Skip to content

BuildNot yet confirmed elsewhere1 publisher3 min readPublished

A fake internet, not a tighter cage: catching a trojan that waits for DNS

FlexenseActivator.exe stays quiet until something answers its connectivity check. Simulating the network, rather than isolating the host harder, is what made the payload observable.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying A fake internet, not a tighter cage: catching a trojan that waits for DNS
Generated illustration

What happened

  • A graduate malware analysis project examined FlexenseActivator.exe, a trojan posing as an activation tool for Flexense disk software.
  • The lab put REMnux with INetSim 1.3.2 and FakeDNS in front of the Windows VM so every DNS lookup and web request got an answer.
  • It then injected code into five separate GoogleUpdater processes, each started with the --update flag.

Why it matters

  • constraint The standard lab safety rule, no internet, is the same condition that keeps this class of sample dormant, so observability now has to be bought back with simulated services rather than tighter...
  • contradiction More than half of VirusTotal's engines were quiet on the file while a mostly disabled Defender reacted at execution, which argues for spending on behavioural telemetry over file reputation for...
  • exposure Cleanup that finds one GoogleUpdater version folder and deletes it leaves the paired copy in place, so removal by path leaves the host reinfected on the analyst's reading.
  • capability A detonation window of a few seconds means sandbox timeouts and polling intervals decide whether anything is captured, independent of how good the analysis tooling is.

A connectivity check costs a malware author almost nothing: one DNS lookup, one HTTP request, then a branch. An air-gapped analysis VM answers it clearly and unhelpfully. So the graduate writeup on dev.to substitutes for the network instead of removing more of it: REMnux at 192.168.56.10 running INetSim 1.3.2 for HTTP, HTTPS and DNS, FakeDNS pointing every lookup from the Windows VM at 192.168.56.20 back at those services, all on a host-only segment with no route out [3][4]. The author's framing is that this is what answers the sample's question with a yes [4].

Worth being precise about what the lab proves. The writeup reports the execution with the simulated services running, and describes the dormancy behaviour as a known technique rather than something measured against a paired run with INetSim switched off [5][19]. The gate is plausible and the setup is the right one; the A/B that would pin it to this SHA-256 is not in the material.

The static picture explains why runtime work was necessary at all. Entropy of 7.916 sits above the 7.5 line where packed or encrypted content lives, and about 99 percent of the theoretical ceiling of 8 [6][17]. PEStudio identified UPX v0.89.6 with a Delphi stub, and the UPX0 section carries zero bytes on disk against 790KB of virtual size, which is the decompression target [7][8]. On VirusTotal, 33 of 76 engines flagged the file, meaning 43 of them, roughly 57 percent, did not [9][16]. Yet Windows Security raised a threat notification at execution with Defender mostly disabled [10]. The file was not the signal; the behaviour was.

That behaviour is short. The process created six threads inside the first second, did its work, and exited within a few seconds without staying resident [11][12]. Anything sampling on a coarser interval than that watches an executable exit cleanly. What it leaves behind is a fake GoogleUpdater tree at two version paths at once, 136.0.7079.0 and 137.0.7129.0, each with updater.exe, a Crashpad attachments directory and uninstall.cmd, followed by injection into five separate GoogleUpdater processes launched with --update [13][15].

The two directories are the operational detail. Legitimate Google Update keeps one version directory, and the analyst reads the pair as mutual reinstatement: delete one and the other restores it [18][14]. That makes the count, not the name, the indicator, and it makes remediation-by-path unreliable for anyone who finds the first folder and stops.

None of this needs a clever delivery chain. The file arrives inside pirated RAR and ZIP archives for Flexense disk tools, with VirusTotal tracking 151 parent archives, all of them pirated bundles [2]. A user who downloads an activator has already agreed to run an unsigned binary, often with local AV turned down to make the crack work. The interesting engineering is on the defender's side, and it is a service simulator on a second VM, not a stronger box around the first.

What to watch

  • A control run of the same SHA-256 with INetSim and FakeDNS switched off, which would show whether the sample really gates on connectivity.
  • Whether generic simulated HTTP responses were enough, or the sample needs specific content from a named endpoint to proceed.
  • INetSim request logs from the five injected updater processes, separating command-and-control traffic from the setup phase.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence54
Adoption24
Hype gap+24
Incentives32
Confidence52
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    FlexenseActivator.exe is a trojan disguised as a software activation tool, SHA-256 18676ae2eaa48ac6037fa239d282acca0b6c7cd6c7d384abe6b5cd379f2c5e50, identified as family Trojan.Win32.Tiggre / Zpevdo.

    ReportedSupportedSource: dev.to analysis writeupView cited source
  2. [2]

    The file is distributed inside pirated RAR and ZIP archives for Flexense disk management software (SysGauge, Disk Pulse Pro, Disk Savvy), and VirusTotal shows 151 tracked execution parent archives, all pirated Flexense bundles.

    ReportedSupportedView cited source
  3. [3]

    Analysis used two virtual machines on a host-only network with no internet access: a Windows 10 analysis VM with AV off at 192.168.56.20 and a REMnux gateway VM at 192.168.56.10.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · August 25, 2026

    I Set Up a Fake Internet to Catch a Trojan: Analyzing FlexenseActivator.exe

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories