File name:

bitdefender_avfree.exe

Full analysis: https://app.any.run/tasks/72139e02-8e1d-44ee-9ab0-b5f18ba22b86
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 18, 2024, 08:46:40
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
installer
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3C1EB0B87403AEFB465B8172E7C0CD55

SHA1:

72D5059A35A888BAC59A21E2D78E9C7253F36DF3

SHA256:

9AC87B3D50D6230BDA18CC6A8748604345E8875F202E9B56E4B2E79BA09FDE42

SSDEEP:

98304:mM5ssWuyR7C/Pxj5vb6wnuJ8rhHQRHUnyfhdwOK5vGvdX5Q7bsDOQ6zje7QctD0c:bvGiQPAjJtAczEnp/FbYJRxUsYFkpmf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • DiscoverySrv.exe (PID: 6204)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • bitdefender_avfree.exe (PID: 3276)
      • agent_launcher.exe (PID: 4076)
    • Executable content was dropped or overwritten

      • bitdefender_avfree.exe (PID: 3276)
      • setuppackage.exe (PID: 3828)
      • installer.exe (PID: 2620)
      • ProductAgentService.exe (PID: 6888)
      • uif3B0A.tmp (PID: 7156)
    • Checks Windows Trust Settings

      • agent_launcher.exe (PID: 4076)
    • Executes as Windows Service

      • bdredline.exe (PID: 3836)
      • ProductAgentService.exe (PID: 6888)
    • Process drops legitimate windows executable

      • ProductAgentService.exe (PID: 6888)
      • uif3B0A.tmp (PID: 7156)
      • MicrosoftEdgeUpdate.exe (PID: 4128)
    • Starts a Microsoft application from unusual location

      • uif3B0A.tmp (PID: 7156)
      • MicrosoftEdgeUpdate.exe (PID: 4128)
    • Starts application with an unusual extension

      • ProductAgentService.exe (PID: 6888)
  • INFO

    • The process uses the downloaded file

      • bitdefender_avfree.exe (PID: 3276)
      • agent_launcher.exe (PID: 4076)
    • Create files in a temporary directory

      • bitdefender_avfree.exe (PID: 3276)
    • Reads the computer name

      • bitdefender_avfree.exe (PID: 3276)
      • agent_launcher.exe (PID: 4076)
    • Checks supported languages

      • agent_launcher.exe (PID: 4076)
      • bitdefender_avfree.exe (PID: 3276)
    • Reads the machine GUID from the registry

      • agent_launcher.exe (PID: 4076)
    • Process checks computer location settings

      • bitdefender_avfree.exe (PID: 3276)
      • agent_launcher.exe (PID: 4076)
    • Reads the software policy settings

      • agent_launcher.exe (PID: 4076)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:08:14 19:15:49+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 188416
InitializedDataSize: 265216
UninitializedDataSize: -
EntryPoint: 0x1cab5
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
19
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bitdefender_avfree.exe agent_launcher.exe no specs bddeploy.exe setuppackage.exe installer.exe productagentservice.exe no specs bdredline.exe productagentservice.exe no specs productagentservice.exe no specs productagentservice.exe no specs productagentservice.exe discoverysrv.exe no specs regsvr32.exe no specs discoverysrv.exe no specs productagentui.exe no specs uif3b0a.tmp microsoftedgeupdate.exe wermgr.exe watchdog.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1156"C:\Program Files\Bitdefender Agent\ProductAgentService.exe" protectC:\Program Files\Bitdefender Agent\ProductAgentService.exeinstaller.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Bitdefender Agent
Exit code:
31
Version:
27.0.1.283
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1172"C:\Program Files\Bitdefender Agent\27.0.1.286\ProductAgentUI.exe" show=progress event_retry=Global\7295237F-E98C-4C46-A4A4-07F0D66278C2 app_name="Bitdefender Security"C:\Program Files\Bitdefender Agent\27.0.1.286\ProductAgentUI.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
Bitdefender Agent
Version:
27.0.1.284
Modules
Images
c:\program files\bitdefender agent\27.0.1.286\productagentui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
2620"C:\Users\admin\AppData\Local\Temp\RarSFX0\packages\installer.exe"C:\Users\admin\AppData\Local\Temp\RarSFX0\packages\installer.exe
bddeploy.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Installation File
Exit code:
0
Version:
27.0.16.281
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\packages\installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3276"C:\Users\admin\Desktop\bitdefender_avfree.exe" C:\Users\admin\Desktop\bitdefender_avfree.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\bitdefender_avfree.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3828"C:\Users\admin\AppData\Local\Temp\RarSFX0\packages\setuppackage.exe"C:\Users\admin\AppData\Local\Temp\RarSFX0\packages\setuppackage.exe
bddeploy.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\packages\setuppackage.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3836"C:\Program Files\Bitdefender Agent\redline\bdredline.exe"C:\Program Files\Bitdefender Agent\redline\bdredline.exe
services.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
Bitdefender redline update
Version:
1.0.1.113
Modules
Images
c:\program files\bitdefender agent\redline\bdredline.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
4040"C:\Program Files\Bitdefender Agent\27.0.1.286\DiscoverySrv.exe"C:\Program Files\Bitdefender Agent\27.0.1.286\DiscoverySrv.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
DiscoverySrv
Version:
27.0.1.283
Modules
Images
c:\program files\bitdefender agent\27.0.1.286\discoverysrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\crypt32.dll
c:\windows\syswow64\ucrtbase.dll
4076"C:\Users\admin\AppData\Local\Temp\RarSFX0\agent_launcher.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\agent_launcher.exebitdefender_avfree.exe
User:
admin
Company:
Bitdefender
Integrity Level:
MEDIUM
Description:
Bitdefender Agent Launcher
Exit code:
0
Version:
27.0.16.281
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\agent_launcher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4128"C:\Program Files (x86)\Microsoft\Temp\EU699B.tmp\MicrosoftEdgeUpdate.exe" /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Program Files (x86)\Microsoft\Temp\EU699B.tmp\MicrosoftEdgeUpdate.exe
uif3B0A.tmp
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Edge Update
Exit code:
2147747592
Version:
1.3.195.25
Modules
Images
c:\program files (x86)\microsoft\temp\eu699b.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
4464"C:\Program Files\Bitdefender Agent\ProductAgentService.exe" installC:\Program Files\Bitdefender Agent\ProductAgentService.exeinstaller.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Bitdefender Agent
Exit code:
0
Version:
27.0.1.283
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
42 156
Read events
42 040
Write events
111
Delete events
5

Modification events

(PID) Process:(2620) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:InstallerLauncher
Value:
(PID) Process:(2620) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:InstallerLauncher
Value:
(PID) Process:(2620) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Install
Operation:writeName:ShortInstallPath
Value:
C:\Program Files\Bitdefender Agent\
(PID) Process:(2620) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Install
Operation:writeName:InstallPath
Value:
C:\Program Files\Bitdefender Agent\
(PID) Process:(2620) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceFolder
Value:
C:\ProgramData\Bitdefender Agent
(PID) Process:(2620) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceLevel
Value:
1
(PID) Process:(2620) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceMode
Value:
0
(PID) Process:(2620) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Submission\Agent Submission Tool
Operation:writeName:AppPath
Value:
C:\Program Files\Bitdefender Agent\27.0.1.286\bdsubwiz.exe
(PID) Process:(2620) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bitdefender Agent
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Bitdefender Agent\27.0.1.286\bdicon.ico
(PID) Process:(2620) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bitdefender Agent
Operation:writeName:DisplayName
Value:
Bitdefender Agent
Executable files
262
Suspicious files
32
Text files
175
Unknown types
0

Dropped files

PID
Process
Filename
Type
3276bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\bddeploy.exeexecutable
MD5:25EC4BC0BEDE15B3387A60F57B26B7E5
SHA256:802909C5996EA420A57954D6F50C2781D7601A62F9BA51B239EAFEAAF48E310F
3276bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\setuppackage.exeexecutable
MD5:1BE6C5E5D48BD16146F1FAC821C9796E
SHA256:3AB74216BE750FD89121FBC458842E557BCDC16FE06364596C66736B9F9BDE97
3828setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\bdnc.ini.md5text
MD5:3A0A7D7823833BE6E8AF5AB1AF295139
SHA256:A5F15BA3B16384B584780F2BBB0EF3E7FD49CCABD0B9CA10437882F65F49C7F2
3276bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\bddeploy.exe.md5text
MD5:E36C618298C4CD97AC09D78BCD9C8337
SHA256:874F112980DE1C94FE7F714909A9B1BCE6A60C03E1C6888F8CC3801DF843184F
3828setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\additional.dllexecutable
MD5:96E0A4B88ADE20EA0580FE5241133083
SHA256:C33B408112C8825AD7199E9DA607695AF1DB83904A9598643C9A4BBA56BB8D29
3276bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\agentpackage.exe.md5text
MD5:A7949160CE936E6F6E8959216AD59A59
SHA256:28A79526F776B75ACCC52197CB633D988D970716906BE0DAD3410EE553901DA1
3276bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\agentpackage.exeexecutable
MD5:AE64C8139346C4D7401482AE96FBAD03
SHA256:34146DA91CC95CB2341905E781C717DBD615CE3D259210C5386DBA69EE57578F
3828setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\bdec.inibinary
MD5:96D15C4F3DB04429631866751A1D2890
SHA256:E8D31C1DE790F738EF75DAA0402584560A0672402D0D3DED0899D2DBC95FB911
5516bddeploy.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\data\params.jsonbinary
MD5:421A73583B2B4BA31F285D6DCDAEA56F
SHA256:0FA4DA77FFC6F078DD98D7ACAAB65674CDE0CC4AA5274CCAD6DF0018A3CD36A8
3828setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\bdnc.dllexecutable
MD5:51F03F28D69A2211AA0824469A3DEB3E
SHA256:97BCCC07CE5B1982120F7EC930F0464ADB830466DABE897CD502009725CC581B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
42
TCP/UDP connections
52
DNS requests
31
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3524
RUXIMICS.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3836
bdredline.exe
GET
404
104.18.169.222:80
http://upgrade.bitdefender.com/redline_com.bitdefender.agent/versions.id
unknown
whitelisted
GET
200
35.190.56.82:443
https://elb-iow-gcp.nimbus.bitdefender.net/_ServerStatus
unknown
text
21 b
whitelisted
GET
200
35.190.56.82:443
https://elb-iow-gcp.nimbus.bitdefender.net/_ServerStatus
unknown
text
21 b
whitelisted
GET
200
34.117.13.33:443
https://us.nimbus.bitdefender.net/_ServerStatus
unknown
text
21 b
whitelisted
GET
200
34.117.13.33:443
https://us.nimbus.bitdefender.net/_ServerStatus
unknown
text
21 b
whitelisted
GET
200
34.120.85.253:443
https://elb-ore-gcp.nimbus.bitdefender.net/_ServerStatus
unknown
text
21 b
whitelisted
GET
200
34.120.68.241:443
https://nimbus.bitdefender.net/bdnc/config
unknown
binary
240 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
3524
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3524
RUXIMICS.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5488
MoUsoCoreWorker.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5488
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.46
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
upgrade.bitdefender.com
  • 104.18.169.222
  • 104.18.168.222
whitelisted
nimbus.bitdefender.net
  • 34.120.68.241
  • 2600:1901:0:69b7::
whitelisted
us.nimbus.bitdefender.net
  • 34.117.13.33
  • 2600:1901:0:4ba4::
whitelisted
elb-iow-gcp.nimbus.bitdefender.net
  • 35.190.56.82
  • 2600:1901:0:5723::
whitelisted
elb-ore-gcp.nimbus.bitdefender.net
  • 34.120.85.253
  • 2600:1901:0:f8b::
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted

Threats

PID
Process
Class
Message
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Process
Message
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.