| URL: | https://install.wavebrowser.co/ |
| Full analysis: | https://app.any.run/tasks/05feae33-0882-4e81-a5b1-dc6f78b5a79e |
| Verdict: | Malicious activity |
| Analysis date: | March 09, 2026, 17:18:42 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MD5: | 8791185603974F0A0F0C0A152A840EC1 |
| SHA1: | F0707B347AFBE14A012E3BE9F0CBE7A8E4F8B50A |
| SHA256: | 1363FDA14BD78A0716C9B389D80FF2E41D3F760924D3E9F35AE8B881B1BFA3A2 |
| SSDEEP: | 3:N8LREJF3K3yKK:2lgZFKK |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 404 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3680,i,12120724712386573099,4550990472230454726,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=3732 /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| 664 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=7708,i,12120724712386573099,4550990472230454726,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=7368 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 676 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://install.wavebrowser.co/thank-you?tid=zhv8zi7r&src=lp0-obem-wav-igAyryHzyOjoqTurLJw-ab51-w64-vtfof-brwsr&iid=wav&uid=e5c56a04-e2d3-4c82-b65e-b958c4b49f54 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 133.0.3065.92 Modules
| |||||||||||||||
| 676 | "C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --force-high-res-timeticks=disabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=24 --field-trial-handle=2056,i,5524234149238960283,5043112965239957477,262144 --variations-seed-version=15 --mojo-platform-channel-handle=5536 /prefetch:1 | C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe | — | wavebrowser.exe | |||||||||||
User: admin Company: Wavesor Software Integrity Level: LOW Description: WaveBrowser Version: 1.5.24.14 Modules
| |||||||||||||||
| 848 | "C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --force-high-res-timeticks=disabled --field-trial-handle=2056,i,5524234149238960283,5043112965239957477,262144 --variations-seed-version=15 --mojo-platform-channel-handle=2428 /prefetch:8 | C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe | — | wavebrowser.exe | |||||||||||
User: admin Company: Wavesor Software Integrity Level: LOW Description: WaveBrowser Version: 1.5.24.14 Modules
| |||||||||||||||
| 1000 | "C:\Users\admin\AppData\Local\Temp\Wave\SWUpdaterSetup.exe" /install "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1&experiments=v2414%3don%7cWed%2c%2023%20Sep%202026%2000%3a00%3a00%20%2b0300" | C:\Users\admin\AppData\Local\Temp\Wave\SWUpdaterSetup.exe | Wave Browser - 2026-03-09T171859.656.exe | ||||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Setup Exit code: 0 Version: 1.3.153.0 Modules
| |||||||||||||||
| 1492 | "C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /handoff "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1&experiments=v2414%3don%7cWed%2c%2023%20Sep%202026%2000%3a00%3a00%20%2b0300" /installsource otherinstallcmd /sessionid "{F1183BB0-CE1A-4E4D-9515-055E1BB55469}" | C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe | — | SWUpdater.exe | |||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: Wavesor SWUpdater Exit code: 0 Version: 1.3.153.0 Modules
| |||||||||||||||
| 1656 | "C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=renderer --enable-dinosaur-easter-egg-alt-images --force-high-res-timeticks=disabled --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=20 --field-trial-handle=2056,i,5524234149238960283,5043112965239957477,262144 --variations-seed-version=15 --mojo-platform-channel-handle=4760 /prefetch:1 | C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe | — | wavebrowser.exe | |||||||||||
User: admin Company: Wavesor Software Integrity Level: LOW Description: WaveBrowser Version: 1.5.24.14 Modules
| |||||||||||||||
| 1732 | "C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --install-type=1 --cd-upload --from-installer | C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe | — | setup.exe | |||||||||||
User: admin Company: Wavesor Software Integrity Level: MEDIUM Description: WaveBrowser Version: 1.5.24.14 Modules
| |||||||||||||||
| 1868 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=3276,i,12120724712386573099,4550990472230454726,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5232 /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 133.0.3065.92 Modules
| |||||||||||||||
| (PID) Process: | (4972) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
| Operation: | write | Name: | CheckSetting |
Value: 23004100430042006C006F00620000000000000000000000010000000000000000000000 | |||
| (PID) Process: | (4972) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000E02E2 |
| Operation: | write | Name: | VirtualDesktop |
Value: 1000000030304456E9BC50E45F05DB4C86F7D791C25A96C7 | |||
| (PID) Process: | (4972) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000F02A6 |
| Operation: | write | Name: | VirtualDesktop |
Value: 1000000030304456E9BC50E45F05DB4C86F7D791C25A96C7 | |||
| (PID) Process: | (4972) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | NodeSlots |
Value: 02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
| (PID) Process: | (4972) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | MRUListEx |
Value: 04000000030000000000000012000000110000000E000000100000000F0000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF | |||
| (PID) Process: | (4972) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4 |
| Operation: | write | Name: | MRUListEx |
Value: 000000000500000003000000040000000200000001000000FFFFFFFF | |||
| (PID) Process: | (4972) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4\0 |
| Operation: | write | Name: | MRUListEx |
Value: 0400000005000000010000000600000008000000020000000C0000000B0000000A00000009000000070000000000000003000000FFFFFFFF | |||
| (PID) Process: | (4972) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4\0\4\0 |
| Operation: | write | Name: | MRUListEx |
Value: 0100000000000000FFFFFFFF | |||
| (PID) Process: | (4972) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar |
| Operation: | write | Name: | Locked |
Value: 1 | |||
| (PID) Process: | (4972) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\208\Shell |
| Operation: | write | Name: | SniffedFolderType |
Value: Pictures | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 8828 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1e508f.TMP | — | |
MD5:— | SHA256:— | |||
| 8828 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 8828 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1e509e.TMP | — | |
MD5:— | SHA256:— | |||
| 8828 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1e509e.TMP | — | |
MD5:— | SHA256:— | |||
| 8828 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1e509e.TMP | — | |
MD5:— | SHA256:— | |||
| 8828 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 8828 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 8828 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1e509e.TMP | — | |
MD5:— | SHA256:— | |||
| 8828 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
| 8828 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
8912 | msedge.exe | GET | 200 | 52.123.243.80:443 | https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=66&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0 | US | text | 4.55 Kb | whitelisted |
8912 | msedge.exe | GET | 200 | 150.171.27.11:80 | http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:xbOhZ0U4QpDGR6fQHp9kFBUdm64xnUo_DFjHhcAFsPA&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | US | text | 96 b | whitelisted |
8912 | msedge.exe | GET | 200 | 150.171.28.11:443 | https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0 | US | text | 446 b | whitelisted |
8912 | msedge.exe | GET | 200 | 3.223.107.166:443 | https://install.wavebrowser.co/ | US | html | 3.09 Kb | unknown |
8912 | msedge.exe | GET | 200 | 13.107.246.44:443 | https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appId=edge-extensions&country=US | US | binary | 82 b | whitelisted |
8912 | msedge.exe | GET | 200 | 104.18.22.222:443 | https://copilot.microsoft.com/c/api/user/eligibility | US | text | 25 b | whitelisted |
8912 | msedge.exe | GET | 200 | 3.223.107.166:443 | https://install.wavebrowser.co/assets/index-d387fe50.js | US | — | 596 Kb | unknown |
8912 | msedge.exe | GET | 200 | 3.223.107.166:443 | https://install.wavebrowser.co/assets/index-3bf5c0ff.css | US | text | 210 Kb | unknown |
8912 | msedge.exe | GET | 200 | 3.223.107.166:443 | https://install.wavebrowser.co/assets/index-d387fe50.js | US | — | 596 Kb | unknown |
8912 | msedge.exe | GET | 200 | 184.24.77.156:443 | https://use.typekit.net/rgb4vnm.css | NL | text | 4.63 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
2328 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7212 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
8912 | msedge.exe | 150.171.27.11:80 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8912 | msedge.exe | 52.123.243.80:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8912 | msedge.exe | 150.171.28.11:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8912 | msedge.exe | 13.107.246.44:443 | api.edgeoffer.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
8912 | msedge.exe | 104.18.22.222:443 | copilot.microsoft.com | CLOUDFLARENET | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
install.wavebrowser.co |
| whitelisted |
api.edgeoffer.microsoft.com |
| whitelisted |
copilot.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
use.typekit.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2328 | svchost.exe | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |
8912 | msedge.exe | Potentially Bad Traffic | ET INFO PE EXE or DLL Windows file download HTTP |
8912 | msedge.exe | Potentially Bad Traffic | ET INFO Executable served from Amazon S3 |
4036 | svchost.exe | Potentially Bad Traffic | ET INFO PE EXE or DLL Windows file download HTTP |
4036 | svchost.exe | Potentially Bad Traffic | ET INFO Executable served from Amazon S3 |