File name:

bitdefender_avfree.exe

Full analysis: https://app.any.run/tasks/b9e67f7d-7826-4cdc-9087-a3ae04abf4ee
Verdict: Malicious activity
Analysis date: May 12, 2025, 00:34:49
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
installer
rust
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

F874BA4FDCBCB75B27A3FEBE5790528B

SHA1:

5B43C936F6275A59435C517369C4C1744606995E

SHA256:

B39B15E2F621D653E274251815C26DC2C07088A77112D6D75FB50BC29E13C7BF

SSDEEP:

196608:l3RF4BhzF+0rBOGtFffXceyGou+761fXU23oa6LCCJWJ3j:l3uhzTBrfXpou+Ak23oJTJWJ3j

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • DiscoverySrv.exe (PID: 2088)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • bitdefender_avfree.exe (PID: 7392)
      • setuppackage.exe (PID: 7772)
      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 5544)
      • qxb1470.tmp (PID: 7520)
    • Reads security settings of Internet Explorer

      • bitdefender_avfree.exe (PID: 7392)
      • agent_launcher.exe (PID: 7564)
      • bddeploy.exe (PID: 7728)
      • installer.exe (PID: 7888)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Creates a software uninstall entry

      • installer.exe (PID: 7888)
    • The process verifies whether the antivirus software is installed

      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 7012)
      • ProductAgentService.exe (PID: 6404)
      • ProductAgentService.exe (PID: 4688)
      • ProductAgentService.exe (PID: 8028)
      • bdredline.exe (PID: 8172)
      • DiscoverySrv.exe (PID: 2088)
      • regsvr32.exe (PID: 920)
      • DiscoverySrv.exe (PID: 4120)
      • ProductAgentService.exe (PID: 5544)
      • ProductAgentUI.exe (PID: 7484)
      • qxb1470.tmp (PID: 7520)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Executes as Windows Service

      • ProductAgentService.exe (PID: 5544)
      • bdredline.exe (PID: 8172)
    • Process drops legitimate windows executable

      • installer.exe (PID: 7888)
      • qxb1470.tmp (PID: 7520)
      • ProductAgentService.exe (PID: 5544)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • There is functionality for taking screenshot (YARA)

      • bitdefender_avfree.exe (PID: 7392)
      • ProductAgentUI.exe (PID: 7484)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 920)
    • Starts application with an unusual extension

      • ProductAgentService.exe (PID: 5544)
    • Starts a Microsoft application from unusual location

      • qxb1470.tmp (PID: 7520)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 7724)
  • INFO

    • Checks supported languages

      • agent_launcher.exe (PID: 7564)
      • bitdefender_avfree.exe (PID: 7392)
      • bddeploy.exe (PID: 7728)
      • setuppackage.exe (PID: 7772)
      • installer.exe (PID: 7888)
      • bdredline.exe (PID: 8172)
      • ProductAgentService.exe (PID: 7012)
      • ProductAgentService.exe (PID: 6404)
      • ProductAgentService.exe (PID: 4688)
      • ProductAgentService.exe (PID: 8028)
      • ProductAgentService.exe (PID: 5544)
      • DiscoverySrv.exe (PID: 2088)
      • DiscoverySrv.exe (PID: 4120)
      • ProductAgentUI.exe (PID: 7484)
      • qxb1470.tmp (PID: 7520)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • The sample compiled with english language support

      • bitdefender_avfree.exe (PID: 7392)
      • setuppackage.exe (PID: 7772)
      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 5544)
      • qxb1470.tmp (PID: 7520)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Create files in a temporary directory

      • bitdefender_avfree.exe (PID: 7392)
      • bddeploy.exe (PID: 7728)
      • setuppackage.exe (PID: 7772)
      • installer.exe (PID: 7888)
    • Reads the computer name

      • bitdefender_avfree.exe (PID: 7392)
      • agent_launcher.exe (PID: 7564)
      • setuppackage.exe (PID: 7772)
      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 7012)
      • ProductAgentService.exe (PID: 4688)
      • ProductAgentService.exe (PID: 8028)
      • bdredline.exe (PID: 8172)
      • ProductAgentService.exe (PID: 6404)
      • ProductAgentService.exe (PID: 5544)
      • DiscoverySrv.exe (PID: 4120)
      • ProductAgentUI.exe (PID: 7484)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Process checks computer location settings

      • bitdefender_avfree.exe (PID: 7392)
      • agent_launcher.exe (PID: 7564)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Reads the machine GUID from the registry

      • agent_launcher.exe (PID: 7564)
      • bddeploy.exe (PID: 7728)
      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 5544)
      • DiscoverySrv.exe (PID: 2088)
      • DiscoverySrv.exe (PID: 4120)
      • ProductAgentUI.exe (PID: 7484)
    • Reads the software policy settings

      • agent_launcher.exe (PID: 7564)
      • bddeploy.exe (PID: 7728)
      • installer.exe (PID: 7888)
      • DiscoverySrv.exe (PID: 2088)
      • DiscoverySrv.exe (PID: 4120)
      • ProductAgentService.exe (PID: 5544)
      • ProductAgentUI.exe (PID: 7484)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
      • wermgr.exe (PID: 7864)
    • Creates files in the program directory

      • installer.exe (PID: 7888)
      • ProductAgentService.exe (PID: 4688)
      • ProductAgentService.exe (PID: 5544)
      • qxb1470.tmp (PID: 7520)
    • Reads Environment values

      • ProductAgentService.exe (PID: 5544)
      • MicrosoftEdgeUpdate.exe (PID: 7724)
    • Reads CPU info

      • ProductAgentService.exe (PID: 5544)
    • Application based on Rust

      • bdredline.exe (PID: 8172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:08:14 19:15:49+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 188416
InitializedDataSize: 265216
UninitializedDataSize: -
EntryPoint: 0x1cab5
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
20
Malicious processes
15
Suspicious processes
1

Behavior graph

Click at the process to see the details
start bitdefender_avfree.exe agent_launcher.exe no specs bddeploy.exe setuppackage.exe installer.exe productagentservice.exe no specs bdredline.exe productagentservice.exe no specs productagentservice.exe no specs productagentservice.exe no specs productagentservice.exe discoverysrv.exe no specs regsvr32.exe no specs discoverysrv.exe no specs productagentui.exe no specs qxb1470.tmp microsoftedgeupdate.exe wermgr.exe slui.exe watchdog.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
920regsvr32 /s "C:\Program Files\Bitdefender Agent\27.1.1.12\DiscoveryComp.dll"C:\Windows\SysWOW64\regsvr32.exeDiscoverySrv.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1052"C:\Program Files\Bitdefender Agent\27.1.1.12\WatchDog.exe" installC:\Program Files\Bitdefender Agent\27.1.1.12\WatchDog.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
Bitdefender Agent WatchDog
Exit code:
0
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\27.1.1.12\watchdog.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
2088"C:\Program Files\Bitdefender Agent\27.1.1.12\DiscoverySrv.exe" installC:\Program Files\Bitdefender Agent\27.1.1.12\DiscoverySrv.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
DiscoverySrv
Exit code:
0
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\27.1.1.12\discoverysrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
2552C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4120"C:\Program Files\Bitdefender Agent\27.1.1.12\DiscoverySrv.exe"C:\Program Files\Bitdefender Agent\27.1.1.12\DiscoverySrv.exeProductAgentService.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
DiscoverySrv
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\27.1.1.12\discoverysrv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\crypt32.dll
c:\windows\syswow64\ucrtbase.dll
4688"C:\Program Files\Bitdefender Agent\ProductAgentService.exe" start "C:\Users\admin\Desktop\bitdefender_avfree.exe"C:\Program Files\Bitdefender Agent\ProductAgentService.exeinstaller.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Bitdefender Agent
Exit code:
0
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5544"C:\Program Files\Bitdefender Agent\ProductAgentService.exe"C:\Program Files\Bitdefender Agent\ProductAgentService.exe
services.exe
User:
SYSTEM
Company:
Bitdefender
Integrity Level:
SYSTEM
Description:
Bitdefender Agent
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
6404"C:\Program Files\Bitdefender Agent\ProductAgentService.exe" enableC:\Program Files\Bitdefender Agent\ProductAgentService.exeinstaller.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Bitdefender Agent
Exit code:
0
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7012"C:\Program Files\Bitdefender Agent\ProductAgentService.exe" installC:\Program Files\Bitdefender Agent\ProductAgentService.exeinstaller.exe
User:
admin
Company:
Bitdefender
Integrity Level:
HIGH
Description:
Bitdefender Agent
Exit code:
0
Version:
27.1.1.12
Modules
Images
c:\program files\bitdefender agent\productagentservice.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
7392"C:\Users\admin\Desktop\bitdefender_avfree.exe" C:\Users\admin\Desktop\bitdefender_avfree.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\bitdefender_avfree.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
45 452
Read events
45 336
Write events
111
Delete events
5

Modification events

(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:InstallerLauncher
Value:
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:InstallerLauncher
Value:
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Install
Operation:writeName:ShortInstallPath
Value:
C:\Program Files\Bitdefender Agent\
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Install
Operation:writeName:InstallPath
Value:
C:\Program Files\Bitdefender Agent\
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceFolder
Value:
C:\ProgramData\Bitdefender Agent
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceLevel
Value:
1
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitdefender Agent
Operation:writeName:traceMode
Value:
0
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Bitdefender Agent\Submission\Agent Submission Tool
Operation:writeName:AppPath
Value:
C:\Program Files\Bitdefender Agent\27.1.1.12\bdsubwiz.exe
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bitdefender Agent
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Bitdefender Agent\27.1.1.12\bdicon.ico
(PID) Process:(7888) installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bitdefender Agent
Operation:writeName:DisplayName
Value:
Bitdefender Agent
Executable files
264
Suspicious files
32
Text files
175
Unknown types
0

Dropped files

PID
Process
Filename
Type
7392bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\agent_launcher.exeexecutable
MD5:9BCA7DCB536E538145FC35D3FD3D37ED
SHA256:13EA984AED446CDF8908CAF941A216A19443927F49009BDF4097ADAB0030A845
7772setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\bdnc.initext
MD5:96B5E37E6494DA2A8F09E98DF5C58004
SHA256:DD5C7A764B9FEA6F8C458D9B669B5764C46284DEA68CE52B43136C4812D27FD7
7392bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\deploy.dllexecutable
MD5:A1181FEC3F4D63E8087A5AB151E535B0
SHA256:173C20A60705ADAFBEE82B1E6E0C5C6796F4C5AC2BA207146113660A83166D98
7392bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\agent_launcher.exe.md5text
MD5:C66594DA8F04A40D614F94CD199CC681
SHA256:149E54F0D1473914164F26A7C9BE9BE9F06F109BA5B106BB3B8FFB0C775A2892
7392bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\setuppackage.exeexecutable
MD5:F0B1BA4D9DD662944BC092D0896A6C78
SHA256:E0342D3BCC18B6777068578CCDF9DC0A4F9058399601668F785D521B29F16700
7392bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\agentpackage.exe.md5text
MD5:F7437BE70D1367128014D025C5CCCA0D
SHA256:246685FC3222F39F6B95966792519D594CC9544710C1571CE79CB1491DB88101
7392bitdefender_avfree.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\deploy.dll.md5text
MD5:2BB4DE1531994B47DCB2204F0EA426FF
SHA256:C35D60C17D424AD87849EA37843CBC1F5D4537F5DC253BCF16F4E62E6416F852
7772setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\bdredline.exeexecutable
MD5:82CD28473E039CECD30A97D8ABBAAEC5
SHA256:729EE5F5E1B7CC0EBE00ADBCBC6F3535A40D6EDB0D1B9B5FA5DD856D9608FC87
7772setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\bdec.inibinary
MD5:96D15C4F3DB04429631866751A1D2890
SHA256:E8D31C1DE790F738EF75DAA0402584560A0672402D0D3DED0899D2DBC95FB911
7772setuppackage.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\packages\bdnc.client_idtext
MD5:F4C2784AA289F17D144A589751C7980D
SHA256:E6E827F81840CE8975CD5E30467DDC1661C3F407CD9D342D00800F32C01DCC26
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
74
TCP/UDP connections
87
DNS requests
42
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5176
RUXIMICS.exe
GET
200
23.48.23.173:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
2104
svchost.exe
GET
200
23.48.23.173:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
2104
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
868 b
whitelisted
5176
RUXIMICS.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
868 b
whitelisted
8172
bdredline.exe
GET
404
104.18.168.222:80
http://upgrade.bitdefender.com/redline_com.bitdefender.agent/versions.id
unknown
html
146 b
whitelisted
POST
400
40.126.31.2:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
POST
200
40.126.31.2:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
POST
400
20.190.159.2:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
POST
400
20.190.159.0:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
POST
400
20.190.159.68:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5176
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
23.48.23.173:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5176
RUXIMICS.exe
23.48.23.173:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 51.104.136.2
whitelisted
google.com
  • 172.217.16.206
whitelisted
crl.microsoft.com
  • 23.48.23.173
  • 23.48.23.147
  • 23.48.23.166
  • 2.19.11.105
  • 2.19.11.120
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.76
  • 20.190.160.130
  • 20.190.160.131
  • 40.126.32.72
  • 40.126.32.74
  • 20.190.160.64
  • 20.190.160.14
whitelisted
upgrade.bitdefender.com
  • 104.18.168.222
  • 104.18.169.222
whitelisted
nimbus.bitdefender.net
  • 34.120.68.241
  • 2600:1901:0:69b7::
whitelisted
us.nimbus.bitdefender.net
  • 34.117.13.33
  • 2600:1901:0:4ba4::
whitelisted
elb-iow-gcp.nimbus.bitdefender.net
  • 35.190.56.82
  • 2600:1901:0:5723::
whitelisted

Threats

PID
Process
Class
Message
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
ET INFO Packed Executable Download
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Misc activity
INSTALLER [ANY.RUN] BDNC Installer HTTP POST Request (UA)
Process
Message
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ProductAgentService.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.