File name:

BraveBrowserSetup-BRV011 (1).exe

Full analysis: https://app.any.run/tasks/e28fac7b-fa12-4a69-b940-7e0ab0b76857
Verdict: Malicious activity
Analysis date: April 28, 2024, 19:11:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4EDC1416396D8901DD50929949854B93

SHA1:

AB8A403E1D3DA99B6967D555F2C6E6D9BAD6155C

SHA256:

AA2C98A6B0BD6406A1306B7FE6806D4C1A8FC75005793642EE5E32A8A28EF4E2

SSDEEP:

49152:hWhUUZEGcSR0IsBXeh1jNnGM/sAWeBfzt/Nqb7TmqJwNFa2cKyOyRIldjPNS59nt:hCyhSunXefIM/szeBrt/OVwNFa2cK1Lr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BraveBrowserSetup-BRV011 (1).exe (PID: 3984)
      • BraveUpdateSetup.exe (PID: 1036)
      • BraveUpdate.exe (PID: 752)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BraveBrowserSetup-BRV011 (1).exe (PID: 3984)
      • BraveUpdateSetup.exe (PID: 1036)
      • BraveUpdate.exe (PID: 752)
    • Starts itself from another location

      • BraveUpdate.exe (PID: 752)
    • Creates/Modifies COM task schedule object

      • BraveUpdate.exe (PID: 372)
    • Reads the Internet Settings

      • BraveUpdate.exe (PID: 1112)
      • BraveUpdate.exe (PID: 2304)
    • Executes as Windows Service

      • BraveUpdate.exe (PID: 316)
    • Reads security settings of Internet Explorer

      • BraveUpdate.exe (PID: 2304)
    • Reads settings of System Certificates

      • BraveUpdate.exe (PID: 1112)
    • Application launched itself

      • BraveUpdate.exe (PID: 316)
    • Disables SEHOP

      • BraveUpdate.exe (PID: 752)
  • INFO

    • Checks supported languages

      • BraveUpdate.exe (PID: 4000)
      • BraveBrowserSetup-BRV011 (1).exe (PID: 3984)
      • BraveUpdateSetup.exe (PID: 1036)
      • BraveUpdate.exe (PID: 752)
      • BraveUpdate.exe (PID: 372)
      • BraveUpdate.exe (PID: 1112)
      • BraveUpdate.exe (PID: 2304)
      • BraveUpdate.exe (PID: 316)
      • BraveUpdate.exe (PID: 1948)
      • wmpnscfg.exe (PID: 2244)
      • BraveUpdate.exe (PID: 2032)
    • Reads the computer name

      • BraveUpdate.exe (PID: 4000)
      • BraveUpdate.exe (PID: 752)
      • BraveUpdate.exe (PID: 2032)
      • BraveUpdate.exe (PID: 372)
      • BraveUpdate.exe (PID: 1112)
      • BraveUpdate.exe (PID: 2304)
      • BraveUpdate.exe (PID: 1948)
      • BraveUpdate.exe (PID: 316)
      • wmpnscfg.exe (PID: 2244)
    • Reads the machine GUID from the registry

      • BraveUpdate.exe (PID: 4000)
      • BraveUpdate.exe (PID: 752)
      • BraveUpdate.exe (PID: 2304)
      • BraveUpdate.exe (PID: 1112)
      • BraveUpdate.exe (PID: 1948)
      • BraveUpdate.exe (PID: 316)
    • Create files in a temporary directory

      • BraveBrowserSetup-BRV011 (1).exe (PID: 3984)
    • Creates files in the program directory

      • BraveUpdateSetup.exe (PID: 1036)
      • BraveUpdate.exe (PID: 752)
      • BraveUpdate.exe (PID: 372)
      • BraveUpdate.exe (PID: 1112)
      • BraveUpdate.exe (PID: 2304)
      • BraveUpdate.exe (PID: 2032)
      • BraveUpdate.exe (PID: 1948)
      • BraveUpdate.exe (PID: 316)
    • Checks proxy server information

      • BraveUpdate.exe (PID: 2304)
    • Reads the software policy settings

      • BraveUpdate.exe (PID: 316)
      • BraveUpdate.exe (PID: 1948)
      • BraveUpdate.exe (PID: 1112)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2244)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:26 08:43:12+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 105472
InitializedDataSize: 1150976
UninitializedDataSize: -
EntryPoint: 0x6ee4
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.361.149
ProductVersionNumber: 1.3.361.149
FileFlagsMask: 0x003f
FileFlags: Private build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BraveSoftware Inc.
FileDescription: BraveSoftware Update Setup
FileVersion: 1.3.361.149
InternalName: BraveSoftware Update Setup
OriginalFileName: BraveUpdateSetup.exe
ProductName: BraveSoftware Update
ProductVersion: 1.3.361.149
LanguageId: en
PrivateBuild: -
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
11
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bravebrowsersetup-brv011 (1).exe braveupdate.exe no specs braveupdatesetup.exe braveupdate.exe braveupdate.exe no specs braveupdate.exe no specs braveupdate.exe braveupdate.exe no specs braveupdate.exe braveupdate.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /svcC:\Program Files\BraveSoftware\Update\BraveUpdate.exe
services.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
372"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regserverC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
752"C:\Program Files\BraveSoftware\Temp\GUM5B52.tmp\BraveUpdate.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevatedC:\Program Files\BraveSoftware\Temp\GUM5B52.tmp\BraveUpdate.exe
BraveUpdateSetup.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\temp\gum5b52.tmp\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1036"C:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveUpdateSetup.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveUpdateSetup.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update Setup
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\users\admin\appdata\local\temp\gum51db.tmp\braveupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1112"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTQ5IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjE0OSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3N0ZBQzRCOC1EMUFGLTRFRDItQjU1Mi0zQ0I1ODUyMDJFMDB9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7RjY2M0YzRUQtMTJGNy00ODI0LTlDRjktQjMyOTM2MUUwRjE3fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QjEzMUM5MzUtOUJFNi00MURBLTk1OTktMUY3NzZCRUI4MDE5fSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjM2MS4xNDkiIGxhbmc9IiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGluc3RhbGxfdGltZV9tcz0iMjIzNCIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1948"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTQ5IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjE0OSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3N0ZBQzRCOC1EMUFGLTRFRDItQjU1Mi0zQ0I1ODUyMDJFMDB9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7RTVDNzkwRDgtOEVBRS00ODEyLTkyMEEtMEEzNkIyNjAyOEMzfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QUZFNkE0NjItQzU3NC00QjhBLUFGNDMtNENDNjBERjQ1NjNCfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iIiBhcD0icmVsZWFzZSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiIgaW5zdGFsbGFnZT0iLTEiIGluc3RhbGxkYXRlPSItMSI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjAiIGVycm9yY29kZT0iLTIxNDcyMTk0NDciIGV4dHJhY29kZTE9IjI2ODQzNTQ1OSIgdXBkYXRlX2NoZWNrX3RpbWVfbXM9IjE0MjIiLz48L2FwcD48L3JlcXVlc3Q-C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2032"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regsvcC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2244"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2304"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /handoff "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installsource taggedmi /sessionid "{77FAC4B8-D1AF-4ED2-B552-3CB585202E00}"C:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3984"C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV011 (1).exe" C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV011 (1).exe
explorer.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
MEDIUM
Description:
BraveSoftware Update Setup
Exit code:
2147747849
Version:
1.3.361.149
Modules
Images
c:\users\admin\appdata\local\temp\bravebrowsersetup-brv011 (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
14 482
Read events
14 264
Write events
150
Delete events
68

Modification events

(PID) Process:(3984) BraveBrowserSetup-BRV011 (1).exeKey:HKEY_CURRENT_USER\Software\BraveSoftware\Promo
Operation:writeName:StubInstallerPath
Value:
C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV011 (1).exe
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:path
Value:
C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:UninstallCmdLine
Value:
"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /uninstall
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.149
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:name
Value:
Brave Update
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\ClientState\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.149
(PID) Process:(752) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BraveUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(2032) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:uid
Value:
(PID) Process:(2032) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:old-uid
Value:
(PID) Process:(2032) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BraveUpdate.exe
Operation:writeName:AppID
Value:
{08F15E98-0442-45D3-82F1-F67495CC51EB}
Executable files
216
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\psuser_arm64.dllexecutable
MD5:F9CAB4C9AE6CBB1C6CAA3F9E8A728BF9
SHA256:00CB491988516481070FC8D3CB63E6AA32F79616759E5388076B822FC75F0EF4
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveCrashHandler64.exeexecutable
MD5:C76935671FF1C0E2AD8EB7A012851188
SHA256:44265556FD4C1346AB86E7DB6FE8E6E3BA48933CF683B813AA6D0D204F60928B
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveUpdateOnDemand.exeexecutable
MD5:C4697746B695BD9A282E5023882DF464
SHA256:FDA78765E83DC0A334E1109376FDC4F67A8F16C97DABFBF2EB7A3C8093B334B8
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveUpdateCore.exeexecutable
MD5:40828ACD80ED13C5791E1D0DC655CF5E
SHA256:B922DC349DBDC5223570CD607DE5709485131AEA6A24CB3A8B04BE184C991E17
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveCrashHandlerArm64.exeexecutable
MD5:A8E5AEC9E74C05CD7601A7F95272D0DB
SHA256:90019F073CACB9FAB365764E52CC39B17F3A58D9B3543B53AFC827866C1113CC
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveUpdateComRegisterShellArm64.exeexecutable
MD5:33614B5085EADFE347CA3B88371BD236
SHA256:620B9C5150AA96829B80F913F444AE014AC6C1588682DE286A9936B2D6F702AE
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\goopdateres_am.dllexecutable
MD5:2900AD6AE4D6D0C86F0838A92A18E53E
SHA256:BB92494102D7FCF63899AE0786B3240F4CF55527178EA5220AEEF1280F656284
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\BraveCrashHandler.exeexecutable
MD5:7EE62CF2A4201EF4343F281A4A05AE1F
SHA256:C441EF51A2B1A01D40E1DAAB3ECC6E5CB826874F51BAB7B601610B4A0FC9671B
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\psuser.dllexecutable
MD5:26E4EC6DDD5F991F7C9EF4F48AF30B1C
SHA256:ACF3BD0AD0F94E1A26AE0B49E977A5C6D85584A18651A07157050A451B994922
3984BraveBrowserSetup-BRV011 (1).exeC:\Users\admin\AppData\Local\Temp\GUM51DB.tmp\psuser_64.dllexecutable
MD5:5ADBD78F2E217ED7F7EDDE5C35F4A95D
SHA256:A9B47E003A81BF0414A77B5721D7E8E9AFD1ACAC7FE19E376E0332BCDBDBA58D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1112
BraveUpdate.exe
13.32.121.70:443
updates.bravesoftware.com
AMAZON-02
US
unknown
4
System
192.168.100.255:137
whitelisted
316
BraveUpdate.exe
13.32.121.70:443
updates.bravesoftware.com
AMAZON-02
US
unknown
1948
BraveUpdate.exe
13.32.121.70:443
updates.bravesoftware.com
AMAZON-02
US
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
updates.bravesoftware.com
  • 13.32.121.70
  • 13.32.121.47
  • 13.32.121.6
  • 13.32.121.124
shared
dl.brave.com
unknown

Threats

No threats detected
No debug info