File name:

bitdefender_avfree.exe

Full analysis: https://app.any.run/tasks/b9e67f7d-7826-4cdc-9087-a3ae04abf4ee
Verdict: Malicious activity
Analysis date: May 12, 2025, 00:34:49
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
installer
rust
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

F874BA4FDCBCB75B27A3FEBE5790528B

SHA1:

5B43C936F6275A59435C517369C4C1744606995E

SHA256:

B39B15E2F621D653E274251815C26DC2C07088A77112D6D75FB50BC29E13C7BF

SSDEEP:

196608:l3RF4BhzF+0rBOGtFffXceyGou+761fXU23oa6LCCJWJ3j:l3uhzTBrfXpou+Ak23oJTJWJ3j

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • DiscoverySrv.exe (PID: 2088)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • bitdefender_avfree.exe (PID: 7392)
      • setuppackage.exe (PID: 7772)
      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 5544)
      • qxb1470.tmp (PID: 7520)
    • Reads security settings of Internet Explorer

      • agent_launcher.exe (PID: 7564)
      • bitdefender_avfree.exe (PID: 7392)
      • bddeploy.exe (PID: 7728)
      • installer.exe (PID: 7888)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Process drops legitimate windows executable

      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 5544)
      • qxb1470.tmp (PID: 7520)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Creates a software uninstall entry

      • installer.exe (PID: 7888)
    • The process verifies whether the antivirus software is installed

      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 8028)
      • bdredline.exe (PID: 8172)
      • ProductAgentService.exe (PID: 7012)
      • ProductAgentService.exe (PID: 6404)
      • ProductAgentService.exe (PID: 5544)
      • DiscoverySrv.exe (PID: 2088)
      • regsvr32.exe (PID: 920)
      • DiscoverySrv.exe (PID: 4120)
      • ProductAgentService.exe (PID: 4688)
      • ProductAgentUI.exe (PID: 7484)
      • qxb1470.tmp (PID: 7520)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • There is functionality for taking screenshot (YARA)

      • bitdefender_avfree.exe (PID: 7392)
      • ProductAgentUI.exe (PID: 7484)
    • Executes as Windows Service

      • ProductAgentService.exe (PID: 5544)
      • bdredline.exe (PID: 8172)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 920)
    • Starts a Microsoft application from unusual location

      • qxb1470.tmp (PID: 7520)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Starts application with an unusual extension

      • ProductAgentService.exe (PID: 5544)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 7724)
  • INFO

    • The sample compiled with english language support

      • bitdefender_avfree.exe (PID: 7392)
      • setuppackage.exe (PID: 7772)
      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 5544)
      • qxb1470.tmp (PID: 7520)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Checks supported languages

      • bitdefender_avfree.exe (PID: 7392)
      • agent_launcher.exe (PID: 7564)
      • bddeploy.exe (PID: 7728)
      • setuppackage.exe (PID: 7772)
      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 8028)
      • ProductAgentService.exe (PID: 7012)
      • ProductAgentService.exe (PID: 6404)
      • ProductAgentService.exe (PID: 5544)
      • bdredline.exe (PID: 8172)
      • ProductAgentService.exe (PID: 4688)
      • DiscoverySrv.exe (PID: 2088)
      • DiscoverySrv.exe (PID: 4120)
      • qxb1470.tmp (PID: 7520)
      • ProductAgentUI.exe (PID: 7484)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Reads the computer name

      • bitdefender_avfree.exe (PID: 7392)
      • agent_launcher.exe (PID: 7564)
      • setuppackage.exe (PID: 7772)
      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 4688)
      • ProductAgentService.exe (PID: 7012)
      • ProductAgentService.exe (PID: 6404)
      • ProductAgentService.exe (PID: 5544)
      • ProductAgentService.exe (PID: 8028)
      • bdredline.exe (PID: 8172)
      • DiscoverySrv.exe (PID: 4120)
      • ProductAgentUI.exe (PID: 7484)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Create files in a temporary directory

      • bitdefender_avfree.exe (PID: 7392)
      • bddeploy.exe (PID: 7728)
      • setuppackage.exe (PID: 7772)
      • installer.exe (PID: 7888)
    • Reads the machine GUID from the registry

      • agent_launcher.exe (PID: 7564)
      • bddeploy.exe (PID: 7728)
      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 5544)
      • DiscoverySrv.exe (PID: 2088)
      • DiscoverySrv.exe (PID: 4120)
      • ProductAgentUI.exe (PID: 7484)
    • Process checks computer location settings

      • bitdefender_avfree.exe (PID: 7392)
      • agent_launcher.exe (PID: 7564)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Reads the software policy settings

      • agent_launcher.exe (PID: 7564)
      • bddeploy.exe (PID: 7728)
      • installer.exe (PID: 7888)
      • DiscoverySrv.exe (PID: 2088)
      • DiscoverySrv.exe (PID: 4120)
      • ProductAgentService.exe (PID: 5544)
      • ProductAgentUI.exe (PID: 7484)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
      • wermgr.exe (PID: 7864)
    • Creates files in the program directory

      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 4688)
      • ProductAgentService.exe (PID: 5544)
      • qxb1470.tmp (PID: 7520)
    • Reads Environment values

      • ProductAgentService.exe (PID: 5544)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Reads CPU info

      • ProductAgentService.exe (PID: 5544)
    • Application based on Rust

      • bdredline.exe (PID: 8172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:08:14 19:15:49+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 188416
InitializedDataSize: 265216
UninitializedDataSize: -
EntryPoint: 0x1cab5
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
20
Malicious processes
15
Suspicious processes
1

Behavior graph

Click at the process to see the details
start bitdefender_avfree.exe agent_launcher.exe no specs bddeploy.exe setuppackage.exe installer.exe productagentservice.exe no specs bdredline.exe productagentservice.exe no specs productagentservice.exe no specs productagentservice.exe no specs productagentservice.exe discoverysrv.exe no specs regsvr32.exe no specs discoverysrv.exe no specs productagentui.exe no specs qxb1470.tmp microsoftedgeupdate.exe wermgr.exe slui.exe watchdog.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
920regsvr32 /s "C:\Program Files\Bitdefender Agent\27.1.1.12\DiscoveryComp.dll"C:\Windows\SysWOW64\regsvr32.exeDiscoverySrv.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1052"C:\Program Files\Bitdefender Agent\27.1.1.12\WatchDog.exe" installC:\Program Files\Bitdefender Agent\27.1.1.12\WatchDog.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
Bitdefender Agent WatchDog
Exit code:
0
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\27.1.1.12\watchdog.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
2088"C:\Program Files\Bitdefender Agent\27.1.1.12\DiscoverySrv.exe" installC:\Program Files\Bitdefender Agent\27.1.1.12\DiscoverySrv.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
DiscoverySrv
Exit code:
0
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\27.1.1.12\discoverysrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
2552C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4120"C:\Program Files\Bitdefender Agent\27.1.1.12\DiscoverySrv.exe"C:\Program Files\Bitdefender Agent\27.1.1.12\DiscoverySrv.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
DiscoverySrv
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\27.1.1.12\discoverysrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\crypt32.dll
c:\windows\syswow64\ucrtbase.dll
4688"C:\Program Files\Bitdefender Agent\ProductAgentService.exe" start "C:\Users\admin\Desktop\bitdefender_avfree.exe"C:\Program Files\Bitdefender Agent\ProductAgentService.exeinstaller.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Bitdefender Agent
Exit code:
0
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5544"C:\Program Files\Bitdefender Agent\ProductAgentService.exe"C:\Program Files\Bitdefender Agent\ProductAgentService.exe
services.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
Bitdefender Agent
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
6404"C:\Program Files\Bitdefender Agent\ProductAgentService.exe" enableC:\Program Files\Bitdefender Agent\ProductAgentService.exeinstaller.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Bitdefender Agent
Exit code:
0
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7012"C:\Program Files\Bitdefender Agent\ProductAgentService.exe" installC:\Program Files\Bitdefender Agent\ProductAgentService.exeinstaller.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Bitdefender Agent
Exit code:
0
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7392"C:\Users\admin\Desktop\bitdefender_avfree.exe" C:\Users\admin\Desktop\bitdefender_avfree.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\bitdefender_avfree.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
45 452
Read events
45 336
Write events
111
Delete events
5

Modification events

(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:InstallerLauncher
Value:
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:InstallerLauncher
Value:
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Install
Operation:writeName:ShortInstallPath
Value:
C:\Program Files\Bitdefender Agent\
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Install
Operation:writeName:InstallPath
Value:
C:\Program Files\Bitdefender Agent\
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceFolder
Value:
C:\ProgramData\Bitdefender Agent
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceLevel
Value:
1
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceMode
Value:
0
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Submission\Agent Submission Tool
Operation:writeName:AppPath
Value:
C:\Program Files\Bitdefender Agent\27.1.1.12\bdsubwiz.exe
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bitdefender Agent
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Bitdefender Agent\27.1.1.12\bdicon.ico
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bitdefender Agent
Operation:writeName:DisplayName
Value:
Bitdefender Agent
Executable files
264
Suspicious files
32
Text files
175
Unknown types
0

Dropped files

PID
Process
Filename
Type
7392bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\bddeploy.exeexecutable
MD5:03A02ABCFB156C7C82099EB62DF9339F
SHA256:5D399883746AA61D41044483FA34A51CB9D59B6370EE35EC281249958D7522F7
7392bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\agent_launcher.exeexecutable
MD5:9BCA7DCB536E538145FC35D3FD3D37ED
SHA256:13EA984AED446CDF8908CAF941A216A19443927F49009BDF4097ADAB0030A845
7392bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\setuppackage.exe.md5text
MD5:BD97FD6AB9E87C4291770D21718DB48F
SHA256:22D143F1D08B7A252820EAF4C8535B90D3C887676D2F2B6420A24464C74AF9E6
7772setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\bdec.inibinary
MD5:96D15C4F3DB04429631866751A1D2890
SHA256:E8D31C1DE790F738EF75DAA0402584560A0672402D0D3DED0899D2DBC95FB911
7772setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\bdnc.client_idtext
MD5:F4C2784AA289F17D144A589751C7980D
SHA256:E6E827F81840CE8975CD5E30467DDC1661C3F407CD9D342D00800F32C01DCC26
7728bddeploy.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\data\params.jsonbinary
MD5:421A73583B2B4BA31F285D6DCDAEA56F
SHA256:0FA4DA77FFC6F078DD98D7ACAAB65674CDE0CC4AA5274CCAD6DF0018A3CD36A8
7392bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\agentpackage.exeexecutable
MD5:4D561CDAF9D31739CCCB709FC8F92163
SHA256:99F6129F23E6968C55AEA5FD763B3AD53DD9B1E2A21F51EF99E140D1694BA64E
7772setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\bdnc.initext
MD5:96B5E37E6494DA2A8F09E98DF5C58004
SHA256:DD5C7A764B9FEA6F8C458D9B669B5764C46284DEA68CE52B43136C4812D27FD7
7772setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\bdnc.dllexecutable
MD5:90AFA3090C7AEC4E5A84444EE852C87C
SHA256:B4EC6ED71144818F05C588BC02357DB6AB99D86BF2E7174DC80FD9DAAF15B98A
7772setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\additional.dllexecutable
MD5:36AC314D55249BDC7A7C7F7DC0E80122
SHA256:A35F9689BD942E66F68301E60B2124A4F8E332026CBB8CD0B4E30CF99514F723
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
74
TCP/UDP connections
87
DNS requests
42
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
23.48.23.173:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
8172
bdredline.exe
GET
404
104.18.168.222:80
http://upgrade.bitdefender.com/redline_com.bitdefender.agent/versions.id
unknown
whitelisted
5176
RUXIMICS.exe
GET
200
23.48.23.173:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2104
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5176
RUXIMICS.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
34.120.68.241:443
https://nimbus.bitdefender.net/bdnc/config
unknown
binary
240 b
whitelisted
POST
400
40.126.32.136:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
text
203 b
whitelisted
GET
200
34.120.85.253:443
https://elb-ore-gcp.nimbus.bitdefender.net/_ServerStatus
unknown
text
21 b
whitelisted
GET
200
35.190.56.82:443
https://elb-iow-gcp.nimbus.bitdefender.net/_ServerStatus
unknown
text
21 b
whitelisted
GET
200
34.117.13.33:443
https://us.nimbus.bitdefender.net/_ServerStatus
unknown
text
21 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5176
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
23.48.23.173:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5176
RUXIMICS.exe
23.48.23.173:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 51.104.136.2
whitelisted
google.com
  • 172.217.16.206
whitelisted
crl.microsoft.com
  • 23.48.23.173
  • 23.48.23.147
  • 23.48.23.166
  • 2.19.11.105
  • 2.19.11.120
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.76
  • 20.190.160.130
  • 20.190.160.131
  • 40.126.32.72
  • 40.126.32.74
  • 20.190.160.64
  • 20.190.160.14
whitelisted
upgrade.bitdefender.com
  • 104.18.168.222
  • 104.18.169.222
whitelisted
nimbus.bitdefender.net
  • 34.120.68.241
  • 2600:1901:0:69b7::
whitelisted
us.nimbus.bitdefender.net
  • 34.117.13.33
  • 2600:1901:0:4ba4::
whitelisted
elb-iow-gcp.nimbus.bitdefender.net
  • 35.190.56.82
  • 2600:1901:0:5723::
whitelisted

Threats

PID
Process
Class
Message
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
ET INFO Packed Executable Download
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Process
Message
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.