| File name: | BraveBrowserSetup-BRV002.exe |
| Full analysis: | https://app.any.run/tasks/8ee8b4dd-00fa-409b-9bf7-593644fb5605 |
| Verdict: | Malicious activity |
| Analysis date: | March 04, 2024, 11:17:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 3C71C2B16998DAD45A883A7B9C1BE4B0 |
| SHA1: | D5C4E68E78094DD3D7246FF83B8385E86A45B1A3 |
| SHA256: | 9B0F892D7B784E125C159CE6C7B57A76C7E5AD4CDF0B7049A23B8EB61E149C3A |
| SSDEEP: | 49152:9XFXotAWsXS+VPYX8Q1jEY1oWr/cuddaN/3+JLjA27nmdn+dTgnTEcwmrFfx6pem:ldBS+VPdajEY1zdI3+JHt7nMnUTgnTw7 |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:04:19 10:02:11+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 101888 |
| InitializedDataSize: | 1289728 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x699b |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.361.137 |
| ProductVersionNumber: | 1.3.361.137 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | BraveSoftware Inc. |
| FileDescription: | BraveSoftware Update Setup |
| FileVersion: | 1.3.361.137 |
| InternalName: | BraveSoftware Update Setup |
| OriginalFileName: | BraveUpdateSetup.exe |
| ProductName: | BraveSoftware Update |
| ProductVersion: | 1.3.361.137 |
| LanguageId: | en |
| PrivateBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regserver | C:\Program Files\BraveSoftware\Update\BraveUpdate.exe | — | BraveUpdate.exe | |||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Exit code: 0 Version: 1.3.361.137 Modules
| |||||||||||||||
| 1492 | "C:\Program Files\BraveSoftware\Temp\GUMFB77.tmp\BraveUpdate.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=x64-rel&referral=none" /installelevated | C:\Program Files\BraveSoftware\Temp\GUMFB77.tmp\BraveUpdate.exe | BraveUpdateSetup.exe | ||||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Exit code: 0 Version: 1.3.361.137 Modules
| |||||||||||||||
| 1836 | "C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTM3IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjEzNyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3QjdFRDVGQi0yNDZELTRGMTItOTRGQS0xNjgxQUE3NEE1M0J9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7NzE3QzM5QUQtM0Q3NC00RjFBLTk1NEQtMkUwMjZCMjUyMjM1fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QjEzMUM5MzUtOUJFNi00MURBLTk1OTktMUY3NzZCRUI4MDE5fSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjM2MS4xMzciIGxhbmc9IiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGluc3RhbGxfdGltZV9tcz0iMTEwOSIvPjwvYXBwPjwvcmVxdWVzdD4 | C:\Program Files\BraveSoftware\Update\BraveUpdate.exe | BraveUpdate.exe | ||||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Exit code: 0 Version: 1.3.361.137 Modules
| |||||||||||||||
| 1876 | "C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdateSetup.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=x64-rel&referral=none" /installelevated /nomitag | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdateSetup.exe | BraveUpdate.exe | ||||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Setup Exit code: 0 Version: 1.3.361.137 Modules
| |||||||||||||||
| 2328 | "C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regsvc | C:\Program Files\BraveSoftware\Update\BraveUpdate.exe | — | BraveUpdate.exe | |||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Exit code: 0 Version: 1.3.361.137 Modules
| |||||||||||||||
| 2648 | "C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /handoff "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=x64-rel&referral=none" /installsource taggedmi /sessionid "{7B7ED5FB-246D-4F12-94FA-1681AA74A53B}" | C:\Program Files\BraveSoftware\Update\BraveUpdate.exe | — | BraveUpdate.exe | |||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Exit code: 0 Version: 1.3.361.137 Modules
| |||||||||||||||
| 2792 | "C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTM3IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjEzNyIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3QjdFRDVGQi0yNDZELTRGMTItOTRGQS0xNjgxQUE3NEE1M0J9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7NzcwM0I4RUMtQzI4Qi00RjM1LUJDNTktRDZGOEFFMjFGRkM0fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QUZFNkE0NjItQzU3NC00QjhBLUFGNDMtNENDNjBERjQ1NjNCfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iIiBhcD0ieDY0LXJlbCIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiIgaW5zdGFsbGFnZT0iLTEiIGluc3RhbGxkYXRlPSItMSI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjAiIGVycm9yY29kZT0iLTIxNDcyMTk0NDciIGV4dHJhY29kZTE9IjI2ODQzNTQ1OSIgdXBkYXRlX2NoZWNrX3RpbWVfbXM9IjM5MSIvPjwvYXBwPjwvcmVxdWVzdD4 | C:\Program Files\BraveSoftware\Update\BraveUpdate.exe | BraveUpdate.exe | ||||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Exit code: 0 Version: 1.3.361.137 Modules
| |||||||||||||||
| 3652 | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdate.exe /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=x64-rel&referral=none" | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdate.exe | — | BraveBrowserSetup-BRV002.exe | |||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: MEDIUM Description: BraveSoftware Update Exit code: 0 Version: 1.3.361.137 Modules
| |||||||||||||||
| 3672 | "C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV002.exe" | C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV002.exe | explorer.exe | ||||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: MEDIUM Description: BraveSoftware Update Setup Exit code: 0 Version: 1.3.361.137 Modules
| |||||||||||||||
| 4044 | "C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /svc | C:\Program Files\BraveSoftware\Update\BraveUpdate.exe | services.exe | ||||||||||||
User: SYSTEM Company: BraveSoftware Inc. Integrity Level: SYSTEM Description: BraveSoftware Update Exit code: 0 Version: 1.3.361.137 Modules
| |||||||||||||||
| (PID) Process: | (3672) BraveBrowserSetup-BRV002.exe | Key: | HKEY_CURRENT_USER\Software\BraveSoftware\Promo |
| Operation: | write | Name: | StubInstallerPath |
Value: C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV002.exe | |||
| (PID) Process: | (1492) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update |
| Operation: | write | Name: | path |
Value: C:\Program Files\BraveSoftware\Update\BraveUpdate.exe | |||
| (PID) Process: | (1492) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update |
| Operation: | write | Name: | UninstallCmdLine |
Value: "C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /uninstall | |||
| (PID) Process: | (1492) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019} |
| Operation: | write | Name: | pv |
Value: 1.3.361.137 | |||
| (PID) Process: | (1492) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019} |
| Operation: | write | Name: | name |
Value: Brave Update | |||
| (PID) Process: | (1492) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\ClientState\{B131C935-9BE6-41DA-9599-1F776BEB8019} |
| Operation: | write | Name: | pv |
Value: 1.3.361.137 | |||
| (PID) Process: | (1492) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BraveUpdate.exe |
| Operation: | write | Name: | DisableExceptionChainValidation |
Value: 0 | |||
| (PID) Process: | (2328) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update |
| Operation: | delete value | Name: | uid |
Value: | |||
| (PID) Process: | (2328) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update |
| Operation: | delete value | Name: | old-uid |
Value: | |||
| (PID) Process: | (2328) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BraveUpdate.exe |
| Operation: | write | Name: | AppID |
Value: {08F15E98-0442-45D3-82F1-F67495CC51EB} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3672 | BraveBrowserSetup-BRV002.exe | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveCrashHandler.exe | executable | |
MD5:F2B03DBF25CC44FDE25A8223E42509BF | SHA256:D0817351294E1425992D939D7CB32B5BCA3826AFABE321298F0C52D51D5B7CB6 | |||
| 3672 | BraveBrowserSetup-BRV002.exe | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdate.exe | executable | |
MD5:523B82BBBE1566D6025E22F34EFBF41F | SHA256:B3D5FD836287C8F79204B130792BCA262A4AF3FDE4772917CB70241C4024BAFB | |||
| 3672 | BraveBrowserSetup-BRV002.exe | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\goopdate.dll | executable | |
MD5:8604C1B4617C393CB55B52D5E30F7123 | SHA256:B68EF91A9F6929DFFD2E74B2D7574823C31C50CDD5CDAAB7601C17CA4479E921 | |||
| 3672 | BraveBrowserSetup-BRV002.exe | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdateBroker.exe | executable | |
MD5:0CE39814B7881062E477CC3EFD9138E3 | SHA256:B180183F3998A1DAB301FA3377D9BB286F9406C127ECD0C8B3FE02A8990B2096 | |||
| 3672 | BraveBrowserSetup-BRV002.exe | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdateOnDemand.exe | executable | |
MD5:BA3D5D67A92FDC010866000978B47D67 | SHA256:0A09764489FC30E78D0CF27A7D6899EE65E296887CA97C724E02B9B2F430F7D4 | |||
| 3672 | BraveBrowserSetup-BRV002.exe | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\goopdateres_am.dll | executable | |
MD5:A2ED79F08657AACF4B059E8B8DA1469D | SHA256:6EB45F7D003F1DCD157E51B8A615B12723DD33E77BFE54ECD50C28ED078CD249 | |||
| 3672 | BraveBrowserSetup-BRV002.exe | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\goopdateres_ar.dll | executable | |
MD5:823DC6CE42B7B349A568C64AA6497F0D | SHA256:9ACFF13D9C7A1E57F7DFFE7B5D0BB82F29BE94C886901468F1FEF52D304F49FB | |||
| 3672 | BraveBrowserSetup-BRV002.exe | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\goopdateres_bg.dll | executable | |
MD5:68D22EE1253B83CAAD9B14523F92757F | SHA256:5A7A323F7A3E8237EC7DC8D01DFF848F30C8CF1DDE445C32CAFEE9AD7C58FF68 | |||
| 3672 | BraveBrowserSetup-BRV002.exe | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\BraveUpdateComRegisterShell64.exe | executable | |
MD5:5EA142A8DCAFA9055BEF646392C006D3 | SHA256:C35626141A1F45CAC29D3B58A83C3B8577E7659BBE1F24B782BBD98B4133151D | |||
| 3672 | BraveBrowserSetup-BRV002.exe | C:\Users\admin\AppData\Local\Temp\GUMF79E.tmp\psmachine.dll | executable | |
MD5:E880FD9AA384006094379F832EDBC200 | SHA256:D128EDB0CACE108EC684585D964CDA0FB14AA546A299F26C041787F8AD407C1B | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1836 | BraveUpdate.exe | 13.32.121.124:443 | updates.bravesoftware.com | AMAZON-02 | US | unknown |
4044 | BraveUpdate.exe | 13.32.121.124:443 | updates.bravesoftware.com | AMAZON-02 | US | unknown |
2792 | BraveUpdate.exe | 13.32.121.124:443 | updates.bravesoftware.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
updates.bravesoftware.com |
| shared |