brrmppqbphchunitain.exe

BIG JOURNEY TECHNOLOGY LIMITED

The application brrmppqbphchunitain.exe by BIG JOURNEY TECHNOLOGY LIMITED has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. While running, it connects to the Internet address server-54-230-182-144.icn50.r.cloudfront.net on port 80 using the HTTP protocol.
Publisher:
BIG JOURNEY TECHNOLOGY LIMITED  (signed and verified)

MD5:
ced9864e865cddffedb21380842a5f47

SHA-1:
b7766f28ac049a11867bf6a2a08f6acb8e0bf691

SHA-256:
872f4082491dfdb471c2c80157561251f79fe3e30066b0ef329c3cc7047a4b15

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/13/2025 4:21:19 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.YesSearches (M)
16.7.26.7

File size:
324.6 KB (332,368 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\proughtprojtion\brrmppqbphchunitain.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/19/2016 2:02:38 AM

Valid to:
1/20/2017 9:56:27 PM

Subject:
CN=BIG JOURNEY TECHNOLOGY LIMITED, O=BIG JOURNEY TECHNOLOGY LIMITED, L=香港, S=香港, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G3, O=GlobalSign nv-sa, C=BE

Serial number:
2A888DD2EA2F8E6B36A04565

File PE Metadata
Compilation timestamp:
7/20/2016 8:14:46 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:tjDEvNnTm6XOT66hkOZAuIJRv+VaP/DvIUoj52Rhp:tjD6NnTDXO/hkOmXmYsBj52Rb

Entry address:
0x1E503

Entry point:
E8, E7, 55, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, E8, E1, 44, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA, 25, F8, C2, 44, 00, 01, 0F, 82, 04, 5B, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02...
 
[+]

Entropy:
6.5222

Code size:
241 KB (246,784 bytes)

Scheduled Task
Task name:
Berary Mapper

Trigger:
Daily (Runs daily at 04:38 a.m.)

Description:
Resolves Berary interfaces identifiers to transport endpoints.


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to server-52-84-16-204.sea32.r.cloudfront.net  (52.84.16.204:80)

TCP (HTTP):
Connects to server-54-230-95-161.fra2.r.cloudfront.net  (54.230.95.161:80)

TCP (HTTP):
Connects to server-54-230-141-182.sfo5.r.cloudfront.net  (54.230.141.182:80)

TCP (HTTP):
Connects to server-54-192-203-72.fra50.r.cloudfront.net  (54.192.203.72:80)

TCP (HTTP):
Connects to server-54-192-159-171.sin3.r.cloudfront.net  (54.192.159.171:80)

TCP (HTTP):
Connects to server-52-85-83-195.lax1.r.cloudfront.net  (52.85.83.195:80)

TCP (HTTP):
Connects to server-54-230-95-249.fra2.r.cloudfront.net  (54.230.95.249:80)

TCP (HTTP):
Connects to server-54-192-159-158.sin3.r.cloudfront.net  (54.192.159.158:80)

TCP (HTTP):
Connects to server-54-230-191-186.maa3.r.cloudfront.net  (54.230.191.186:80)

TCP (HTTP):
Connects to server-54-192-159-234.sin3.r.cloudfront.net  (54.192.159.234:80)

TCP (HTTP):
Connects to server-54-239-132-107.sfo9.r.cloudfront.net  (54.239.132.107:80)

TCP (HTTP):
Connects to server-54-230-95-119.fra2.r.cloudfront.net  (54.230.95.119:80)

TCP (HTTP):
Connects to server-54-230-150-222.sin2.r.cloudfront.net  (54.230.150.222:80)

TCP (HTTP):
Connects to server-54-230-141-247.sfo5.r.cloudfront.net  (54.230.141.247:80)

TCP (HTTP):
Connects to server-54-230-141-200.sfo5.r.cloudfront.net  (54.230.141.200:80)

TCP (HTTP):
Connects to server-54-239-132-236.sfo9.r.cloudfront.net  (54.239.132.236:80)

TCP (HTTP):
Connects to server-54-239-132-118.sfo9.r.cloudfront.net  (54.239.132.118:80)

TCP (HTTP):
Connects to server-54-192-159-101.sin3.r.cloudfront.net  (54.192.159.101:80)

TCP (HTTP):
Connects to server-52-84-25-146.sea32.r.cloudfront.net  (52.84.25.146:80)

TCP (HTTP):
Connects to server-54-239-132-103.sfo9.r.cloudfront.net  (54.239.132.103:80)

Remove brrmppqbphchunitain.exe - Powered by Reason Core Security