| File name: | BraveBrowserSetup-BRV011.exe |
| Full analysis: | https://app.any.run/tasks/8e1655c8-0bab-4a40-8e7a-31ddb8a910fd |
| Verdict: | Malicious activity |
| Analysis date: | July 20, 2024, 09:22:57 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F53F9124EB5EFA98FBC32CB489F5459B |
| SHA1: | 8A6095A94B9B80ABECAAD7FDD7C461BD6EDD837D |
| SHA256: | EA45663EB7A87AE2F908C9760C1AC6B91E702B3F19072E94EA532DA7B10CC76A |
| SSDEEP: | 49152:etxRmfjNpG2UG0uPrbc6nXdEsfSqK+ee8c+tLVQnwijx3GMkQ5wWX/bwDqWjr9Vl:eJ4xpCGxPr467fzK+edcELeRp/kQ/vbU |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:25 08:25:08+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.4 |
| CodeSize: | 105984 |
| InitializedDataSize: | 1148928 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x6f17 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.361.149 |
| ProductVersionNumber: | 1.3.361.149 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | BraveSoftware Inc. |
| FileDescription: | BraveSoftware Update Setup |
| FileVersion: | 1.3.361.149 |
| InternalName: | BraveSoftware Update Setup |
| OriginalFileName: | BraveUpdateSetup.exe |
| ProductName: | BraveSoftware Update |
| ProductVersion: | 1.3.361.149 |
| LanguageId: | en |
| PrivateBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 620 | "C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /regsvc | C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe | — | BraveUpdate.exe | |||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Exit code: 0 Version: 1.3.361.149 Modules
| |||||||||||||||
| 1332 | "C:\Program Files (x86)\BraveSoftware\Update\1.3.361.149\BraveUpdateComRegisterShell64.exe" | C:\Program Files (x86)\BraveSoftware\Update\1.3.361.149\BraveUpdateComRegisterShell64.exe | — | BraveUpdate.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3020 | "C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4zNjEuMTQ5IiBzaGVsbF92ZXJzaW9uPSIxLjMuMzYxLjE0OSIgaXNtYWNoaW5lPSIxIiBzZXNzaW9uaWQ9IntBMjNFNDg2MS1BQTU3LTRCMEMtQkZBQy1GNTkwRTBEMThCQzJ9IiBpbnN0YWxsc291cmNlPSJ0YWdnZWRtaSIgdGVzdHNvdXJjZT0iYXV0byIgcmVxdWVzdGlkPSJ7QzJBMUNGQkEtRDg4Ni00MTc2LTg4RUEtQURENkQ4QjBDOTNCfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBwaHlzbWVtb3J5PSI0IiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIvPjxhcHAgYXBwaWQ9IntCMTMxQzkzNS05QkU2LTQxREEtOTU5OS0xRjc3NkJFQjgwMTl9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxLjMuMzYxLjE0OSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSI4NjAiLz48L2FwcD48L3JlcXVlc3Q- | C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe | BraveUpdate.exe | ||||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Exit code: 0 Version: 1.3.361.149 Modules
| |||||||||||||||
| 3868 | "C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /handoff "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installsource taggedmi /sessionid "{A23E4861-AA57-4B0C-BFAC-F590E0D18BC2}" | C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe | — | BraveUpdate.exe | |||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Version: 1.3.361.149 Modules
| |||||||||||||||
| 4020 | "C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /svc | C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe | services.exe | ||||||||||||
User: SYSTEM Company: BraveSoftware Inc. Integrity Level: SYSTEM Description: BraveSoftware Update Version: 1.3.361.149 Modules
| |||||||||||||||
| 5112 | "C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\BraveUpdateSetup.exe" /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevated /nomitag | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\BraveUpdateSetup.exe | BraveUpdate.exe | ||||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Setup Version: 1.3.361.149 Modules
| |||||||||||||||
| 6800 | "C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV011.exe" | C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV011.exe | explorer.exe | ||||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: MEDIUM Description: BraveSoftware Update Setup Version: 1.3.361.149 Modules
| |||||||||||||||
| 6968 | C:\WINDOWS\SystemTemp\GUM9C6E.tmp\BraveUpdate.exe /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" /installelevated | C:\Windows\SystemTemp\GUM9C6E.tmp\BraveUpdate.exe | BraveUpdateSetup.exe | ||||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Version: 1.3.361.149 Modules
| |||||||||||||||
| 7028 | "C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /regserver | C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe | — | BraveUpdate.exe | |||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: HIGH Description: BraveSoftware Update Exit code: 0 Version: 1.3.361.149 Modules
| |||||||||||||||
| 7204 | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\BraveUpdate.exe /installsource taggedmi /install "appguid={AFE6A462-C574-4B8A-AF43-4CC60DF4563B}&appname=Brave-Release&needsadmin=prefers&ap=release&installdataindex=default&referral=none" | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\BraveUpdate.exe | — | BraveBrowserSetup-BRV011.exe | |||||||||||
User: admin Company: BraveSoftware Inc. Integrity Level: MEDIUM Description: BraveSoftware Update Version: 1.3.361.149 Modules
| |||||||||||||||
| (PID) Process: | (6800) BraveBrowserSetup-BRV011.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\BraveSoftware\Promo |
| Operation: | write | Name: | StubInstallerPath |
Value: C:\Users\admin\AppData\Local\Temp\BraveBrowserSetup-BRV011.exe | |||
| (PID) Process: | (6968) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BraveSoftware\Update |
| Operation: | write | Name: | path |
Value: C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe | |||
| (PID) Process: | (6968) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BraveSoftware\Update |
| Operation: | write | Name: | UninstallCmdLine |
Value: "C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe" /uninstall | |||
| (PID) Process: | (6968) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019} |
| Operation: | write | Name: | pv |
Value: 1.3.361.149 | |||
| (PID) Process: | (6968) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BraveSoftware\Update\Clients\{B131C935-9BE6-41DA-9599-1F776BEB8019} |
| Operation: | write | Name: | name |
Value: Brave Update | |||
| (PID) Process: | (6968) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BraveSoftware\Update\ClientState\{B131C935-9BE6-41DA-9599-1F776BEB8019} |
| Operation: | write | Name: | pv |
Value: 1.3.361.149 | |||
| (PID) Process: | (6968) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BraveUpdate.exe |
| Operation: | write | Name: | DisableExceptionChainValidation |
Value: 0 | |||
| (PID) Process: | (6968) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BraveSoftware\Update |
| Operation: | write | Name: | brave_task_name_c |
Value: BraveSoftwareUpdateTaskMachineCore{FB3B4A78-6A33-45CE-908E-439B8A327D08} | |||
| (PID) Process: | (6968) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BraveSoftware\Update |
| Operation: | write | Name: | brave_task_name_ua |
Value: BraveSoftwareUpdateTaskMachineUA{859B70C0-221F-42F9-BFC5-075EC67A579A} | |||
| (PID) Process: | (6968) BraveUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\BraveSoftware\Update |
| Operation: | delete value | Name: | mi |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6800 | BraveBrowserSetup-BRV011.exe | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\BraveUpdateBroker.exe | executable | |
MD5:4F6B0368F5E2BD9FCAE705D6AED361CF | SHA256:C5D244771EBDE292A224C9D37F502367ECB7B2DEB78B918F2380F51F91626C89 | |||
| 6800 | BraveBrowserSetup-BRV011.exe | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\psmachine_64.dll | executable | |
MD5:C40CE976ACA1BAC0639F1DB8A380F72A | SHA256:E4375F02B8CFD7222288206AC16C25F864B4978D070D1E8BB8C725E5DA8FF214 | |||
| 6800 | BraveBrowserSetup-BRV011.exe | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\goopdate.dll | executable | |
MD5:3DC1E42D04CEC506AED38940EAC8A57A | SHA256:000D1EC9D9E3450C2D8029A3D100735756A59B6CF2181892CA200263EEB4E039 | |||
| 6800 | BraveBrowserSetup-BRV011.exe | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\BraveUpdateComRegisterShell64.exe | executable | |
MD5:A2CFF9714964372A14E0EDFC001F9B86 | SHA256:1DEACD81D09E9399C086C72F8A10238E27F0F83EC85E65DC68C36D74F028F6D5 | |||
| 6800 | BraveBrowserSetup-BRV011.exe | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\BraveUpdateOnDemand.exe | executable | |
MD5:926CABCFEB0864D95970D7A6D4EECA89 | SHA256:0A3180274D467B66AA483A40BF5B248FE06209B5C67ECE94B97F78E2F76E5C2F | |||
| 6800 | BraveBrowserSetup-BRV011.exe | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\psuser_64.dll | executable | |
MD5:6CB702FF205A260CF7296689B6330208 | SHA256:16368A6383D17534C1BAE20909913C8F33A6B812ABBB6B5D25967A24866FEEEA | |||
| 6800 | BraveBrowserSetup-BRV011.exe | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\BraveCrashHandlerArm64.exe | executable | |
MD5:5F92D34DCFF00A37E90B98E33AD8D1DB | SHA256:D9B0CDA160918B3D3DDF6B3875621C8858C4665AC8B7D868E299EACA61AF58B8 | |||
| 6800 | BraveBrowserSetup-BRV011.exe | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\psuser.dll | executable | |
MD5:7085E51E957D65C01A6AC19EB7D326D4 | SHA256:922DE9B1FFD0DA578C35EB3B313A75424D1526DFC279E3608D1812A7B5B094DB | |||
| 6800 | BraveBrowserSetup-BRV011.exe | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\BraveUpdateCore.exe | executable | |
MD5:E218373B2A048E05E79D5FB79DECE052 | SHA256:97679DB9B816E0F46398C7AEB83E1784F56920DE77ECBE57706E1F5253C2CE8A | |||
| 6800 | BraveBrowserSetup-BRV011.exe | C:\Users\admin\AppData\Local\Temp\GUM9152.tmp\goopdateres_am.dll | executable | |
MD5:6CF6316830AFA38060A60A7D012136DC | SHA256:24BDBD05EB763F0262C49D8512F61DD7C44F11D4DDE1F8101C8FA12EE8E8D1DF | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
4716 | svchost.exe | 40.126.32.136:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
5620 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
7856 | svchost.exe | 4.209.32.67:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3020 | BraveUpdate.exe | 13.32.121.47:443 | updates.bravesoftware.com | AMAZON-02 | US | unknown |
4020 | BraveUpdate.exe | 13.32.121.47:443 | updates.bravesoftware.com | AMAZON-02 | US | unknown |
1144 | svchost.exe | 3.161.82.23:443 | updates-cdn.bravesoftware.com | — | US | unknown |
2760 | svchost.exe | 40.113.103.199:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
updates.bravesoftware.com |
| shared |
dl.brave.com |
| whitelisted |
updates-cdn.bravesoftware.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
licensing.mp.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
www.bing.com |
| whitelisted |