beaglebrowser.exe

BeagleBrowser

The BeagleBrowser Authors

The application beaglebrowser.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘BeagleBrowser’. This file is typically installed with the program BeagleBrowser. The file has been seen being downloaded from dl-mail.ymail.com. While running, it connects to the Internet address 201-217-205-205-host.ifx.net.co on port 443.
Publisher:
The BeagleBrowser Authors

Product:
BeagleBrowser

Version:
45.0.2454.108

MD5:
963b5d317968808f55c377f3f9f8bec4

SHA-1:
13f76ac1f752b832469c99489fd442610f51d713

SHA-256:
8dd1cd11784a647a34f322bc11c0113703600bee813d9d2d1a5f46d89af859a0

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
11/20/2017 8:43:58 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Chir.B
7.11.30.172

Reason Heuristics
PUP.BeagleBrowser.TheBeagleBrowserAuthors.Meta (M)
16.1.3.13

File size:
588 KB (602,112 bytes)

Product version:
45.0.2454.108

Copyright:
Copyright 2015 The BeagleBrowser Authors. All rights reserved.

Original file name:
chrome.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\beaglebrowser\application\beaglebrowser.exe

File PE Metadata
Compilation timestamp:
12/3/2015 9:06:58 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:n2OoA84+x2v7aGYDqbF+h/n8AUy/qF1wadOJKN8XxcaNin1pgRaIHU:n2I8keHxs17IHU

Entry address:
0x42804

Entry point:
E8, A8, 96, 00, 00, E9, 7F, FE, FF, FF, CC, CC, 8B, 44, 24, 08, 8B, 4C, 24, 10, 0B, C8, 8B, 4C, 24, 0C, 75, 09, 8B, 44, 24, 04, F7, E1, C2, 10, 00, 53, F7, E1, 8B, D8, 8B, 44, 24, 08, F7, 64, 24, 14, 03, D8, 8B, 44, 24, 08, F7, E1, 03, D3, 5B, C2, 10, 00, 55, 8B, EC, 83, EC, 14, 53, 56, 33, DB, 57, 8B, 7D, 08, 89, 5D, F8, 89, 5D, F4, 89, 5D, FC, 85, FF, 75, 18, E8, F0, 13, 00, 00, 6A, 16, 5E, 89, 30, E8, E5, D0, FF, FF, 8B, C6, 5F, 5E, 5B, 8B, E5, 5D, C3, 6A, 24, 68, FF, 00, 00, 00, 57, E8, 1C, FA, FF, FF...
 
[+]

Code size:
367 KB (375,808 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BeagleBrowser

Command:
C:\users\{user}\appdata\local\beaglebrowser\application\beaglebrowser.exe


The file beaglebrowser.exe has been discovered within the following program.

BeagleBrowser  by BeagleBrowser
About 2% of users remove it
 
Powered by Should I Remove It?

The file beaglebrowser.exe has been seen being distributed by the following URL.

https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjJ-O1ASyE2dX6rX30f2NjmayWbjR2hXst45PmokCcgZ8axlyTudvDCytzrqmBQsSa4P8JjduORtDaB3BP2h4xIM7Q/messages/@.id==AE2_imIACP7bV3VGkwoOOEKB-WM/content/parts/@.id==2/raw?appid=YahooMailNeo&ymreqid=2bc2c711-445b-afbe-01f5-b2008e010000&token=nM5yCylfE-ATfopU6P8pf4J10hPHVvbXJVEhqdeAjDMP2oly2uAmsJ-VCrHkbtSQYnKFQFGizLtl8ROjNwreZw&error=https://br-mg5.mail.yahoo.com/.../iframemsg?id=368685f2-7a2d-0807-44fe-89ab9fdcb907

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to c937e974.virtua.com.br  (201.55.233.116:443)

TCP (HTTP SSL):
Connects to c937e975.virtua.com.br  (201.55.233.117:443)

TCP (HTTP SSL):
Connects to 80.83.2ea9.ip4.static.sl-reverse.com  (169.46.131.128:443)

TCP (HTTP SSL):
Connects to edge-star-shv-01-gru2.facebook.com  (31.13.85.8:443)

TCP (HTTP SSL):
Connects to edge-star-mini-shv-01-gru2.facebook.com  (31.13.85.36:443)

TCP (HTTP):
Connects to ec2-50-19-220-99.compute-1.amazonaws.com  (50.19.220.99:80)

TCP (HTTP SSL):
Connects to 189-113-79-145.static.sumicity.net.br  (189.113.79.145:443)

TCP (HTTP):
Connects to ec2-52-207-48-5.compute-1.amazonaws.com  (52.207.48.5:80)

TCP (HTTP SSL):
Connects to server-52-84-179-211.gru50.r.cloudfront.net  (52.84.179.211:443)

TCP (HTTP):
Connects to a23-213-198-156.deploy.static.akamaitechnologies.com  (23.213.198.156:80)

TCP (HTTP SSL):
Connects to a23-1-112-103.deploy.static.akamaitechnologies.com  (23.1.112.103:443)

TCP (HTTP SSL):
Connects to 57.247.178.107.bc.googleusercontent.com  (107.178.247.57:443)

TCP (HTTP SSL):
Connects to 132.253.178.107.bc.googleusercontent.com  (107.178.253.132:443)

TCP (HTTP SSL):
Connects to edge-z-m-mini-shv-01-gru2.facebook.com  (31.13.85.37:443)

TCP (HTTP SSL):
Connects to ec2-50-19-113-170.compute-1.amazonaws.com  (50.19.113.170:443)

TCP (HTTP):
Connects to ec2-23-21-219-9.compute-1.amazonaws.com  (23.21.219.9:80)

TCP (HTTP):
Connects to a189-113-79-98.google.com.br  (189.113.79.98:80)

TCP (HTTP):
Connects to a189-113-79-83.google.com.br  (189.113.79.83:80)

TCP (HTTP):

TCP (HTTP SSL):
Connects to ec2-23-23-112-220.compute-1.amazonaws.com  (23.23.112.220:443)

Remove beaglebrowser.exe - Powered by Reason Core Security