File name:

BraveBrowserSetup-BRV010.exe

Full analysis: https://app.any.run/tasks/cc70ce49-03ef-4465-9ae3-7d5e13b78137
Verdict: Malicious activity
Analysis date: June 12, 2024, 20:05:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F7284DACD9314C4B9ACA730B0DD12278

SHA1:

3C772F75CA632813EEE80BA14E71447B9523BA52

SHA256:

B50D5FFAAFA1F3367773029B0BFC39915CF83CEF76FE01145272D6B6861073F8

SSDEEP:

49152:stxo1PX+Xyhif8dfGP1YrAQmAzbNN851WLQkGAbzeLmbApACdrfw/7wDG563755B:sQXe+M8xGP1YDmAzb4ExzeLmbNkjw/7w

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • BraveBrowserSetup-BRV010.exe (PID: 3964)
      • BraveUpdateSetup.exe (PID: 2104)
      • BraveUpdate.exe (PID: 2108)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • BraveBrowserSetup-BRV010.exe (PID: 3964)
      • BraveUpdateSetup.exe (PID: 2104)
      • BraveUpdate.exe (PID: 2108)
    • Creates/Modifies COM task schedule object

      • BraveUpdate.exe (PID: 2028)
    • Reads settings of System Certificates

      • BraveUpdate.exe (PID: 336)
    • Reads security settings of Internet Explorer

      • BraveUpdate.exe (PID: 2204)
    • Reads the Internet Settings

      • BraveUpdate.exe (PID: 2204)
      • BraveUpdate.exe (PID: 336)
    • Executes as Windows Service

      • BraveUpdate.exe (PID: 304)
    • Application launched itself

      • BraveUpdate.exe (PID: 304)
    • Starts itself from another location

      • BraveUpdate.exe (PID: 2108)
    • Disables SEHOP

      • BraveUpdate.exe (PID: 2108)
  • INFO

    • Checks supported languages

      • BraveBrowserSetup-BRV010.exe (PID: 3964)
      • BraveUpdate.exe (PID: 3980)
      • BraveUpdateSetup.exe (PID: 2104)
      • BraveUpdate.exe (PID: 2108)
      • BraveUpdate.exe (PID: 2028)
      • BraveUpdate.exe (PID: 336)
      • BraveUpdate.exe (PID: 2204)
      • BraveUpdate.exe (PID: 304)
      • BraveUpdate.exe (PID: 2008)
      • wmpnscfg.exe (PID: 1824)
      • BraveUpdate.exe (PID: 1136)
    • Create files in a temporary directory

      • BraveBrowserSetup-BRV010.exe (PID: 3964)
    • Reads the computer name

      • BraveUpdate.exe (PID: 3980)
      • BraveUpdate.exe (PID: 2108)
      • BraveUpdate.exe (PID: 2028)
      • BraveUpdate.exe (PID: 1136)
      • BraveUpdate.exe (PID: 336)
      • BraveUpdate.exe (PID: 2204)
      • BraveUpdate.exe (PID: 304)
      • BraveUpdate.exe (PID: 2008)
      • wmpnscfg.exe (PID: 1824)
    • Reads the machine GUID from the registry

      • BraveUpdate.exe (PID: 3980)
      • BraveUpdate.exe (PID: 2108)
      • BraveUpdate.exe (PID: 304)
      • BraveUpdate.exe (PID: 336)
      • BraveUpdate.exe (PID: 2204)
      • BraveUpdate.exe (PID: 2008)
    • Creates files in the program directory

      • BraveUpdateSetup.exe (PID: 2104)
      • BraveUpdate.exe (PID: 1136)
      • BraveUpdate.exe (PID: 2028)
      • BraveUpdate.exe (PID: 336)
      • BraveUpdate.exe (PID: 2204)
      • BraveUpdate.exe (PID: 304)
      • BraveUpdate.exe (PID: 2008)
      • BraveUpdate.exe (PID: 2108)
    • Checks proxy server information

      • BraveUpdate.exe (PID: 2204)
    • Reads the software policy settings

      • BraveUpdate.exe (PID: 336)
      • BraveUpdate.exe (PID: 304)
      • BraveUpdate.exe (PID: 2008)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1824)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:05:31 04:18:08+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.4
CodeSize: 105984
InitializedDataSize: 1149440
UninitializedDataSize: -
EntryPoint: 0x6f17
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.361.149
ProductVersionNumber: 1.3.361.149
FileFlagsMask: 0x003f
FileFlags: Private build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: BraveSoftware Inc.
FileDescription: BraveSoftware Update Setup
FileVersion: 1.3.361.149
InternalName: BraveSoftware Update Setup
OriginalFileName: BraveUpdateSetup.exe
ProductName: BraveSoftware Update
ProductVersion: 1.3.361.149
LanguageId: en
PrivateBuild: -
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
11
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
start bravebrowsersetup-brv010.exe braveupdate.exe no specs braveupdatesetup.exe braveupdate.exe braveupdate.exe no specs braveupdate.exe no specs braveupdate.exe braveupdate.exe no specs braveupdate.exe braveupdate.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /svcC:\Program Files\BraveSoftware\Update\BraveUpdate.exe
services.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
336"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTQ5IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjE0OSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3N0ZBQzRCOC1EMUFGLTRFRDItQjU1Mi0zQ0I1ODUyMDJFMDB9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7RjY2M0YzRUQtMTJGNy00ODI0LTlDRjktQjMyOTM2MUUwRjE3fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QjEzMUM5MzUtOUJFNi00MURBLTk1OTktMUY3NzZCRUI4MDE5fSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjM2MS4xNDkiIGxhbmc9IiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGluc3RhbGxfdGltZV9tcz0iMTM0MyIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1136"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regsvcC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1824"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2008"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTQ5IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjE0OSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9Ins3N0ZBQzRCOC1EMUFGLTRFRDItQjU1Mi0zQ0I1ODUyMDJFMDB9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7RTVDNzkwRDgtOEVBRS00ODEyLTkyMEEtMEEzNkIyNjAyOEMzfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSIzIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiLz48YXBwIGFwcGlkPSJ7QUZFNkE0NjItQzU3NC00QjhBLUFGNDMtNENDNjBERjQ1NjNCfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iIiBhcD0icmVsZWFzZSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiIgaW5zdGFsbGFnZT0iLTEiIGluc3RhbGxkYXRlPSItMSI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjAiIGVycm9yY29kZT0iLTIxNDcyMTk0NDciIGV4dHJhY29kZTE9IjI2ODQzNTQ1OSIgdXBkYXRlX2NoZWNrX3RpbWVfbXM9IjE0MDciLz48L2FwcD48L3JlcXVlc3Q-C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
BraveUpdate.exe
User:
SYSTEM
Company:
BraveSoftware Inc.
Integrity Level:
SYSTEM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2028"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /regserverC:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2104"C:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveUpdateSetup.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveUpdateSetup.exe
BraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update Setup
Version:
1.3.361.149
Modules
Images
c:\users\admin\appdata\local\temp\gum3182.tmp\braveupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2108"C:\Program Files\BraveSoftware\Temp\GUM3A8B.tmp\BraveUpdate.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevatedC:\Program Files\BraveSoftware\Temp\GUM3A8B.tmp\BraveUpdate.exe
BraveUpdateSetup.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\temp\gum3a8b.tmp\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2204"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /handoff "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installsource taggedmi /sessionid "{77FAC4B8-D1AF-4ED2-B552-3CB585202E00}"C:\Program Files\BraveSoftware\Update\BraveUpdate.exeBraveUpdate.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
HIGH
Description:
BraveSoftware Update
Version:
1.3.361.149
Modules
Images
c:\program files\bravesoftware\update\braveupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3964"C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV010.exe" C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV010.exe
explorer.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
MEDIUM
Description:
BraveSoftware Update Setup
Version:
1.3.361.149
Modules
Images
c:\users\admin\appdata\local\temp\bravebrowsersetup-brv010.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
14 409
Read events
14 194
Write events
149
Delete events
66

Modification events

(PID) Process:(3964) BraveBrowserSetup-BRV010.exeKey:HKEY_CURRENT_USER\Software\BraveSoftware\Promo
Operation:writeName:StubInstallerPath
Value:
C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV010.exe
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:path
Value:
C:\Program Files\BraveSoftware\Update\BraveUpdate.exe
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:writeName:UninstallCmdLine
Value:
"C:\Program Files\BraveSoftware\Update\BraveUpdate.exe" /uninstall
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.149
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:name
Value:
Brave Update
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update\ClientState\{B131C935-9BE6-41DA-9599-1F776BEB8019}
Operation:writeName:pv
Value:
1.3.361.149
(PID) Process:(2108) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BraveUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(1136) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:uid
Value:
(PID) Process:(1136) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\BraveSoftware\Update
Operation:delete valueName:old-uid
Value:
(PID) Process:(1136) BraveUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BraveUpdate.exe
Operation:writeName:AppID
Value:
{08F15E98-0442-45D3-82F1-F67495CC51EB}
Executable files
216
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveUpdateBroker.exeexecutable
MD5:26F49564EF9210266F602AC5DC9F4C1A
SHA256:4C5633524C743B6DED0C75FF2F6046A3711FB68A51EDB7B791E1B6999DC40EDA
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveUpdateComRegisterShell64.exeexecutable
MD5:E1B88B573EC7BB96C450A2D9DD23DBE7
SHA256:4417306699CA5D2265C0BCF312122883BF4CD44F2B78FA524E4DC15B76FD617C
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\psuser_64.dllexecutable
MD5:D14D0DB0D61D7007AC82681C3094EA44
SHA256:02A062DC4957CB265A240F8A423B06D6FD43D251A1E7A7740D1B5AD0DDDBD982
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\psuser_arm64.dllexecutable
MD5:CCC45B103C654E19D7554F8756473D44
SHA256:E214CC9554C860713C6B25A33206503AD8694A8066902653DBF76050FD48C475
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveCrashHandlerArm64.exeexecutable
MD5:9A7B4118C28A676F1E9CC96B3ECAA502
SHA256:5414F9C3CCBBEE1427CA73EDDFEA795952DFD47F86DA45715492460DDC033842
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\psmachine_arm64.dllexecutable
MD5:FA46EE4BA679FD63DD20802E25D2AB28
SHA256:4A5B59CE00777E4F715C7A476E5E76E47CC39514065E8E00474AFCAEF7733BBC
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\BraveUpdateComRegisterShellArm64.exeexecutable
MD5:872C3539D0E09A3DBA481E917AB95BC0
SHA256:F8955D34C1E9C043B76DFAD0472561BA5B74EAEC7667E461D745F9554E787F68
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\goopdateres_am.dllexecutable
MD5:4BFCF96BCA30C7596FDC8077D3F1B497
SHA256:DC6BCB120D3B92C4E91AB14466479530F4143AFF5D10911F1106D5C465AD1106
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\goopdateres_ar.dllexecutable
MD5:D6CFEC9D78AD35C085B90B31B9D0C391
SHA256:AA5ECD1E8CF81247E38003AA2768A02756C98F6CB0E0015C8EE1D82DDC417195
3964BraveBrowserSetup-BRV010.exeC:\Users\admin\AppData\Local\Temp\GUM3182.tmp\goopdateres_bg.dllexecutable
MD5:5E7BF512451E8BE7C6730A923E366CA6
SHA256:FC642A0EF0D30990D41695DD322EC8431DC735FC162FB33AA467F6ACC39028F5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
336
BraveUpdate.exe
18.66.196.102:443
updates.bravesoftware.com
US
unknown
304
BraveUpdate.exe
18.66.196.102:443
updates.bravesoftware.com
US
unknown
2008
BraveUpdate.exe
18.66.196.102:443
updates.bravesoftware.com
US
unknown

DNS requests

Domain
IP
Reputation
updates.bravesoftware.com
  • 18.66.196.102
  • 18.66.196.60
  • 18.66.196.18
  • 18.66.196.116
shared
dl.brave.com
unknown

Threats

No threats detected
No debug info