| File name: | BrightVPN-Setup-1.482.985-7b19f841.exe |
| Full analysis: | https://app.any.run/tasks/14496d68-31bc-4ebe-8641-22b089fba029 |
| Verdict: | Malicious activity |
| Analysis date: | November 13, 2024, 18:41:48 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | 5196666BEFB423B00F15756EF40E31D1 |
| SHA1: | 37D744E993358B1E0A24A907C593754A0C47A11A |
| SHA256: | 34A5C9C0106B37687FBDD51A60A026D06E7301EC40B1F7FB49384D8FE748E9E6 |
| SSDEEP: | 98304:NNBD05oURLZGXweYMQ3SbP+T+HD/g5I4WFYjlqHwhnd48i4xaTBNZEUm6Qf1YlYf:HQ0Nkp+j22fWoEgO0YQANBOkf |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:12:15 22:26:14+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26624 |
| InitializedDataSize: | 473088 |
| UninitializedDataSize: | 16384 |
| EntryPoint: | 0x338f |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.482.985.0 |
| ProductVersionNumber: | 1.482.985.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Bright Data Ltd. |
| FileDescription: | - |
| FileVersion: | 1.482.985 |
| LegalCopyright: | Copyright © 2024 Bright Data Ltd. |
| ProductName: | Bright VPN |
| ProductVersion: | 1.482.985 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 528 | C:\ProgramData\BrightData\6cca5f7f15056f66a3211bbbd92076486a2361bb\idle_report.exe --id 47489 --screen | C:\ProgramData\BrightData\6cca5f7f15056f66a3211bbbd92076486a2361bb\idle_report.exe | — | net_updater32.exe | |||||||||||
User: admin Company: BrightData Ltd. Integrity Level: MEDIUM Description: idle_report Exit code: 0 Version: 1.482.985 Modules
| |||||||||||||||
| 1176 | rasdial | C:\Windows\SysWOW64\rasdial.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Remote Access Command Line Dial UI Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2692 | C:\ProgramData\BrightData\6cca5f7f15056f66a3211bbbd92076486a2361bb\test_wpf.exe | C:\ProgramData\BrightData\6cca5f7f15056f66a3211bbbd92076486a2361bb\test_wpf.exe | — | net_updater32.exe | |||||||||||
User: SYSTEM Company: BrightData Ltd. (certified) Integrity Level: SYSTEM Description: test_wpf Exit code: 0 Version: 1.482.985 Modules
| |||||||||||||||
| 3076 | "C:\Program Files (x86)\Bright VPN\net_updater32.exe" --install-ui win_brightvpn.com | C:\Program Files (x86)\Bright VPN\net_updater32.exe | — | BrightVPN-Setup-1.482.985-7b19f841.exe | |||||||||||
User: admin Company: BrightData Ltd. (certified) Integrity Level: HIGH Description: BrightData service allows free use of certain features in an app you installed Exit code: 1 Version: 1.482.985 Modules
| |||||||||||||||
| 3276 | C:\ProgramData\BrightData\6cca5f7f15056f66a3211bbbd92076486a2361bb\test_wpf.exe | C:\ProgramData\BrightData\6cca5f7f15056f66a3211bbbd92076486a2361bb\test_wpf.exe | — | Bright VPN.exe | |||||||||||
User: admin Company: BrightData Ltd. (certified) Integrity Level: MEDIUM Description: test_wpf Exit code: 0 Version: 1.482.985 Modules
| |||||||||||||||
| 3568 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | idle_report.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3832 | C:\WINDOWS\system32\cmd.exe /d /s /c "rasdial " | C:\Windows\SysWOW64\cmd.exe | — | Bright VPN.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3844 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3952 | C:\ProgramData\BrightData\6cca5f7f15056f66a3211bbbd92076486a2361bb\brightdata.exe --appid win_brightvpn.com | C:\ProgramData\BrightData\6cca5f7f15056f66a3211bbbd92076486a2361bb\brightdata.exe | — | net_updater32.exe | |||||||||||
User: admin Company: BrightData Ltd. (certified) Integrity Level: MEDIUM Description: BrightData service allows free use of certain features in an app you installed Version: 1.482.985 Modules
| |||||||||||||||
| 4144 | "C:/Program Files (x86)/Bright VPN/net_updater32.exe" --updater win_brightvpn.com | C:\Program Files (x86)\Bright VPN\net_updater32.exe | services.exe | ||||||||||||
User: SYSTEM Company: BrightData Ltd. (certified) Integrity Level: SYSTEM Description: BrightData service allows free use of certain features in an app you installed Version: 1.482.985 Modules
| |||||||||||||||
| (PID) Process: | (5588) BrightVPN-Setup-1.482.985-7b19f841.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (5588) BrightVPN-Setup-1.482.985-7b19f841.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (5588) BrightVPN-Setup-1.482.985-7b19f841.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6220) brightvpn_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (6220) brightvpn_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (6220) brightvpn_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (6220) brightvpn_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (6220) brightvpn_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (6220) brightvpn_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (6220) brightvpn_installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\brightvpn_installer_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | C:\Users\admin\AppData\Local\Temp\nsrBFEE.tmp\System.dll | executable | |
MD5:0D7AD4F45DC6F5AA87F606D0331C6901 | SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA | |||
| 5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\84DF2A3C8D04ED2830223FCB4944994E | der | |
MD5:9EB5991DC6A9B784D49DE3BA5447CDD6 | SHA256:E2248695C0D1012854651A43AD1E8E59DC8AF08718C04A5709CFDC73EB164159 | |||
| 5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | binary | |
MD5:CEAFD43A701A258487682CAF51DCF634 | SHA256:4CEF651096D155401D416DA6655242234F3AF78928BFE6D3194C46F81DE13300 | |||
| 5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850D | der | |
MD5:0EAC09B5481F803AE584970AF050C78B | SHA256:EA2291749F05798C1CBA29110B66796407393D5406ED36647897DB42EFD24504 | |||
| 5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | C:\Users\admin\AppData\Local\Temp\nsrBFEE.tmp\INetC.dll | executable | |
MD5:38CAA11A462B16538E0A3DAEB2FC0EAF | SHA256:ED04A4823F221E9197B8F3C3DA1D6859FF5B176185BDE2F1C923A442516C810A | |||
| 5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | der | |
MD5:3CC0D5937762DEB6BFB20E13C73E0344 | SHA256:67E3437216AE66182BEBFBFD9F5BFF3C49B661E507900F93AE1BCBFC7174F894 | |||
| 5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\runAfterInstall[1] | text | |
MD5:F827CF462F62848DF37C5E1E94A4DA74 | SHA256:3CBC87C7681F34DB4617FEAA2C8801931BC5E42D8D0F560E756DD4CD92885F18 | |||
| 5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | C:\Users\admin\AppData\Local\Temp\nsrBFEE.tmp\StdUtils.dll | executable | |
MD5:C6A6E03F77C313B267498515488C5740 | SHA256:B72E9013A6204E9F01076DC38DABBF30870D44DFC66962ADBF73619D4331601E | |||
| 5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | C:\Users\admin\AppData\Local\Temp\nsrBFEE.tmp\brightvpn_installer.exe | executable | |
MD5:8CA6ED0227F58FB9C25B215362B2F492 | SHA256:F4EB94B7655CEAB41552165480800381BD64017311B9C1E94B4711273253BB1B | |||
| 5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\84DF2A3C8D04ED2830223FCB4944994E | binary | |
MD5:9FEFA924C65A9359A56FB4A9786F0603 | SHA256:24062784501619EC3C3AA2F5CD7DF3772D01B94EBCE5264919D175D62081BADD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.48.23.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4360 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | unknown | — | — | whitelisted |
5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQDsB7aeXtY5zOySTqVNSGKF | unknown | — | — | whitelisted |
5588 | BrightVPN-Setup-1.482.985-7b19f841.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | unknown | — | — | whitelisted |
2776 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
4040 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6944 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5488 | MoUsoCoreWorker.exe | 23.48.23.176:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.48.23.176:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5488 | MoUsoCoreWorker.exe | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4360 | SearchApp.exe | 92.123.104.47:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4360 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4020 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
google.com |
| whitelisted |
perr.brightvpn.com |
| unknown |
ocsp.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2172 | svchost.exe | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |
4144 | net_updater32.exe | Misc activity | ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI |
2948 | svchost.exe | Generic Protocol Command Decode | SURICATA IKE weak cryptographic parameters (PRF) |
2948 | svchost.exe | Generic Protocol Command Decode | SURICATA IKE weak cryptographic parameters (Auth) |