File name:

BrightVPN-Setup-1.422.631-9bd00ef1.exe

Full analysis: https://app.any.run/tasks/cf546d10-ea38-4c1e-a373-57fd5719f352
Verdict: Malicious activity
Analysis date: January 13, 2024, 17:00:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

675AA8BEFA9D517CC6264816D946EC73

SHA1:

25AD029E425FFEE5A38F10B5177A6D348DFFCF6B

SHA256:

729F18179DCE4FF60566C140A2EB57C1FF8675C16EC8D16BC101B579825C2489

SSDEEP:

49152:3NZuj4HyNt85qTnYDn/dbPpVfUQCW9CkQ+vux1OWAYRTXVIJ/mXymUHCW0GAaAVV:3NMD050n0n/ZRV5CW9CklvOkWtNXwx1A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • net_updater32.exe (PID: 2532)
      • Bright VPN.exe (PID: 2676)
    • Creates a writable file in the system directory

      • net_updater32.exe (PID: 2532)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
    • Reads the Internet Settings

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • brightvpn_installer.exe (PID: 1936)
      • Bright VPN.exe (PID: 2676)
    • Reads security settings of Internet Explorer

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
    • Adds/modifies Windows certificates

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
    • Executable content was dropped or overwritten

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • net_updater32.exe (PID: 2532)
      • Bright VPN.exe (PID: 2676)
    • Checks Windows Trust Settings

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • net_updater32.exe (PID: 2532)
    • The process creates files with name similar to system file names

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
    • Reads settings of System Certificates

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • brightvpn_installer.exe (PID: 1936)
      • net_updater32.exe (PID: 2912)
      • Bright VPN.exe (PID: 2676)
    • Executes as Windows Service

      • net_updater32.exe (PID: 2532)
    • Drops 7-zip archiver for unpacking

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
    • Process drops legitimate windows executable

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • net_updater32.exe (PID: 2532)
    • Starts application with an unusual extension

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
    • Starts SC.EXE for service management

      • ns2611.tmp (PID: 2804)
    • The process drops C-runtime libraries

      • net_updater32.exe (PID: 2532)
    • Detected use of alternative data streams (AltDS)

      • net_updater32.exe (PID: 2532)
      • Bright VPN.exe (PID: 2676)
      • rasdial.exe (PID: 1740)
      • rasdial.exe (PID: 3608)
    • Starts CMD.EXE for commands execution

      • Bright VPN.exe (PID: 2676)
    • Application launched itself

      • Bright VPN.exe (PID: 2676)
  • INFO

    • Checks supported languages

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • brightvpn_installer.exe (PID: 1936)
      • ns268F.tmp (PID: 1000)
      • net_updater32.exe (PID: 2912)
      • net_updater32.exe (PID: 2532)
      • ns2611.tmp (PID: 2804)
      • test_wpf.exe (PID: 2364)
      • Bright VPN.exe (PID: 2676)
      • test_wpf.exe (PID: 3200)
      • brightdata.exe (PID: 3352)
      • Bright VPN.exe (PID: 4088)
      • Bright VPN.exe (PID: 2092)
      • Bright VPN.exe (PID: 3820)
      • idle_report.exe (PID: 3300)
      • Bright VPN.exe (PID: 1216)
      • wmpnscfg.exe (PID: 2052)
      • idle_report.exe (PID: 2580)
      • wmpnscfg.exe (PID: 2260)
      • idle_report.exe (PID: 392)
      • wmpnscfg.exe (PID: 1816)
      • wmpnscfg.exe (PID: 784)
      • wmpnscfg.exe (PID: 1604)
    • Reads the computer name

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • brightvpn_installer.exe (PID: 1936)
      • net_updater32.exe (PID: 2912)
      • test_wpf.exe (PID: 2364)
      • net_updater32.exe (PID: 2532)
      • test_wpf.exe (PID: 3200)
      • Bright VPN.exe (PID: 2676)
      • Bright VPN.exe (PID: 2092)
      • Bright VPN.exe (PID: 4088)
      • idle_report.exe (PID: 3300)
      • brightdata.exe (PID: 3352)
      • Bright VPN.exe (PID: 1216)
      • wmpnscfg.exe (PID: 2052)
      • wmpnscfg.exe (PID: 2260)
      • wmpnscfg.exe (PID: 784)
      • wmpnscfg.exe (PID: 1604)
      • idle_report.exe (PID: 2580)
      • wmpnscfg.exe (PID: 1816)
      • idle_report.exe (PID: 392)
    • Checks proxy server information

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
    • Reads the machine GUID from the registry

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • brightvpn_installer.exe (PID: 1936)
      • net_updater32.exe (PID: 2912)
      • test_wpf.exe (PID: 2364)
      • net_updater32.exe (PID: 2532)
      • Bright VPN.exe (PID: 2676)
      • test_wpf.exe (PID: 3200)
      • idle_report.exe (PID: 3300)
      • brightdata.exe (PID: 3352)
      • idle_report.exe (PID: 2580)
      • idle_report.exe (PID: 392)
    • Creates files in the program directory

      • brightvpn_installer.exe (PID: 1936)
      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • net_updater32.exe (PID: 2912)
      • net_updater32.exe (PID: 2532)
      • Bright VPN.exe (PID: 2676)
      • brightdata.exe (PID: 3352)
    • Reads Environment values

      • brightvpn_installer.exe (PID: 1936)
      • net_updater32.exe (PID: 2532)
      • Bright VPN.exe (PID: 2676)
      • brightdata.exe (PID: 3352)
      • Bright VPN.exe (PID: 3820)
    • Create files in a temporary directory

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • Bright VPN.exe (PID: 2676)
    • Creates files or folders in the user directory

      • BrightVPN-Setup-1.422.631-9bd00ef1.exe (PID: 2268)
      • net_updater32.exe (PID: 2912)
      • brightvpn_installer.exe (PID: 1936)
      • Bright VPN.exe (PID: 2676)
      • Bright VPN.exe (PID: 3820)
      • Bright VPN.exe (PID: 2092)
    • Process checks computer location settings

      • net_updater32.exe (PID: 2532)
      • Bright VPN.exe (PID: 2676)
      • Bright VPN.exe (PID: 3820)
    • Manual execution by a user

      • Bright VPN.exe (PID: 2676)
      • wmpnscfg.exe (PID: 2260)
      • wmpnscfg.exe (PID: 2052)
      • wmpnscfg.exe (PID: 1604)
      • wmpnscfg.exe (PID: 784)
      • wmpnscfg.exe (PID: 1816)
    • Reads product name

      • Bright VPN.exe (PID: 2676)
      • Bright VPN.exe (PID: 3820)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 23:26:14+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 473088
UninitializedDataSize: 16384
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.422.631.0
ProductVersionNumber: 1.422.631.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Bright Data Ltd.
FileDescription: -
FileVersion: 1.422.631
LegalCopyright: Copyright © 2023 Bright Data Ltd.
ProductName: Bright VPN
ProductVersion: 1.422.631
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
401
Monitored processes
244
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start brightvpn-setup-1.422.631-9bd00ef1.exe brightvpn_installer.exe ns2611.tmp no specs sc.exe no specs ns268f.tmp no specs net_updater32.exe net_updater32.exe test_wpf.exe no specs bright vpn.exe cmd.exe no specs rasdial.exe no specs test_wpf.exe no specs brightdata.exe no specs idle_report.exe no specs bright vpn.exe no specs bright vpn.exe bright vpn.exe no specs bright vpn.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs wmpnscfg.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs wmpnscfg.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs idle_report.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs wmpnscfg.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs wmpnscfg.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs wmpnscfg.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs idle_report.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs cmd.exe no specs rasdial.exe no specs brightvpn-setup-1.422.631-9bd00ef1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316rasdial C:\Windows\System32\rasdial.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Remote Access Command Line Dial UI
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rasdial.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
324rasdial C:\Windows\System32\rasdial.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Remote Access Command Line Dial UI
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rasdial.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
376C:\Windows\system32\cmd.exe /d /s /c "rasdial "C:\Windows\System32\cmd.exeBright VPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
392C:\ProgramData\BrightData\e29051f7300cbcfc586e9ad053effe7bc56cfa61\idle_report.exe --id 66296C:\ProgramData\BrightData\e29051f7300cbcfc586e9ad053effe7bc56cfa61\idle_report.exenet_updater32.exe
User:
admin
Company:
BrightData Ltd.
Integrity Level:
MEDIUM
Description:
idle_report
Exit code:
0
Version:
1.422.631
Modules
Images
c:\programdata\brightdata\e29051f7300cbcfc586e9ad053effe7bc56cfa61\idle_report.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
476C:\Windows\system32\cmd.exe /d /s /c "rasdial "C:\Windows\System32\cmd.exeBright VPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
480C:\Windows\system32\cmd.exe /d /s /c "rasdial "C:\Windows\System32\cmd.exeBright VPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
480rasdial C:\Windows\System32\rasdial.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Remote Access Command Line Dial UI
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rasdial.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
568C:\Windows\system32\cmd.exe /d /s /c "rasdial "C:\Windows\System32\cmd.exeBright VPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
664C:\Windows\system32\cmd.exe /d /s /c "rasdial "C:\Windows\System32\cmd.exeBright VPN.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
748rasdial C:\Windows\System32\rasdial.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Remote Access Command Line Dial UI
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rasdial.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
Total events
49 682
Read events
49 562
Write events
120
Delete events
0

Modification events

(PID) Process:(2268) BrightVPN-Setup-1.422.631-9bd00ef1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2268) BrightVPN-Setup-1.422.631-9bd00ef1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2268) BrightVPN-Setup-1.422.631-9bd00ef1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2268) BrightVPN-Setup-1.422.631-9bd00ef1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2268) BrightVPN-Setup-1.422.631-9bd00ef1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2268) BrightVPN-Setup-1.422.631-9bd00ef1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2268) BrightVPN-Setup-1.422.631-9bd00ef1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2268) BrightVPN-Setup-1.422.631-9bd00ef1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2268) BrightVPN-Setup-1.422.631-9bd00ef1.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2268) BrightVPN-Setup-1.422.631-9bd00ef1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E
Operation:writeName:Blob
Value:
53000000010000004300000030413022060C2B06010401B231010201050130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000EA6089055218053DD01E37E1D806EEDF620000000100000020000000E793C9B02FD8AA13E21C31228ACCB08119643B749C898964B1746D46C3D4CBD21400000001000000140000005379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB1D0000000100000010000000885010358D29A38F059B028559C95F900B00000001000000100000005300650063007400690067006F0000000300000001000000140000002B8F1B57330DBBA2D07A6C51F70EE90DDAB9AD8E0F000000010000003000000066B764A96581128168CF208E374DDA479D54E311F32457F4AEE0DBD2A6C8D171D531289E1CD22BFDBBD4CFD979625483090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703082000000001000000E2050000308205DE308203C6A003020102021001FD6D30FCA3CA51A81BBC640E35032D300D06092A864886F70D01010C0500308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F72697479301E170D3130303230313030303030305A170D3338303131383233353935395A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010080126517360EC3DB08B3D0AC570D76EDCD27D34CAD508361E2AA204D092D6409DCCE899FCC3DA9ECF6CFC1DCF1D3B1D67B3728112B47DA39C6BC3A19B45FA6BD7D9DA36342B676F2A93B2B91F8E26FD0EC162090093EE2E874C918B491D46264DB7FA306F188186A90223CBCFE13F087147BF6E41F8ED4E451C61167460851CB8614543FBC33FE7E6C9CFF169D18BD518E35A6A766C87267DB2166B1D49B7803C0503AE8CCF0DCBC9E4CFEAF0596351F575AB7FFCEF93DB72CB6F654DDC8E7123A4DAE4C8AB75C9AB4B7203DCA7F2234AE7E3B68660144E7014E46539B3360F794BE5337907343F332C353EFDBAAFE744E69C76B8C6093DEC4C70CDFE132AECC933B517895678BEE3D56FE0CD0690F1B0FF325266B336DF76E47FA7343E57E0EA566B1297C3284635589C40DC19354301913ACD37D37A7EB5D3A6C355CDB41D712DAA9490BDFD8808A0993628EB566CF2588CD84B8B13FA4390FD9029EEB124C957CF36B05A95E1683CCB867E2E8139DCC5B82D34CB3ED5BFFDEE573AC233B2D00BF3555740949D849581A7F9236E651920EF3267D1C4D17BCC9EC4326D0BF415F40A94444F499E757879E501F5754A83EFD74632FB1506509E658422E431A4CB4F0254759FA041E93D426464A5081B2DEBE78B7FC6715E1C957841E0F63D6E962BAD65F552EEA5CC62808042539B80E2BA9F24C971C073F0D52F5EDEF2F820F0203010001A3423040301D0603551D0E041604145379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D01010C050003820201005CD47C0DCFF7017D4199650C73C5529FCBF8CF99067F1BDA43159F9E0255579614F1523C27879428ED1F3A0137A276FC5350C0849BC66B4EBA8C214FA28E556291F36915D8BC88E3C4AA0BFDEFA8E94B552A06206D55782919EE5F305C4B241155FF249A6E5E2A2BEE0B4D9F7FF70138941495430709FB60A9EE1CAB128CA09A5EA7986A596D8B3F08FBC8D145AF18156490120F73282EC5E2244EFC58ECF0F445FE22B3EB2F8ED2D9456105C1976FA876728F8B8C36AFBF0D05CE718DE6A66F1F6CA67162C5D8D083720CF16711890C9C134C7234DFBCD571DFAA71DDE1B96C8C3C125D65DABD5712B6436BFFE5DE4D661151CF99AEEC17B6E871918CDE49FEDD3571A21527941CCF61E326BB6FA36725215DE6DD1D0B2E681B3B82AFEC836785D4985174B1B9998089FF7F78195C794A602E9240AE4C372A2CC9C762C80E5DF7365BCAE0252501B4DD1A079C77003FD0DCD5EC3DD4FABB3FCC85D66F7FA92DDFB902F7F5979AB535DAC367B0874AA9289E238EFF5C276BE1B04FF307EE002ED45987CB524195EAF447D7EE6441557C8D590295DD629DC2B9EE5A287484A59BB790C70C07DFF589367432D628C1B0B00BE09C4CC31CD6FCE369B54746812FA282ABD3634470C48DFF2D33BAAD8F7BB57088AE3E19CF4028D8FCC890BB5D9922F552E658C51F883143EE881DD7C68E3C436A1DA718DE7D3D16F162F9CA90A8FD
Executable files
41
Suspicious files
222
Text files
31
Unknown types
1

Dropped files

PID
Process
Filename
Type
2268BrightVPN-Setup-1.422.631-9bd00ef1.exeC:\Users\admin\AppData\Local\Temp\nsrFFCE.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
2268BrightVPN-Setup-1.422.631-9bd00ef1.exeC:\Users\admin\AppData\Local\Temp\nsrFFCE.tmp\INetC.dllexecutable
MD5:38CAA11A462B16538E0A3DAEB2FC0EAF
SHA256:ED04A4823F221E9197B8F3C3DA1D6859FF5B176185BDE2F1C923A442516C810A
2268BrightVPN-Setup-1.422.631-9bd00ef1.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2268BrightVPN-Setup-1.422.631-9bd00ef1.exeC:\Users\admin\AppData\Local\Temp\nsrFFCE.tmp\StdUtils.dllexecutable
MD5:C6A6E03F77C313B267498515488C5740
SHA256:B72E9013A6204E9F01076DC38DABBF30870D44DFC66962ADBF73619D4331601E
2268BrightVPN-Setup-1.422.631-9bd00ef1.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\init[1]text
MD5:115D0B1B2A63CB42AE4D45A2860DDB96
SHA256:DE89AC85A9E383E1AD01089796729CBEB28AAE5D1989AEF07BF313F8C07AFE54
2268BrightVPN-Setup-1.422.631-9bd00ef1.exeC:\Users\admin\AppData\Local\Temp\nsrFFCE.tmp\nsProcess.dllexecutable
MD5:F0438A894F3A7E01A4AAE8D1B5DD0289
SHA256:30C6C3DD3CC7FCEA6E6081CE821ADC7B2888542DAE30BF00E881C0A105EB4D11
2268BrightVPN-Setup-1.422.631-9bd00ef1.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\394AED4116FFD9B32F111818CF5811F3binary
MD5:44192D9D077BAB0781306196E53D800C
SHA256:7B27C45B84E3F14160ABEAC5A4A4BFE8640960EFEBB195E0BDE78F69B91CD5FD
2268BrightVPN-Setup-1.422.631-9bd00ef1.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\runAfterInstall[1]text
MD5:F827CF462F62848DF37C5E1E94A4DA74
SHA256:3CBC87C7681F34DB4617FEAA2C8801931BC5E42D8D0F560E756DD4CD92885F18
2268BrightVPN-Setup-1.422.631-9bd00ef1.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\runOnStartup[1]text
MD5:F827CF462F62848DF37C5E1E94A4DA74
SHA256:3CBC87C7681F34DB4617FEAA2C8801931BC5E42D8D0F560E756DD4CD92885F18
2268BrightVPN-Setup-1.422.631-9bd00ef1.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\userConsent[1]text
MD5:6A6334B478289B4FB3060C4F803EAFD3
SHA256:94D5C9D96025716090F176F76E07C45B1296250FE9BFE1823F77F53881548690
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
119
DNS requests
30
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
GET
200
173.222.108.201:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?4a53176c7d6f234f
unknown
compressed
4.66 Kb
unknown
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
binary
1.42 Kb
unknown
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
binary
2.18 Kb
unknown
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
GET
200
69.192.161.44:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
GET
200
173.222.108.201:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e62fdf5a3d383eaa
unknown
compressed
65.2 Kb
unknown
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEC8IwCaGdYb0RCPlgXfb73o%3D
unknown
binary
471 b
unknown
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
GET
200
184.24.77.57:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOZ0YEe5XUaXD7ztJrhI95Vqw%3D%3D
unknown
binary
503 b
unknown
2532
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
unknown
binary
727 b
unknown
2532
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
unknown
binary
471 b
unknown
2532
net_updater32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAdTF0YC22Gdh8cnyPwWxE0%3D
unknown
binary
727 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
44.194.147.247:443
perr.brightvpn.com
AMAZON-AES
US
unknown
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
173.222.108.201:80
ctldl.windowsupdate.com
Akamai International B.V.
CH
unknown
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
1936
brightvpn_installer.exe
44.194.147.247:443
perr.brightvpn.com
AMAZON-AES
US
unknown
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
138.199.36.8:443
cdn.brightvpn.com
Datacamp Limited
DE
unknown
2268
BrightVPN-Setup-1.422.631-9bd00ef1.exe
69.192.161.44:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
perr.brightvpn.com
  • 44.194.147.247
unknown
ctldl.windowsupdate.com
  • 173.222.108.201
  • 173.222.108.147
  • 173.222.108.193
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.sectigo.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
client.brightvpn.com
  • 44.194.147.247
unknown
cdn.brightvpn.com
  • 138.199.36.8
unknown
x1.c.lencr.org
  • 69.192.161.44
whitelisted
r3.o.lencr.org
  • 184.24.77.57
  • 184.24.77.47
  • 184.24.77.71
  • 184.24.77.83
  • 184.24.77.78
  • 184.24.77.54
  • 184.24.77.56
shared
perr.l-err.biz
  • 159.223.133.120
  • 206.189.231.23
  • 161.35.48.195
  • 192.81.214.145
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .biz TLD
2532
net_updater32.exe
Potential Corporate Privacy Violation
ET POLICY Dropbox.com Offsite File Backup in Use
2532
net_updater32.exe
Misc activity
ET INFO DropBox User Content Download Access over SSL M2
No debug info