File name:

Wave Browser (1).exe

Full analysis: https://app.any.run/tasks/a6fcddb7-8141-4b11-80b6-5bf9f21448f7
Verdict: Malicious activity
Analysis date: April 04, 2024, 07:08:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

A69D796AB71F88742EBC5317FF46015A

SHA1:

E0161537372941371751CFC3DEFE9041B03251C1

SHA256:

204259FC2CAF158EB9BFAE76AA4204DDE93A18643F5CBB578D8F93260F11593D

SSDEEP:

49152:prU1o43o9bUFcRfZQ2hTh9kuuSRONSOykQeEZV1rj6oGiTmOV8LBqsU9/Cywt9Bu:pA1o44xUF4ZQ2Fh9kuuSROrBQea1/6HW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Wave Browser (1).exe (PID: 2120)
      • SWUpdaterSetup.exe (PID: 956)
      • SWUpdater.exe (PID: 1348)
    • Changes the autorun value in the registry

      • SWUpdater.exe (PID: 1348)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Wave Browser (1).exe (PID: 2120)
      • SWUpdater.exe (PID: 3724)
      • SWUpdater.exe (PID: 3508)
      • SWUpdater.exe (PID: 3072)
    • Reads security settings of Internet Explorer

      • Wave Browser (1).exe (PID: 2120)
    • Checks Windows Trust Settings

      • Wave Browser (1).exe (PID: 2120)
    • Reads settings of System Certificates

      • Wave Browser (1).exe (PID: 2120)
      • SWUpdater.exe (PID: 3508)
      • SWUpdater.exe (PID: 3072)
      • SWUpdater.exe (PID: 3724)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Wave Browser (1).exe (PID: 2120)
    • The process creates files with name similar to system file names

      • Wave Browser (1).exe (PID: 2120)
    • Starts itself from another location

      • SWUpdater.exe (PID: 1348)
    • Creates/Modifies COM task schedule object

      • SWUpdater.exe (PID: 1972)
    • Application launched itself

      • SWUpdater.exe (PID: 3508)
    • Non-standard symbols in registry

      • SWUpdater.exe (PID: 1348)
  • INFO

    • Checks supported languages

      • Wave Browser (1).exe (PID: 2120)
      • SWUpdaterSetup.exe (PID: 956)
      • SWUpdater.exe (PID: 1348)
      • SWUpdater.exe (PID: 1972)
      • SWUpdater.exe (PID: 3724)
      • SWUpdater.exe (PID: 3508)
      • SWUpdater.exe (PID: 3516)
      • SWUpdater.exe (PID: 1848)
      • SWUpdater.exe (PID: 3072)
    • Reads the computer name

      • Wave Browser (1).exe (PID: 2120)
      • SWUpdater.exe (PID: 1348)
      • SWUpdater.exe (PID: 3724)
      • SWUpdater.exe (PID: 3516)
      • SWUpdater.exe (PID: 3508)
      • SWUpdater.exe (PID: 3072)
    • Checks proxy server information

      • Wave Browser (1).exe (PID: 2120)
    • Create files in a temporary directory

      • Wave Browser (1).exe (PID: 2120)
      • SWUpdaterSetup.exe (PID: 956)
    • Reads the machine GUID from the registry

      • Wave Browser (1).exe (PID: 2120)
      • SWUpdater.exe (PID: 1348)
      • SWUpdater.exe (PID: 3508)
      • SWUpdater.exe (PID: 3516)
      • SWUpdater.exe (PID: 3072)
      • SWUpdater.exe (PID: 3724)
    • Reads the software policy settings

      • Wave Browser (1).exe (PID: 2120)
      • SWUpdater.exe (PID: 3508)
      • SWUpdater.exe (PID: 3072)
      • SWUpdater.exe (PID: 3724)
    • Creates files or folders in the user directory

      • Wave Browser (1).exe (PID: 2120)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:09:14 19:13:20+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x31d6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.3.15.3
ProductVersionNumber: 1.3.15.3
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Wavesor Software
FileDescription: WaveBrowser
FileVersion: 1.3.15.3
LegalCopyright: Copyright 2023 Wavesor Software. All rights reserved.
OriginalFileName: Wave Browser
ProductName: WaveBrowser
ProductVersion: 1.3.15.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
9
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start wave browser (1).exe swupdatersetup.exe no specs swupdater.exe swupdater.exe no specs swupdater.exe swupdater.exe no specs swupdater.exe swupdater.exe swupdater.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
956"C:\Users\admin\AppData\Local\Temp\nse244D.tmp\SWUpdaterSetup.exe" /install "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1"C:\Users\admin\AppData\Local\Temp\nse244D.tmp\SWUpdaterSetup.exeWave Browser (1).exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater Setup
Exit code:
2147747849
Version:
1.3.133.0
Modules
Images
c:\users\admin\appdata\local\temp\nse244d.tmp\swupdatersetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1348C:\Users\admin\AppData\Local\Temp\GUM3F17.tmp\SWUpdater.exe /install "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1"C:\Users\admin\AppData\Local\Temp\GUM3F17.tmp\SWUpdater.exe
SWUpdaterSetup.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
2147747849
Version:
1.3.133.0
Modules
Images
c:\users\admin\appdata\local\temp\gum3f17.tmp\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1848"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /unregserverC:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.133.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1972"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /regserverC:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.133.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2120"C:\Users\admin\AppData\Local\Temp\Wave Browser (1).exe" C:\Users\admin\AppData\Local\Temp\Wave Browser (1).exe
explorer.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
WaveBrowser
Exit code:
2
Version:
1.3.15.3
Modules
Images
c:\users\admin\appdata\local\temp\wave browser (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3072"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJTV1VwZGF0ZXIiIHVwZGF0ZXJ2ZXJzaW9uPSIxLjMuMTMzLjAiIHNoZWxsX3ZlcnNpb249IjEuMy4xMzMuMCIgaXNtYWNoaW5lPSIwIiBzZXNzaW9uaWQ9Ins5Q0NBQzA5Qy0yMzYyLTQxRDQtODVFQi04Q0Y1MzBFMTJBRTJ9IiB1c2VyaWQ9InsyYzllNTI5OS01YTYwLTRmZGQtYjgxYi0zNGQ5NGI5Y2JmNWJ9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHJlcXVlc3RpZD0iezQ0QkQxQ0RELTlERTItNEExRi05RDg1LTkxOTgwNUNEOTM2Rn0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgcGh5c21lbW9yeT0iMyIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iNi4xLjc2MDEuMjQ1NDYiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0ie0VCMTQ5QUQyLUNFNEUtNEY1MS1CN0ZDLUExNDlGQUE0Q0NBRn0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IiIgbGFuZz0iZW4iIGJyYW5kPSIiIGNsaWVudD0iIiBpbnN0YWxsYWdlPSItMSIgaW5zdGFsbGRhdGU9Ii0xIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMCIgZXJyb3Jjb2RlPSItMjE0NzIxOTQ0NyIgZXh0cmFjb2RlMT0iMjY4NDM1NDU5IiB1cGRhdGVfY2hlY2tfdGltZV9tcz0iNDc1MDAiLz48L2FwcD48L3JlcXVlc3Q-C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe
SWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.133.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3508"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" -EmbeddingC:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe
svchost.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.133.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3516"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /handoff "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1" /installsource otherinstallcmd /sessionid "{9CCAC09C-2362-41D4-85EB-8CF530E12AE2}"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
2147747849
Version:
1.3.133.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3724"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJTV1VwZGF0ZXIiIHVwZGF0ZXJ2ZXJzaW9uPSIxLjMuMTMzLjAiIHNoZWxsX3ZlcnNpb249IjEuMy4xMzMuMCIgaXNtYWNoaW5lPSIwIiBzZXNzaW9uaWQ9Ins5Q0NBQzA5Qy0yMzYyLTQxRDQtODVFQi04Q0Y1MzBFMTJBRTJ9IiB1c2VyaWQ9InsyYzllNTI5OS01YTYwLTRmZGQtYjgxYi0zNGQ5NGI5Y2JmNWJ9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHJlcXVlc3RpZD0iezIxMTI2MEI3LUI1NTAtNERGQi05RjMwLTI2NTMxNEU4MUYyNH0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgcGh5c21lbW9yeT0iMyIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iNi4xLjc2MDEuMjQ1NDYiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0ie0Y2RjYwQUNFLTcxQUQtNDYxMC04MEQ0LTkyNTM3MjlGQjRCN30iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4xMzMuMCIgbGFuZz0iZW4iIGJyYW5kPSIiIGNsaWVudD0iIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBpbnN0YWxsX3RpbWVfbXM9IjMyOCIvPjwvYXBwPjwvcmVxdWVzdD4C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe
SWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.133.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
25 079
Read events
24 328
Write events
556
Delete events
195

Modification events

(PID) Process:(2120) Wave Browser (1).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2120) Wave Browser (1).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(2120) Wave Browser (1).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(2120) Wave Browser (1).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(2120) Wave Browser (1).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(2120) Wave Browser (1).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2120) Wave Browser (1).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2120) Wave Browser (1).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2120) Wave Browser (1).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2120) Wave Browser (1).exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
31
Suspicious files
5
Text files
9
Unknown types
5

Dropped files

PID
Process
Filename
Type
2120Wave Browser (1).exeC:\Users\admin\AppData\Local\Temp\nse244D.tmp\inetc.dllexecutable
MD5:
SHA256:
2120Wave Browser (1).exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:
SHA256:
2120Wave Browser (1).exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:
SHA256:
2120Wave Browser (1).exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B66240B0F6C84BD4857ABA60CF5CE4A0_5043E0F5DF723415C9EECC201C838A62binary
MD5:
SHA256:
2120Wave Browser (1).exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:
SHA256:
2120Wave Browser (1).exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\BAD725C80F9E10846F35D039A996E4A8_88B6AE015495C1ECC395D19C1DD02894binary
MD5:
SHA256:
2120Wave Browser (1).exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8binary
MD5:
SHA256:
2120Wave Browser (1).exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_B5D3A17E5BEDD2EDA793611A0A74E1E8binary
MD5:
SHA256:
2120Wave Browser (1).exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D03E46CD585BBE111C712E6577BC5F07_879B5BB4D389070BD08B98FB516E4EFAbinary
MD5:
SHA256:
2120Wave Browser (1).exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D03E46CD585BBE111C712E6577BC5F07_879B5BB4D389070BD08B98FB516E4EFAbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
17
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
Wave Browser (1).exe
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
US
binary
1.37 Kb
unknown
1080
svchost.exe
GET
200
23.53.40.18:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?3e412f7b4eff0943
DE
compressed
68.3 Kb
unknown
1080
svchost.exe
GET
304
23.53.40.18:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?0754c686571bd23f
DE
compressed
68.3 Kb
unknown
2120
Wave Browser (1).exe
GET
304
23.53.40.49:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c41d92d6b09abc02
DE
unknown
2120
Wave Browser (1).exe
GET
200
108.138.2.195:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
US
binary
2.02 Kb
unknown
2120
Wave Browser (1).exe
GET
200
18.245.39.64:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
US
binary
1.49 Kb
unknown
2120
Wave Browser (1).exe
GET
200
18.245.65.219:80
http://ocsp.r2m01.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBShdVEFnSEQ0gG5CBtzM48cPMe9XwQUgbgOY4qJEhjl%2Bjs7UJWf5uWQE4UCEASvMWuUfgVrMIzyBjvGjBw%3D
US
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2120
Wave Browser (1).exe
44.196.72.70:443
api.wavebrowserbase.com
AMAZON-AES
US
unknown
2120
Wave Browser (1).exe
23.53.40.49:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2120
Wave Browser (1).exe
108.138.2.195:80
o.ss2.us
AMAZON-02
US
unknown
2120
Wave Browser (1).exe
18.245.39.64:80
ocsp.rootg2.amazontrust.com
US
unknown
2120
Wave Browser (1).exe
18.245.65.219:80
ocsp.r2m01.amazontrust.com
US
unknown
3724
SWUpdater.exe
44.219.174.215:443
swupdater.com
AMAZON-AES
US
unknown

DNS requests

Domain
IP
Reputation
api.wavebrowserbase.com
  • 44.196.72.70
  • 52.55.167.244
  • 3.224.44.80
  • 35.174.71.143
  • 34.198.96.168
  • 50.17.18.191
unknown
ctldl.windowsupdate.com
  • 23.53.40.49
  • 23.53.40.72
  • 23.53.40.35
  • 23.53.40.18
  • 23.53.40.56
  • 23.53.40.40
whitelisted
o.ss2.us
  • 108.138.2.195
  • 108.138.2.10
  • 108.138.2.107
  • 108.138.2.173
whitelisted
ocsp.rootg2.amazontrust.com
  • 18.245.39.64
whitelisted
ocsp.rootca1.amazontrust.com
  • 18.245.39.64
shared
ocsp.r2m01.amazontrust.com
  • 18.245.65.219
whitelisted
swupdater.com
  • 44.219.174.215
  • 52.1.189.69
unknown

Threats

No threats detected
No debug info