URL:

https://brave.com

Full analysis: https://app.any.run/tasks/71515a64-b335-4089-96b9-c7ad2b6e2129
Verdict: Malicious activity
Analysis date: May 18, 2021, 01:44:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

B9FC7042355EB514FB7457DC56CC098C

SHA1:

18664F013396A51EBD6F6EB9E384A8B81C7AD0F7

SHA256:

BECEBDD01012941FBABADA61A497387D261C4B0B5653B65B68BC9AEA92E6ED0C

SSDEEP:

3:N8a1n:2I

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • BraveBrowserSetup32.exe (PID: 3616)
      • BraveUpdate.exe (PID: 3924)
      • BraveUpdate.exe (PID: 1720)
      • BraveUpdateSetup.exe (PID: 2708)
      • BraveUpdate.exe (PID: 1868)
      • BraveUpdate.exe (PID: 2580)
      • BraveUpdate.exe (PID: 1936)
      • BraveUpdate.exe (PID: 2188)
      • BraveUpdate.exe (PID: 2984)
      • setup.exe (PID: 3096)
      • setup.exe (PID: 3124)
      • BraveUpdate.exe (PID: 3276)
      • BraveUpdateOnDemand.exe (PID: 960)
      • BraveUpdate.exe (PID: 3128)
      • brave.exe (PID: 2560)
      • brave.exe (PID: 3532)
      • brave.exe (PID: 2648)
      • brave.exe (PID: 2100)
      • brave.exe (PID: 324)
      • brave.exe (PID: 3316)
      • brave.exe (PID: 1392)
      • brave.exe (PID: 3840)
      • brave.exe (PID: 2356)
      • brave.exe (PID: 1184)
      • chrmstp.exe (PID: 2608)
      • brave.exe (PID: 2620)
      • chrmstp.exe (PID: 2940)
      • brave.exe (PID: 2468)
      • brave.exe (PID: 2948)
      • brave.exe (PID: 2848)
      • brave.exe (PID: 3244)
      • brave.exe (PID: 3980)
      • brave.exe (PID: 1016)
      • brave.exe (PID: 844)
      • brave.exe (PID: 3212)
      • brave.exe (PID: 648)
      • brave.exe (PID: 1096)
      • brave.exe (PID: 3104)
      • brave.exe (PID: 3228)
      • brave.exe (PID: 2964)
      • brave.exe (PID: 1736)
      • brave.exe (PID: 1476)
      • brave.exe (PID: 2084)
      • brave.exe (PID: 2292)
      • brave.exe (PID: 2768)
      • brave.exe (PID: 2196)
      • brave.exe (PID: 2060)
    • Loads dropped or rewritten executable

      • BraveUpdate.exe (PID: 3924)
      • BraveUpdate.exe (PID: 1720)
      • BraveUpdate.exe (PID: 1868)
      • BraveUpdate.exe (PID: 2580)
      • BraveUpdate.exe (PID: 2188)
      • BraveUpdate.exe (PID: 1936)
      • BraveUpdate.exe (PID: 2984)
      • svchost.exe (PID: 672)
      • BraveUpdate.exe (PID: 3276)
      • BraveUpdate.exe (PID: 3128)
      • brave.exe (PID: 2560)
      • brave.exe (PID: 3532)
      • brave.exe (PID: 2648)
      • brave.exe (PID: 324)
      • brave.exe (PID: 3316)
      • brave.exe (PID: 1392)
      • brave.exe (PID: 3840)
      • brave.exe (PID: 2100)
      • brave.exe (PID: 2356)
      • brave.exe (PID: 1184)
      • brave.exe (PID: 2620)
      • brave.exe (PID: 2468)
      • brave.exe (PID: 2948)
      • brave.exe (PID: 2848)
      • brave.exe (PID: 3980)
      • brave.exe (PID: 3244)
      • brave.exe (PID: 844)
      • brave.exe (PID: 3212)
      • brave.exe (PID: 648)
      • brave.exe (PID: 1096)
      • brave.exe (PID: 3104)
      • brave.exe (PID: 1016)
      • brave.exe (PID: 3228)
      • brave.exe (PID: 2292)
      • brave.exe (PID: 2964)
      • brave.exe (PID: 1476)
      • brave.exe (PID: 1736)
      • brave.exe (PID: 2060)
      • brave.exe (PID: 2768)
      • brave.exe (PID: 2196)
      • brave.exe (PID: 2084)
    • Drops executable file immediately after starts

      • BraveUpdateSetup.exe (PID: 2708)
      • BraveUpdate.exe (PID: 1720)
      • brave_installer-ia32.exe (PID: 3728)
    • Loads the Task Scheduler COM API

      • BraveUpdate.exe (PID: 1720)
    • Changes settings of System certificates

      • BraveUpdate.exe (PID: 1936)
      • BraveUpdate.exe (PID: 2984)
    • Actions looks like stealing of personal data

      • brave_installer-ia32.exe (PID: 3728)
      • BraveUpdate.exe (PID: 3276)
      • brave.exe (PID: 2648)
      • brave.exe (PID: 3532)
      • setup.exe (PID: 3124)
      • brave.exe (PID: 3316)
      • brave.exe (PID: 1392)
      • brave.exe (PID: 3840)
      • brave.exe (PID: 2100)
      • brave.exe (PID: 2356)
      • brave.exe (PID: 1184)
      • brave.exe (PID: 324)
      • brave.exe (PID: 2620)
      • chrmstp.exe (PID: 2940)
      • brave.exe (PID: 2468)
      • brave.exe (PID: 2948)
      • brave.exe (PID: 2848)
      • brave.exe (PID: 3244)
      • brave.exe (PID: 3980)
      • brave.exe (PID: 648)
      • brave.exe (PID: 1016)
      • brave.exe (PID: 844)
      • brave.exe (PID: 2560)
      • brave.exe (PID: 3212)
      • brave.exe (PID: 1096)
      • chrmstp.exe (PID: 2608)
      • brave.exe (PID: 3228)
      • brave.exe (PID: 2964)
      • brave.exe (PID: 2292)
      • brave.exe (PID: 2084)
      • brave.exe (PID: 1476)
      • brave.exe (PID: 3104)
      • brave.exe (PID: 1736)
      • brave.exe (PID: 2060)
      • brave.exe (PID: 2196)
      • brave.exe (PID: 2768)
    • Changes the autorun value in the registry

      • setup.exe (PID: 3124)
    • Steals credentials from Web Browsers

      • brave.exe (PID: 2560)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 3784)
      • chrome.exe (PID: 3192)
      • BraveBrowserSetup32.exe (PID: 3616)
      • BraveUpdate.exe (PID: 3924)
      • BraveUpdateSetup.exe (PID: 2708)
      • BraveUpdate.exe (PID: 1720)
      • brave_installer-ia32.exe (PID: 3728)
      • setup.exe (PID: 3124)
      • brave.exe (PID: 2560)
    • Drops a file that was compiled in debug mode

      • chrome.exe (PID: 3784)
      • chrome.exe (PID: 3192)
      • BraveUpdate.exe (PID: 3924)
      • BraveBrowserSetup32.exe (PID: 3616)
      • BraveUpdateSetup.exe (PID: 2708)
      • BraveUpdate.exe (PID: 1720)
      • brave_installer-ia32.exe (PID: 3728)
      • setup.exe (PID: 3124)
    • Drops a file with a compile date too recent

      • BraveBrowserSetup32.exe (PID: 3616)
      • chrome.exe (PID: 3192)
      • chrome.exe (PID: 3784)
      • BraveUpdate.exe (PID: 3924)
      • BraveUpdateSetup.exe (PID: 2708)
      • BraveUpdate.exe (PID: 1720)
      • brave_installer-ia32.exe (PID: 3728)
      • setup.exe (PID: 3124)
    • Creates files in the program directory

      • BraveUpdateSetup.exe (PID: 2708)
      • BraveUpdate.exe (PID: 1720)
      • BraveUpdate.exe (PID: 2984)
      • brave_installer-ia32.exe (PID: 3728)
      • setup.exe (PID: 3124)
    • Creates a directory in Program Files

      • BraveUpdateSetup.exe (PID: 2708)
      • BraveUpdate.exe (PID: 1720)
      • BraveUpdate.exe (PID: 2984)
      • brave_installer-ia32.exe (PID: 3728)
      • setup.exe (PID: 3124)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 3192)
    • Disables SEHOP

      • BraveUpdate.exe (PID: 1720)
    • Starts itself from another location

      • BraveUpdate.exe (PID: 1720)
    • Creates/Modifies COM task schedule object

      • BraveUpdate.exe (PID: 2580)
    • Executed as Windows Service

      • BraveUpdate.exe (PID: 2984)
    • Adds / modifies Windows certificates

      • BraveUpdate.exe (PID: 1936)
      • BraveUpdate.exe (PID: 2984)
    • Application launched itself

      • setup.exe (PID: 3124)
      • BraveUpdate.exe (PID: 2984)
      • brave.exe (PID: 2560)
      • chrmstp.exe (PID: 2608)
    • Drops a file with too old compile date

      • setup.exe (PID: 3124)
    • Changes default file association

      • setup.exe (PID: 3124)
    • Creates a software uninstall entry

      • setup.exe (PID: 3124)
    • Creates files in the user directory

      • setup.exe (PID: 3124)
      • brave.exe (PID: 2560)
    • Executed via COM

      • BraveUpdateOnDemand.exe (PID: 960)
  • INFO

    • Changes internet zones settings

      • iexplore.exe (PID: 1912)
    • Reads internet explorer settings

      • iexplore.exe (PID: 1748)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 1912)
    • Application launched itself

      • iexplore.exe (PID: 1912)
      • chrome.exe (PID: 3192)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 1912)
      • chrome.exe (PID: 3192)
      • brave.exe (PID: 2560)
    • Reads the hosts file

      • chrome.exe (PID: 3784)
      • chrome.exe (PID: 3192)
      • brave.exe (PID: 2560)
      • brave.exe (PID: 324)
    • Changes settings of System certificates

      • iexplore.exe (PID: 1912)
    • Manual execution by user

      • chrome.exe (PID: 3192)
    • Creates files in the user directory

      • iexplore.exe (PID: 1912)
    • Dropped object may contain Bitcoin addresses

      • setup.exe (PID: 3124)
    • Dropped object may contain TOR URL's

      • setup.exe (PID: 3124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
84
Malicious processes
46
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs bravebrowsersetup32.exe braveupdate.exe chrome.exe no specs braveupdatesetup.exe braveupdate.exe braveupdate.exe no specs braveupdate.exe no specs braveupdate.exe braveupdate.exe no specs braveupdate.exe chrome.exe no specs chrome.exe no specs brave_installer-ia32.exe setup.exe setup.exe no specs braveupdateondemand.exe no specs braveupdate.exe braveupdate.exe svchost.exe no specs brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe chrmstp.exe chrmstp.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe brave.exe

Process information

PID
CMD
Path
Indicators
Parent process
252"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1044,3120543078726495830,15516331788618405329,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=4351406391188436888 --mojo-platform-channel-handle=4760 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
324"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1124,11984642901785131676,3406294281416360661,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,IdleDetection,LangClientHintHeader,NetworkTimeServiceQuerying,NotificationTriggers,SafeBrowsingEnhancedProtection,SafeBrowsingEnhancedProtectionMessageInInterstitials,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,WebOTP --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1480 /prefetch:8C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
brave.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
MEDIUM
Description:
Brave Browser
Exit code:
0
Version:
90.1.24.85
Modules
Images
c:\program files\bravesoftware\brave-browser\application\brave.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\bravesoftware\brave-browser\application\90.1.24.85\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
444"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1044,3120543078726495830,15516331788618405329,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=4149828496204424587 --mojo-platform-channel-handle=4668 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
648"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=1124,11984642901785131676,3406294281416360661,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,IdleDetection,LangClientHintHeader,NetworkTimeServiceQuerying,NotificationTriggers,SafeBrowsingEnhancedProtection,SafeBrowsingEnhancedProtectionMessageInInterstitials,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,WebOTP --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1828 /prefetch:8C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
brave.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
MEDIUM
Description:
Brave Browser
Exit code:
0
Version:
90.1.24.85
Modules
Images
c:\program files\bravesoftware\brave-browser\application\brave.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\bravesoftware\brave-browser\application\90.1.24.85\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
668"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1044,3120543078726495830,15516331788618405329,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=12436499934922725203 --mojo-platform-channel-handle=5012 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
672C:\Windows\system32\svchost.exe -k RPCSSC:\Windows\System32\svchost.exeservices.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\rpcepmap.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\secur32.dll
764"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=1044,3120543078726495830,15516331788618405329,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=14792888061913692417 --mojo-platform-channel-handle=3372 --ignored=" --type=renderer " /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
75.0.3770.100
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\75.0.3770.100\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
844"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1124,11984642901785131676,3406294281416360661,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,IdleDetection,LangClientHintHeader,NetworkTimeServiceQuerying,NotificationTriggers,SafeBrowsingEnhancedProtection,SafeBrowsingEnhancedProtectionMessageInInterstitials,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,WebOTP --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=4088 /prefetch:8C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
brave.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
LOW
Description:
Brave Browser
Exit code:
0
Version:
90.1.24.85
Modules
Images
c:\program files\bravesoftware\brave-browser\application\brave.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\bravesoftware\brave-browser\application\90.1.24.85\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
960"C:\Program Files\BraveSoftware\Update\1.3.101.0\BraveUpdateOnDemand.exe" -EmbeddingC:\Program Files\BraveSoftware\Update\1.3.101.0\BraveUpdateOnDemand.exesvchost.exe
User:
admin
Company:
BraveSoftware Inc.
Integrity Level:
MEDIUM
Description:
BraveSoftware Update
Exit code:
0
Version:
1.3.101.0
Modules
Images
c:\program files\bravesoftware\update\1.3.101.0\braveupdateondemand.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1016"C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=1124,11984642901785131676,3406294281416360661,131072 --enable-features=AutoupgradeMixedContent,LegacyTLSEnforced,PasswordImport,PrefetchPrivacyChanges,ReducedReferrerGranularity,SafetyTip,WebUIDarkMode,WinrtGeolocationImplementation --disable-features=AutofillEnableAccountWalletStorage,AutofillServerCommunication,DirectSockets,EnableProfilePickerOnStartup,IdleDetection,LangClientHintHeader,NetworkTimeServiceQuerying,NotificationTriggers,SafeBrowsingEnhancedProtection,SafeBrowsingEnhancedProtectionMessageInInterstitials,SharingQRCodeGenerator,SignedExchangePrefetchCacheForNavigations,SignedExchangeSubresourcePrefetch,SubresourceWebBundles,TabHoverCards,TextFragmentAnchor,WebOTP --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=3872 /prefetch:8C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
brave.exe
User:
admin
Company:
Brave Software, Inc.
Integrity Level:
LOW
Description:
Brave Browser
Exit code:
0
Version:
90.1.24.85
Modules
Images
c:\program files\bravesoftware\brave-browser\application\brave.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\bravesoftware\brave-browser\application\90.1.24.85\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
6 545
Read events
3 719
Write events
2 797
Delete events
29

Modification events

(PID) Process:(1748) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
1833432864
(PID) Process:(1912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30886791
(PID) Process:(1912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(1912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(1912) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
231
Suspicious files
99
Text files
876
Unknown types
99

Dropped files

PID
Process
Filename
Type
1748iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab9629.tmp
MD5:
SHA256:
1748iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar962A.tmp
MD5:
SHA256:
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\QU1RJ31L.htmhtml
MD5:
SHA256:
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\localize.min[1].jstext
MD5:
SHA256:
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\brave-logo[1].svgimage
MD5:
SHA256:
1748iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\644B8874112055B5E195ECB0E8F243A4binary
MD5:
SHA256:
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\ie-compat.min[1].jstext
MD5:
SHA256:
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\detect-platform.en.min[1].jstext
MD5:
SHA256:
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\intel-icon[1].svgimage
MD5:
SHA256:
1748iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\main.min[1].csstext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
84
DNS requests
59
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
403
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ALmz5CcfhgIwbIOXgcWkFQw_20210510.373778619/AIC0QefD6KValk5AwpXQYyk
US
whitelisted
HEAD
200
173.194.165.169:80
http://r3---sn-4g5edney.gvt1.com/edgedl/release2/chrome_component/ALmz5CcfhgIwbIOXgcWkFQw_20210510.373778619/AIC0QefD6KValk5AwpXQYyk?cms_redirect=yes&mh=av&mip=154.16.179.15&mm=28&mn=sn-4g5edney&ms=nvh&mt=1621302182&mv=u&mvi=3&pl=24&shardbypass=yes
US
whitelisted
HEAD
302
142.250.185.238:80
http://redirector.gvt1.com/edgedl/release2/chrome_component/ALmz5CcfhgIwbIOXgcWkFQw_20210510.373778619/AIC0QefD6KValk5AwpXQYyk
US
whitelisted
1912
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
1748
iexplore.exe
GET
200
2.16.186.27:80
http://crl.identrust.com/DSTROOTCAX3CRL.crl
unknown
der
1.16 Kb
whitelisted
1912
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
der
471 b
whitelisted
1912
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8Ull8gIGmZT9XHrHiJQeI%3D
US
der
1.47 Kb
whitelisted
3784
chrome.exe
GET
302
216.58.212.174:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx
US
html
519 b
whitelisted
GET
302
142.250.185.238:80
http://redirector.gvt1.com/edgedl/release2/chrome_component/ALmz5CcfhgIwbIOXgcWkFQw_20210510.373778619/AIC0QefD6KValk5AwpXQYyk
US
html
485 b
whitelisted
GET
206
173.194.165.169:80
http://r3---sn-4g5edney.gvt1.com/edgedl/release2/chrome_component/ALmz5CcfhgIwbIOXgcWkFQw_20210510.373778619/AIC0QefD6KValk5AwpXQYyk?cms_redirect=yes&mh=av&mip=154.16.179.15&mm=28&mn=sn-4g5edney&ms=nvh&mt=1621302182&mv=u&mvi=3&pl=24&shardbypass=yes
US
binary
5.74 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1748
iexplore.exe
151.101.65.32:443
brave.com
Fastly
US
unknown
1748
iexplore.exe
2.16.186.27:80
crl.identrust.com
Akamai International B.V.
whitelisted
1912
iexplore.exe
151.101.65.32:443
brave.com
Fastly
US
unknown
1748
iexplore.exe
151.101.1.32:443
brave.com
Fastly
US
unknown
1912
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
1912
iexplore.exe
13.107.21.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
1912
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
1912
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
3784
chrome.exe
142.250.74.195:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
3784
chrome.exe
142.250.181.237:443
accounts.google.com
Google Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
brave.com
  • 151.101.65.32
  • 151.101.1.32
  • 151.101.193.32
  • 151.101.129.32
whitelisted
crl.identrust.com
  • 2.16.186.27
  • 2.16.186.10
whitelisted
analytics.brave.com
  • 151.101.1.32
  • 151.101.65.32
  • 151.101.129.32
  • 151.101.193.32
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
clientservices.googleapis.com
  • 142.250.74.195
whitelisted

Threats

No threats detected
No debug info