File name:

Wave Browser.exe

Full analysis: https://app.any.run/tasks/aa7588e8-b5c7-4023-bd9b-b8df06567b08
Verdict: Malicious activity
Analysis date: January 27, 2025, 20:04:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

5D05A1F3AF61FC7A701F6C36945ED50F

SHA1:

31B136D7E47E4DB3686C807999B2B9102C819BDE

SHA256:

3C1921B7F1B78F69B33307E1CF383726551F84EFA3DD65C7491C4F33D565689E

SSDEEP:

49152:RVI6dpMYopoDfBDgxa/nkADrjeXlZmi9vTqGvduOljO4q1mOv8kogGiDqvNgfpHH:RfMOpDggf7DeRJZv4OljBCTEkogivEpn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • SWUpdater.exe (PID: 6488)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Wave Browser.exe (PID: 3736)
      • SWUpdater.exe (PID: 6488)
    • Executable content was dropped or overwritten

      • Wave Browser.exe (PID: 3736)
      • SWUpdaterSetup.exe (PID: 6468)
      • SWUpdater.exe (PID: 6488)
    • Checks Windows Trust Settings

      • Wave Browser.exe (PID: 3736)
    • The process creates files with name similar to system file names

      • Wave Browser.exe (PID: 3736)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Wave Browser.exe (PID: 3736)
    • Starts itself from another location

      • SWUpdater.exe (PID: 6488)
    • Creates/Modifies COM task schedule object

      • SWUpdaterComRegisterShell64.exe (PID: 6552)
      • SWUpdater.exe (PID: 6524)
      • SWUpdaterComRegisterShell64.exe (PID: 6576)
      • SWUpdaterComRegisterShell64.exe (PID: 6600)
    • Application launched itself

      • SWUpdater.exe (PID: 6728)
  • INFO

    • The sample compiled with english language support

      • Wave Browser.exe (PID: 3736)
      • SWUpdaterSetup.exe (PID: 6468)
      • SWUpdater.exe (PID: 6488)
    • Reads the computer name

      • Wave Browser.exe (PID: 3736)
      • SWUpdater.exe (PID: 6488)
      • SWUpdater.exe (PID: 6524)
      • SWUpdater.exe (PID: 6728)
      • SWUpdater.exe (PID: 6648)
      • SWUpdater.exe (PID: 6688)
      • SWUpdater.exe (PID: 6872)
    • Checks supported languages

      • Wave Browser.exe (PID: 3736)
      • SWUpdaterSetup.exe (PID: 6468)
      • SWUpdater.exe (PID: 6488)
      • SWUpdater.exe (PID: 6524)
      • SWUpdaterComRegisterShell64.exe (PID: 6552)
      • SWUpdater.exe (PID: 6728)
      • SWUpdaterComRegisterShell64.exe (PID: 6576)
      • SWUpdaterComRegisterShell64.exe (PID: 6600)
      • SWUpdater.exe (PID: 6648)
      • SWUpdater.exe (PID: 6688)
      • SWUpdater.exe (PID: 6796)
      • SWUpdater.exe (PID: 6872)
      • SWUpdaterComRegisterShell64.exe (PID: 6924)
      • SWUpdaterComRegisterShell64.exe (PID: 6900)
      • SWUpdaterComRegisterShell64.exe (PID: 6948)
    • Checks proxy server information

      • Wave Browser.exe (PID: 3736)
      • SWUpdater.exe (PID: 6728)
      • SWUpdater.exe (PID: 6648)
      • SWUpdater.exe (PID: 6796)
    • Reads the machine GUID from the registry

      • Wave Browser.exe (PID: 3736)
      • SWUpdater.exe (PID: 6648)
      • SWUpdater.exe (PID: 6796)
      • SWUpdater.exe (PID: 6728)
    • Reads the software policy settings

      • Wave Browser.exe (PID: 3736)
      • SWUpdater.exe (PID: 6648)
      • SWUpdater.exe (PID: 6796)
      • SWUpdater.exe (PID: 6728)
    • Create files in a temporary directory

      • Wave Browser.exe (PID: 3736)
      • SWUpdaterSetup.exe (PID: 6468)
    • Wave updater related mutex has been found

      • SWUpdater.exe (PID: 6488)
      • SWUpdater.exe (PID: 6524)
      • SWUpdater.exe (PID: 6728)
      • SWUpdater.exe (PID: 6648)
      • SWUpdater.exe (PID: 6796)
      • SWUpdater.exe (PID: 6688)
      • SWUpdater.exe (PID: 6872)
    • Process checks computer location settings

      • SWUpdater.exe (PID: 6488)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:28 20:00:52+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x31d6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.1.3.4
ProductVersionNumber: 1.1.3.4
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Wavesor Software
FileDescription: WaveBrowser
FileVersion: 1.1.3.4
LegalCopyright: Copyright 2021 Wavesor Software. All rights reserved.
OriginalFileName: Wave Browser
ProductName: WaveBrowser
ProductVersion: 1.1.3.4
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
15
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wave browser.exe swupdatersetup.exe swupdater.exe swupdater.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs swupdater.exe swupdater.exe no specs swupdater.exe swupdater.exe swupdater.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3736"C:\Users\admin\Downloads\Wave Browser.exe" C:\Users\admin\Downloads\Wave Browser.exe
explorer.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
WaveBrowser
Exit code:
2
Version:
1.1.3.4
Modules
Images
c:\users\admin\downloads\wave browser.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6468"C:\Users\admin\AppData\Local\Temp\nsj61FA.tmp\SWUpdaterSetup.exe" /install "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1"C:\Users\admin\AppData\Local\Temp\nsj61FA.tmp\SWUpdaterSetup.exe
Wave Browser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater Setup
Exit code:
2147754388
Version:
1.3.109.0
Modules
Images
c:\users\admin\appdata\local\temp\nsj61fa.tmp\swupdatersetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
6488C:\Users\admin\AppData\Local\Temp\GUM902D.tmp\SWUpdater.exe /install "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1"C:\Users\admin\AppData\Local\Temp\GUM902D.tmp\SWUpdater.exe
SWUpdaterSetup.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
2147754388
Version:
1.3.109.0
Modules
Images
c:\users\admin\appdata\local\temp\gum902d.tmp\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6524"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /regserverC:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.109.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6552"C:\Users\admin\Wavesor Software\SWUpdater\1.3.109.0\SWUpdaterComRegisterShell64.exe" /user C:\Users\admin\Wavesor Software\SWUpdater\1.3.109.0\SWUpdaterComRegisterShell64.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.109.0
Modules
Images
c:\users\admin\wavesor software\swupdater\1.3.109.0\swupdatercomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6576"C:\Users\admin\Wavesor Software\SWUpdater\1.3.109.0\SWUpdaterComRegisterShell64.exe" /user C:\Users\admin\Wavesor Software\SWUpdater\1.3.109.0\SWUpdaterComRegisterShell64.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.109.0
Modules
Images
c:\users\admin\wavesor software\swupdater\1.3.109.0\swupdatercomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6600"C:\Users\admin\Wavesor Software\SWUpdater\1.3.109.0\SWUpdaterComRegisterShell64.exe" /user C:\Users\admin\Wavesor Software\SWUpdater\1.3.109.0\SWUpdaterComRegisterShell64.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.109.0
Modules
Images
c:\users\admin\wavesor software\swupdater\1.3.109.0\swupdatercomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6648"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJTV1VwZGF0ZXIiIHVwZGF0ZXJ2ZXJzaW9uPSIxLjMuMTA5LjAiIHNoZWxsX3ZlcnNpb249IjEuMy4xMDkuMCIgaXNtYWNoaW5lPSIwIiBzZXNzaW9uaWQ9InsxMkE5NUIzNS00NzhGLTREMzgtOTFFNS1BRDRFNDZENTNBQTB9IiB1c2VyaWQ9IntDRkIyOEQ2Ni03RUYyLTQxMUItOEE1Ny01ODgxRDMxNzEyQzZ9IiBpbnN0YWxsc291cmNlPSJvdGhlcmluc3RhbGxjbWQiIHJlcXVlc3RpZD0iezJBN0YzQzM0LTc0MTUtNDkzNy1BQUJELThGN0NCNjY5QzlDMn0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgcGh5c21lbW9yeT0iNCIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iMTAuMC4xOTA0NS40MDQ2IiBzcD0iIiBhcmNoPSJ4NjQiLz48YXBwIGFwcGlkPSJ7RjZGNjBBQ0UtNzFBRC00NjEwLTgwRDQtOTI1MzcyOUZCNEI3fSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjEwOS4wIiBsYW5nPSJlbiIgYnJhbmQ9IiIgY2xpZW50PSIiPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIGluc3RhbGxfdGltZV9tcz0iMTU0NyIvPjwvYXBwPjwvcmVxdWVzdD4C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe
SWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
2147754388
Version:
1.3.109.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6688"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /handoff "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1" /installsource otherinstallcmd /sessionid "{12A95B35-478F-4D38-91E5-AD4E46D53AA0}"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
2147754388
Version:
1.3.109.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6728"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" -EmbeddingC:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe
svchost.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.109.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
15 005
Read events
14 600
Write events
94
Delete events
311

Modification events

(PID) Process:(3736) Wave Browser.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3736) Wave Browser.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3736) Wave Browser.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3736) Wave Browser.exeKey:HKEY_CURRENT_USER\SOFTWARE\Wavesor\SWUpdater\ClientState\{EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}
Operation:writeName:CustomInstallPath
Value:
C:\Users\admin\Wavesor Software\WaveBrowser
(PID) Process:(3736) Wave Browser.exeKey:HKEY_CURRENT_USER\SOFTWARE\Wavesor\SWUpdater\ClientState\{EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}
Operation:writeName:SWUSetupOptions
Value:
/R /DWID=-0F
(PID) Process:(6488) SWUpdater.exeKey:HKEY_CURRENT_USER\SOFTWARE\Wavesor\SWUpdater
Operation:delete valueName:uid
Value:
(PID) Process:(6488) SWUpdater.exeKey:HKEY_CURRENT_USER\SOFTWARE\Wavesor\SWUpdater
Operation:delete valueName:old-uid
Value:
(PID) Process:(6488) SWUpdater.exeKey:HKEY_CURRENT_USER\SOFTWARE\Wavesor\SWUpdater
Operation:writeName:path
Value:
C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe
(PID) Process:(6488) SWUpdater.exeKey:HKEY_CURRENT_USER\SOFTWARE\Wavesor\SWUpdater
Operation:writeName:UninstallCmdLine
Value:
"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /uninstall
(PID) Process:(6488) SWUpdater.exeKey:HKEY_CURRENT_USER\SOFTWARE\Wavesor\SWUpdater\Clients\{F6F60ACE-71AD-4610-80D4-9253729FB4B7}
Operation:writeName:pv
Value:
1.3.109.0
Executable files
35
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6468SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM902D.tmp\SWUpdater.exeexecutable
MD5:1152E84337D5D4C56C66A692676B7422
SHA256:02F6094B5D14E880A1FB7EEF90228DBB34102788B5E513836750F90894DDE185
3736Wave Browser.exeC:\Users\admin\AppData\Local\Temp\nsj61FA.tmp\nsArray.dllexecutable
MD5:FBD9CD84DA2090B46B3192157A1FDCC4
SHA256:DEAED02C720ABCF82A76615F5F0DEEBDCDF72412CC716D133AEA0C624D84921F
3736Wave Browser.exeC:\Users\admin\AppData\Local\Temp\nsj61FA.tmp\Info.rtftext
MD5:767F781EB67AEE56105952F96FD2D763
SHA256:FA9C25A216BCF521FFFC805F697B91E1A5705642A4EDC879F9F2A180D38D2B44
3736Wave Browser.exeC:\Users\admin\AppData\Local\Temp\nsj61FA.tmp\SWUpdaterSetup.exeexecutable
MD5:1C7B11F88CE42B1867A0C44851E68637
SHA256:ADAE512E5A87C04E2C7E7C8C953C2A802B38B8510CC9BD42620F7AFC92C93EEF
6468SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM902D.tmp\swupdater.dllexecutable
MD5:49FABC04D46D6B66D1A37353DD4607E6
SHA256:9FBD7317BC53BD50543BD10574721D5C54061E0631E17FAFD6E4584B200D3058
3736Wave Browser.exeC:\Users\admin\AppData\Local\Temp\nsj61FA.tmp\nsDialogs.dllexecutable
MD5:68B59D5146DBAC3961030DD0A6356E8C
SHA256:B56B44111F7310C775DF3FD626CBD10ECCF29B50C3E78FE2CE4C42A7C314899C
6468SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM902D.tmp\SWUpdaterCrashHandler.exeexecutable
MD5:9E09818F5844A8CEC16512A6D61154D8
SHA256:FF575480EBF0FFDAD280390C93182F5D437AF627C672C3C36963E06F0231D38F
3736Wave Browser.exeC:\Users\admin\AppData\Local\Temp\nsj61FA.tmp\System.dllexecutable
MD5:58147A97903FE5E038F6D30B92A767B8
SHA256:569C6B076D87DFD97BA4BC06B037A55F51BE0052840C362BE88AB6BF905023C0
3736Wave Browser.exeC:\Users\admin\AppData\Local\Temp\nsj61FA.tmp\nsResize.dllexecutable
MD5:FC98E463A6BCA53F9AAF65BFE58AC2A0
SHA256:0A26E09C338080A1C2AFB434E72BF9D4AC183D0F8E6266E1B071548BCDA7EACF
3736Wave Browser.exeC:\Users\admin\AppData\Local\Temp\nsj61FA.tmp\inetc.dllexecutable
MD5:77712B0AB4C825BF3CB82D89BDD0083D
SHA256:ECE8274B656EE8DCED08FCBA0365E1344CD1F1558203EAC4C5BA53BAA41F279B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
59
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6648
SWUpdater.exe
POST
404
44.199.149.204:80
http://swupdater.com/service/update2
unknown
unknown
6728
SWUpdater.exe
POST
404
44.199.149.204:80
http://swupdater.com/service/update2?cup2key=1:963202026&cup2hreq=fa5bf7b24268ae2efee27e732c490f0d1d34856ec88000c41a9d9527c442c1e2
unknown
unknown
6796
SWUpdater.exe
POST
404
44.199.149.204:80
http://swupdater.com/service/update2
unknown
unknown
6728
SWUpdater.exe
POST
404
44.199.149.204:80
http://swupdater.com/service/update2
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
104.126.37.147:443
Akamai International B.V.
DE
unknown
5064
SearchApp.exe
104.126.37.131:443
Akamai International B.V.
DE
unknown
4712
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3736
Wave Browser.exe
72.44.40.189:443
api.wavebrowserbase.com
AMAZON-AES
US
unknown
3976
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2040
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6648
SWUpdater.exe
44.199.149.204:443
swupdater.com
AMAZON-AES
US
unknown
6648
SWUpdater.exe
44.199.149.204:80
swupdater.com
AMAZON-AES
US
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
api.wavebrowserbase.com
  • 72.44.40.189
  • 34.202.55.69
  • 52.70.207.234
  • 18.205.102.74
  • 34.238.206.53
  • 52.201.92.148
unknown
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
swupdater.com
  • 44.199.149.204
  • 107.21.1.208
unknown
login.live.com
  • 40.126.31.67
  • 20.190.159.2
  • 20.190.159.4
  • 20.190.159.23
  • 20.190.159.64
  • 20.190.159.71
  • 20.190.159.75
  • 40.126.31.69
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
  • 2603:1030:c02:2::284
whitelisted

Threats

No threats detected
No debug info