File name:

Brave.exe

Full analysis: https://app.any.run/tasks/5868b522-c65a-484b-b9c7-468427bf274e
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 24, 2025, 19:47:14
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
autorun-download
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 8 sections
MD5:

4E4C82586D5463D298CF16CDA5978BBE

SHA1:

4E42352AC32834B53346B47F7206C7B52CBD2E34

SHA256:

0ED2B6C373446E31C3AB8E424BE0783B7DC397B67DB6DBE29173271321C3F426

SSDEEP:

98304:Q5SWISjW2svVyxboNUeCv8j7F6ptO+p2fyke/N5:a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • Brave.exe (PID: 6240)
      • Brave.exe (PID: 6872)
      • Brave.exe (PID: 4488)
      • Brave.exe (PID: 4172)
      • Brave.exe (PID: 4980)
      • Brave.exe (PID: 4736)
      • Brave.exe (PID: 2564)
      • Brave.exe (PID: 5072)
      • Brave.exe (PID: 3156)
      • Brave.exe (PID: 5384)
      • setup.exe (PID: 8640)
      • setup.exe (PID: 8848)
      • BraveUpdate.exe (PID: 8984)
      • csrss.exe (PID: 5824)
      • brave.exe (PID: 7592)
      • services.exe (PID: 748)
      • csrss.exe (PID: 532)
      • elevation_service.exe (PID: 5008)
      • brave.exe (PID: 9084)
      • brave.exe (PID: 7516)
      • brave.exe (PID: 7288)
      • brave.exe (PID: 7524)
      • brave.exe (PID: 7220)
      • brave.exe (PID: 9056)
      • brave.exe (PID: 7980)
      • brave.exe (PID: 7360)
      • brave.exe (PID: 7336)
      • brave.exe (PID: 5988)
      • brave.exe (PID: 8512)
      • brave.exe (PID: 7352)
      • CompatTelRunner.exe (PID: 7616)
      • brave.exe (PID: 7368)
      • chrmstp.exe (PID: 7464)
      • chrmstp.exe (PID: 6192)
      • chrmstp.exe (PID: 2108)
      • chrmstp.exe (PID: 7912)
      • brave.exe (PID: 6576)
      • brave.exe (PID: 6392)
      • brave.exe (PID: 2040)
      • brave.exe (PID: 1628)
      • brave.exe (PID: 3240)
      • brave.exe (PID: 4920)
      • Brave.exe (PID: 2600)
      • Brave.exe (PID: 6892)
      • Brave.exe (PID: 8652)
      • Brave.exe (PID: 9044)
      • Brave.exe (PID: 4572)
      • Brave.exe (PID: 5588)
      • Brave.exe (PID: 7764)
      • brave.exe (PID: 6820)
      • brave.exe (PID: 9164)
      • Brave.exe (PID: 9012)
      • brave.exe (PID: 7376)
      • elevation_service.exe (PID: 1804)
      • brave.exe (PID: 7704)
      • brave.exe (PID: 1280)
      • brave.exe (PID: 7620)
      • brave.exe (PID: 8496)
      • brave.exe (PID: 8252)
      • brave.exe (PID: 3020)
      • brave.exe (PID: 2236)
      • brave.exe (PID: 1764)
      • brave.exe (PID: 7648)
      • brave.exe (PID: 7420)
      • brave.exe (PID: 3156)
      • brave.exe (PID: 864)
      • brave.exe (PID: 7928)
      • brave.exe (PID: 7176)
      • brave.exe (PID: 7592)
      • brave.exe (PID: 7432)
      • brave.exe (PID: 7612)
      • brave.exe (PID: 9112)
      • Brave.exe (PID: 4620)
      • Brave.exe (PID: 6252)
      • brave.exe (PID: 668)
      • Brave.exe (PID: 8912)
      • Brave.exe (PID: 8284)
      • Brave.exe (PID: 8676)
      • Brave.exe (PID: 5204)
      • Brave.exe (PID: 7808)
      • brave.exe (PID: 9128)
      • brave.exe (PID: 1676)
      • brave.exe (PID: 7932)
      • brave.exe (PID: 2408)
      • brave.exe (PID: 7468)
      • brave.exe (PID: 3900)
    • Steals credentials from Web Browsers

      • brave.exe (PID: 9056)
      • brave.exe (PID: 9164)
  • SUSPICIOUS

    • Creates file in the systems drive root

      • explorer.exe (PID: 5492)
    • Executable content was dropped or overwritten

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • setup.exe (PID: 8640)
      • brave_installer-x64.exe (PID: 8620)
      • BraveUpdate.exe (PID: 6852)
      • brave.exe (PID: 9164)
    • Creates/Modifies COM task schedule object

      • BraveUpdateComRegisterShell64.exe (PID: 2084)
      • BraveUpdateComRegisterShell64.exe (PID: 1748)
      • BraveUpdate.exe (PID: 5056)
      • BraveUpdateComRegisterShell64.exe (PID: 7396)
    • Disables SEHOP

      • BraveUpdate.exe (PID: 6852)
    • Starts itself from another location

      • BraveUpdate.exe (PID: 6852)
    • Reads security settings of Internet Explorer

      • BraveUpdate.exe (PID: 6852)
      • BraveUpdate.exe (PID: 4040)
      • chrmstp.exe (PID: 6192)
      • Brave.exe (PID: 2600)
      • Brave.exe (PID: 5588)
      • Brave.exe (PID: 6892)
      • Brave.exe (PID: 4572)
      • Brave.exe (PID: 7764)
      • Brave.exe (PID: 9012)
      • Brave.exe (PID: 9044)
      • Brave.exe (PID: 8568)
      • Brave.exe (PID: 6252)
      • Brave.exe (PID: 8284)
      • Brave.exe (PID: 8912)
      • Brave.exe (PID: 8676)
      • Brave.exe (PID: 5204)
      • brave.exe (PID: 2408)
    • Executes as Windows Service

      • BraveUpdate.exe (PID: 6744)
      • elevation_service.exe (PID: 5008)
      • elevation_service.exe (PID: 1804)
    • There is functionality for taking screenshot (YARA)

      • BraveUpdate.exe (PID: 4448)
      • BraveUpdate.exe (PID: 6852)
      • BraveUpdate.exe (PID: 6744)
      • BraveUpdate.exe (PID: 4040)
    • Application launched itself

      • setup.exe (PID: 8640)
      • BraveUpdate.exe (PID: 6744)
      • setup.exe (PID: 8848)
      • chrmstp.exe (PID: 7912)
      • chrmstp.exe (PID: 6192)
      • brave.exe (PID: 9056)
      • brave.exe (PID: 9164)
    • Searches for installed software

      • setup.exe (PID: 8848)
      • CompatTelRunner.exe (PID: 7616)
      • chrmstp.exe (PID: 7912)
      • chrmstp.exe (PID: 6192)
    • Reads Mozilla Firefox installation path

      • brave.exe (PID: 9056)
      • brave.exe (PID: 9164)
    • The process checks if it is being run in the virtual environment

      • brave.exe (PID: 9056)
      • brave.exe (PID: 9164)
    • Reads the date of Windows installation

      • chrmstp.exe (PID: 6192)
    • Reads Microsoft Outlook installation path

      • brave.exe (PID: 2408)
  • INFO

    • Checks supported languages

      • Brave.exe (PID: 6240)
      • Brave.exe (PID: 4488)
      • Brave.exe (PID: 6872)
      • Brave.exe (PID: 4172)
      • Brave.exe (PID: 4980)
      • Brave.exe (PID: 4736)
      • Brave.exe (PID: 2564)
      • Brave.exe (PID: 3156)
      • Brave.exe (PID: 5072)
      • Brave.exe (PID: 5384)
      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdate.exe (PID: 4448)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 5232)
      • BraveUpdate.exe (PID: 5056)
      • BraveUpdateComRegisterShell64.exe (PID: 1748)
      • BraveUpdateComRegisterShell64.exe (PID: 2084)
      • BraveUpdateComRegisterShell64.exe (PID: 7396)
      • BraveUpdate.exe (PID: 6852)
      • BraveUpdate.exe (PID: 2064)
      • BraveUpdate.exe (PID: 4040)
      • BraveUpdate.exe (PID: 6744)
      • brave_installer-x64.exe (PID: 8620)
      • setup.exe (PID: 8664)
      • setup.exe (PID: 8848)
      • setup.exe (PID: 8640)
      • BraveUpdateOnDemand.exe (PID: 8964)
      • BraveUpdate.exe (PID: 8984)
      • brave.exe (PID: 9056)
      • setup.exe (PID: 8868)
      • brave.exe (PID: 9084)
      • BraveUpdate.exe (PID: 8948)
      • brave.exe (PID: 7288)
      • brave.exe (PID: 7592)
      • brave.exe (PID: 7220)
      • elevation_service.exe (PID: 5008)
      • brave.exe (PID: 7516)
      • brave.exe (PID: 7524)
      • brave.exe (PID: 7980)
      • brave.exe (PID: 7336)
      • brave.exe (PID: 7352)
      • brave.exe (PID: 8512)
      • brave.exe (PID: 7368)
      • chrmstp.exe (PID: 7912)
      • chrmstp.exe (PID: 7464)
      • chrmstp.exe (PID: 6192)
      • brave.exe (PID: 6576)
      • brave.exe (PID: 6392)
      • brave.exe (PID: 2040)
      • brave.exe (PID: 4920)
      • Brave.exe (PID: 2600)
      • Brave.exe (PID: 4572)
      • Brave.exe (PID: 6892)
      • Brave.exe (PID: 8652)
      • Brave.exe (PID: 7764)
      • Brave.exe (PID: 9012)
      • brave.exe (PID: 7620)
      • elevation_service.exe (PID: 1804)
      • brave.exe (PID: 7376)
      • brave.exe (PID: 1280)
      • brave.exe (PID: 9164)
      • brave.exe (PID: 7704)
      • brave.exe (PID: 8496)
      • brave.exe (PID: 8252)
      • brave.exe (PID: 3020)
      • brave.exe (PID: 7420)
      • brave.exe (PID: 3156)
      • brave.exe (PID: 7648)
      • brave.exe (PID: 864)
      • brave.exe (PID: 7176)
      • brave.exe (PID: 2236)
      • brave.exe (PID: 7432)
      • brave.exe (PID: 7612)
      • brave.exe (PID: 9112)
      • Brave.exe (PID: 4620)
      • Brave.exe (PID: 8568)
      • Brave.exe (PID: 6252)
      • Brave.exe (PID: 5204)
      • brave.exe (PID: 668)
      • Brave.exe (PID: 8912)
      • Brave.exe (PID: 8284)
      • Brave.exe (PID: 8676)
      • brave.exe (PID: 9128)
      • brave.exe (PID: 1676)
    • Manual execution by a user

      • Brave.exe (PID: 6872)
      • Brave.exe (PID: 4488)
      • Brave.exe (PID: 4736)
      • Brave.exe (PID: 4172)
      • Brave.exe (PID: 4980)
      • Brave.exe (PID: 2564)
      • Brave.exe (PID: 5072)
      • Brave.exe (PID: 5384)
      • firefox.exe (PID: 5416)
      • Brave.exe (PID: 3156)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 5492)
    • Application launched itself

      • firefox.exe (PID: 5436)
      • firefox.exe (PID: 5416)
    • The sample compiled with english language support

      • firefox.exe (PID: 5436)
      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
      • setup.exe (PID: 8640)
      • brave_installer-x64.exe (PID: 8620)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 5436)
    • Autorun file from Downloads

      • firefox.exe (PID: 5436)
    • Creates files or folders in the user directory

      • explorer.exe (PID: 5492)
      • BraveUpdate.exe (PID: 4040)
      • setup.exe (PID: 8848)
      • setup.exe (PID: 8640)
      • brave.exe (PID: 9084)
      • brave.exe (PID: 9056)
      • brave.exe (PID: 7288)
      • chrmstp.exe (PID: 6192)
      • brave.exe (PID: 9164)
      • brave.exe (PID: 7620)
      • brave.exe (PID: 9128)
    • Checks proxy server information

      • explorer.exe (PID: 5492)
      • BraveUpdate.exe (PID: 2064)
      • BraveUpdate.exe (PID: 4040)
      • brave.exe (PID: 9056)
      • slui.exe (PID: 8568)
      • Brave.exe (PID: 2600)
      • Brave.exe (PID: 5588)
      • Brave.exe (PID: 4572)
      • Brave.exe (PID: 6892)
      • Brave.exe (PID: 7764)
      • Brave.exe (PID: 9012)
      • Brave.exe (PID: 9044)
      • brave.exe (PID: 9164)
      • Brave.exe (PID: 8568)
      • Brave.exe (PID: 6252)
      • Brave.exe (PID: 7808)
      • Brave.exe (PID: 8912)
      • Brave.exe (PID: 8284)
      • Brave.exe (PID: 8676)
      • Brave.exe (PID: 5204)
    • Reads the software policy settings

      • explorer.exe (PID: 5492)
      • BraveUpdate.exe (PID: 6744)
      • BraveUpdate.exe (PID: 4040)
      • slui.exe (PID: 5156)
      • BraveUpdate.exe (PID: 8948)
      • CompatTelRunner.exe (PID: 7616)
    • Create files in a temporary directory

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • brave.exe (PID: 9056)
      • brave.exe (PID: 9164)
    • The sample compiled with bulgarian language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with german language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with arabic language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with portuguese language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • Reads Microsoft Office registry keys

      • explorer.exe (PID: 5492)
    • The sample compiled with czech language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with french language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with Indonesian language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with Italian language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with japanese language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with russian language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with korean language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with polish language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with slovak language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with swedish language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with turkish language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • The sample compiled with chinese language support

      • BraveBrowserSetup-BRV010.exe (PID: 7228)
      • BraveUpdateSetup.exe (PID: 7932)
      • BraveUpdate.exe (PID: 6852)
    • Reads the computer name

      • BraveUpdate.exe (PID: 4448)
      • BraveUpdate.exe (PID: 6852)
      • BraveUpdate.exe (PID: 5232)
      • BraveUpdate.exe (PID: 5056)
      • BraveUpdateComRegisterShell64.exe (PID: 1748)
      • BraveUpdateComRegisterShell64.exe (PID: 2084)
      • BraveUpdate.exe (PID: 4040)
      • BraveUpdate.exe (PID: 6744)
      • BraveUpdateComRegisterShell64.exe (PID: 7396)
      • BraveUpdate.exe (PID: 2064)
      • setup.exe (PID: 8848)
      • brave_installer-x64.exe (PID: 8620)
      • BraveUpdate.exe (PID: 8948)
      • BraveUpdate.exe (PID: 8984)
      • brave.exe (PID: 9056)
      • brave.exe (PID: 7220)
      • brave.exe (PID: 7288)
      • elevation_service.exe (PID: 5008)
      • chrmstp.exe (PID: 7912)
      • Brave.exe (PID: 2600)
      • Brave.exe (PID: 6892)
      • Brave.exe (PID: 8652)
      • Brave.exe (PID: 4572)
      • Brave.exe (PID: 7764)
      • Brave.exe (PID: 9012)
      • brave.exe (PID: 9164)
      • elevation_service.exe (PID: 1804)
      • brave.exe (PID: 7376)
      • brave.exe (PID: 7620)
      • Brave.exe (PID: 4620)
      • Brave.exe (PID: 8568)
      • Brave.exe (PID: 6252)
      • Brave.exe (PID: 5204)
      • Brave.exe (PID: 7808)
      • Brave.exe (PID: 8912)
      • Brave.exe (PID: 8676)
      • brave.exe (PID: 9128)
      • brave.exe (PID: 2408)
    • Brave updater related mutex has been found

      • BraveUpdate.exe (PID: 4448)
      • BraveUpdate.exe (PID: 6852)
      • BraveUpdate.exe (PID: 5232)
      • BraveUpdate.exe (PID: 5056)
      • BraveUpdate.exe (PID: 2064)
      • BraveUpdate.exe (PID: 4040)
      • BraveUpdate.exe (PID: 6744)
      • BraveUpdate.exe (PID: 8948)
      • BraveUpdate.exe (PID: 8984)
    • Process checks computer location settings

      • BraveUpdate.exe (PID: 4448)
      • BraveUpdate.exe (PID: 6852)
      • brave.exe (PID: 9056)
      • brave.exe (PID: 7516)
      • brave.exe (PID: 7524)
      • brave.exe (PID: 9164)
      • brave.exe (PID: 8496)
      • brave.exe (PID: 1280)
      • brave.exe (PID: 7432)
      • brave.exe (PID: 2236)
    • Creates files in the program directory

      • BraveUpdate.exe (PID: 6852)
      • brave_installer-x64.exe (PID: 8620)
      • BraveUpdate.exe (PID: 6744)
      • setup.exe (PID: 8640)
      • setup.exe (PID: 8848)
    • Reads the machine GUID from the registry

      • BraveUpdate.exe (PID: 4040)
      • brave.exe (PID: 9056)
      • brave.exe (PID: 9128)
    • Disables trace logs

      • brave.exe (PID: 9056)
    • Reads CPU info

      • brave.exe (PID: 9056)
      • brave.exe (PID: 9164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (57.6)
.exe | Win64 Executable (generic) (36.9)
.exe | Generic Win/DOS Executable (2.6)
.exe | DOS Executable Generic (2.6)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:01:03 02:09:49+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.41
CodeSize: 1560064
InitializedDataSize: 1151488
UninitializedDataSize: 543232
EntryPoint: 0x615d0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Brave
FileDescription: Brave
FileVersion: 1.0.0.0
InternalName: Brave.dll
LegalCopyright:
OriginalFileName: Brave.dll
ProductName: Brave
ProductVersion: 1.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
287
Monitored processes
148
Malicious processes
84
Suspicious processes
13

Behavior graph

Click at the process to see the details
start brave.exe conhost.exe no specs sppextcomobj.exe no specs slui.exe brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs rundll32.exe no specs explorer.exe bravebrowsersetup-brv010.exe mspaint.exe no specs braveupdate.exe no specs braveupdatesetup.exe braveupdate.exe braveupdate.exe no specs braveupdate.exe no specs braveupdatecomregistershell64.exe no specs braveupdatecomregistershell64.exe no specs braveupdatecomregistershell64.exe no specs braveupdate.exe braveupdate.exe braveupdate.exe slui.exe brave_installer-x64.exe setup.exe setup.exe no specs setup.exe setup.exe no specs braveupdate.exe braveupdateondemand.exe no specs braveupdate.exe brave.exe brave.exe brave.exe brave.exe elevation_service.exe brave.exe compattelrunner.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe chrmstp.exe chrmstp.exe chrmstp.exe chrmstp.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe brave.exe brave.exe brave.exe elevation_service.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe conhost.exe no specs brave.exe no specs conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe csrss.exe services.exe csrss.exe

Process information

PID
CMD
Path
Indicators
Parent process
532%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16C:\Windows\System32\csrss.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Client Server Runtime Process
Version:
10.0.19041.1 (WinBuild.160101.0800)
632\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeBrave.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
668"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=2000,i,10047240377421711770,2379675323616251786,262144 --variations-seed-version=main@533f1f2dd75e8be37bc43f03ace8b2228d90641e --mojo-platform-channel-handle=5320 /prefetch:8C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
brave.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
LOW
Description:
Brave Browser
Exit code:
0
Version:
134.1.76.81
Modules
Images
c:\program files\bravesoftware\brave-browser\application\brave.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\bravesoftware\brave-browser\application\134.1.76.81\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
748C:\WINDOWS\system32\services.exeC:\Windows\System32\services.exe
wininit.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Services and Controller app
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\apphelp.dll
812\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeBrave.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
864"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=2000,i,10047240377421711770,2379675323616251786,262144 --variations-seed-version=main@533f1f2dd75e8be37bc43f03ace8b2228d90641e --mojo-platform-channel-handle=5612 /prefetch:8C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
brave.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
LOW
Description:
Brave Browser
Exit code:
0
Version:
134.1.76.81
Modules
Images
c:\program files\bravesoftware\brave-browser\application\brave.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\bravesoftware\brave-browser\application\134.1.76.81\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
976\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeBrave.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1280"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --enable-distillability-service --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=2000,i,10047240377421711770,2379675323616251786,262144 --variations-seed-version=main@533f1f2dd75e8be37bc43f03ace8b2228d90641e --mojo-platform-channel-handle=3864 /prefetch:1C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
brave.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
LOW
Description:
Brave Browser
Exit code:
0
Version:
134.1.76.81
Modules
Images
c:\program files\bravesoftware\brave-browser\application\brave.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\bravesoftware\brave-browser\application\134.1.76.81\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1628"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=2052,i,7505033154410202411,6483294057552096932,262144 --variations-seed-version=main@533f1f2dd75e8be37bc43f03ace8b2228d90641e --mojo-platform-channel-handle=5808 /prefetch:8C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
brave.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
LOW
Description:
Brave Browser
Exit code:
0
Version:
134.1.76.81
Modules
Images
c:\program files\bravesoftware\brave-browser\application\brave.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\bravesoftware\brave-browser\application\134.1.76.81\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1676"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=renderer --enable-distillability-service --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --start-stack-profiler --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=23 --field-trial-handle=2000,i,10047240377421711770,2379675323616251786,262144 --variations-seed-version=main@533f1f2dd75e8be37bc43f03ace8b2228d90641e --mojo-platform-channel-handle=4072 /prefetch:1C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
brave.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
LOW
Description:
Brave Browser
Version:
134.1.76.81
Modules
Images
c:\program files\bravesoftware\brave-browser\application\brave.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\bravesoftware\brave-browser\application\134.1.76.81\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
118 053
Read events
115 694
Write events
2 179
Delete events
180

Modification events

(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:0000000000040346
Operation:writeName:VirtualDesktop
Value:
1000000030304456BFA0DB55E4278845B426357D5B5F97B3
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:0000000000040346
Operation:delete keyName:(default)
Value:
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconLayouts
Value:
00000000000000000000000000000000030001000100010012000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C0000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C0000000D0000000000000053006B007900700065002E006C006E006B003E0020007C0000000D0000000000000061006E006200610079002E0070006E0067003E00200020000000120000000000000063006F006E00740072006F006C007900650073002E007200740066003E00200020000000160000000000000063006F0075006E0074007200690065007300620065006100630068002E006A00700067003E0020002000000011000000000000006500760065007200790066006100630065002E0070006E0067003E0020002000000012000000000000006600720065006E006300680077006500730074002E0070006E0067003E0020002000000010000000000000006C00650066007400730065006E0064002E007200740066003E00200020000000100000000000000070006C0061006E00770065006E0074002E007200740066003E00200020000000170000000000000073006F00750074006800650072006E006300680061006E006E0065006C002E006A00700067003E002000200000001300000000000000760069006500770073006E006F0072006D0061006C002E0070006E0067003E002000200000000D00000000000000420072006100760065002E006500780065003E00200020000000010000000000000002000100000000000000000001000000000000000200010000000000000000001100000006000000010000001200000000000000000000000000000000000000803F0000004008000000803F0000404009000000803F000080400A000000803F0000A0400B0000000040000000000C00000000400000803F0D0000000040000000400E0000000040000040400F0000000040000080401000000000000000803F0100000000000000004002000000000000004040030000000000000080400400000000000000A04005000000803F0000000006000000803F0000803F0700000000400000A0401100
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconNameVersion
Value:
1
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts
Operation:writeName:LastUpdate
Value:
C8B6E16700000000
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:000000000008028A
Operation:writeName:VirtualDesktop
Value:
1000000030304456BFA0DB55E4278845B426357D5B5F97B3
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:000000000008028A
Operation:delete keyName:(default)
Value:
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:00000000000A028A
Operation:delete keyName:(default)
Value:
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:00000000000E02D4
Operation:writeName:VirtualDesktop
Value:
1000000030304456BFA0DB55E4278845B426357D5B5F97B3
(PID) Process:(5492) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\5\ApplicationViewManagement\W32:00000000000A028A
Operation:writeName:VirtualDesktop
Value:
1000000030304456BFA0DB55E4278845B426357D5B5F97B3
Executable files
258
Suspicious files
532
Text files
143
Unknown types
7

Dropped files

PID
Process
Filename
Type
5436firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
5436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
5436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
5436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
5436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
5492explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.datbinary
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
5436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.jstext
MD5:BDDB43822B43392D4C9D823BC34418E9
SHA256:585029B3FBE89E1CFB759A1DE597950BE7F8202305F07A32449083F1BCF6ED06
5436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.tmpbinary
MD5:3B156E12141F8CBCE9D60CDCE2077617
SHA256:E6287E44B44ABEA20E1B2E3F415D22B9E5E5FBBC155AD9DADBABA63951B2AF6F
5436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.dbbinary
MD5:3FD91FC28DD6ED847064A23DE10E6489
SHA256:1F84F969799C37CB029E921D513CE0BC91345C4D1D6B27B83EB5372234A74B1D
5436firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\datareporting\glean\db\data.safe.binbinary
MD5:3B156E12141F8CBCE9D60CDCE2077617
SHA256:E6287E44B44ABEA20E1B2E3F415D22B9E5E5FBBC155AD9DADBABA63951B2AF6F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
50
TCP/UDP connections
190
DNS requests
192
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.24.77.37:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1184
backgroundTaskHost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5436
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
5436
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
5436
firefox.exe
POST
200
172.217.16.195:80
http://o.pki.goog/s/wr3/cgo
unknown
whitelisted
5436
firefox.exe
POST
200
184.24.77.46:80
http://r10.o.lencr.org/
unknown
whitelisted
5436
firefox.exe
POST
172.217.16.195:80
http://o.pki.goog/s/wr3/UTA
unknown
whitelisted
5436
firefox.exe
POST
200
172.217.16.195:80
http://o.pki.goog/we2
unknown
whitelisted
5436
firefox.exe
POST
200
172.217.16.195:80
http://o.pki.goog/we2
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
184.24.77.37:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
23.54.109.203:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
20.198.162.78:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1184
backgroundTaskHost.exe
20.199.58.43:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
1184
backgroundTaskHost.exe
23.54.109.203:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 184.24.77.37
  • 184.24.77.35
  • 184.24.77.12
whitelisted
google.com
  • 142.250.184.238
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.5
  • 20.190.160.132
  • 20.190.160.3
  • 40.126.32.133
  • 40.126.32.134
  • 20.190.160.65
  • 40.126.32.72
whitelisted
ocsp.digicert.com
  • 23.54.109.203
whitelisted
client.wns.windows.com
  • 20.198.162.78
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted

Threats

PID
Process
Class
Message
7288
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
7288
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
7288
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
7288
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
7288
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
7288
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
7288
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
7620
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
7620
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
7620
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info