brastub6abb_trmbl_inst.exe

The application brastub6abb_trmbl_inst.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from d1w4lp7kic29jz.cloudfront.net. While running, it connects to the Internet address server-52-85-63-150.lhr50.r.cloudfront.net on port 443.
Version:
1.0.2.6

MD5:
4d7d42e0d944d6aabdf7b53a724bd76e

SHA-1:
8250cc9daf7397abc72959535d1c99acf7fc4335

SHA-256:
4fed5849bcaf168db1ed777db25b8f6aded5042a383dd7de5f4dc1f1b4f49d4b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 3:01:46 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Downloader (M)
17.2.12.13

File size:
277.5 KB (284,160 bytes)

Product version:
1.0.2.6

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\brastub6abb_trmbl_inst.exe

File PE Metadata
Compilation timestamp:
2/12/2017 2:39:00 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
14.0

Entry address:
0x13A0

Entry point:
E8, A2, D4, 01, 00, E9, 48, CE, 01, 00, 55, 8B, EC, 51, 51, 83, 65, F8, 00, 56, 8B, F1, 89, 75, FC, E8, D3, 59, 00, 00, 8B, C6, 5E, 8B, E5, 5D, C3, 55, 8B, EC, 83, EC, 10, A1, 08, 40, 44, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 89, 55, F0, 57, 8B, F9, C7, 45, F4, 5E, 7F, 7D, 5E, C7, 45, F8, 7F, 7D, 4C, 00, 8B, C3, 80, 44, 05, F4, F5, 40, 83, F8, 07, 72, F5, 8D, 45, F4, 50, FF, 35, F8, F2, 44, 00, FF, 15, F0, 60, 43, 00, 8B, F0, 85, F6, 74, 10, FF, 75, F0, 8B, CE, 57, FF, 15, 28, 62, 43, 00, FF, D6, 8B, D8...
 
[+]

Code size:
208.5 KB (213,504 bytes)

The file brastub6abb_trmbl_inst.exe has been seen being distributed by the following URL.

http://d1w4lp7kic29jz.cloudfront.net/.../brastub6abb_trmbl_inst.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-52-85-151-21.hkg51.r.cloudfront.net  (52.85.151.21:80)

TCP (HTTP):
Connects to server-52-85-151-222.hkg51.r.cloudfront.net  (52.85.151.222:80)

TCP (HTTP):
Connects to server-52-85-151-72.hkg51.r.cloudfront.net  (52.85.151.72:80)

TCP (HTTP):
Connects to server-54-230-11-181.lhr3.r.cloudfront.net  (54.230.11.181:80)

TCP (HTTP SSL):
Connects to server-52-85-151-238.hkg51.r.cloudfront.net  (52.85.151.238:443)

TCP (HTTP):
Connects to server-52-85-151-25.hkg51.r.cloudfront.net  (52.85.151.25:80)

TCP (HTTP):
Connects to server-54-230-150-92.sin2.r.cloudfront.net  (54.230.150.92:80)

TCP (HTTP SSL):
Connects to server-52-85-151-190.hkg51.r.cloudfront.net  (52.85.151.190:443)

TCP (HTTP SSL):
Connects to server-54-230-11-94.lhr3.r.cloudfront.net  (54.230.11.94:443)

TCP (HTTP SSL):
Connects to server-54-230-11-25.lhr3.r.cloudfront.net  (54.230.11.25:443)

TCP (HTTP SSL):
Connects to server-54-230-11-118.lhr3.r.cloudfront.net  (54.230.11.118:443)

TCP (HTTP SSL):
Connects to server-54-230-150-37.sin2.r.cloudfront.net  (54.230.150.37:443)

TCP (HTTP):
Connects to server-54-230-150-138.sin2.r.cloudfront.net  (54.230.150.138:80)

TCP (HTTP):
Connects to server-54-192-159-98.sin3.r.cloudfront.net  (54.192.159.98:80)

TCP (HTTP):

TCP (HTTP SSL):
Connects to server-54-192-159-95.sin3.r.cloudfront.net  (54.192.159.95:443)

TCP (HTTP):
Connects to server-54-192-159-49.sin3.r.cloudfront.net  (54.192.159.49:80)

TCP (HTTP):
Connects to server-54-192-159-24.sin3.r.cloudfront.net  (54.192.159.24:80)

TCP (HTTP):
Connects to server-54-192-159-18.sin3.r.cloudfront.net  (54.192.159.18:80)

TCP (HTTP SSL):
Connects to server-54-192-159-148.sin3.r.cloudfront.net  (54.192.159.148:443)

Remove brastub6abb_trmbl_inst.exe - Powered by Reason Core Security