File name:

BraveBrowserSetup-BRV002.exe

Full analysis: https://app.any.run/tasks/8ee8b4dd-00fa-409b-9bf7-593644fb5605
Verdict: Malicious activity
Analysis date: March 04, 2024, 11:17:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3C71C2B16998DAD45A883A7B9C1BE4B0

SHA1:

D5C4E68E78094DD3D7246FF83B8385E86A45B1A3

SHA256:

9B0F892D7B784E125C159CE6C7B57A76C7E5AD4CDF0B7049A23B8EB61E149C3A

SSDEEP:

49152:9XFXotAWsXS+VPYX8Q1jEY1oWr/cuddaN/3+JLjA27nmdn+dTgnTEcwmrFfx6pem:ldBS+VPdajEY1zdI3+JHt7nMnUTgnTw7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BraveUpdateSetup.exe (PID: 1876)
      • BraveUpdate.exe (PID: 1492)
      • BraveBrowserSetup-BRV002.exe (PID: 3672)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BraveUpdateSetup.exe (PID: 1876)
      • BraveBrowserSetup-BRV002.exe (PID: 3672)
      • BraveUpdate.exe (PID: 1492)
    • Starts itself from another location

      • BraveUpdate.exe (PID: 1492)
    • Disables SEHOP

      • BraveUpdate.exe (PID: 1492)
    • Creates/Modifies COM task schedule object

      • BraveUpdate.exe (PID: 120)
    • Reads the Internet Settings

      • BraveUpdate.exe (PID: 1836)
      • BraveUpdate.exe (PID: 2792)
    • Executes as Windows Service

      • BraveUpdate.exe (PID: 4044)
    • Reads settings of System Certificates

      • BraveUpdate.exe (PID: 1836)
      • BraveUpdate.exe (PID: 2792)
    • Application launched itself

      • BraveUpdate.exe (PID: 4044)
  • INFO

    • Checks supported languages

      • BraveBrowserSetup-BRV002.exe (PID: 3672)
      • BraveUpdate.exe (PID: 3652)
      • BraveUpdateSetup.exe (PID: 1876)
      • BraveUpdate.exe (PID: 1492)
      • BraveUpdate.exe (PID: 2328)
      • BraveUpdate.exe (PID: 120)
      • BraveUpdate.exe (PID: 1836)
      • BraveUpdate.exe (PID: 2648)
      • BraveUpdate.exe (PID: 4044)
      • BraveUpdate.exe (PID: 2792)
    • Reads the computer name

      • BraveUpdate.exe (PID: 3652)
      • BraveUpdate.exe (PID: 1492)
      • BraveUpdate.exe (PID: 2328)
      • BraveUpdate.exe (PID: 2648)
      • BraveUpdate.exe (PID: 1836)
      • BraveUpdate.exe (PID: 4044)
      • BraveUpdate.exe (PID: 120)
      • BraveUpdate.exe (PID: 2792)
    • Reads the machine GUID from the registry

      • BraveUpdate.exe (PID: 3652)
      • BraveUpdate.exe (PID: 4044)
      • BraveUpdate.exe (PID: 1836)
      • BraveUpdate.exe (PID: 1492)
      • BraveUpdate.exe (PID: 2648)
      • BraveUpdate.exe (PID: 2792)
    • Creates files in the program directory

      • BraveUpdate.exe (PID: 1492)
      • BraveUpdateSetup.exe (PID: 1876)
      • BraveUpdate.exe (PID: 4044)
    • Create files in a temporary directory

      • BraveBrowserSetup-BRV002.exe (PID: 3672)
    • Reads the software policy settings

      • BraveUpdate.exe (PID: 1836)
      • BraveUpdate.exe (PID: 4044)
      • BraveUpdate.exe (PID: 2792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:04:19 10:02:11+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 101888
InitializedDataSize: 1289728
UninitializedDataSize: -
EntryPoint: 0x699b
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.361.137
ProductVersionNumber: 1.3.361.137
FileFlagsMask: 0x003f
FileFlags: Private build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BraveSoftware Inc.
FileDescription: BraveSoftware Update Setup
FileVersion: 1.3.361.137
InternalName: BraveSoftware Update Setup
OriginalFileName: BraveUpdateSetup.exe
ProductName: BraveSoftware Update
ProductVersion: 1.3.361.137
LanguageId: en
PrivateBuild: -
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
10
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start bravebrowsersetup-brv002.exe braveupdate.exe no specs braveupdatesetup.exe braveupdate.exe braveupdate.exe no specs braveupdate.exe no specs braveupdate.exe braveupdate.exe no specs braveupdate.exe braveupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regserverC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.137
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1492"C:\Program Files\BraveSoftware\Temp\GUMFB77.tmp\BraveUpdate.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=x64-rel&referral=none" /installelevatedC:\Program Files\BraveSoftware\Temp\GUMFB77.tmp\BraveUpdate.exe
BraveUpdateSetup.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.137
Modules
Images
c:\program files\bravesoftware\temp\gumfb77.tmp\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1836"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTM3IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjEzNyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3QjdFRDVGQi0yNDZELTRGMTItOTRGQS0xNjgxQUE3NEE1M0J9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7NzE3QzM5QUQtM0Q3NC00RjFBLTk1NEQtMkUwMjZCMjUyMjM1fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QjEzMUM5MzUtOUJFNi00MURBLTk1OTktMUY3NzZCRUI4MDE5fSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjM2MS4xMzciIGxhbmc9IiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGluc3RhbGxfdGltZV9tcz0iMTEwOSIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.137
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1876"C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdateSetup.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=x64-rel&referral=none" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdateSetup.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update Setup
Exit code:
0
Version:
1.3.361.137
Modules
Images
c:\users\admin\appdata\local\temp\gumf79e.tmp\braveupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2328"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regsvcC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.137
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2648"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /handoff "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=x64-rel&referral=none" /installsource taggedmi /sessionid "{7B7ED5FB-246D-4F12-94FA-1681AA74A53B}"C:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.137
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2792"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTM3IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjEzNyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3QjdFRDVGQi0yNDZELTRGMTItOTRGQS0xNjgxQUE3NEE1M0J9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7NzcwM0I4RUMtQzI4Qi00RjM1LUJDNTktRDZGOEFFMjFGRkM0fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QUZFNkE0NjItQzU3NC00QjhBLUFGNDMtNENDNjBERjQ1NjNCfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iIiBhcD0ieDY0LXJlbCIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiIgaW5zdGFsbGFnZT0iLTEiIGluc3RhbGxkYXRlPSItMSI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjAiIGVycm9yY29kZT0iLTIxNDcyMTk0NDciIGV4dHJhY29kZTE9IjI2ODQzNTQ1OSIgdXBkYXRlX2NoZWNrX3RpbWVfbXM9IjM5MSIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.137
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3652C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdate.exe /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=x64-rel&referral=none"C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdate.exeBraveBrowserSetup-BRV002.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
MEDIUM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.137
Modules
Images
c:\users\admin\appdata\local\temp\gumf79e.tmp\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3672"C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV002.exe" C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV002.exe
explorer.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
MEDIUM
Description:
BraveSoftware Update Setup
Exit code:
0
Version:
1.3.361.137
Modules
Images
c:\users\admin\appdata\local\temp\bravebrowsersetup-brv002.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
4044"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /svcC:\Program Files\BraveSoftware\Update\BraveUpdate.exe
services.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.137
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
13 686
Read events
13 506
Write events
120
Delete events
60

Modification events

(PID) Process:(3672) BraveBrowserSetup-BRV002.exeKey:HKEY_CURRENT_USER\Software\BraveSoftware\Promo
Operation:writeName:StubInstallerPath
Value:
C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV002.exe
(PID) Process:(1492) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:path
Value:
C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
(PID) Process:(1492) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:UninstallCmdLine
Value:
"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /uninstall
(PID) Process:(1492) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.137
(PID) Process:(1492) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:name
Value:
Brave Update
(PID) Process:(1492) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\ClientState\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.137
(PID) Process:(1492) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BraveUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(2328) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:uid
Value:
(PID) Process:(2328) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:old-uid
Value:
(PID) Process:(2328) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BraveUpdate.exe
Operation:writeName:AppID
Value:
{08F15E98-0442-45D3-82F1-F67495CC51EB}
Executable files
217
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3672BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveCrashHandler.exeexecutable
MD5:F2B03DBF25CC44FDE25A8223E42509BF
SHA256:D0817351294E1425992D939D7CB32B5BCA3826AFABE321298F0C52D51D5B7CB6
3672BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdate.exeexecutable
MD5:523B82BBBE1566D6025E22F34EFBF41F
SHA256:B3D5FD836287C8F79204B130792BCA262A4AF3FDE4772917CB70241C4024BAFB
3672BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\goopdate.dllexecutable
MD5:8604C1B4617C393CB55B52D5E30F7123
SHA256:B68EF91A9F6929DFFD2E74B2D7574823C31C50CDD5CDAAB7601C17CA4479E921
3672BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdateBroker.exeexecutable
MD5:0CE39814B7881062E477CC3EFD9138E3
SHA256:B180183F3998A1DAB301FA3377D9BB286F9406C127ECD0C8B3FE02A8990B2096
3672BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdateOnDemand.exeexecutable
MD5:BA3D5D67A92FDC010866000978B47D67
SHA256:0A09764489FC30E78D0CF27A7D6899EE65E296887CA97C724E02B9B2F430F7D4
3672BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\goopdateres_am.dllexecutable
MD5:A2ED79F08657AACF4B059E8B8DA1469D
SHA256:6EB45F7D003F1DCD157E51B8A615B12723DD33E77BFE54ECD50C28ED078CD249
3672BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\goopdateres_ar.dllexecutable
MD5:823DC6CE42B7B349A568C64AA6497F0D
SHA256:9ACFF13D9C7A1E57F7DFFE7B5D0BB82F29BE94C886901468F1FEF52D304F49FB
3672BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\goopdateres_bg.dllexecutable
MD5:68D22EE1253B83CAAD9B14523F92757F
SHA256:5A7A323F7A3E8237EC7DC8D01DFF848F30C8CF1DDE445C32CAFEE9AD7C58FF68
3672BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdateComRegisterShell64.exeexecutable
MD5:5EA142A8DCAFA9055BEF646392C006D3
SHA256:C35626141A1F45CAC29D3B58A83C3B8577E7659BBE1F24B782BBD98B4133151D
3672BraveBrowserSetup-BRV002.exeC:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\psmachine.dllexecutable
MD5:E880FD9AA384006094379F832EDBC200
SHA256:D128EDB0CACE108EC684585D964CDA0FB14AA546A299F26C041787F8AD407C1B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1836
BraveUpdate.exe
13.32.121.124:443
updates.bravesoftware.com
AMAZON-02
US
unknown
4044
BraveUpdate.exe
13.32.121.124:443
updates.bravesoftware.com
AMAZON-02
US
unknown
2792
BraveUpdate.exe
13.32.121.124:443
updates.bravesoftware.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
updates.bravesoftware.com
  • 13.32.121.124
  • 13.32.121.47
  • 13.32.121.6
  • 13.32.121.70
shared

Threats

No threats detected
No debug info