| File name: | BrightVPN-Setup-1.388.85.exe |
| Full analysis: | https://app.any.run/tasks/3df23d99-4d30-4e71-8c71-c8d897c2d06d |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | November 19, 2023, 00:12:41 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 3716961C55FE2E1B4A8CC5B5CA0E4E73 |
| SHA1: | E9E4E94A14AF4DB47EE194BFCC3F279A444EA467 |
| SHA256: | 01C1A482A3975441D85DEDAA8DEF0ED915E767C2578F81CFF64AAB37D3935E45 |
| SSDEEP: | 98304:Ayi384iD1MupZSGySqJLzww3Kj0Q7CoRZCHDzVJG4qoG0aNFYJmLLSHpzLTHY7z7:Xmk |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:03:03 14:15:57+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.3 |
| CodeSize: | 203776 |
| InitializedDataSize: | 387072 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1f530 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2928 | "C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup.exe" | C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup.exe | — | BrightVPN-Setup-1.388.85.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3028 | "C:\Users\admin\AppData\Local\Temp\nss8B5D.tmp\brightvpn_installer.exe" /pid=3632 /port=6451 /affiliate= /silent= /exe="C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.416.561-cea485f2.exe" | C:\Users\admin\AppData\Local\Temp\nss8B5D.tmp\brightvpn_installer.exe | — | BrightVPN-Setup-1.416.561-cea485f2.exe | |||||||||||
User: admin Company: Bright Data Ltd Integrity Level: HIGH Description: Bright VPN Exit code: 0 Version: 1.416.561 Modules
| |||||||||||||||
| 3128 | "C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.388.85.exe" | C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.388.85.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3404 | "C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.416.561-cea485f2.exe" | C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.416.561-cea485f2.exe | — | BrightVPN-Setup-1.388.85.exe | |||||||||||
User: admin Company: Bright Data Ltd. Integrity Level: MEDIUM Exit code: 3221226540 Version: 1.416.561 Modules
| |||||||||||||||
| 3408 | "C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup.exe" | C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup.exe | BrightVPN-Setup-1.388.85.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
DcRat(PID) Process(3408) BrightVPN-Setup.exe C2 (1)http://976435cm.nyashtyan.top/@0J3bwBXdzh2chlnb Options MutexDCR_MUTEX-VAIpQJRl6E5uMUU7bxMn searchpath%UsersFolder% - Fast Targetals | |||||||||||||||
| 3632 | "C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.416.561-cea485f2.exe" | C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.416.561-cea485f2.exe | BrightVPN-Setup-1.388.85.exe | ||||||||||||
User: admin Company: Bright Data Ltd. Integrity Level: HIGH Exit code: 0 Version: 1.416.561 Modules
| |||||||||||||||
| 3892 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3128) BrightVPN-Setup-1.388.85.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3128) BrightVPN-Setup-1.388.85.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3128) BrightVPN-Setup-1.388.85.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3128) BrightVPN-Setup-1.388.85.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3632) BrightVPN-Setup-1.416.561-cea485f2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3632) BrightVPN-Setup-1.416.561-cea485f2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3632) BrightVPN-Setup-1.416.561-cea485f2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3632) BrightVPN-Setup-1.416.561-cea485f2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3632) BrightVPN-Setup-1.416.561-cea485f2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3632) BrightVPN-Setup-1.416.561-cea485f2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3632 | BrightVPN-Setup-1.416.561-cea485f2.exe | C:\Users\admin\AppData\Local\Temp\nss8B5D.tmp\INetC.dll | executable | |
MD5:38CAA11A462B16538E0A3DAEB2FC0EAF | SHA256:ED04A4823F221E9197B8F3C3DA1D6859FF5B176185BDE2F1C923A442516C810A | |||
| 3632 | BrightVPN-Setup-1.416.561-cea485f2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850D | binary | |
MD5:44C73E7978CC1CDE5661B7B09F8E35F6 | SHA256:3372EA5FECD6D3661BC651BEB1D9DAC021E7C7EEC06B9CD07E7D483231CF2B1A | |||
| 3632 | BrightVPN-Setup-1.416.561-cea485f2.exe | C:\Users\admin\AppData\Local\Temp\nss8B5D.tmp\StdUtils.dll | executable | |
MD5:C6A6E03F77C313B267498515488C5740 | SHA256:B72E9013A6204E9F01076DC38DABBF30870D44DFC66962ADBF73619D4331601E | |||
| 3632 | BrightVPN-Setup-1.416.561-cea485f2.exe | C:\Users\admin\AppData\Local\Temp\nss8B5D.tmp\System.dll | executable | |
MD5:0D7AD4F45DC6F5AA87F606D0331C6901 | SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA | |||
| 3632 | BrightVPN-Setup-1.416.561-cea485f2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89 | SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8 | |||
| 3632 | BrightVPN-Setup-1.416.561-cea485f2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\394AED4116FFD9B32F111818CF5811F3 | binary | |
MD5:4414C0C8490B5C2EEBE96A52AC742A35 | SHA256:6B0ED5025F0F340B6C1A4DE9608081E3CC09041E50F430DF94FCC6D361EA1382 | |||
| 3632 | BrightVPN-Setup-1.416.561-cea485f2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\394AED4116FFD9B32F111818CF5811F3 | binary | |
MD5:92E4B29C5575FA14240F7260F2EA0AF1 | SHA256:6A49052FDF6E1FDEDE332BFF95B150FDCBF0BBE821E4B84D5959E466221076EA | |||
| 3632 | BrightVPN-Setup-1.416.561-cea485f2.exe | C:\Users\admin\AppData\Local\Temp\nss8B5D.tmp\brightvpn_installer.exe | executable | |
MD5:3423E9103519375818F70763CB251FB1 | SHA256:D261DD855033F1A868D463F35BA0A80F02AFF86A54379A239157C8BE95F09FAA | |||
| 3632 | BrightVPN-Setup-1.416.561-cea485f2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850D | binary | |
MD5:21D638581F8E80F3FFD9715F3EBF347A | SHA256:36743F4C36975E0BC8D4C82CF88D20E58BD1ABE92DB9E262E3E0FD97A713B874 | |||
| 3632 | BrightVPN-Setup-1.416.561-cea485f2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:34072B1AA63D6E6BB3672664D4CCB39A | SHA256:AC8C35DCEF2DFA084FE44019FC8C54B0D8664FF0741C13FC1FA202C7E6E0BCCB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3408 | BrightVPN-Setup.exe | GET | 200 | 188.114.97.3:80 | http://976435cm.nyashtyan.top/nyashsupport.php?JDXvCnGTK=g3Unz73ay3z35hDEJnaX34gW2xHJ&aa2df8cfca37a52611c833a071110f54=gNkN2MlZGOwUDMzATO5gzYkZzM5ATZhhDO4Y2N2AzN5U2YkRzM0ATM4ITN3UjM4czNxQDNzYzM&7857ef87b7ef1d106cfcf3b205280486=QOmVmMkFDO3IjM3UTM0gTOlFWZ3kDMykjY1AzNlhDOllTO5UGZhN2M&323673ac45c6d74610bbe3baae9d64b9=0VfiIiOiMTOkNDM4QzMhVTZxEWO3IzY0YjYjR2NkJGOyMWZmFjNiwiIhRGMmZ2Y5IGNwMmZ5kTY3I2Y4EmM1EmZlFWZkZTYjFzMiRjY4YTNyIiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W | unknown | — | — | unknown |
3408 | BrightVPN-Setup.exe | GET | 200 | 188.114.97.3:80 | http://976435cm.nyashtyan.top/nyashsupport.php?HvdPLQiY0oFxkg=PI0s8dd2x8mW8u&0t=ZvDZ&2be918fa85c26493bc99002a9afddf0c=ffe5b558d9b144cd868dfdd66fe46323&7857ef87b7ef1d106cfcf3b205280486=QZxIjYwUzNwADZwcTYiZWMwUjYxIzYmJWN4YmY3ATN1ETNwcjYzMDM&HvdPLQiY0oFxkg=PI0s8dd2x8mW8u&0t=ZvDZ | unknown | text | 2.07 Kb | unknown |
3408 | BrightVPN-Setup.exe | GET | 200 | 188.114.97.3:80 | http://976435cm.nyashtyan.top/nyashsupport.php?JDXvCnGTK=g3Unz73ay3z35hDEJnaX34gW2xHJ&aa2df8cfca37a52611c833a071110f54=gNkN2MlZGOwUDMzATO5gzYkZzM5ATZhhDO4Y2N2AzN5U2YkRzM0ATM4ITN3UjM4czNxQDNzYzM&7857ef87b7ef1d106cfcf3b205280486=QOmVmMkFDO3IjM3UTM0gTOlFWZ3kDMykjY1AzNlhDOllTO5UGZhN2M&7c8517c92c6ab52822183472d584b425=d1nIzEjYhFzNhJGZzYmMiJDM4gjY2Y2NlJDM5IDO0QDMkJWO5YzY3IWOmJiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W&323673ac45c6d74610bbe3baae9d64b9=d1nIiojIzkDZzADO0MTY1UWMhlzNyMGN2I2YkdDZihjMjVmZxYjIsIyMxIWYxcTYiR2MmJjYyADO4ImNmdTZyATOygDN0ADZilTO2M2NiljZiojIhVjMklzYxYmZ3gDZwU2NwIjZ5UDO5UDNhJTY3MmNzEmIsIyYwUmNiNWMkJDM0MTY0MDO5UGZkNjZ0cTOjRzN2czY3kTOxEjY3gTOiojIkNmYwImY5czYilTOwYzYlNTYlJzN3kDO0ETN5cDOxQjI7xSfiElZx8maJBjVzIGbxcVYVJEWaxGeyUVa3lWSspFWhBjTXFVavpWS6ZFSkhmUzUVNShVYyw2RkpmRrl0cJl2YsR2VZVnRXR1ZwcVW5RmMilnQslkNJlHZ2JVbiBHZGZFRGtWSzlUaUl2bqlEdGJTWpZlMWpHbtl0cJN1Vp9maJxWNyI2bCNjY550Vh5kTYFWa3lWSwRjMkZXNyEWdWZ0SnRjMkZXNyEWdWxWS2k0UaRnRtRlVCFTUpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXST9ENFpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiMTOkNDM4QzMhVTZxEWO3IzY0YjYjR2NkJGOyMWZmFjNiwiI5U2NihjMmBjNjBTYwYTMiV2Y5MDZjRjMyMWNmNWMlljY2UmN2Q2Y4IiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W | unknown | text | 104 b | unknown |
3408 | BrightVPN-Setup.exe | GET | 200 | 188.114.97.3:80 | http://976435cm.nyashtyan.top/nyashsupport.php?JDXvCnGTK=g3Unz73ay3z35hDEJnaX34gW2xHJ&aa2df8cfca37a52611c833a071110f54=gNkN2MlZGOwUDMzATO5gzYkZzM5ATZhhDO4Y2N2AzN5U2YkRzM0ATM4ITN3UjM4czNxQDNzYzM&7857ef87b7ef1d106cfcf3b205280486=QOmVmMkFDO3IjM3UTM0gTOlFWZ3kDMykjY1AzNlhDOllTO5UGZhN2M&7c8517c92c6ab52822183472d584b425=d1nIzEjYhFzNhJGZzYmMiJDM4gjY2Y2NlJDM5IDO0QDMkJWO5YzY3IWOmJiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W&323673ac45c6d74610bbe3baae9d64b9=d1nIiojIzkDZzADO0MTY1UWMhlzNyMGN2I2YkdDZihjMjVmZxYjIsIyMxIWYxcTYiR2MmJjYyADO4ImNmdTZyATOygDN0ADZilTO2M2NiljZiojIhVjMklzYxYmZ3gDZwU2NwIjZ5UDO5UDNhJTY3MmNzEmIsIyYwUmNiNWMkJDM0MTY0MDO5UGZkNjZ0cTOjRzN2czY3kTOxEjY3gTOiojIkNmYwImY5czYilTOwYzYlNTYlJzN3kDO0ETN5cDOxQjI7xSfiElZx8maJBjVzIGbxcVYVJEWaxGeyUVa3lWSspFWhBjTXFVavpWS6ZFSkhmUzUVNShVYyw2RkpmRrl0cJl2YsR2VZVnRXR1ZwcVW5RmMilnQslkNJlHZ2JVbiBHZGZFRGtWSzlUaUl2bqlEdGJTWpZlMWpHbtl0cJN1Vp9maJxWNyI2bCNjY550Vh5kTYFWa3lWSwRjMkZXNyEWdWZ0SnRjMkZXNyEWdWxWS2k0UaRnRtRlVCFTUpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXST9ENFpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiMTOkNDM4QzMhVTZxEWO3IzY0YjYjR2NkJGOyMWZmFjNiwiI5U2NihjMmBjNjBTYwYTMiV2Y5MDZjRjMyMWNmNWMlljY2UmN2Q2Y4IiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W | unknown | text | 104 b | unknown |
3408 | BrightVPN-Setup.exe | GET | 200 | 188.114.97.3:80 | http://976435cm.nyashtyan.top/nyashsupport.php?JDXvCnGTK=g3Unz73ay3z35hDEJnaX34gW2xHJ&aa2df8cfca37a52611c833a071110f54=gNkN2MlZGOwUDMzATO5gzYkZzM5ATZhhDO4Y2N2AzN5U2YkRzM0ATM4ITN3UjM4czNxQDNzYzM&7857ef87b7ef1d106cfcf3b205280486=QOmVmMkFDO3IjM3UTM0gTOlFWZ3kDMykjY1AzNlhDOllTO5UGZhN2M&7c8517c92c6ab52822183472d584b425=d1nIzEjYhFzNhJGZzYmMiJDM4gjY2Y2NlJDM5IDO0QDMkJWO5YzY3IWOmJiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W&323673ac45c6d74610bbe3baae9d64b9=d1nIiojIzkDZzADO0MTY1UWMhlzNyMGN2I2YkdDZihjMjVmZxYjIsIyMxIWYxcTYiR2MmJjYyADO4ImNmdTZyATOygDN0ADZilTO2M2NiljZiojIhVjMklzYxYmZ3gDZwU2NwIjZ5UDO5UDNhJTY3MmNzEmIsIyYwUmNiNWMkJDM0MTY0MDO5UGZkNjZ0cTOjRzN2czY3kTOxEjY3gTOiojIkNmYwImY5czYilTOwYzYlNTYlJzN3kDO0ETN5cDOxQjI7xSfiElZx8maJBjVzIGbxcVYVJEWaxGeyUVa3lWSspFWhBjTXFVavpWS6ZFSkhmUzUVNShVYyw2RkpmRrl0cJl2YsR2VZVnRXR1ZwcVW5RmMilnQslkNJlHZ2JVbiBHZGZFRGtWSzlUaUl2bqlEdGJTWpZlMWpHbtl0cJN1Vp9maJxWNyI2bCNjY550Vh5kTYFWa3lWSwRjMkZXNyEWdWZ0SnRjMkZXNyEWdWxWS2k0UaRnRtRlVCFTUpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXST9ENFpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiMTOkNDM4QzMhVTZxEWO3IzY0YjYjR2NkJGOyMWZmFjNiwiI5U2NihjMmBjNjBTYwYTMiV2Y5MDZjRjMyMWNmNWMlljY2UmN2Q2Y4IiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W | unknown | text | 104 b | unknown |
3408 | BrightVPN-Setup.exe | GET | 200 | 188.114.97.3:80 | http://976435cm.nyashtyan.top/nyashsupport.php?JDXvCnGTK=g3Unz73ay3z35hDEJnaX34gW2xHJ&aa2df8cfca37a52611c833a071110f54=gNkN2MlZGOwUDMzATO5gzYkZzM5ATZhhDO4Y2N2AzN5U2YkRzM0ATM4ITN3UjM4czNxQDNzYzM&7857ef87b7ef1d106cfcf3b205280486=QOmVmMkFDO3IjM3UTM0gTOlFWZ3kDMykjY1AzNlhDOllTO5UGZhN2M&9edffb2c5b3d62ab573063a7de2159fe=QX9JSUml2aU1keBpXT1FkaMBTWIh1Y012Y2RGWaRnRtN2R4ZEWVZ1aUVXUupldONjY550Vh5EeGhlekNjYrVzVhhFeGhlNNtWS2k0QhBjRHVVa3lWS1R2MiVHdtJmVKl2Tpd2RkhmQGpVe5ITW6x2RSl2dplUavpWSvJFWZFVMXlVekdlWzZ1RWl2dplUavpWS6JESjJUMXlFbSNTVpdXaJVHZzIWd01mYWpUaPlWUVNVeWJzYWFzVZxmUzUVa3lWS6ljMaBnSIpFaKNDWzZ1VhlnSXllbKl2TplEWapnVWJGaWdEZUp0QMNHeXRWdwpWSuVzVZ1UMXlFbSNTVpdXaJRnRXpFMONDT6Z1RiBnWHlEdG12YulTbjdXOp9kaKl2Tpd2RkhmQWJGaWdEZUp0QMl2a5JGcSdFZCJUeOVzY5FlQClXYsJFSihmVtV1bBlmYKJ0UaVHbHRVd4x2YjlzVhtmVYF1ZjR1Tu1UVRd2cXpFM4dVWspkRLdWVtJmdod0Y2p0MZBXMrlkNJl3YsVjMi9mQzIWeOdVYOp0QMlWSp9UaNhlYo5UbZxGZsl0cJlmYjpESYh3aWFVTCFTVKJVRYNWNDh1Y4ZEWp9maJpXNXpFbKNTWUp0QMlWSqxUM0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiMTOkNDM4QzMhVTZxEWO3IzY0YjYjR2NkJGOyMWZmFjNiwiIhRGMmZ2Y5IGNwMmZ5kTY3I2Y4EmM1EmZlFWZkZTYjFzMiRjY4YTNyIiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W | unknown | text | 104 b | unknown |
3408 | BrightVPN-Setup.exe | GET | 200 | 188.114.97.3:80 | http://976435cm.nyashtyan.top/nyashsupport.php?JDXvCnGTK=g3Unz73ay3z35hDEJnaX34gW2xHJ&aa2df8cfca37a52611c833a071110f54=gNkN2MlZGOwUDMzATO5gzYkZzM5ATZhhDO4Y2N2AzN5U2YkRzM0ATM4ITN3UjM4czNxQDNzYzM&7857ef87b7ef1d106cfcf3b205280486=QOmVmMkFDO3IjM3UTM0gTOlFWZ3kDMykjY1AzNlhDOllTO5UGZhN2M&7c8517c92c6ab52822183472d584b425=d1nIzEjYhFzNhJGZzYmMiJDM4gjY2Y2NlJDM5IDO0QDMkJWO5YzY3IWOmJiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W&323673ac45c6d74610bbe3baae9d64b9=d1nIiojIzkDZzADO0MTY1UWMhlzNyMGN2I2YkdDZihjMjVmZxYjIsIyMxIWYxcTYiR2MmJjYyADO4ImNmdTZyATOygDN0ADZilTO2M2NiljZiojIhVjMklzYxYmZ3gDZwU2NwIjZ5UDO5UDNhJTY3MmNzEmIsIyYwUmNiNWMkJDM0MTY0MDO5UGZkNjZ0cTOjRzN2czY3kTOxEjY3gTOiojIkNmYwImY5czYilTOwYzYlNTYlJzN3kDO0ETN5cDOxQjI7xSfiElZx8maJBjVzIGbxcVYVJEWaxGeyUVa3lWSspFWhBjTXFVavpWS6ZFSkhmUzUVNShVYyw2RkpmRrl0cJl2YsR2VZVnRXR1ZwcVW5RmMilnQslkNJlHZ2JVbiBHZGZFRGtWSzlUaUl2bqlEdGJTWpZlMWpHbtl0cJN1Vp9maJxWNyI2bCNjY550Vh5kTYFWa3lWSwRjMkZXNyEWdWZ0SnRjMkZXNyEWdWxWS2k0UaRnRtRlVCFTUpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXST9ENFpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiMTOkNDM4QzMhVTZxEWO3IzY0YjYjR2NkJGOyMWZmFjNiwiI5U2NihjMmBjNjBTYwYTMiV2Y5MDZjRjMyMWNmNWMlljY2UmN2Q2Y4IiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W | unknown | text | 104 b | unknown |
3408 | BrightVPN-Setup.exe | GET | 200 | 188.114.97.3:80 | http://976435cm.nyashtyan.top/nyashsupport.php?JDXvCnGTK=g3Unz73ay3z35hDEJnaX34gW2xHJ&aa2df8cfca37a52611c833a071110f54=gNkN2MlZGOwUDMzATO5gzYkZzM5ATZhhDO4Y2N2AzN5U2YkRzM0ATM4ITN3UjM4czNxQDNzYzM&7857ef87b7ef1d106cfcf3b205280486=QOmVmMkFDO3IjM3UTM0gTOlFWZ3kDMykjY1AzNlhDOllTO5UGZhN2M&7c8517c92c6ab52822183472d584b425=d1nIzEjYhFzNhJGZzYmMiJDM4gjY2Y2NlJDM5IDO0QDMkJWO5YzY3IWOmJiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W&323673ac45c6d74610bbe3baae9d64b9=d1nIiojIzkDZzADO0MTY1UWMhlzNyMGN2I2YkdDZihjMjVmZxYjIsIyMxIWYxcTYiR2MmJjYyADO4ImNmdTZyATOygDN0ADZilTO2M2NiljZiojIhVjMklzYxYmZ3gDZwU2NwIjZ5UDO5UDNhJTY3MmNzEmIsIyYwUmNiNWMkJDM0MTY0MDO5UGZkNjZ0cTOjRzN2czY3kTOxEjY3gTOiojIkNmYwImY5czYilTOwYzYlNTYlJzN3kDO0ETN5cDOxQjI7xSfiElZx8maJBjVzIGbxcVYVJEWaxGeyUVa3lWSspFWhBjTXFVavpWS6ZFSkhmUzUVNShVYyw2RkpmRrl0cJl2YsR2VZVnRXR1ZwcVW5RmMilnQslkNJlHZ2JVbiBHZGZFRGtWSzlUaUl2bqlEdGJTWpZlMWpHbtl0cJN1Vp9maJxWNyI2bCNjY550Vh5kTYFWa3lWSwRjMkZXNyEWdWZ0SnRjMkZXNyEWdWxWS2k0UaRnRtRlVCFTUpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXST9ENFpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiMTOkNDM4QzMhVTZxEWO3IzY0YjYjR2NkJGOyMWZmFjNiwiI5U2NihjMmBjNjBTYwYTMiV2Y5MDZjRjMyMWNmNWMlljY2UmN2Q2Y4IiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W | unknown | text | 104 b | unknown |
3408 | BrightVPN-Setup.exe | GET | 200 | 188.114.97.3:80 | http://976435cm.nyashtyan.top/nyashsupport.php?JDXvCnGTK=g3Unz73ay3z35hDEJnaX34gW2xHJ&aa2df8cfca37a52611c833a071110f54=gNkN2MlZGOwUDMzATO5gzYkZzM5ATZhhDO4Y2N2AzN5U2YkRzM0ATM4ITN3UjM4czNxQDNzYzM&7857ef87b7ef1d106cfcf3b205280486=QOmVmMkFDO3IjM3UTM0gTOlFWZ3kDMykjY1AzNlhDOllTO5UGZhN2M&7c8517c92c6ab52822183472d584b425=d1nIzEjYhFzNhJGZzYmMiJDM4gjY2Y2NlJDM5IDO0QDMkJWO5YzY3IWOmJiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W&323673ac45c6d74610bbe3baae9d64b9=d1nIiojIzkDZzADO0MTY1UWMhlzNyMGN2I2YkdDZihjMjVmZxYjIsIyMxIWYxcTYiR2MmJjYyADO4ImNmdTZyATOygDN0ADZilTO2M2NiljZiojIhVjMklzYxYmZ3gDZwU2NwIjZ5UDO5UDNhJTY3MmNzEmIsIyYwUmNiNWMkJDM0MTY0MDO5UGZkNjZ0cTOjRzN2czY3kTOxEjY3gTOiojIkNmYwImY5czYilTOwYzYlNTYlJzN3kDO0ETN5cDOxQjI7xSfiElZx8maJBjVzIGbxcVYVJEWaxGeyUVa3lWSspFWhBjTXFVavpWS6ZFSkhmUzUVNShVYyw2RkpmRrl0cJl2YsR2VZVnRXR1ZwcVW5RmMilnQslkNJlHZ2JVbiBHZGZFRGtWSzlUaUl2bqlEdGJTWpZlMWpHbtl0cJN1Vp9maJxWNyI2bCNjY550Vh5kTYFWa3lWSwRjMkZXNyEWdWZ0SnRjMkZXNyEWdWxWS2k0UaRnRtRlVCFTUpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXST9ENFpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiMTOkNDM4QzMhVTZxEWO3IzY0YjYjR2NkJGOyMWZmFjNiwiI5U2NihjMmBjNjBTYwYTMiV2Y5MDZjRjMyMWNmNWMlljY2UmN2Q2Y4IiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W | unknown | text | 104 b | unknown |
3408 | BrightVPN-Setup.exe | GET | 200 | 188.114.97.3:80 | http://976435cm.nyashtyan.top/nyashsupport.php?JDXvCnGTK=g3Unz73ay3z35hDEJnaX34gW2xHJ&aa2df8cfca37a52611c833a071110f54=gNkN2MlZGOwUDMzATO5gzYkZzM5ATZhhDO4Y2N2AzN5U2YkRzM0ATM4ITN3UjM4czNxQDNzYzM&7857ef87b7ef1d106cfcf3b205280486=QOmVmMkFDO3IjM3UTM0gTOlFWZ3kDMykjY1AzNlhDOllTO5UGZhN2M&7c8517c92c6ab52822183472d584b425=d1nIzEjYhFzNhJGZzYmMiJDM4gjY2Y2NlJDM5IDO0QDMkJWO5YzY3IWOmJiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W&323673ac45c6d74610bbe3baae9d64b9=d1nIiojIzkDZzADO0MTY1UWMhlzNyMGN2I2YkdDZihjMjVmZxYjIsIyMxIWYxcTYiR2MmJjYyADO4ImNmdTZyATOygDN0ADZilTO2M2NiljZiojIhVjMklzYxYmZ3gDZwU2NwIjZ5UDO5UDNhJTY3MmNzEmIsIyYwUmNiNWMkJDM0MTY0MDO5UGZkNjZ0cTOjRzN2czY3kTOxEjY3gTOiojIkNmYwImY5czYilTOwYzYlNTYlJzN3kDO0ETN5cDOxQjI7xSfiElZx8maJBjVzIGbxcVYVJEWaxGeyUVa3lWSspFWhBjTXFVavpWS6ZFSkhmUzUVNShVYyw2RkpmRrl0cJl2YsR2VZVnRXR1ZwcVW5RmMilnQslkNJlHZ2JVbiBHZGZFRGtWSzlUaUl2bqlEdGJTWpZlMWpHbtl0cJN1Vp9maJxWNyI2bCNjY550Vh5kTYFWa3lWSwRjMkZXNyEWdWZ0SnRjMkZXNyEWdWxWS2k0UaRnRtRlVCFTUpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXST9ENFpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiMTOkNDM4QzMhVTZxEWO3IzY0YjYjR2NkJGOyMWZmFjNiwiI5U2NihjMmBjNjBTYwYTMiV2Y5MDZjRjMyMWNmNWMlljY2UmN2Q2Y4IiOiEWNyQWOjFjZmdDOkBTZ3AjMmlTN4kTN0EmMhdzY2MTYiwiIjBTZ2I2YxQmMwQzMhRzM4kTZkR2MmRzN5MGN3YzNjdTO5ETMidDO5IiOiQ2YiBjYilzNjJWO5AjNjV2MhVmM3cTO4QTM1kzN4EDNis3W | unknown | text | 104 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3632 | BrightVPN-Setup-1.416.561-cea485f2.exe | 44.194.147.247:443 | perr.brightvpn.com | AMAZON-AES | US | unknown |
3408 | BrightVPN-Setup.exe | 188.114.97.3:80 | 976435cm.nyashtyan.top | CLOUDFLARENET | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
perr.brightvpn.com |
| unknown |
976435cm.nyashtyan.top |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
3408 | BrightVPN-Setup.exe | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |
3408 | BrightVPN-Setup.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.top domain |