File name:

Brave.exe

Full analysis: https://app.any.run/tasks/ecf26ca7-776a-4b58-b6b0-1f37078aac15
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 22, 2025, 15:51:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 8 sections
MD5:

4E4C82586D5463D298CF16CDA5978BBE

SHA1:

4E42352AC32834B53346B47F7206C7B52CBD2E34

SHA256:

0ED2B6C373446E31C3AB8E424BE0783B7DC397B67DB6DBE29173271321C3F426

SSDEEP:

98304:Q5SWISjW2svVyxboNUeCv8j7F6ptO+p2fyke/N5:a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • Brave.exe (PID: 7400)
      • setup.exe (PID: 1244)
      • setup.exe (PID: 2340)
      • csrss.exe (PID: 5824)
      • BraveUpdate.exe (PID: 4608)
      • brave.exe (PID: 6972)
      • brave.exe (PID: 7184)
      • services.exe (PID: 748)
      • brave.exe (PID: 3900)
      • brave.exe (PID: 2416)
      • elevation_service.exe (PID: 5112)
      • brave.exe (PID: 6572)
      • csrss.exe (PID: 532)
      • brave.exe (PID: 8048)
      • CompatTelRunner.exe (PID: 3176)
      • brave.exe (PID: 4628)
      • brave.exe (PID: 8104)
      • brave.exe (PID: 7472)
      • brave.exe (PID: 7504)
      • brave.exe (PID: 6700)
      • brave.exe (PID: 4996)
      • brave.exe (PID: 7356)
      • brave.exe (PID: 4980)
      • brave.exe (PID: 2552)
      • chrmstp.exe (PID: 3768)
      • brave.exe (PID: 7840)
      • chrmstp.exe (PID: 7292)
      • chrmstp.exe (PID: 5260)
      • chrmstp.exe (PID: 7784)
      • brave.exe (PID: 8072)
      • brave.exe (PID: 904)
      • brave.exe (PID: 8176)
      • brave.exe (PID: 7472)
      • brave.exe (PID: 2780)
      • brave.exe (PID: 7268)
      • brave.exe (PID: 7012)
      • Brave.exe (PID: 7412)
      • Brave.exe (PID: 6416)
      • brave.exe (PID: 904)
      • brave.exe (PID: 4300)
      • brave.exe (PID: 1348)
      • brave.exe (PID: 2980)
      • brave.exe (PID: 2896)
      • brave.exe (PID: 7704)
      • brave.exe (PID: 7144)
      • brave.exe (PID: 5172)
      • brave.exe (PID: 8104)
      • Brave.exe (PID: 7172)
      • brave.exe (PID: 7332)
      • Brave.exe (PID: 1004)
      • Brave.exe (PID: 7292)
      • Brave.exe (PID: 8004)
      • Brave.exe (PID: 7880)
    • Changes the autorun value in the registry

      • setup.exe (PID: 1244)
    • Steals credentials from Web Browsers

      • brave.exe (PID: 6972)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
      • brave_installer-x64.exe (PID: 2284)
      • setup.exe (PID: 1244)
    • Reads security settings of Internet Explorer

      • BraveUpdate.exe (PID: 5360)
      • BraveUpdate.exe (PID: 6032)
      • BraveUpdate.exe (PID: 5228)
      • ShellExperienceHost.exe (PID: 7728)
      • chrmstp.exe (PID: 7292)
      • Brave.exe (PID: 7412)
      • Brave.exe (PID: 6416)
      • Brave.exe (PID: 7172)
      • Brave.exe (PID: 1004)
      • Brave.exe (PID: 7292)
      • Brave.exe (PID: 7880)
      • Brave.exe (PID: 8004)
    • Starts itself from another location

      • BraveUpdate.exe (PID: 6032)
    • Creates/Modifies COM task schedule object

      • BraveUpdateComRegisterShell64.exe (PID: 2092)
      • BraveUpdateComRegisterShell64.exe (PID: 7704)
      • BraveUpdateComRegisterShell64.exe (PID: 968)
      • BraveUpdate.exe (PID: 7796)
    • Disables SEHOP

      • BraveUpdate.exe (PID: 6032)
    • Executes as Windows Service

      • BraveUpdate.exe (PID: 1168)
      • elevation_service.exe (PID: 5112)
    • There is functionality for taking screenshot (YARA)

      • BraveUpdate.exe (PID: 5360)
      • BraveUpdate.exe (PID: 6032)
      • BraveUpdate.exe (PID: 5228)
      • BraveUpdate.exe (PID: 1168)
    • Application launched itself

      • setup.exe (PID: 1244)
      • setup.exe (PID: 2340)
      • BraveUpdate.exe (PID: 1168)
      • brave.exe (PID: 6972)
      • chrmstp.exe (PID: 7784)
      • chrmstp.exe (PID: 7292)
    • Searches for installed software

      • setup.exe (PID: 1244)
      • setup.exe (PID: 2340)
      • CompatTelRunner.exe (PID: 3176)
      • chrmstp.exe (PID: 7784)
      • chrmstp.exe (PID: 7292)
    • Creates a software uninstall entry

      • setup.exe (PID: 1244)
    • Reads Mozilla Firefox installation path

      • brave.exe (PID: 6972)
    • The process checks if it is being run in the virtual environment

      • brave.exe (PID: 6972)
    • Reads the date of Windows installation

      • chrmstp.exe (PID: 7292)
  • INFO

    • Checks supported languages

      • Brave.exe (PID: 7400)
      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdate.exe (PID: 5360)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
      • BraveUpdate.exe (PID: 4724)
      • BraveUpdate.exe (PID: 7796)
      • BraveUpdateComRegisterShell64.exe (PID: 2092)
      • BraveUpdateComRegisterShell64.exe (PID: 7704)
      • BraveUpdateComRegisterShell64.exe (PID: 968)
      • BraveUpdate.exe (PID: 7788)
      • BraveUpdate.exe (PID: 5228)
      • BraveUpdate.exe (PID: 1168)
      • setup.exe (PID: 7884)
      • brave_installer-x64.exe (PID: 2284)
      • setup.exe (PID: 1244)
      • setup.exe (PID: 2340)
      • setup.exe (PID: 5408)
      • ShellExperienceHost.exe (PID: 7728)
      • BraveUpdateOnDemand.exe (PID: 7792)
      • brave.exe (PID: 7184)
      • BraveUpdate.exe (PID: 4608)
      • brave.exe (PID: 6972)
      • BraveUpdate.exe (PID: 7544)
      • brave.exe (PID: 2416)
      • brave.exe (PID: 3900)
      • elevation_service.exe (PID: 5112)
      • brave.exe (PID: 6572)
      • brave.exe (PID: 8104)
      • brave.exe (PID: 4628)
      • brave.exe (PID: 8048)
      • brave.exe (PID: 7504)
      • brave.exe (PID: 7356)
      • brave.exe (PID: 4996)
      • brave.exe (PID: 6700)
      • brave.exe (PID: 2552)
      • brave.exe (PID: 4980)
      • brave.exe (PID: 7472)
      • chrmstp.exe (PID: 3768)
      • chrmstp.exe (PID: 7292)
      • chrmstp.exe (PID: 5260)
      • chrmstp.exe (PID: 7784)
      • brave.exe (PID: 7840)
      • brave.exe (PID: 904)
      • brave.exe (PID: 7268)
      • brave.exe (PID: 7012)
      • brave.exe (PID: 8072)
      • brave.exe (PID: 8176)
      • brave.exe (PID: 2780)
      • brave.exe (PID: 7472)
      • Brave.exe (PID: 7412)
      • brave.exe (PID: 904)
      • brave.exe (PID: 4300)
      • Brave.exe (PID: 6416)
      • brave.exe (PID: 7144)
      • brave.exe (PID: 1348)
      • brave.exe (PID: 2896)
      • brave.exe (PID: 7704)
      • brave.exe (PID: 5172)
      • brave.exe (PID: 8104)
      • Brave.exe (PID: 7172)
      • brave.exe (PID: 7332)
      • brave.exe (PID: 2980)
      • Brave.exe (PID: 1004)
      • Brave.exe (PID: 7292)
      • Brave.exe (PID: 8004)
      • Brave.exe (PID: 7880)
    • Manual execution by a user

      • chrome.exe (PID: 7716)
      • Brave.exe (PID: 7412)
      • Brave.exe (PID: 6416)
      • Brave.exe (PID: 7172)
      • Brave.exe (PID: 1004)
      • Brave.exe (PID: 7292)
      • Brave.exe (PID: 8004)
      • Brave.exe (PID: 7880)
    • Executable content was dropped or overwritten

      • chrome.exe (PID: 7716)
      • chrome.exe (PID: 7952)
    • Application launched itself

      • chrome.exe (PID: 7716)
    • The sample compiled with english language support

      • chrome.exe (PID: 7952)
      • chrome.exe (PID: 7716)
      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
      • brave_installer-x64.exe (PID: 2284)
      • setup.exe (PID: 1244)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 5360)
      • BraveUpdate.exe (PID: 7788)
      • BraveUpdate.exe (PID: 5228)
      • brave.exe (PID: 6972)
      • Brave.exe (PID: 7412)
      • slui.exe (PID: 7984)
      • Brave.exe (PID: 6416)
      • Brave.exe (PID: 7172)
      • Brave.exe (PID: 7292)
      • Brave.exe (PID: 1004)
      • Brave.exe (PID: 8004)
      • Brave.exe (PID: 7880)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7236)
      • BackgroundTransferHost.exe (PID: 5360)
      • BackgroundTransferHost.exe (PID: 7516)
      • BackgroundTransferHost.exe (PID: 1512)
      • BackgroundTransferHost.exe (PID: 5064)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 5360)
      • BraveUpdate.exe (PID: 5228)
      • setup.exe (PID: 2340)
      • setup.exe (PID: 1244)
      • brave.exe (PID: 7184)
      • brave.exe (PID: 6972)
      • brave.exe (PID: 3900)
      • chrmstp.exe (PID: 7292)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 5360)
      • BraveUpdate.exe (PID: 7788)
      • BraveUpdate.exe (PID: 1168)
      • BraveUpdate.exe (PID: 5228)
      • slui.exe (PID: 7600)
      • BraveUpdate.exe (PID: 7544)
      • CompatTelRunner.exe (PID: 3176)
      • slui.exe (PID: 7984)
    • Create files in a temporary directory

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • brave.exe (PID: 6972)
    • The sample compiled with arabic language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • Reads the computer name

      • BraveUpdate.exe (PID: 5360)
      • BraveUpdate.exe (PID: 6032)
      • BraveUpdate.exe (PID: 7796)
      • BraveUpdateComRegisterShell64.exe (PID: 2092)
      • BraveUpdateComRegisterShell64.exe (PID: 7704)
      • BraveUpdateComRegisterShell64.exe (PID: 968)
      • BraveUpdate.exe (PID: 4724)
      • BraveUpdate.exe (PID: 7788)
      • BraveUpdate.exe (PID: 5228)
      • BraveUpdate.exe (PID: 1168)
      • brave_installer-x64.exe (PID: 2284)
      • setup.exe (PID: 1244)
      • setup.exe (PID: 2340)
      • ShellExperienceHost.exe (PID: 7728)
      • BraveUpdate.exe (PID: 4608)
      • brave.exe (PID: 6972)
      • BraveUpdate.exe (PID: 7544)
      • brave.exe (PID: 2416)
      • brave.exe (PID: 3900)
      • elevation_service.exe (PID: 5112)
      • brave.exe (PID: 4628)
      • chrmstp.exe (PID: 7784)
      • chrmstp.exe (PID: 7292)
      • Brave.exe (PID: 7412)
      • Brave.exe (PID: 6416)
      • Brave.exe (PID: 1004)
      • Brave.exe (PID: 7292)
      • Brave.exe (PID: 7172)
      • Brave.exe (PID: 7880)
      • Brave.exe (PID: 8004)
    • The sample compiled with bulgarian language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with czech language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with Indonesian language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with german language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with french language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with Italian language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with japanese language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with korean language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with polish language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with russian language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with portuguese language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with swedish language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with slovak language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with turkish language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • The sample compiled with chinese language support

      • BraveBrowserSetup-BRV010.exe (PID: 1324)
      • BraveUpdateSetup.exe (PID: 8120)
      • BraveUpdate.exe (PID: 6032)
    • Brave updater related mutex has been found

      • BraveUpdate.exe (PID: 5360)
      • BraveUpdate.exe (PID: 6032)
      • BraveUpdate.exe (PID: 4724)
      • BraveUpdate.exe (PID: 7796)
      • BraveUpdate.exe (PID: 7788)
      • BraveUpdate.exe (PID: 5228)
      • BraveUpdate.exe (PID: 1168)
      • BraveUpdate.exe (PID: 7544)
      • BraveUpdate.exe (PID: 4608)
    • Process checks computer location settings

      • BraveUpdate.exe (PID: 5360)
      • BraveUpdate.exe (PID: 6032)
      • brave.exe (PID: 6972)
      • brave.exe (PID: 8048)
      • brave.exe (PID: 8104)
      • brave.exe (PID: 7472)
      • brave.exe (PID: 2780)
      • brave.exe (PID: 4300)
    • Creates files in the program directory

      • BraveUpdate.exe (PID: 6032)
      • BraveUpdate.exe (PID: 1168)
      • setup.exe (PID: 1244)
      • brave_installer-x64.exe (PID: 2284)
      • setup.exe (PID: 2340)
    • Reads the machine GUID from the registry

      • BraveUpdate.exe (PID: 5228)
      • brave.exe (PID: 6972)
    • Disables trace logs

      • brave.exe (PID: 6972)
    • Reads CPU info

      • brave.exe (PID: 6972)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (57.6)
.exe | Win64 Executable (generic) (36.9)
.exe | Generic Win/DOS Executable (2.6)
.exe | DOS Executable Generic (2.6)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:01:03 02:09:49+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.41
CodeSize: 1560064
InitializedDataSize: 1151488
UninitializedDataSize: 543232
EntryPoint: 0x615d0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Brave
FileDescription: Brave
FileVersion: 1.0.0.0
InternalName: Brave.dll
LegalCopyright:
OriginalFileName: Brave.dll
ProductName: Brave
ProductVersion: 1.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
247
Monitored processes
104
Malicious processes
57
Suspicious processes
2

Behavior graph

Click at the process to see the details
start brave.exe conhost.exe no specs sppextcomobj.exe no specs slui.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs bravebrowsersetup-brv010.exe braveupdate.exe no specs braveupdatesetup.exe braveupdate.exe braveupdate.exe no specs braveupdate.exe no specs braveupdatecomregistershell64.exe no specs braveupdatecomregistershell64.exe no specs braveupdatecomregistershell64.exe no specs braveupdate.exe braveupdate.exe braveupdate.exe brave_installer-x64.exe setup.exe setup.exe no specs slui.exe shellexperiencehost.exe no specs setup.exe setup.exe no specs braveupdate.exe braveupdateondemand.exe no specs braveupdate.exe brave.exe brave.exe brave.exe brave.exe elevation_service.exe compattelrunner.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe chrmstp.exe chrmstp.exe brave.exe chrmstp.exe chrmstp.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe rundll32.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs brave.exe conhost.exe no specs csrss.exe services.exe csrss.exe

Process information

PID
CMD
Path
Indicators
Parent process
300C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
532%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16C:\Windows\System32\csrss.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Client Server Runtime Process
Version:
10.0.19041.1 (WinBuild.160101.0800)
672\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeBrave.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
748C:\WINDOWS\system32\services.exeC:\Windows\System32\services.exe
wininit.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Services and Controller app
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\apphelp.dll
904"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=2088,i,16410355635624569303,9999578894497312549,262144 --variations-seed-version=main@533f1f2dd75e8be37bc43f03ace8b2228d90641e --mojo-platform-channel-handle=5616 /prefetch:8C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
brave.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
LOW
Description:
Brave Browser
Exit code:
0
Version:
134.1.76.80
Modules
Images
c:\program files\bravesoftware\brave-browser\application\brave.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\bravesoftware\brave-browser\application\134.1.76.80\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
904"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --field-trial-handle=2088,i,16410355635624569303,9999578894497312549,262144 --variations-seed-version=main@533f1f2dd75e8be37bc43f03ace8b2228d90641e --mojo-platform-channel-handle=3564 /prefetch:8C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
brave.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
LOW
Description:
Brave Browser
Exit code:
0
Version:
134.1.76.80
Modules
Images
c:\program files\bravesoftware\brave-browser\application\brave.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\bravesoftware\brave-browser\application\134.1.76.80\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
968"C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveUpdateComRegisterShell64.exe" C:\Program Files (x86)\BraveSoftware\Update\1.3.361.151\BraveUpdateComRegisterShell64.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.151
Modules
Images
c:\program files (x86)\bravesoftware\update\1.3.361.151\braveupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1004"C:\Users\admin\AppData\Local\Temp\Brave.exe" C:\Users\admin\AppData\Local\Temp\Brave.exe
explorer.exe
User:
admin
Company:
Brave
Integrity Level:
MEDIUM
Description:
Brave
Exit code:
4294967295
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\brave.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ole32.dll
1168"C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /svcC:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe
services.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.151
Modules
Images
c:\program files (x86)\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1244"C:\Program Files (x86)\BraveSoftware\Update\Install\{A5DC400B-AC54-43F4-BD7E-1AED8A84EBF8}\CR_D1204.tmp\setup.exe" --install-archive="C:\Program Files (x86)\BraveSoftware\Update\Install\{A5DC400B-AC54-43F4-BD7E-1AED8A84EBF8}\CR_D1204.tmp\CHROME.PACKED.7Z" --do-not-launch-chrome /installerdata="C:\Program Files (x86)\BraveSoftware\Update\Install\{A5DC400B-AC54-43F4-BD7E-1AED8A84EBF8}\guiA065.tmp" --brave-referral-code="BRV010"C:\Program Files (x86)\BraveSoftware\Update\Install\{A5DC400B-AC54-43F4-BD7E-1AED8A84EBF8}\CR_D1204.tmp\setup.exe
brave_installer-x64.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
HIGH
Description:
Brave Installer
Exit code:
0
Version:
134.1.76.80
Modules
Images
c:\program files (x86)\bravesoftware\update\install\{a5dc400b-ac54-43f4-bd7e-1aed8a84ebf8}\cr_d1204.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
80 986
Read events
78 873
Write events
1 986
Delete events
127

Modification events

(PID) Process:(7716) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(7716) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(7716) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(7716) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(7716) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(7716) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Common\Rlz\Events\C
Operation:writeName:C1F
Value:
1
(PID) Process:(4724) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
0100000000000000D77E4654429BDB01
(PID) Process:(7236) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7236) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7236) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
255
Suspicious files
549
Text files
148
Unknown types
0

Dropped files

PID
Process
Filename
Type
7716chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF10cd35.TMP
MD5:
SHA256:
7716chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF10cd35.TMP
MD5:
SHA256:
7716chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
7716chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7716chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF10cd45.TMP
MD5:
SHA256:
7716chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF10cd45.TMP
MD5:
SHA256:
7716chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
7716chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7716chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF10cd45.TMP
MD5:
SHA256:
7716chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF10cd45.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
130
DNS requests
106
Threats
20

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.19.117.22:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
GB
binary
825 b
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
7792
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
DE
binary
471 b
whitelisted
7716
chrome.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
DE
binary
727 b
whitelisted
7716
chrome.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
DE
binary
471 b
whitelisted
5360
BackgroundTransferHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
312 b
whitelisted
7716
chrome.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA6YL93wbpPpEQZdA31N1II%3D
DE
binary
727 b
whitelisted
2420
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
CL
binary
419 b
whitelisted
2420
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
CL
binary
407 b
whitelisted
5228
BraveUpdate.exe
GET
200
18.66.145.213:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
US
binary
1.40 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.19.117.22:80
crl.microsoft.com
Akamai International B.V.
GB
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7716
chrome.exe
239.255.255.250:1900
whitelisted
7952
chrome.exe
142.250.185.195:443
clientservices.googleapis.com
GOOGLE
US
whitelisted
7952
chrome.exe
142.251.5.84:443
accounts.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.206
whitelisted
crl.microsoft.com
  • 2.19.117.22
  • 2.19.117.18
whitelisted
client.wns.windows.com
  • 40.113.110.67
  • 40.115.3.253
whitelisted
clientservices.googleapis.com
  • 142.250.185.195
whitelisted
accounts.google.com
  • 142.251.5.84
whitelisted
login.live.com
  • 40.126.31.129
  • 40.126.31.67
  • 20.190.159.23
  • 20.190.159.68
  • 20.190.159.129
  • 40.126.31.69
  • 20.190.159.71
  • 20.190.159.75
whitelisted
www.google.com
  • 216.58.206.68
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
www.gstatic.com
  • 142.250.185.163
whitelisted

Threats

PID
Process
Class
Message
3900
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3900
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3900
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3900
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3900
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3900
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3900
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3900
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3900
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
3900
brave.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info