
SHA256:B72E9013A6204E9F01076DC38DABBF30870D44DFC66962ADBF73619D4331601E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
16
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
300
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
300
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5244
Bitwarden-Installer-2025.2.1.exe
GET
200
23.209.209.135:80
http://x1.c.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
300
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
300
SIHClient.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.159.75
  • 20.190.159.129
  • 40.126.31.128
  • 20.190.159.130
  • 20.190.159.0
  • 20.190.159.73
  • 40.126.31.130
  • 40.126.31.71
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
artifacts.bitwarden.com
  • 199.232.197.91
  • 199.232.193.91
whitelisted
x1.c.lencr.org
  • 23.209.209.135
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info