File name:

BrightVPN-Setup-1.422.634-fb2e56b7.exe

Full analysis: https://app.any.run/tasks/31a7cf82-8ef8-4ac6-8a62-329d55077dde
Verdict: Malicious activity
Analysis date: June 30, 2024, 11:01:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1CA12C1DDBBC4547FEF82491C23913F4

SHA1:

E2E057825A10E8BA97C0185F7C01DA6B449F7023

SHA256:

2B1B91075512986F811A419C62FE115D5CC8880D8126B9F94386861F82B2C995

SSDEEP:

98304:Iyi3UHGAx+DerS6sg03JwywLWiFwiDAfwh4X5MphqOnuY5/HSPfOY8xUBMqFtM71:vgdf8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Reads security settings of Internet Explorer

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
    • Reads the date of Windows installation

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • The process creates files with name similar to system file names

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Checks Windows Trust Settings

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Drops 7-zip archiver for unpacking

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Process drops legitimate windows executable

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Connects to unusual port

      • VPN.exe (PID: 2648)
  • INFO

    • Checks supported languages

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • VPN.exe (PID: 2648)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
    • Reads the computer name

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • VPN.exe (PID: 2648)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
    • Create files in a temporary directory

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Process checks computer location settings

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
    • Checks proxy server information

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
    • Reads the machine GUID from the registry

      • VPN.exe (PID: 2648)
      • brightvpn_installer.exe (PID: 964)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Reads the software policy settings

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
    • Disables trace logs

      • brightvpn_installer.exe (PID: 964)
    • Creates files or folders in the user directory

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Reads Environment values

      • brightvpn_installer.exe (PID: 964)
    • Creates files in the program directory

      • brightvpn_installer.exe (PID: 964)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:03:03 13:15:57+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.3
CodeSize: 203776
InitializedDataSize: 116736
UninitializedDataSize: -
EntryPoint: 0x1f530
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start brightvpn-setup-1.422.634-fb2e56b7.exe vpn.exe conhost.exe no specs brightvpn-setup-1.422.631-fb2e56b2.exe no specs brightvpn-setup-1.422.631-fb2e56b2.exe brightvpn_installer.exe

Process information

PID
CMD
Path
Indicators
Parent process
964"C:\Users\admin\AppData\Local\Temp\nsiE939.tmp\brightvpn_installer.exe" /pid=3532 /port=6451 /affiliate= /silent= /exe="C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exe"C:\Users\admin\AppData\Local\Temp\nsiE939.tmp\brightvpn_installer.exe
BrightVPN-Setup-1.422.631-fb2e56b2.exe
User:
admin
Company:
Bright Data Ltd
Integrity Level:
HIGH
Description:
Bright VPN
Version:
1.422.631
Modules
Images
c:\users\admin\appdata\local\temp\nsie939.tmp\brightvpn_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2100\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeVPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2648"C:\Users\admin\AppData\Local\Temp\VPN.exe" C:\Users\admin\AppData\Local\Temp\VPN.exe
BrightVPN-Setup-1.422.634-fb2e56b7.exe
User:
admin
Company:
Isogeny
Integrity Level:
MEDIUM
Description:
Isogeny
Version:
51.64.94
Modules
Images
c:\users\admin\appdata\local\temp\vpn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2832"C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exe" C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exeBrightVPN-Setup-1.422.634-fb2e56b7.exe
User:
admin
Company:
Bright Data Ltd.
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.422.631
Modules
Images
c:\users\admin\appdata\local\temp\brightvpn-setup-1.422.631-fb2e56b2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3532"C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exe" C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exe
BrightVPN-Setup-1.422.634-fb2e56b7.exe
User:
admin
Company:
Bright Data Ltd.
Integrity Level:
HIGH
Version:
1.422.631
Modules
Images
c:\users\admin\appdata\local\temp\brightvpn-setup-1.422.631-fb2e56b2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4164"C:\Users\admin\Downloads\BrightVPN-Setup-1.422.634-fb2e56b7.exe" C:\Users\admin\Downloads\BrightVPN-Setup-1.422.634-fb2e56b7.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\downloads\brightvpn-setup-1.422.634-fb2e56b7.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
12 939
Read events
12 905
Write events
34
Delete events
0

Modification events

(PID) Process:(4164) BrightVPN-Setup-1.422.634-fb2e56b7.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4164) BrightVPN-Setup-1.422.634-fb2e56b7.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4164) BrightVPN-Setup-1.422.634-fb2e56b7.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4164) BrightVPN-Setup-1.422.634-fb2e56b7.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
25
Suspicious files
44
Text files
12
Unknown types
26

Dropped files

PID
Process
Filename
Type
4164BrightVPN-Setup-1.422.634-fb2e56b7.exeC:\Users\admin\AppData\Local\Temp\VPN.exeexecutable
MD5:26E59E7CF9436BEEC765505FDD4E0D46
SHA256:E46A9E520DE05D8EB717D49E9F3B9581692EC2690A5413F677AA8DA435483284
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Eder
MD5:ED2A9A68771EE23BE0553A587B8BB371
SHA256:242A9612CD48D37C5911B5470863ED4C41D7782A2E5B8BE5B8D6A9467549D3F4
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\Local\Temp\nsiE939.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\84DF2A3C8D04ED2830223FCB4944994Ebinary
MD5:C94F56A53F16F65240FB355BF3B7F3A7
SHA256:0E66C13949E77D8390169ED6F94445794A4701EAAAA29D2CFBABB9954D13AE2F
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\Local\Temp\nsiE939.tmp\StdUtils.dllexecutable
MD5:C6A6E03F77C313B267498515488C5740
SHA256:B72E9013A6204E9F01076DC38DABBF30870D44DFC66962ADBF73619D4331601E
4164BrightVPN-Setup-1.422.634-fb2e56b7.exeC:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exeexecutable
MD5:675AA8BEFA9D517CC6264816D946EC73
SHA256:729F18179DCE4FF60566C140A2EB57C1FF8675C16EC8D16BC101B579825C2489
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\Local\Temp\nsiE939.tmp\INetC.dllexecutable
MD5:38CAA11A462B16538E0A3DAEB2FC0EAF
SHA256:ED04A4823F221E9197B8F3C3DA1D6859FF5B176185BDE2F1C923A442516C810A
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850Dbinary
MD5:B0DD11DB46BFCFA335070CB354D0BF3A
SHA256:893D338F52E401F483D563D3797F46BD2DAFDC071FEF64189273DC88C3BC54A1
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\bright-vpn-1.422.631-ia32.nsis[1].7z
MD5:
SHA256:
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\Local\Temp\nsiE939.tmp\package.7z
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
110
DNS requests
25
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQDsB7aeXtY5zOySTqVNSGKF
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
2568
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
2568
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
3040
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
GET
200
95.101.54.131:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgMWyehMgE5mlLq70cNksD1gbQ%3D%3D
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
1544
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
3168
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4032
svchost.exe
239.255.255.250:1900
unknown
2568
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
unknown
4004
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2336
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
44.194.147.247:443
perr.brightvpn.com
AMAZON-AES
US
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
unknown
964
brightvpn_installer.exe
44.194.147.247:443
perr.brightvpn.com
AMAZON-AES
US
unknown

DNS requests

Domain
IP
Reputation
perr.brightvpn.com
  • 44.194.147.247
unknown
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
unknown
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
unknown
ocsp.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
unknown
settings-win.data.microsoft.com
  • 40.127.240.158
unknown
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
unknown
www.microsoft.com
  • 88.221.169.152
unknown
self.events.data.microsoft.com
  • 20.189.173.12
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
client.brightvpn.com
  • 44.194.147.247
unknown

Threats

No threats detected
No debug info