URL:

https://brightvpn.com/

Full analysis: https://app.any.run/tasks/65eb004c-c0ee-4f4a-9276-92e0470d8803
Verdict: Malicious activity
Analysis date: May 24, 2025, 10:36:49
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
nodejs
evasion
Indicators:
MD5:

6C6964AF3F47F84730F0EFAF2918234F

SHA1:

66681629911F6090AD7FCFB042D7842A5AA3703C

SHA256:

20FF5EDB854C6DA960130BF556076B95FC324E0BDD32D61A12204D36EF09522D

SSDEEP:

3:N8SOR/IK:2lv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • net.exe (PID: 8312)
    • Changes the autorun value in the registry

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
    • The process creates files with name similar to system file names

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
    • Reads security settings of Internet Explorer

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • brightvpn_installer.exe (PID: 8876)
      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 5048)
    • Executable content was dropped or overwritten

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 5048)
      • Bright VPN.exe (PID: 8064)
      • net_updater32.exe (PID: 8976)
    • There is functionality for taking screenshot (YARA)

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • brightvpn_installer.exe (PID: 8876)
      • Bright VPN.exe (PID: 7356)
    • Application launched itself

      • net_updater32.exe (PID: 6324)
      • net_updater32.exe (PID: 8572)
      • net_updater32.exe (PID: 5048)
      • Bright VPN.exe (PID: 8064)
    • Detected use of alternative data streams (AltDS)

      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 5048)
    • Starts CMD.EXE for commands execution

      • net_updater32.exe (PID: 8520)
      • Bright VPN.exe (PID: 8064)
    • Process drops legitimate windows executable

      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 5048)
      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
    • The process drops C-runtime libraries

      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 5048)
    • Drops 7-zip archiver for unpacking

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
    • Creates a software uninstall entry

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
    • Executes as Windows Service

      • net_updater32.exe (PID: 8976)
      • WmiApSrv.exe (PID: 2320)
    • Checks for external IP

      • svchost.exe (PID: 2196)
      • net_updater32.exe (PID: 8976)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 904)
      • firefox.exe (PID: 6300)
      • firefox.exe (PID: 4304)
      • firefox.exe (PID: 7260)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 6300)
    • The sample compiled with english language support

      • firefox.exe (PID: 6300)
      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 5048)
    • Checks supported languages

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • brightvpn_installer.exe (PID: 8876)
      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 6324)
      • net_updater32.exe (PID: 8572)
      • net_updater32.exe (PID: 8520)
      • net_updater32.exe (PID: 5048)
      • net_updater32.exe (PID: 1180)
      • Bright VPN.exe (PID: 8064)
      • test_wpf.exe (PID: 5072)
    • Reads the computer name

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • brightvpn_installer.exe (PID: 8876)
      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 8520)
      • net_updater32.exe (PID: 5048)
      • net_updater32.exe (PID: 1180)
      • test_wpf.exe (PID: 5072)
      • Bright VPN.exe (PID: 8064)
    • Create files in a temporary directory

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • Bright VPN.exe (PID: 8064)
    • Creates files or folders in the user directory

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 5048)
      • brightvpn_installer.exe (PID: 8876)
    • Reads the machine GUID from the registry

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • brightvpn_installer.exe (PID: 8876)
      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 5048)
      • Bright VPN.exe (PID: 8064)
      • test_wpf.exe (PID: 5072)
    • Checks proxy server information

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • net_updater32.exe (PID: 1532)
      • brightvpn_installer.exe (PID: 8876)
      • net_updater32.exe (PID: 5048)
    • Reads the software policy settings

      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • brightvpn_installer.exe (PID: 8876)
      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 8520)
      • slui.exe (PID: 8096)
      • net_updater32.exe (PID: 5048)
    • Disables trace logs

      • brightvpn_installer.exe (PID: 8876)
      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 5048)
    • Creates files in the program directory

      • brightvpn_installer.exe (PID: 8876)
      • BrightVPN-Setup-1.530.981.exe (PID: 8768)
      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 6324)
      • net_updater32.exe (PID: 8520)
      • net_updater32.exe (PID: 5048)
      • net_updater32.exe (PID: 1180)
      • net_updater32.exe (PID: 8572)
      • Bright VPN.exe (PID: 8064)
    • Process checks computer location settings

      • net_updater32.exe (PID: 1532)
      • net_updater32.exe (PID: 5048)
      • Bright VPN.exe (PID: 8064)
    • Manual execution by a user

      • Bright VPN.exe (PID: 8064)
      • firefox.exe (PID: 7260)
      • rasphone.exe (PID: 5332)
      • rasphone.exe (PID: 1912)
      • notepad++.exe (PID: 7260)
      • notepad++.exe (PID: 8160)
    • Node.js compiler has been detected

      • Bright VPN.exe (PID: 8064)
      • Bright VPN.exe (PID: 7356)
      • Bright VPN.exe (PID: 7196)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
596
Monitored processes
453
Malicious processes
8
Suspicious processes
2

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs sppextcomobj.exe no specs firefox.exe no specs slui.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs brightvpn-setup-1.530.981.exe no specs brightvpn-setup-1.530.981.exe brightvpn_installer.exe net_updater32.exe no specs conhost.exe no specs net_updater32.exe net_updater32.exe conhost.exe no specs cmd.exe no specs choice.exe no specs net_updater32.exe no specs conhost.exe no specs net_updater32.exe net_updater32.exe conhost.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs slui.exe bright vpn.exe test_wpf.exe no specs net_updater32.exe cmd.exe no specs conhost.exe no specs rasdial.exe no specs bright vpn.exe no specs test_wpf.exe no specs bright vpn.exe bright vpn.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs slui.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs wmiapsrv.exe no specs idle_report.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs brightdata.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs idle_report.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs slui.exe cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs reg.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs slui.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs bright vpn.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs bright vpn.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs svchost.exe cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs firefox.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs bright vpn.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs rasdial.exe no specs cmd.exe no specs conhost.exe no specs rasdial.exe no specs idle_report.exe no specs conhost.exe no specs rundll32.exe no specs rasphone.exe no specs notepad++.exe no specs rasphone.exe no specs idle_report.exe no specs conhost.exe no specs notepad++.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
132C:\WINDOWS\system32\cmd.exe /d /s /c "rasdial "C:\Windows\SysWOW64\cmd.exeBright VPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
232C:\WINDOWS\system32\cmd.exe /d /s /c "rasdial "C:\Windows\SysWOW64\cmd.exeBright VPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
236\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
436\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
456\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
456C:\WINDOWS\system32\cmd.exe /d /s /c "rasdial "C:\Windows\SysWOW64\cmd.exeBright VPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
516C:\WINDOWS\system32\cmd.exe /d /s /c "rasdial "C:\Windows\SysWOW64\cmd.exeBright VPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
516rasdial C:\Windows\SysWOW64\rasdial.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Remote Access Command Line Dial UI
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rasdial.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
516C:\WINDOWS\system32\cmd.exe /d /s /c "rasdial "C:\Windows\SysWOW64\cmd.exeBright VPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
616\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
121 485
Read events
121 274
Write events
191
Delete events
20

Modification events

(PID) Process:(6300) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(6300) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(8768) BrightVPN-Setup-1.530.981.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(8768) BrightVPN-Setup-1.530.981.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(8768) BrightVPN-Setup-1.530.981.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(8876) brightvpn_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(8876) brightvpn_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(8876) brightvpn_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(8876) brightvpn_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(8876) brightvpn_installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
Executable files
39
Suspicious files
547
Text files
86
Unknown types
3

Dropped files

PID
Process
Filename
Type
6300firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
6300firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6300firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6300firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.binbinary
MD5:C78F36BF78A74A5C37232FA18305FA6E
SHA256:319C730AC6614FDCE611894E281CBE1B5E1A304DCD812D6B642D3BE978E82EEC
6300firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6300firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
6300firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.tmpbinary
MD5:C78F36BF78A74A5C37232FA18305FA6E
SHA256:319C730AC6614FDCE611894E281CBE1B5E1A304DCD812D6B642D3BE978E82EEC
6300firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
6300firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs.jstext
MD5:2C99A16AED3906D92FFE3EF1808E2753
SHA256:08412578CC3BB4922388F8FF8C23962F616B69A1588DA720ADE429129C73C452
6300firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.binbinary
MD5:4B79E9334393F3494CDF70F8B8E61626
SHA256:F5B175FB6835881A4F18362243870ECE99E17B0CAD82D6D10115D25497190DA4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
188
DNS requests
224
Threats
23

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6300
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6300
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
6300
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
6300
firefox.exe
POST
200
184.24.77.56:80
http://r11.o.lencr.org/
unknown
whitelisted
6300
firefox.exe
POST
200
142.250.185.195:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
6300
firefox.exe
POST
200
184.24.77.56:80
http://r11.o.lencr.org/
unknown
whitelisted
6300
firefox.exe
POST
200
142.250.185.195:80
http://o.pki.goog/we2
unknown
whitelisted
6300
firefox.exe
POST
200
142.250.185.195:80
http://o.pki.goog/s/wr3/3H4
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6300
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
whitelisted
6300
firefox.exe
142.250.186.170:443
safebrowsing.googleapis.com
whitelisted
6300
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
6300
firefox.exe
34.107.243.93:443
push.services.mozilla.com
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 23.219.150.101
whitelisted
google.com
  • 142.250.181.238
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
example.org
  • 23.215.0.133
  • 96.7.128.186
  • 96.7.128.192
  • 23.215.0.132
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
brightvpn.com
  • 104.18.24.5
  • 104.18.25.5
unknown
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted

Threats

PID
Process
Class
Message
Generic Protocol Command Decode
SURICATA IKE weak cryptographic parameters (PRF)
Generic Protocol Command Decode
SURICATA IKE weak cryptographic parameters (Auth)
Generic Protocol Command Decode
SURICATA IKE weak cryptographic parameters (PRF)
Generic Protocol Command Decode
SURICATA IKE weak cryptographic parameters (Auth)
Generic Protocol Command Decode
SURICATA IKE weak cryptographic parameters (PRF)
Generic Protocol Command Decode
SURICATA IKE weak cryptographic parameters (Auth)
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
No debug info