File name:

BrightVPN-Setup-1.422.634-fb2e56b7.exe

Full analysis: https://app.any.run/tasks/31a7cf82-8ef8-4ac6-8a62-329d55077dde
Verdict: Malicious activity
Analysis date: June 30, 2024, 11:01:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1CA12C1DDBBC4547FEF82491C23913F4

SHA1:

E2E057825A10E8BA97C0185F7C01DA6B449F7023

SHA256:

2B1B91075512986F811A419C62FE115D5CC8880D8126B9F94386861F82B2C995

SSDEEP:

98304:Iyi3UHGAx+DerS6sg03JwywLWiFwiDAfwh4X5MphqOnuY5/HSPfOY8xUBMqFtM71:vgdf8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
    • Executable content was dropped or overwritten

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Reads the date of Windows installation

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • The process creates files with name similar to system file names

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Checks Windows Trust Settings

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Process drops legitimate windows executable

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Drops 7-zip archiver for unpacking

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Connects to unusual port

      • VPN.exe (PID: 2648)
  • INFO

    • Reads the computer name

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • VPN.exe (PID: 2648)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
    • Checks supported languages

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • VPN.exe (PID: 2648)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
    • Process checks computer location settings

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
    • Create files in a temporary directory

      • BrightVPN-Setup-1.422.634-fb2e56b7.exe (PID: 4164)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Checks proxy server information

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
    • Reads the machine GUID from the registry

      • VPN.exe (PID: 2648)
      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
    • Reads the software policy settings

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
    • Creates files or folders in the user directory

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
    • Reads Environment values

      • brightvpn_installer.exe (PID: 964)
    • Disables trace logs

      • brightvpn_installer.exe (PID: 964)
    • Creates files in the program directory

      • BrightVPN-Setup-1.422.631-fb2e56b2.exe (PID: 3532)
      • brightvpn_installer.exe (PID: 964)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:03:03 13:15:57+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.3
CodeSize: 203776
InitializedDataSize: 116736
UninitializedDataSize: -
EntryPoint: 0x1f530
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start brightvpn-setup-1.422.634-fb2e56b7.exe vpn.exe conhost.exe no specs brightvpn-setup-1.422.631-fb2e56b2.exe no specs brightvpn-setup-1.422.631-fb2e56b2.exe brightvpn_installer.exe

Process information

PID
CMD
Path
Indicators
Parent process
964"C:\Users\admin\AppData\Local\Temp\nsiE939.tmp\brightvpn_installer.exe" /pid=3532 /port=6451 /affiliate= /silent= /exe="C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exe"C:\Users\admin\AppData\Local\Temp\nsiE939.tmp\brightvpn_installer.exe
BrightVPN-Setup-1.422.631-fb2e56b2.exe
User:
admin
Company:
Bright Data Ltd
Integrity Level:
HIGH
Description:
Bright VPN
Version:
1.422.631
Modules
Images
c:\users\admin\appdata\local\temp\nsie939.tmp\brightvpn_installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2100\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeVPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2648"C:\Users\admin\AppData\Local\Temp\VPN.exe" C:\Users\admin\AppData\Local\Temp\VPN.exe
BrightVPN-Setup-1.422.634-fb2e56b7.exe
User:
admin
Company:
Isogeny
Integrity Level:
MEDIUM
Description:
Isogeny
Version:
51.64.94
Modules
Images
c:\users\admin\appdata\local\temp\vpn.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2832"C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exe" C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exeBrightVPN-Setup-1.422.634-fb2e56b7.exe
User:
admin
Company:
Bright Data Ltd.
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.422.631
Modules
Images
c:\users\admin\appdata\local\temp\brightvpn-setup-1.422.631-fb2e56b2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3532"C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exe" C:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exe
BrightVPN-Setup-1.422.634-fb2e56b7.exe
User:
admin
Company:
Bright Data Ltd.
Integrity Level:
HIGH
Version:
1.422.631
Modules
Images
c:\users\admin\appdata\local\temp\brightvpn-setup-1.422.631-fb2e56b2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4164"C:\Users\admin\Downloads\BrightVPN-Setup-1.422.634-fb2e56b7.exe" C:\Users\admin\Downloads\BrightVPN-Setup-1.422.634-fb2e56b7.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\downloads\brightvpn-setup-1.422.634-fb2e56b7.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
12 939
Read events
12 905
Write events
34
Delete events
0

Modification events

(PID) Process:(4164) BrightVPN-Setup-1.422.634-fb2e56b7.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4164) BrightVPN-Setup-1.422.634-fb2e56b7.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4164) BrightVPN-Setup-1.422.634-fb2e56b7.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4164) BrightVPN-Setup-1.422.634-fb2e56b7.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3532) BrightVPN-Setup-1.422.631-fb2e56b2.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
25
Suspicious files
44
Text files
12
Unknown types
26

Dropped files

PID
Process
Filename
Type
4164BrightVPN-Setup-1.422.634-fb2e56b7.exeC:\Users\admin\AppData\Local\Temp\BrightVPN-Setup-1.422.631-fb2e56b2.exeexecutable
MD5:675AA8BEFA9D517CC6264816D946EC73
SHA256:729F18179DCE4FF60566C140A2EB57C1FF8675C16EC8D16BC101B579825C2489
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:BAF36052CF0BCFB8935C464E695844DF
SHA256:46EDC41A2B5CEFE763D6EF73176C2B4B570807C3D90AEDB3C09FB3D0CA0F2DF5
964brightvpn_installer.exeC:\ProgramData\BrightData\6cca5f7f15056f66a3211bbbd92076486a2361bb\lum_sdk_install_idtext
MD5:95374A91042A855D2C9D10CA537B9D8A
SHA256:DA3750B33666AA053D69C2CBFA97A41B1ED036AD8CA8AF69E7B6184C266352D4
4164BrightVPN-Setup-1.422.634-fb2e56b7.exeC:\Users\admin\AppData\Local\Temp\VPN.exeexecutable
MD5:26E59E7CF9436BEEC765505FDD4E0D46
SHA256:E46A9E520DE05D8EB717D49E9F3B9581692EC2690A5413F677AA8DA435483284
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\Local\Temp\nsiE939.tmp\nsProcess.dllexecutable
MD5:F0438A894F3A7E01A4AAE8D1B5DD0289
SHA256:30C6C3DD3CC7FCEA6E6081CE821ADC7B2888542DAE30BF00E881C0A105EB4D11
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\Local\Temp\nsiE939.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\userConsent[1]text
MD5:6A6334B478289B4FB3060C4F803EAFD3
SHA256:94D5C9D96025716090F176F76E07C45B1296250FE9BFE1823F77F53881548690
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\Local\Temp\nsiE939.tmp\INetC.dllexecutable
MD5:38CAA11A462B16538E0A3DAEB2FC0EAF
SHA256:ED04A4823F221E9197B8F3C3DA1D6859FF5B176185BDE2F1C923A442516C810A
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\bright-vpn-1.422.631-ia32.nsis[1].7z
MD5:
SHA256:
3532BrightVPN-Setup-1.422.631-fb2e56b2.exeC:\Users\admin\AppData\Local\Temp\nsiE939.tmp\package.7z
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
110
DNS requests
25
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
unknown
2568
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQDsB7aeXtY5zOySTqVNSGKF
unknown
unknown
2568
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
3040
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
GET
200
95.101.54.131:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgMWyehMgE5mlLq70cNksD1gbQ%3D%3D
unknown
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
unknown
1544
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
3168
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4032
svchost.exe
239.255.255.250:1900
whitelisted
2568
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
4004
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2336
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
44.194.147.247:443
perr.brightvpn.com
AMAZON-AES
US
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
3532
BrightVPN-Setup-1.422.631-fb2e56b2.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
964
brightvpn_installer.exe
44.194.147.247:443
perr.brightvpn.com
AMAZON-AES
US
unknown

DNS requests

Domain
IP
Reputation
perr.brightvpn.com
  • 44.194.147.247
unknown
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.sectigo.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
self.events.data.microsoft.com
  • 20.189.173.12
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.brightvpn.com
  • 44.194.147.247
unknown

Threats

No threats detected
No debug info