File name:

BraveBrowserSetup-BRV002.exe

Full analysis: https://app.any.run/tasks/e4c08fd0-bfad-4ff5-853a-a477552e1e54
Verdict: Malicious activity
Analysis date: April 17, 2024, 10:57:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3DB83CBEDBC8F154D7DB3F275D0E57E2

SHA1:

CE309D3BF5DF4447684D13656625490A0DDA05F8

SHA256:

31E9539C07C2CDD18CF9AC5BEB00B73135847E7B648701D58BD8817EC80DAD59

SSDEEP:

49152:0WhcURqfoSGD9eK0pIS7v+syHfQ5aZL3X16exkrLcjlqmoOjb0dZ9hYis1h9BPLy:0pURqwt9eK2LWH45qnAexkrgJqmoJdYo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BraveUpdateSetup.exe (PID: 2268)
      • BraveBrowserSetup-BRV002.exe (PID: 668)
      • BraveUpdate.exe (PID: 2740)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BraveBrowserSetup-BRV002.exe (PID: 668)
      • BraveUpdateSetup.exe (PID: 2268)
      • BraveUpdate.exe (PID: 2740)
    • Disables SEHOP

      • BraveUpdate.exe (PID: 2740)
    • Starts itself from another location

      • BraveUpdate.exe (PID: 2740)
    • Creates/Modifies COM task schedule object

      • BraveUpdate.exe (PID: 3156)
    • Reads the Internet Settings

      • BraveUpdate.exe (PID: 3604)
      • BraveUpdate.exe (PID: 1172)
    • Executes as Windows Service

      • BraveUpdate.exe (PID: 796)
    • Reads security settings of Internet Explorer

      • BraveUpdate.exe (PID: 1172)
    • Reads settings of System Certificates

      • BraveUpdate.exe (PID: 3604)
    • Application launched itself

      • BraveUpdate.exe (PID: 796)
  • INFO

    • Checks supported languages

      • BraveBrowserSetup-BRV002.exe (PID: 668)
      • BraveUpdate.exe (PID: 324)
      • BraveUpdateSetup.exe (PID: 2268)
      • BraveUpdate.exe (PID: 2740)
      • BraveUpdate.exe (PID: 2448)
      • BraveUpdate.exe (PID: 3156)
      • BraveUpdate.exe (PID: 3604)
      • BraveUpdate.exe (PID: 796)
      • BraveUpdate.exe (PID: 1172)
      • BraveUpdate.exe (PID: 3576)
    • Reads the machine GUID from the registry

      • BraveUpdate.exe (PID: 324)
      • BraveUpdate.exe (PID: 2740)
      • BraveUpdate.exe (PID: 796)
      • BraveUpdate.exe (PID: 1172)
      • BraveUpdate.exe (PID: 3604)
      • BraveUpdate.exe (PID: 3576)
    • Reads the computer name

      • BraveUpdate.exe (PID: 324)
      • BraveUpdate.exe (PID: 2740)
      • BraveUpdate.exe (PID: 2448)
      • BraveUpdate.exe (PID: 3156)
      • BraveUpdate.exe (PID: 3604)
      • BraveUpdate.exe (PID: 1172)
      • BraveUpdate.exe (PID: 796)
      • BraveUpdate.exe (PID: 3576)
    • Create files in a temporary directory

      • BraveBrowserSetup-BRV002.exe (PID: 668)
    • Creates files in the program directory

      • BraveUpdate.exe (PID: 2740)
      • BraveUpdateSetup.exe (PID: 2268)
      • BraveUpdate.exe (PID: 2448)
      • BraveUpdate.exe (PID: 3156)
      • BraveUpdate.exe (PID: 3604)
      • BraveUpdate.exe (PID: 1172)
      • BraveUpdate.exe (PID: 3576)
      • BraveUpdate.exe (PID: 796)
    • Reads the software policy settings

      • BraveUpdate.exe (PID: 3604)
      • BraveUpdate.exe (PID: 796)
      • BraveUpdate.exe (PID: 3576)
    • Checks proxy server information

      • BraveUpdate.exe (PID: 1172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:11 10:12:12+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 105472
InitializedDataSize: 1150464
UninitializedDataSize: -
EntryPoint: 0x6ee4
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.361.149
ProductVersionNumber: 1.3.361.149
FileFlagsMask: 0x003f
FileFlags: Private build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BraveSoftware Inc.
FileDescription: BraveSoftware Update Setup
FileVersion: 1.3.361.149
InternalName: BraveSoftware Update Setup
OriginalFileName: BraveUpdateSetup.exe
ProductName: BraveSoftware Update
ProductVersion: 1.3.361.149
LanguageId: en
PrivateBuild: -
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
10
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bravebrowsersetup-brv002.exe braveupdate.exe no specs braveupdatesetup.exe braveupdate.exe braveupdate.exe no specs braveupdate.exe no specs braveupdate.exe braveupdate.exe no specs braveupdate.exe braveupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
324C:\Users\admin\AppData\Local\Temp\GUMD638.tmp\BraveUpdate.exe /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none"C:\Users\admin\AppData\Local\Temp\GUMD638.tmp\BraveUpdate.exeBraveBrowserSetup-BRV002.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
MEDIUM
Description:
BraveSoftware Update
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\users\admin\appdata\local\temp\gumd638.tmp\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
668"C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV002.exe" C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV002.exe
explorer.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
MEDIUM
Description:
BraveSoftware Update Setup
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\users\admin\appdata\local\temp\bravebrowsersetup-brv002.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
796"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /svcC:\Program Files\BraveSoftware\Update\BraveUpdate.exe
services.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1172"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /handoff "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installsource taggedmi /sessionid "{11ECC29A-00FC-4285-94F7-52B5ADB26F38}"C:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2268"C:\Users\admin\AppData\Local\Temp\GUMD638.tmp\BraveUpdateSetup.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\GUMD638.tmp\BraveUpdateSetup.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update Setup
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\users\admin\appdata\local\temp\gumd638.tmp\braveupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2448"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regsvcC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2740"C:\Program Files\BraveSoftware\Temp\GUMD9C3.tmp\BraveUpdate.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevatedC:\Program Files\BraveSoftware\Temp\GUMD9C3.tmp\BraveUpdate.exe
BraveUpdateSetup.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\temp\gumd9c3.tmp\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3156"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regserverC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3576"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTQ5IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjE0OSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9InsxMUVDQzI5QS0wMEZDLTQyODUtOTRGNy01MkI1QURCMjZGMzh9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7RTZERDRFOEUtNDUwNi00QTkzLTg0ODYtQjZEOTY1Q0UzNzdBfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QUZFNkE0NjItQzU3NC00QjhBLUFGNDMtNENDNjBERjQ1NjNCfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iIiBhcD0icmVsZWFzZSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiIgaW5zdGFsbGFnZT0iLTEiIGluc3RhbGxkYXRlPSItMSI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjAiIGVycm9yY29kZT0iLTIxNDcyMTk0NDciIGV4dHJhY29kZTE9IjI2ODQzNTQ1OSIgdXBkYXRlX2NoZWNrX3RpbWVfbXM9IjM5MSIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3604"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTQ5IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjE0OSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9InsxMUVDQzI5QS0wMEZDLTQyODUtOTRGNy01MkI1QURCMjZGMzh9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7NTFEN0VDNTctNjEwNS00MjI2LTg5ODQtNERGNEQ5NzlFQTFGfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QjEzMUM5MzUtOUJFNi00MURBLTk1OTktMUY3NzZCRUI4MDE5fSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjM2MS4xNDkiIGxhbmc9IiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGluc3RhbGxfdGltZV9tcz0iMTE1NiIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
14 495
Read events
14 274
Write events
150
Delete events
71

Modification events

(PID) Process:(668) BraveBrowserSetup-BRV002.exeKey:HKEY_CURRENT_USER\Software\BraveSoftware\Promo
Operation:writeName:StubInstallerPath
Value:
C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV002.exe
(PID) Process:(2740) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:path
Value:
C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
(PID) Process:(2740) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:UninstallCmdLine
Value:
"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /uninstall
(PID) Process:(2740) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.149
(PID) Process:(2740) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:name
Value:
Brave Update
(PID) Process:(2740) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\ClientState\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.149
(PID) Process:(2740) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BraveUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(2448) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:uid
Value:
(PID) Process:(2448) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:old-uid
Value:
(PID) Process:(2448) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BraveUpdate.exe
Operation:writeName:AppID
Value:
{08F15E98-0442-45D3-82F1-F67495CC51EB}
Executable files
216
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
668BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMD638.tmp\BraveUpdateOnDemand.exeexecutable
MD5:D439927C94DF664CFCDA56016BCF17BC
SHA256:0927C23DB6917B5A316C589014BD9E33159AB97141D664265097013C9DDC6A90
668BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMD638.tmp\BraveUpdate.exeexecutable
MD5:DDD12A654903926B2F2521A54B33F858
SHA256:ABF3726C60D3B7D7E5490DE04C18FB1D0C10A06E45D9E6BA2201D80A2C2A1770
668BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMD638.tmp\BraveCrashHandler.exeexecutable
MD5:994F1A1D7190B4B69C3EA0EDBD9AAD75
SHA256:CAA18E7065F27372FAC2C3B986FF1752C6D8D4ADDA38831FC002C98AF5597C45
668BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMD638.tmp\BraveUpdateBroker.exeexecutable
MD5:E51D1CF8426C4D6797C12FBA2F77C29F
SHA256:9301AF9B2473BA165F63EEFCF33B4FB36E6893491ABFD46A4A196D32D34E3CA1
668BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMD638.tmp\goopdate.dllexecutable
MD5:5CC0AA5592DEC5F39FCD9A8932430481
SHA256:C2D236477A51F35E7E7C4D5A9FADD076370357752CD86EFEE5F6BB0E4DC1A420
668BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMD638.tmp\BraveUpdateComRegisterShell64.exeexecutable
MD5:4238D31D155902FE6D0C94DD1A46EDFE
SHA256:CE3102DB24E5EAFA6B0079E4445E0850C0D0A3F1DA263EA5F6255685896F9C61
668BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMD638.tmp\BraveCrashHandler64.exeexecutable
MD5:BB811C6670DC2A6CCDE4F15411BBB860
SHA256:C3168DFBB08E9B840588F41650349EA1C413AA3EE163B0320F4E83F96F208FA3
668BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMD638.tmp\goopdateres_bn.dllexecutable
MD5:8C255E39B39240E3137CFB4E999D2974
SHA256:E945C3C7F6B68D43716FE95EB59310E464E9E617A180784B08C71B57E2FE6B4A
668BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMD638.tmp\goopdateres_bg.dllexecutable
MD5:C8565B9D0D5199DE17FD4A28CE01AA1F
SHA256:A6AFC8E612B6BAD95658A7B0E7664D536BBA304AE01F9A9DE6357F0A62CB70A1
668BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMD638.tmp\psuser.dllexecutable
MD5:4CDA7D2D5AF5403C0BD2CA49EDA1B47D
SHA256:C79DF144EFC8B5C1DAA2CCFDC3FF56CD94F640BC6CF48970F60D72A50A743EA8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3604
BraveUpdate.exe
13.32.121.70:443
updates.bravesoftware.com
AMAZON-02
US
unknown
796
BraveUpdate.exe
13.32.121.70:443
updates.bravesoftware.com
AMAZON-02
US
unknown
3576
BraveUpdate.exe
13.32.121.70:443
updates.bravesoftware.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
updates.bravesoftware.com
  • 13.32.121.70
  • 13.32.121.47
  • 13.32.121.6
  • 13.32.121.124
shared
dl.brave.com
unknown

Threats

No threats detected
No debug info