| File name: | Wave Browser.exe |
| Full analysis: | https://app.any.run/tasks/b7c41253-bdb6-45b8-9e58-0ac4e43fcdcc |
| Verdict: | Malicious activity |
| Analysis date: | May 11, 2025, 20:11:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections |
| MD5: | 6069B6AEF105861C5AC4982946FEE7C1 |
| SHA1: | 9BE56ACDDB67C6CA33C009A244DE0266F1AE3477 |
| SHA256: | 07655313AA7FE9697A2365602CD14C14008DECCD4837E49E8FFFED5F1A4C1A7F |
| SSDEEP: | 49152:v2o3U1o477Q7gb3tUaYcPE6+hTXALAz15A7eA5x/O6X0IknHD6WI3cuGBmcW6KJ5:JE1o47XbdUaj+hTXt15sBxXXyDs3ctm/ |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2078:11:07 22:39:56+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 1450496 |
| InitializedDataSize: | 180736 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1640b2 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.5.21.2 |
| ProductVersionNumber: | 1.5.21.2 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | WaveBrowser |
| CompanyName: | Wavesor Software |
| FileDescription: | WaveBrowser |
| FileVersion: | 1.5.21.2 |
| InternalName: | Wave Browser.exe |
| LegalCopyright: | Copyright 2025 Wavesor Software. All rights reserved. |
| LegalTrademarks: | - |
| OriginalFileName: | Wave Browser.exe |
| ProductName: | WaveBrowser |
| ProductVersion: | 1.5.21.2 |
| AssemblyVersion: | 1.5.21.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 268 | "C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /handoff "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1" /installsource otherinstallcmd /sessionid "{B0A0383C-22FD-4D6F-ABF2-330D370780F2}" | C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe | — | SWUpdater.exe | |||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Exit code: 2147747849 Version: 1.3.139.0 Modules
| |||||||||||||||
| 576 | "C:\Users\admin\AppData\Local\Temp\Wave\SWUpdaterSetup.exe" /install "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1" | C:\Users\admin\AppData\Local\Temp\Wave\SWUpdaterSetup.exe | Wave Browser.exe | ||||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Setup Exit code: 2147747849 Version: 1.3.139.0 Modules
| |||||||||||||||
| 752 | "C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJTV1VwZGF0ZXIiIHVwZGF0ZXJ2ZXJzaW9uPSIxLjMuMTM5LjAiIHNoZWxsX3ZlcnNpb249IjEuMy4xMzkuMCIgaXNtYWNoaW5lPSIwIiBzZXNzaW9uaWQ9IntCMEEwMzgzQy0yMkZELTRENkYtQUJGMi0zMzBEMzcwNzgwRjJ9IiB1c2VyaWQ9InthYTQ2ZTBmYS1jN2IxLTQ3NmQtODI1Zi1lNzY4OWU1MDUwZWZ9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHJlcXVlc3RpZD0ie0JBRDlCODIxLTk4MTMtNDBDRS1CMkU0LTFGRDAwMjcxMTgyMH0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgcGh5c21lbW9yeT0iMyIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iNi4xLjc2MDEuMjQ1NDYiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0ie0Y2RjYwQUNFLTcxQUQtNDYxMC04MEQ0LTkyNTM3MjlGQjRCN30iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4xMzkuMCIgbGFuZz0iZW4iIGJyYW5kPSIiIGNsaWVudD0iIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9IjQ2OSIvPjwvYXBwPjwvcmVxdWVzdD4 | C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe | SWUpdater.exe | ||||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Exit code: 0 Version: 1.3.139.0 Modules
| |||||||||||||||
| 1824 | "C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /regserver | C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe | — | SWUpdater.exe | |||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Exit code: 0 Version: 1.3.139.0 Modules
| |||||||||||||||
| 2384 | "C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /unregserver | C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe | — | SWUpdater.exe | |||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Exit code: 0 Version: 1.3.139.0 Modules
| |||||||||||||||
| 2396 | C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdater.exe /install "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1" | C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdater.exe | SWUpdaterSetup.exe | ||||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Exit code: 2147747849 Version: 1.3.139.0 Modules
| |||||||||||||||
| 2448 | "C:\Users\admin\AppData\Local\Temp\Wave Browser.exe" | C:\Users\admin\AppData\Local\Temp\Wave Browser.exe | explorer.exe | ||||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: WaveBrowser Exit code: 0 Version: 1.5.21.2 Modules
| |||||||||||||||
| 2832 | "C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" -Embedding | C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe | svchost.exe | ||||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Exit code: 0 Version: 1.3.139.0 Modules
| |||||||||||||||
| 3124 | "C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJTV1VwZGF0ZXIiIHVwZGF0ZXJ2ZXJzaW9uPSIxLjMuMTM5LjAiIHNoZWxsX3ZlcnNpb249IjEuMy4xMzkuMCIgaXNtYWNoaW5lPSIwIiBzZXNzaW9uaWQ9IntCMEEwMzgzQy0yMkZELTRENkYtQUJGMi0zMzBEMzcwNzgwRjJ9IiB1c2VyaWQ9InthYTQ2ZTBmYS1jN2IxLTQ3NmQtODI1Zi1lNzY4OWU1MDUwZWZ9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHJlcXVlc3RpZD0iezcwNDRCQ0VELTA1MEMtNDA4NS1BMTVDLTIzQkY0NjZBOTY3NX0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgcGh5c21lbW9yeT0iMyIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iNi4xLjc2MDEuMjQ1NDYiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0ie0VCMTQ5QUQyLUNFNEUtNEY1MS1CN0ZDLUExNDlGQUE0Q0NBRn0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IiIgbGFuZz0iZW4iIGJyYW5kPSIiIGNsaWVudD0iIiBpbnN0YWxsYWdlPSItMSIgaW5zdGFsbGRhdGU9Ii0xIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMCIgZXJyb3Jjb2RlPSItMjE0NzIxOTQ0NyIgZXh0cmFjb2RlMT0iMjY4NDM1NDU5IiB1cGRhdGVfY2hlY2tfdGltZV9tcz0iODI4Ii8-PC9hcHA-PC9yZXF1ZXN0Pg | C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe | SWUpdater.exe | ||||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Exit code: 0 Version: 1.3.139.0 Modules
| |||||||||||||||
| (PID) Process: | (2448) Wave Browser.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2448) Wave Browser.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2448) Wave Browser.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (2448) Wave Browser.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (2448) Wave Browser.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (2448) Wave Browser.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (2448) Wave Browser.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2448) Wave Browser.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2448) Wave Browser.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (2448) Wave Browser.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 576 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\swupdater.dll | executable | |
MD5:F8D2134C1DB5B9110C869C6D093F2C12 | SHA256:E60ECF8A974A7210DF2F1EA06E1B19CD3DCF5CAC6024C2B1CEF509AA6AF4F1D2 | |||
| 576 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdaterBroker.exe | executable | |
MD5:AA476B0F86AA1DED20A69B8F70FD6688 | SHA256:7F0CF244AE86A32FD9296FF8AE4EBAB2E44663AD90C9F5BEC8BE8E94B51B4FDB | |||
| 576 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\psmachine_64.dll | executable | |
MD5:C7FD940E573D9C0EDC302F52BC5A9CFA | SHA256:2BB6080168A52AF06098AAD299C4B79FFDB8DE7349D49DCF816C73A0C11E4644 | |||
| 576 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdaterOnDemand.exe | executable | |
MD5:CBC3F8783D640E261136A75530E30C25 | SHA256:CA4AB0A584CB97ECA35848ACE35FBB918E811DBD7CD046C60200E22799428935 | |||
| 576 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdater.exe | executable | |
MD5:6DC889107D15512BD4A8F544F96B751A | SHA256:0F990FA4CC71C1954B300D2B56CEF02D1C0D3CD33FB4981B02D64F6488A51CE9 | |||
| 2448 | Wave Browser.exe | C:\Users\admin\AppData\Local\Temp\Wave\SWUpdaterSetup.exe | executable | |
MD5:5813F14260ADB068F4B289003DC97FEF | SHA256:0F7C252831041C590B60F1CA997750C58A8F10A1B1AA8A7B4AD8CE844C7E413F | |||
| 576 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdaterComRegisterShell64.exe | executable | |
MD5:0B66C4A341A2DE0525C4EA3203934629 | SHA256:3452CF4B6419BC78C4B59FB907761AA4FBE2B13EDF354194BF571AB2404B8B7C | |||
| 576 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\psmachine.dll | executable | |
MD5:E7FFAB130261A1653EF4604AA5C3CB4B | SHA256:745621681B9A699549A71A1903806DB9B46ACE2A01FFFF70BE8123F2EC749766 | |||
| 576 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\psuser.dll | executable | |
MD5:5CEFB5492D456649CC9BC29D2ECDD839 | SHA256:A6E43374BEBACA7D8559057D82FCEB68CCBD11AEC45F7B1F4F7B3CD117E1E5FE | |||
| 576 | SWUpdaterSetup.exe | C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\psuser_64.dll | executable | |
MD5:7A7549EDA44453563FA88D594E8C8200 | SHA256:9947C3A4ADE9EBA68E6818E2031463691F1BFA614ECBB125BF6E8813DD1975A9 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
2448 | Wave Browser.exe | 54.144.90.228:443 | api.wavebrowserbase.com | AMAZON-AES | US | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
752 | SWUpdater.exe | 44.219.233.154:443 | swupdater.com | AMAZON-AES | US | unknown |
2832 | SWUpdater.exe | 44.219.233.154:443 | swupdater.com | AMAZON-AES | US | unknown |
3124 | SWUpdater.exe | 44.219.233.154:443 | swupdater.com | AMAZON-AES | US | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
api.wavebrowserbase.com |
| unknown |
swupdater.com |
| unknown |