File name:

Wave Browser.exe

Full analysis: https://app.any.run/tasks/b7c41253-bdb6-45b8-9e58-0ac4e43fcdcc
Verdict: Malicious activity
Analysis date: May 11, 2025, 20:11:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

6069B6AEF105861C5AC4982946FEE7C1

SHA1:

9BE56ACDDB67C6CA33C009A244DE0266F1AE3477

SHA256:

07655313AA7FE9697A2365602CD14C14008DECCD4837E49E8FFFED5F1A4C1A7F

SSDEEP:

49152:v2o3U1o477Q7gb3tUaYcPE6+hTXALAz15A7eA5x/O6X0IknHD6WI3cuGBmcW6KJ5:JE1o47XbdUaj+hTXt15sBxXXyDs3ctm/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • SWUpdater.exe (PID: 2396)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Wave Browser.exe (PID: 2448)
      • SWUpdater.exe (PID: 752)
      • SWUpdater.exe (PID: 2832)
      • SWUpdater.exe (PID: 3124)
    • Reads settings of System Certificates

      • Wave Browser.exe (PID: 2448)
      • SWUpdater.exe (PID: 752)
      • SWUpdater.exe (PID: 3124)
      • SWUpdater.exe (PID: 2832)
    • Reads security settings of Internet Explorer

      • Wave Browser.exe (PID: 2448)
    • Executable content was dropped or overwritten

      • Wave Browser.exe (PID: 2448)
      • SWUpdaterSetup.exe (PID: 576)
      • SWUpdater.exe (PID: 2396)
    • Creates/Modifies COM task schedule object

      • SWUpdater.exe (PID: 1824)
    • Starts itself from another location

      • SWUpdater.exe (PID: 2396)
    • Application launched itself

      • SWUpdater.exe (PID: 2832)
  • INFO

    • Reads Environment values

      • Wave Browser.exe (PID: 2448)
    • Reads the computer name

      • Wave Browser.exe (PID: 2448)
      • SWUpdater.exe (PID: 2396)
      • SWUpdater.exe (PID: 268)
      • SWUpdater.exe (PID: 752)
      • SWUpdater.exe (PID: 2832)
      • SWUpdater.exe (PID: 3124)
    • Checks supported languages

      • Wave Browser.exe (PID: 2448)
      • SWUpdaterSetup.exe (PID: 576)
      • SWUpdater.exe (PID: 2396)
      • SWUpdater.exe (PID: 2832)
      • SWUpdater.exe (PID: 268)
      • SWUpdater.exe (PID: 752)
      • SWUpdater.exe (PID: 1824)
      • SWUpdater.exe (PID: 3124)
      • SWUpdater.exe (PID: 2384)
    • Disables trace logs

      • Wave Browser.exe (PID: 2448)
    • Reads the machine GUID from the registry

      • Wave Browser.exe (PID: 2448)
      • SWUpdater.exe (PID: 2396)
      • SWUpdater.exe (PID: 268)
      • SWUpdater.exe (PID: 752)
      • SWUpdater.exe (PID: 2832)
      • SWUpdater.exe (PID: 3124)
    • Reads the software policy settings

      • Wave Browser.exe (PID: 2448)
      • SWUpdater.exe (PID: 752)
      • SWUpdater.exe (PID: 3124)
      • SWUpdater.exe (PID: 2832)
    • Create files in a temporary directory

      • Wave Browser.exe (PID: 2448)
      • SWUpdaterSetup.exe (PID: 576)
    • The sample compiled with english language support

      • Wave Browser.exe (PID: 2448)
      • SWUpdaterSetup.exe (PID: 576)
      • SWUpdater.exe (PID: 2396)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2078:11:07 22:39:56+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 1450496
InitializedDataSize: 180736
UninitializedDataSize: -
EntryPoint: 0x1640b2
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.5.21.2
ProductVersionNumber: 1.5.21.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: WaveBrowser
CompanyName: Wavesor Software
FileDescription: WaveBrowser
FileVersion: 1.5.21.2
InternalName: Wave Browser.exe
LegalCopyright: Copyright 2025 Wavesor Software. All rights reserved.
LegalTrademarks: -
OriginalFileName: Wave Browser.exe
ProductName: WaveBrowser
ProductVersion: 1.5.21.2
AssemblyVersion: 1.5.21.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
9
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start wave browser.exe swupdatersetup.exe swupdater.exe swupdater.exe no specs swupdater.exe swupdater.exe no specs swupdater.exe swupdater.exe swupdater.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /handoff "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1" /installsource otherinstallcmd /sessionid "{B0A0383C-22FD-4D6F-ABF2-330D370780F2}"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
2147747849
Version:
1.3.139.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
576"C:\Users\admin\AppData\Local\Temp\Wave\SWUpdaterSetup.exe" /install "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1"C:\Users\admin\AppData\Local\Temp\Wave\SWUpdaterSetup.exe
Wave Browser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater Setup
Exit code:
2147747849
Version:
1.3.139.0
Modules
Images
c:\users\admin\appdata\local\temp\wave\swupdatersetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
752"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJTV1VwZGF0ZXIiIHVwZGF0ZXJ2ZXJzaW9uPSIxLjMuMTM5LjAiIHNoZWxsX3ZlcnNpb249IjEuMy4xMzkuMCIgaXNtYWNoaW5lPSIwIiBzZXNzaW9uaWQ9IntCMEEwMzgzQy0yMkZELTRENkYtQUJGMi0zMzBEMzcwNzgwRjJ9IiB1c2VyaWQ9InthYTQ2ZTBmYS1jN2IxLTQ3NmQtODI1Zi1lNzY4OWU1MDUwZWZ9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHJlcXVlc3RpZD0ie0JBRDlCODIxLTk4MTMtNDBDRS1CMkU0LTFGRDAwMjcxMTgyMH0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgcGh5c21lbW9yeT0iMyIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iNi4xLjc2MDEuMjQ1NDYiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0ie0Y2RjYwQUNFLTcxQUQtNDYxMC04MEQ0LTkyNTM3MjlGQjRCN30iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4xMzkuMCIgbGFuZz0iZW4iIGJyYW5kPSIiIGNsaWVudD0iIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9IjQ2OSIvPjwvYXBwPjwvcmVxdWVzdD4C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe
SWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.139.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1824"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /regserverC:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.139.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2384"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /unregserverC:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.139.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2396C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdater.exe /install "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1"C:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdater.exe
SWUpdaterSetup.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
2147747849
Version:
1.3.139.0
Modules
Images
c:\users\admin\appdata\local\temp\gum80f3.tmp\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2448"C:\Users\admin\AppData\Local\Temp\Wave Browser.exe" C:\Users\admin\AppData\Local\Temp\Wave Browser.exe
explorer.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
WaveBrowser
Exit code:
0
Version:
1.5.21.2
Modules
Images
c:\users\admin\appdata\local\temp\wave browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2832"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" -EmbeddingC:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe
svchost.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.139.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3124"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJTV1VwZGF0ZXIiIHVwZGF0ZXJ2ZXJzaW9uPSIxLjMuMTM5LjAiIHNoZWxsX3ZlcnNpb249IjEuMy4xMzkuMCIgaXNtYWNoaW5lPSIwIiBzZXNzaW9uaWQ9IntCMEEwMzgzQy0yMkZELTRENkYtQUJGMi0zMzBEMzcwNzgwRjJ9IiB1c2VyaWQ9InthYTQ2ZTBmYS1jN2IxLTQ3NmQtODI1Zi1lNzY4OWU1MDUwZWZ9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHJlcXVlc3RpZD0iezcwNDRCQ0VELTA1MEMtNDA4NS1BMTVDLTIzQkY0NjZBOTY3NX0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgcGh5c21lbW9yeT0iMyIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iNi4xLjc2MDEuMjQ1NDYiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0ie0VCMTQ5QUQyLUNFNEUtNEY1MS1CN0ZDLUExNDlGQUE0Q0NBRn0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IiIgbGFuZz0iZW4iIGJyYW5kPSIiIGNsaWVudD0iIiBpbnN0YWxsYWdlPSItMSIgaW5zdGFsbGRhdGU9Ii0xIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMCIgZXJyb3Jjb2RlPSItMjE0NzIxOTQ0NyIgZXh0cmFjb2RlMT0iMjY4NDM1NDU5IiB1cGRhdGVfY2hlY2tfdGltZV9tcz0iODI4Ii8-PC9hcHA-PC9yZXF1ZXN0PgC:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe
SWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.139.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
14 686
Read events
14 362
Write events
135
Delete events
189

Modification events

(PID) Process:(2448) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2448) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2448) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(2448) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(2448) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2448) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2448) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2448) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2448) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:FileTracingMask
Value:
(PID) Process:(2448) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
Executable files
26
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
576SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\swupdater.dllexecutable
MD5:F8D2134C1DB5B9110C869C6D093F2C12
SHA256:E60ECF8A974A7210DF2F1EA06E1B19CD3DCF5CAC6024C2B1CEF509AA6AF4F1D2
576SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdaterBroker.exeexecutable
MD5:AA476B0F86AA1DED20A69B8F70FD6688
SHA256:7F0CF244AE86A32FD9296FF8AE4EBAB2E44663AD90C9F5BEC8BE8E94B51B4FDB
576SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\psmachine_64.dllexecutable
MD5:C7FD940E573D9C0EDC302F52BC5A9CFA
SHA256:2BB6080168A52AF06098AAD299C4B79FFDB8DE7349D49DCF816C73A0C11E4644
576SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdaterOnDemand.exeexecutable
MD5:CBC3F8783D640E261136A75530E30C25
SHA256:CA4AB0A584CB97ECA35848ACE35FBB918E811DBD7CD046C60200E22799428935
576SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdater.exeexecutable
MD5:6DC889107D15512BD4A8F544F96B751A
SHA256:0F990FA4CC71C1954B300D2B56CEF02D1C0D3CD33FB4981B02D64F6488A51CE9
2448Wave Browser.exeC:\Users\admin\AppData\Local\Temp\Wave\SWUpdaterSetup.exeexecutable
MD5:5813F14260ADB068F4B289003DC97FEF
SHA256:0F7C252831041C590B60F1CA997750C58A8F10A1B1AA8A7B4AD8CE844C7E413F
576SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\SWUpdaterComRegisterShell64.exeexecutable
MD5:0B66C4A341A2DE0525C4EA3203934629
SHA256:3452CF4B6419BC78C4B59FB907761AA4FBE2B13EDF354194BF571AB2404B8B7C
576SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\psmachine.dllexecutable
MD5:E7FFAB130261A1653EF4604AA5C3CB4B
SHA256:745621681B9A699549A71A1903806DB9B46ACE2A01FFFF70BE8123F2EC749766
576SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\psuser.dllexecutable
MD5:5CEFB5492D456649CC9BC29D2ECDD839
SHA256:A6E43374BEBACA7D8559057D82FCEB68CCBD11AEC45F7B1F4F7B3CD117E1E5FE
576SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM80F3.tmp\psuser_64.dllexecutable
MD5:7A7549EDA44453563FA88D594E8C8200
SHA256:9947C3A4ADE9EBA68E6818E2031463691F1BFA614ECBB125BF6E8813DD1975A9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
2448
Wave Browser.exe
54.144.90.228:443
api.wavebrowserbase.com
AMAZON-AES
US
unknown
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
752
SWUpdater.exe
44.219.233.154:443
swupdater.com
AMAZON-AES
US
unknown
2832
SWUpdater.exe
44.219.233.154:443
swupdater.com
AMAZON-AES
US
unknown
3124
SWUpdater.exe
44.219.233.154:443
swupdater.com
AMAZON-AES
US
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.18.14
whitelisted
api.wavebrowserbase.com
  • 54.144.90.228
  • 44.220.125.252
  • 52.21.23.174
  • 54.221.228.202
  • 34.198.33.118
  • 52.201.186.180
unknown
swupdater.com
  • 44.219.233.154
  • 54.87.74.53
unknown

Threats

No threats detected
No debug info