File name:

BraveBrowserSetup-BRV011 (1).exe

Full analysis: https://app.any.run/tasks/e28fac7b-fa12-4a69-b940-7e0ab0b76857
Verdict: Malicious activity
Analysis date: April 28, 2024, 19:11:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4EDC1416396D8901DD50929949854B93

SHA1:

AB8A403E1D3DA99B6967D555F2C6E6D9BAD6155C

SHA256:

AA2C98A6B0BD6406A1306B7FE6806D4C1A8FC75005793642EE5E32A8A28EF4E2

SSDEEP:

49152:hWhUUZEGcSR0IsBXeh1jNnGM/sAWeBfzt/Nqb7TmqJwNFa2cKyOyRIldjPNS59nt:hCyhSunXefIM/szeBrt/OVwNFa2cK1Lr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BraveUpdateSetup.exe (PID: 1036)
      • BraveUpdate.exe (PID: 752)
      • BraveBrowserSetup-BRV011 (1).exe (PID: 3984)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BraveBrowserSetup-BRV011 (1).exe (PID: 3984)
      • BraveUpdateSetup.exe (PID: 1036)
      • BraveUpdate.exe (PID: 752)
    • Starts itself from another location

      • BraveUpdate.exe (PID: 752)
    • Disables SEHOP

      • BraveUpdate.exe (PID: 752)
    • Reads the Internet Settings

      • BraveUpdate.exe (PID: 1112)
      • BraveUpdate.exe (PID: 2304)
    • Executes as Windows Service

      • BraveUpdate.exe (PID: 316)
    • Creates/Modifies COM task schedule object

      • BraveUpdate.exe (PID: 372)
    • Reads security settings of Internet Explorer

      • BraveUpdate.exe (PID: 2304)
    • Reads settings of System Certificates

      • BraveUpdate.exe (PID: 1112)
    • Application launched itself

      • BraveUpdate.exe (PID: 316)
  • INFO

    • Reads the machine GUID from the registry

      • BraveUpdate.exe (PID: 4000)
      • BraveUpdate.exe (PID: 752)
      • BraveUpdate.exe (PID: 2304)
      • BraveUpdate.exe (PID: 1112)
      • BraveUpdate.exe (PID: 1948)
      • BraveUpdate.exe (PID: 316)
    • Checks supported languages

      • BraveBrowserSetup-BRV011 (1).exe (PID: 3984)
      • BraveUpdate.exe (PID: 4000)
      • BraveUpdateSetup.exe (PID: 1036)
      • BraveUpdate.exe (PID: 752)
      • BraveUpdate.exe (PID: 2032)
      • BraveUpdate.exe (PID: 2304)
      • BraveUpdate.exe (PID: 372)
      • BraveUpdate.exe (PID: 1112)
      • BraveUpdate.exe (PID: 316)
      • BraveUpdate.exe (PID: 1948)
      • wmpnscfg.exe (PID: 2244)
    • Reads the computer name

      • BraveUpdate.exe (PID: 4000)
      • BraveUpdate.exe (PID: 752)
      • BraveUpdate.exe (PID: 2032)
      • BraveUpdate.exe (PID: 372)
      • BraveUpdate.exe (PID: 1112)
      • BraveUpdate.exe (PID: 2304)
      • BraveUpdate.exe (PID: 316)
      • BraveUpdate.exe (PID: 1948)
      • wmpnscfg.exe (PID: 2244)
    • Create files in a temporary directory

      • BraveBrowserSetup-BRV011 (1).exe (PID: 3984)
    • Creates files in the program directory

      • BraveUpdateSetup.exe (PID: 1036)
      • BraveUpdate.exe (PID: 752)
      • BraveUpdate.exe (PID: 2032)
      • BraveUpdate.exe (PID: 372)
      • BraveUpdate.exe (PID: 1112)
      • BraveUpdate.exe (PID: 2304)
      • BraveUpdate.exe (PID: 1948)
      • BraveUpdate.exe (PID: 316)
    • Checks proxy server information

      • BraveUpdate.exe (PID: 2304)
    • Reads the software policy settings

      • BraveUpdate.exe (PID: 1112)
      • BraveUpdate.exe (PID: 316)
      • BraveUpdate.exe (PID: 1948)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2244)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:26 08:43:12+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 105472
InitializedDataSize: 1150976
UninitializedDataSize: -
EntryPoint: 0x6ee4
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.361.149
ProductVersionNumber: 1.3.361.149
FileFlagsMask: 0x003f
FileFlags: Private build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BraveSoftware Inc.
FileDescription: BraveSoftware Update Setup
FileVersion: 1.3.361.149
InternalName: BraveSoftware Update Setup
OriginalFileName: BraveUpdateSetup.exe
ProductName: BraveSoftware Update
ProductVersion: 1.3.361.149
LanguageId: en
PrivateBuild: -
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
11
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bravebrowsersetup-brv011 (1).exe braveupdate.exe no specs braveupdatesetup.exe braveupdate.exe braveupdate.exe no specs braveupdate.exe no specs braveupdate.exe braveupdate.exe no specs braveupdate.exe braveupdate.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /svcC:\Program Files\BraveSoftware\Update\BraveUpdate.exe
services.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
372"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regserverC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
752"C:\Program Files\BraveSoftware\Temp\GUM5B52.tmp\BraveUpdate.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevatedC:\Program Files\BraveSoftware\Temp\GUM5B52.tmp\BraveUpdate.exe
BraveUpdateSetup.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\temp\gum5b52.tmp\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1036"C:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveUpdateSetup.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveUpdateSetup.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update Setup
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\users\admin\appdata\local\temp\gum51db.tmp\braveupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1112"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTQ5IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjE0OSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3N0ZBQzRCOC1EMUFGLTRFRDItQjU1Mi0zQ0I1ODUyMDJFMDB9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7RjY2M0YzRUQtMTJGNy00ODI0LTlDRjktQjMyOTM2MUUwRjE3fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QjEzMUM5MzUtOUJFNi00MURBLTk1OTktMUY3NzZCRUI4MDE5fSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjM2MS4xNDkiIGxhbmc9IiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGluc3RhbGxfdGltZV9tcz0iMjIzNCIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1948"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTQ5IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjE0OSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3N0ZBQzRCOC1EMUFGLTRFRDItQjU1Mi0zQ0I1ODUyMDJFMDB9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7RTVDNzkwRDgtOEVBRS00ODEyLTkyMEEtMEEzNkIyNjAyOEMzfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QUZFNkE0NjItQzU3NC00QjhBLUFGNDMtNENDNjBERjQ1NjNCfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iIiBhcD0icmVsZWFzZSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiIgaW5zdGFsbGFnZT0iLTEiIGluc3RhbGxkYXRlPSItMSI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjAiIGVycm9yY29kZT0iLTIxNDcyMTk0NDciIGV4dHJhY29kZTE9IjI2ODQzNTQ1OSIgdXBkYXRlX2NoZWNrX3RpbWVfbXM9IjE0MjIiLz48L2FwcD48L3JlcXVlc3Q-C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2032"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regsvcC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2244"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2304"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /handoff "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installsource taggedmi /sessionid "{77FAC4B8-D1AF-4ED2-B552-3CB585202E00}"C:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3984"C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV011 (1).exe" C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV011 (1).exe
explorer.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
MEDIUM
Description:
BraveSoftware Update Setup
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\users\admin\appdata\local\temp\bravebrowsersetup-brv011 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
14 482
Read events
14 264
Write events
150
Delete events
68

Modification events

(PID) Process:(3984) BraveBrowserSetup-BRV011 (1).exeKey:HKEY_CURRENT_USER\Software\BraveSoftware\Promo
Operation:writeName:StubInstallerPath
Value:
C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV011 (1).exe
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:path
Value:
C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:UninstallCmdLine
Value:
"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /uninstall
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.149
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:name
Value:
Brave Update
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\ClientState\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.149
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BraveUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(2032) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:uid
Value:
(PID) Process:(2032) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:old-uid
Value:
(PID) Process:(2032) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BraveUpdate.exe
Operation:writeName:AppID
Value:
{08F15E98-0442-45D3-82F1-F67495CC51EB}
Executable files
216
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveCrashHandler.exeexecutable
MD5:7EE62CF2A4201EF4343F281A4A05AE1F
SHA256:C441EF51A2B1A01D40E1DAAB3ECC6E5CB826874F51BAB7B601610B4A0FC9671B
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveUpdate.exeexecutable
MD5:699C05198D781C5AE6AD2276E3EB4A69
SHA256:0E3405A8456C390A19C90EF408BC998931FFB070463CA1C3F01FF2A404A01CAD
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\psuser.dllexecutable
MD5:26E4EC6DDD5F991F7C9EF4F48AF30B1C
SHA256:ACF3BD0AD0F94E1A26AE0B49E977A5C6D85584A18651A07157050A451B994922
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveUpdateBroker.exeexecutable
MD5:A0193749BB599F77396051C6769FE2EA
SHA256:C40AF5804DE486E30B7118C92C5D73BE215E32E398687994C043E2A2CA53D526
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveUpdateCore.exeexecutable
MD5:40828ACD80ED13C5791E1D0DC655CF5E
SHA256:B922DC349DBDC5223570CD607DE5709485131AEA6A24CB3A8B04BE184C991E17
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveCrashHandler64.exeexecutable
MD5:C76935671FF1C0E2AD8EB7A012851188
SHA256:44265556FD4C1346AB86E7DB6FE8E6E3BA48933CF683B813AA6D0D204F60928B
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveCrashHandlerArm64.exeexecutable
MD5:A8E5AEC9E74C05CD7601A7F95272D0DB
SHA256:90019F073CACB9FAB365764E52CC39B17F3A58D9B3543B53AFC827866C1113CC
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\psmachine_arm64.dllexecutable
MD5:736339EF5FBF46757B555CAB50951A16
SHA256:8042EDDB9431517A7EF769905342B45879D7B295A01785426BCC32E0B8D7FA56
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveUpdateComRegisterShellArm64.exeexecutable
MD5:33614B5085EADFE347CA3B88371BD236
SHA256:620B9C5150AA96829B80F913F444AE014AC6C1588682DE286A9936B2D6F702AE
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\goopdateres_ar.dllexecutable
MD5:BB30091F22ABB31C6B7149962DACB8C9
SHA256:18BAA80C12ACB361604516DBAA827FB17081C01F0C03EA6D8A8B2E50A48572B1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1112
BraveUpdate.exe
13.32.121.70:443
updates.bravesoftware.com
AMAZON-02
US
unknown
4
System
192.168.100.255:137
whitelisted
316
BraveUpdate.exe
13.32.121.70:443
updates.bravesoftware.com
AMAZON-02
US
unknown
1948
BraveUpdate.exe
13.32.121.70:443
updates.bravesoftware.com
AMAZON-02
US
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
updates.bravesoftware.com
  • 13.32.121.70
  • 13.32.121.47
  • 13.32.121.6
  • 13.32.121.124
shared
dl.brave.com
unknown

Threats

No threats detected
No debug info