File name:

BraveBrowserSetup-BRV010.exe

Full analysis: https://app.any.run/tasks/cc70ce49-03ef-4465-9ae3-7d5e13b78137
Verdict: Malicious activity
Analysis date: June 12, 2024, 20:05:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F7284DACD9314C4B9ACA730B0DD12278

SHA1:

3C772F75CA632813EEE80BA14E71447B9523BA52

SHA256:

B50D5FFAAFA1F3367773029B0BFC39915CF83CEF76FE01145272D6B6861073F8

SSDEEP:

49152:stxo1PX+Xyhif8dfGP1YrAQmAzbNN851WLQkGAbzeLmbApACdrfw/7wDG563755B:sQXe+M8xGP1YDmAzb4ExzeLmbNkjw/7w

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BraveBrowserSetup-BRV010.exe (PID: 3964)
      • BraveUpdate.exe (PID: 2108)
      • BraveUpdateSetup.exe (PID: 2104)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BraveUpdateSetup.exe (PID: 2104)
      • BraveUpdate.exe (PID: 2108)
      • BraveBrowserSetup-BRV010.exe (PID: 3964)
    • Starts itself from another location

      • BraveUpdate.exe (PID: 2108)
    • Disables SEHOP

      • BraveUpdate.exe (PID: 2108)
    • Creates/Modifies COM task schedule object

      • BraveUpdate.exe (PID: 2028)
    • Reads the Internet Settings

      • BraveUpdate.exe (PID: 336)
      • BraveUpdate.exe (PID: 2204)
    • Executes as Windows Service

      • BraveUpdate.exe (PID: 304)
    • Reads security settings of Internet Explorer

      • BraveUpdate.exe (PID: 2204)
    • Reads settings of System Certificates

      • BraveUpdate.exe (PID: 336)
    • Application launched itself

      • BraveUpdate.exe (PID: 304)
  • INFO

    • Checks supported languages

      • BraveUpdate.exe (PID: 3980)
      • BraveBrowserSetup-BRV010.exe (PID: 3964)
      • BraveUpdateSetup.exe (PID: 2104)
      • BraveUpdate.exe (PID: 2108)
      • BraveUpdate.exe (PID: 1136)
      • BraveUpdate.exe (PID: 2028)
      • BraveUpdate.exe (PID: 2204)
      • BraveUpdate.exe (PID: 336)
      • BraveUpdate.exe (PID: 304)
      • BraveUpdate.exe (PID: 2008)
      • wmpnscfg.exe (PID: 1824)
    • Create files in a temporary directory

      • BraveBrowserSetup-BRV010.exe (PID: 3964)
    • Creates files in the program directory

      • BraveUpdateSetup.exe (PID: 2104)
      • BraveUpdate.exe (PID: 2108)
      • BraveUpdate.exe (PID: 1136)
      • BraveUpdate.exe (PID: 2028)
      • BraveUpdate.exe (PID: 336)
      • BraveUpdate.exe (PID: 2204)
      • BraveUpdate.exe (PID: 304)
      • BraveUpdate.exe (PID: 2008)
    • Reads the computer name

      • BraveUpdate.exe (PID: 2108)
      • BraveUpdate.exe (PID: 1136)
      • BraveUpdate.exe (PID: 2204)
      • BraveUpdate.exe (PID: 336)
      • BraveUpdate.exe (PID: 2028)
      • BraveUpdate.exe (PID: 304)
      • BraveUpdate.exe (PID: 2008)
      • wmpnscfg.exe (PID: 1824)
      • BraveUpdate.exe (PID: 3980)
    • Reads the machine GUID from the registry

      • BraveUpdate.exe (PID: 2108)
      • BraveUpdate.exe (PID: 2204)
      • BraveUpdate.exe (PID: 304)
      • BraveUpdate.exe (PID: 336)
      • BraveUpdate.exe (PID: 2008)
      • BraveUpdate.exe (PID: 3980)
    • Checks proxy server information

      • BraveUpdate.exe (PID: 2204)
    • Reads the software policy settings

      • BraveUpdate.exe (PID: 336)
      • BraveUpdate.exe (PID: 304)
      • BraveUpdate.exe (PID: 2008)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1824)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:05:31 04:18:08+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.4
CodeSize: 105984
InitializedDataSize: 1149440
UninitializedDataSize: -
EntryPoint: 0x6f17
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.361.149
ProductVersionNumber: 1.3.361.149
FileFlagsMask: 0x003f
FileFlags: Private build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BraveSoftware Inc.
FileDescription: BraveSoftware Update Setup
FileVersion: 1.3.361.149
InternalName: BraveSoftware Update Setup
OriginalFileName: BraveUpdateSetup.exe
ProductName: BraveSoftware Update
ProductVersion: 1.3.361.149
LanguageId: en
PrivateBuild: -
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
11
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bravebrowsersetup-brv010.exe braveupdate.exe no specs braveupdatesetup.exe braveupdate.exe braveupdate.exe no specs braveupdate.exe no specs braveupdate.exe braveupdate.exe no specs braveupdate.exe braveupdate.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /svcC:\Program Files\BraveSoftware\Update\BraveUpdate.exe
services.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
336"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTQ5IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjE0OSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3N0ZBQzRCOC1EMUFGLTRFRDItQjU1Mi0zQ0I1ODUyMDJFMDB9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7RjY2M0YzRUQtMTJGNy00ODI0LTlDRjktQjMyOTM2MUUwRjE3fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QjEzMUM5MzUtOUJFNi00MURBLTk1OTktMUY3NzZCRUI4MDE5fSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjM2MS4xNDkiIGxhbmc9IiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGluc3RhbGxfdGltZV9tcz0iMTM0MyIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1136"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regsvcC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1824"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2008"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTQ5IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjE0OSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3N0ZBQzRCOC1EMUFGLTRFRDItQjU1Mi0zQ0I1ODUyMDJFMDB9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7RTVDNzkwRDgtOEVBRS00ODEyLTkyMEEtMEEzNkIyNjAyOEMzfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QUZFNkE0NjItQzU3NC00QjhBLUFGNDMtNENDNjBERjQ1NjNCfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iIiBhcD0icmVsZWFzZSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiIgaW5zdGFsbGFnZT0iLTEiIGluc3RhbGxkYXRlPSItMSI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjAiIGVycm9yY29kZT0iLTIxNDcyMTk0NDciIGV4dHJhY29kZTE9IjI2ODQzNTQ1OSIgdXBkYXRlX2NoZWNrX3RpbWVfbXM9IjE0MDciLz48L2FwcD48L3JlcXVlc3Q-C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2028"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regserverC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2104"C:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveUpdateSetup.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveUpdateSetup.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update Setup
Version:
1.3.361.149
Modules
Images
c:\users\admin\appdata\local\temp\gum3182.tmp\braveupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2108"C:\Program Files\BraveSoftware\Temp\GUM3A8B.tmp\BraveUpdate.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevatedC:\Program Files\BraveSoftware\Temp\GUM3A8B.tmp\BraveUpdate.exe
BraveUpdateSetup.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\temp\gum3a8b.tmp\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2204"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /handoff "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installsource taggedmi /sessionid "{77FAC4B8-D1AF-4ED2-B552-3CB585202E00}"C:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3964"C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV010.exe" C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV010.exe
explorer.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
MEDIUM
Description:
BraveSoftware Update Setup
Version:
1.3.361.149
Modules
Images
c:\users\admin\appdata\local\temp\bravebrowsersetup-brv010.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
14 409
Read events
14 194
Write events
149
Delete events
66

Modification events

(PID) Process:(3964) BraveBrowserSetup-BRV010.exeKey:HKEY_CURRENT_USER\Software\BraveSoftware\Promo
Operation:writeName:StubInstallerPath
Value:
C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV010.exe
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:path
Value:
C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:UninstallCmdLine
Value:
"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /uninstall
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.149
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:name
Value:
Brave Update
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\ClientState\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.149
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BraveUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(1136) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:uid
Value:
(PID) Process:(1136) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:old-uid
Value:
(PID) Process:(1136) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BraveUpdate.exe
Operation:writeName:AppID
Value:
{08F15E98-0442-45D3-82F1-F67495CC51EB}
Executable files
216
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveUpdateComRegisterShell64.exeexecutable
MD5:E1B88B573EC7BB96C450A2D9DD23DBE7
SHA256:4417306699CA5D2265C0BCF312122883BF4CD44F2B78FA524E4DC15B76FD617C
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\psmachine_64.dllexecutable
MD5:08E8BD1AE66D939AE6580C0A9B388D56
SHA256:23A7C1B5C0917EDF14491160753FDC182938E91983455F08E5D19805FE8DD0E7
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\psuser_64.dllexecutable
MD5:D14D0DB0D61D7007AC82681C3094EA44
SHA256:02A062DC4957CB265A240F8A423B06D6FD43D251A1E7A7740D1B5AD0DDDBD982
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveUpdateBroker.exeexecutable
MD5:26F49564EF9210266F602AC5DC9F4C1A
SHA256:4C5633524C743B6DED0C75FF2F6046A3711FB68A51EDB7B791E1B6999DC40EDA
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveUpdateOnDemand.exeexecutable
MD5:C232A87A7BCEC860C121D0B546F4A340
SHA256:D8AD6B93EC905EA7BAD1E041C30C887A034A1043FC02C31BB60D191E317FDC44
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveUpdateCore.exeexecutable
MD5:446B52AB736570578F54BF7EB314C86B
SHA256:E4E87B90282FB321FE596CD98F7CFC18950BDB6092C5B7618FB5E3BA92847A13
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\psmachine.dllexecutable
MD5:890AEE757C78E88D3AAC3EC98687B4D1
SHA256:0E891D9E4AF237AE2B7D3844B80B1243E6862173E50BA95449F747D15EBE7932
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveCrashHandler64.exeexecutable
MD5:5A0B2C88D214E16B4E1092842D8EF470
SHA256:F69597EC823BE88EEB7148FAC9387A6025DBCBDC665C1806DCC566C9D2D1BDCA
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\psuser.dllexecutable
MD5:A60DDA424FC10B2BD7A21772E34FEC0F
SHA256:FC7C316B46FF0728D6648094876621B3E030875BA51611F45DC2420D833D1086
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\goopdateres_am.dllexecutable
MD5:4BFCF96BCA30C7596FDC8077D3F1B497
SHA256:DC6BCB120D3B92C4E91AB14466479530F4143AFF5D10911F1106D5C465AD1106
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
336
BraveUpdate.exe
18.66.196.102:443
updates.bravesoftware.com
US
unknown
304
BraveUpdate.exe
18.66.196.102:443
updates.bravesoftware.com
US
unknown
2008
BraveUpdate.exe
18.66.196.102:443
updates.bravesoftware.com
US
unknown

DNS requests

Domain
IP
Reputation
updates.bravesoftware.com
  • 18.66.196.102
  • 18.66.196.60
  • 18.66.196.18
  • 18.66.196.116
shared
dl.brave.com
unknown

Threats

No threats detected
No debug info