BuildNot yet confirmed elsewhere1 publisher3 min readPublished
A fake internet, not a tighter cage: catching a trojan that waits for DNS
FlexenseActivator.exe stays quiet until something answers its connectivity check. Simulating the network, rather than isolating the host harder, is what made the payload observable.
The Engineer · Build desk

What happened
- A graduate malware analysis project examined FlexenseActivator.exe, a trojan posing as an activation tool for Flexense disk software.
- The lab put REMnux with INetSim 1.3.2 and FakeDNS in front of the Windows VM so every DNS lookup and web request got an answer.
- It then injected code into five separate GoogleUpdater processes, each started with the --update flag.
Why it matters
- constraint The standard lab safety rule, no internet, is the same condition that keeps this class of sample dormant, so observability now has to be bought back with simulated services rather than tighter...
- contradiction More than half of VirusTotal's engines were quiet on the file while a mostly disabled Defender reacted at execution, which argues for spending on behavioural telemetry over file reputation for...
- exposure Cleanup that finds one GoogleUpdater version folder and deletes it leaves the paired copy in place, so removal by path leaves the host reinfected on the analyst's reading.
- capability A detonation window of a few seconds means sandbox timeouts and polling intervals decide whether anything is captured, independent of how good the analysis tooling is.
A connectivity check costs a malware author almost nothing: one DNS lookup, one HTTP request, then a branch. An air-gapped analysis VM answers it clearly and unhelpfully. So the graduate writeup on dev.to substitutes for the network instead of removing more of it: REMnux at 192.168.56.10 running INetSim 1.3.2 for HTTP, HTTPS and DNS, FakeDNS pointing every lookup from the Windows VM at 192.168.56.20 back at those services, all on a host-only segment with no route out [3][4]. The author's framing is that this is what answers the sample's question with a yes [4].
Worth being precise about what the lab proves. The writeup reports the execution with the simulated services running, and describes the dormancy behaviour as a known technique rather than something measured against a paired run with INetSim switched off [5][19]. The gate is plausible and the setup is the right one; the A/B that would pin it to this SHA-256 is not in the material.
The static picture explains why runtime work was necessary at all. Entropy of 7.916 sits above the 7.5 line where packed or encrypted content lives, and about 99 percent of the theoretical ceiling of 8 [6][17]. PEStudio identified UPX v0.89.6 with a Delphi stub, and the UPX0 section carries zero bytes on disk against 790KB of virtual size, which is the decompression target [7][8]. On VirusTotal, 33 of 76 engines flagged the file, meaning 43 of them, roughly 57 percent, did not [9][16]. Yet Windows Security raised a threat notification at execution with Defender mostly disabled [10]. The file was not the signal; the behaviour was.
That behaviour is short. The process created six threads inside the first second, did its work, and exited within a few seconds without staying resident [11][12]. Anything sampling on a coarser interval than that watches an executable exit cleanly. What it leaves behind is a fake GoogleUpdater tree at two version paths at once, 136.0.7079.0 and 137.0.7129.0, each with updater.exe, a Crashpad attachments directory and uninstall.cmd, followed by injection into five separate GoogleUpdater processes launched with --update [13][15].
The two directories are the operational detail. Legitimate Google Update keeps one version directory, and the analyst reads the pair as mutual reinstatement: delete one and the other restores it [18][14]. That makes the count, not the name, the indicator, and it makes remediation-by-path unreliable for anyone who finds the first folder and stops.
None of this needs a clever delivery chain. The file arrives inside pirated RAR and ZIP archives for Flexense disk tools, with VirusTotal tracking 151 parent archives, all of them pirated bundles [2]. A user who downloads an activator has already agreed to run an unsigned binary, often with local AV turned down to make the crack work. The interesting engineering is on the defender's side, and it is a service simulator on a second VM, not a stronger box around the first.
What to watch
- A control run of the same SHA-256 with INetSim and FakeDNS switched off, which would show whether the sample really gates on connectivity.
- Whether generic simulated HTTP responses were enough, or the sample needs specific content from a named endpoint to proceed.
- INetSim request logs from the five injected updater processes, separating command-and-control traffic from the setup phase.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence54
- Adoption24
- Hype gap+24
- Incentives32
- Confidence52
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
FlexenseActivator.exe is a trojan disguised as a software activation tool, SHA-256 18676ae2eaa48ac6037fa239d282acca0b6c7cd6c7d384abe6b5cd379f2c5e50, identified as family Trojan.Win32.Tiggre / Zpevdo.
- [2]
The file is distributed inside pirated RAR and ZIP archives for Flexense disk management software (SysGauge, Disk Pulse Pro, Disk Savvy), and VirusTotal shows 151 tracked execution parent archives, all pirated Flexense bundles.
- [3]
Analysis used two virtual machines on a host-only network with no internet access: a Windows 10 analysis VM with AV off at 192.168.56.20 and a REMnux gateway VM at 192.168.56.10.
- [4]
The REMnux VM ran INetSim 1.3.2 simulating HTTP, HTTPS and DNS, with FakeDNS redirecting every DNS query from the Windows VM to INetSim, so the malware's connectivity check received an affirmative answer.
- [5]
The author states that many modern trojans check for connectivity before acting and stay dormant on a disconnected analysis machine, so the analyst sees nothing.
- [6]
PEStudio reported entropy of 7.916; normal executables fall between 5 and 7, and packed or encrypted content pushes above 7.5 on a 0 to 8 scale.
- [7]
PEStudio identified the packer as UPX v0.89.6 with a Delphi stub, with the malicious code compressed inside and only present in memory at runtime.
- [8]
The UPX0 section has zero raw size on disk and 790KB of virtual size, the decompression target filled at runtime.
- [9]
VirusTotal showed 33 of 76 AV vendors detecting the file; Hybrid Analysis scored it 100/100.
- [10]
On launch the sample appeared highlighted pink in Process Hacker as suspicious, and Windows Security fired a threat notification even with Defender mostly disabled.
- [11]
The process lived for a few seconds, did its work and terminated; it does not stay resident.
- [12]
Process Monitor recorded six threads created within the first second of execution.
- [13]
The malware dropped a fake GoogleUpdater installation under two version directories simultaneously, 136.0.7079.0 and 137.0.7129.0, each containing updater.exe, a Crashpad attachments directory and uninstall.cmd.
- [14]
Legitimate Google Update has one version directory, and multiple numbered Google directories in Program Files (for example Google1184, Google2872, Google2972) are a strong indicator of compromise.
- [15]
The malware injected its code into five separate GoogleUpdater processes, each launched with --update.
- [16]
43 of the 76 VirusTotal engines, about 57 percent, did not flag the file.
- [17]
An entropy reading of 7.916 is about 99 percent of the theoretical maximum of 8.
- [18]
The analyst reads the two dropped version directories as a persistence mechanism designed to survive removal: delete one version and the other reinstates it.
ReportedInsufficientSource: dev.to analysis writeup2 sources— create a free account to open themView cited source - [19]
The writeup reports only executions with the simulated network services in place; no control run with INetSim and FakeDNS disabled appears among the reported results.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toI Set Up a Fake Internet to Catch a Trojan: Analyzing FlexenseActivator.exe
1 article · August 25, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
Entities
- FlexenseActivator.exeFollow
- Trojan.Win32.Tiggre / ZpevdoFollow
- SHA-256 18676ae2eaa48ac6037fa239d282acca0b6c7cd6c7d384abe6b5cd379f2c5e50Follow
- INetSimFollow
- REMnuxFollow
- FakeDNSFollow
- UPXFollow
- PEStudioFollow
- Process HackerFollow
- Process MonitorFollow
- WiresharkFollow
- VirusTotalFollow
- Hybrid AnalysisFollow
- FlexenseFollow
- GoogleUpdaterFollow
- Microsoft NCSIFollow
- Windows Security / DefenderFollow