File name:

Wave Browser.exe

Full analysis: https://app.any.run/tasks/bb112a27-2d3e-47ea-9ae4-3029a508a039
Verdict: Malicious activity
Analysis date: August 02, 2024, 21:27:47
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
crypto-regex
pup
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

1684AAB6FAE1ED888CF6D3C45E3F5FA7

SHA1:

6ACC87B81836575BF7B497F0E8A9A23A221F06B7

SHA256:

4114122C0DCA23F637D83EED33F9ABCDC92709E2AC6F63FFD55F5AAE519B58AB

SSDEEP:

49152:Go3U1o4h7d7esHiVe4aSw/017+zQnWGTvjpu0+IggeNo+yC0/gODj7RgldaaY99P:BE1o4hl8VefSwsJ+zQnJF+zm+yzgqj1t

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Wave Browser.exe (PID: 6368)
      • SWUpdaterSetup.exe (PID: 6816)
      • SWUpdater.exe (PID: 6796)
      • WaveInstaller-v1.5.18.2.exe (PID: 2992)
      • setup.exe (PID: 6288)
    • Changes the autorun value in the registry

      • SWUpdater.exe (PID: 6796)
    • Scans artifacts that could help determine the target

      • setup.exe (PID: 6288)
      • setup.exe (PID: 4064)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Wave Browser.exe (PID: 6368)
      • SWUpdater.exe (PID: 6796)
      • setup.exe (PID: 6288)
      • setup.exe (PID: 4064)
      • SWUpdater.exe (PID: 3116)
    • Reads the date of Windows installation

      • Wave Browser.exe (PID: 6368)
      • SWUpdater.exe (PID: 6796)
      • setup.exe (PID: 4064)
      • SWUpdater.exe (PID: 3116)
    • Executable content was dropped or overwritten

      • Wave Browser.exe (PID: 6368)
      • SWUpdaterSetup.exe (PID: 6816)
      • SWUpdater.exe (PID: 6796)
      • WaveInstaller-v1.5.18.2.exe (PID: 2992)
      • setup.exe (PID: 6288)
    • Creates/Modifies COM task schedule object

      • SWUpdaterComRegisterShell64.exe (PID: 1248)
      • SWUpdaterComRegisterShell64.exe (PID: 3992)
      • SWUpdater.exe (PID: 2204)
      • SWUpdaterComRegisterShell64.exe (PID: 5400)
    • Starts itself from another location

      • SWUpdater.exe (PID: 6796)
    • Application launched itself

      • setup.exe (PID: 6288)
      • setup.exe (PID: 4064)
      • SWUpdater.exe (PID: 3116)
      • wavebrowser.exe (PID: 7136)
    • Searches for installed software

      • setup.exe (PID: 6288)
    • Creates a software uninstall entry

      • setup.exe (PID: 6288)
    • Checks Windows Trust Settings

      • setup.exe (PID: 6288)
      • setup.exe (PID: 4064)
    • Found regular expressions for crypto-addresses (YARA)

      • wavebrowser.exe (PID: 7536)
  • INFO

    • Disables trace logs

      • Wave Browser.exe (PID: 6368)
    • Create files in a temporary directory

      • Wave Browser.exe (PID: 6368)
      • SWUpdaterSetup.exe (PID: 6816)
      • WaveInstaller-v1.5.18.2.exe (PID: 2992)
      • SWUpdater.exe (PID: 3116)
      • setup.exe (PID: 6288)
      • wavebrowser.exe (PID: 7136)
    • Process checks computer location settings

      • Wave Browser.exe (PID: 6368)
      • SWUpdater.exe (PID: 6796)
      • SWUpdater.exe (PID: 3116)
      • wavebrowser.exe (PID: 7136)
      • wavebrowser.exe (PID: 7048)
      • wavebrowser.exe (PID: 7008)
      • wavebrowser.exe (PID: 3180)
      • wavebrowser.exe (PID: 2992)
      • wavebrowser.exe (PID: 7104)
      • wavebrowser.exe (PID: 5476)
      • wavebrowser.exe (PID: 8140)
      • wavebrowser.exe (PID: 6904)
      • wavebrowser.exe (PID: 7092)
      • wavebrowser.exe (PID: 7204)
      • wavebrowser.exe (PID: 7196)
      • wavebrowser.exe (PID: 7184)
      • wavebrowser.exe (PID: 7116)
      • wavebrowser.exe (PID: 5088)
      • wavebrowser.exe (PID: 7220)
      • wavebrowser.exe (PID: 7000)
      • wavebrowser.exe (PID: 7408)
      • wavebrowser.exe (PID: 7296)
      • wavebrowser.exe (PID: 8044)
      • wavebrowser.exe (PID: 8068)
      • wavebrowser.exe (PID: 8072)
      • wavebrowser.exe (PID: 8088)
      • wavebrowser.exe (PID: 7540)
      • wavebrowser.exe (PID: 7676)
      • wavebrowser.exe (PID: 7536)
      • wavebrowser.exe (PID: 5900)
      • wavebrowser.exe (PID: 7404)
      • wavebrowser.exe (PID: 7868)
      • wavebrowser.exe (PID: 7864)
      • wavebrowser.exe (PID: 8076)
      • wavebrowser.exe (PID: 7200)
      • wavebrowser.exe (PID: 6496)
      • wavebrowser.exe (PID: 2572)
      • wavebrowser.exe (PID: 6724)
    • Checks supported languages

      • SWUpdaterSetup.exe (PID: 6816)
      • Wave Browser.exe (PID: 6368)
      • SWUpdater.exe (PID: 6796)
      • SWUpdater.exe (PID: 2204)
      • SWUpdaterComRegisterShell64.exe (PID: 3992)
      • SWUpdaterComRegisterShell64.exe (PID: 1248)
      • SWUpdaterComRegisterShell64.exe (PID: 5400)
      • SWUpdater.exe (PID: 2064)
      • SWUpdater.exe (PID: 4404)
      • SWUpdater.exe (PID: 3116)
      • WaveInstaller-v1.5.18.2.exe (PID: 2992)
      • setup.exe (PID: 6288)
      • setup.exe (PID: 1984)
      • setup.exe (PID: 4064)
      • setup.exe (PID: 888)
      • wavebrowser.exe (PID: 7136)
      • wavebrowser.exe (PID: 6208)
      • SWUpdater.exe (PID: 6396)
      • wavebrowser.exe (PID: 1104)
      • wavebrowser.exe (PID: 2900)
      • wavebrowser.exe (PID: 6340)
      • wavebrowser.exe (PID: 6308)
      • wavebrowser.exe (PID: 6196)
      • wavebrowser.exe (PID: 7048)
      • wavebrowser.exe (PID: 7008)
      • wavebrowser.exe (PID: 7104)
      • wavebrowser.exe (PID: 4024)
      • wavebrowser.exe (PID: 2960)
      • TextInputHost.exe (PID: 7064)
      • wavebrowser.exe (PID: 3180)
      • wavebrowser.exe (PID: 2992)
      • wavebrowser.exe (PID: 6240)
      • wavebrowser.exe (PID: 5068)
      • wavebrowser.exe (PID: 6804)
      • wavebrowser.exe (PID: 6576)
      • wavebrowser.exe (PID: 3184)
      • wavebrowser.exe (PID: 6580)
      • wavebrowser.exe (PID: 5476)
      • wavebrowser.exe (PID: 5940)
      • wavebrowser.exe (PID: 2628)
      • wavebrowser.exe (PID: 7080)
      • wavebrowser.exe (PID: 6232)
      • wavebrowser.exe (PID: 7100)
      • wavebrowser.exe (PID: 872)
      • wavebrowser.exe (PID: 7000)
      • wavebrowser.exe (PID: 2900)
      • wavebrowser.exe (PID: 1120)
      • wavebrowser.exe (PID: 3684)
      • wavebrowser.exe (PID: 6196)
      • wavebrowser.exe (PID: 3008)
      • wavebrowser.exe (PID: 3880)
      • wavebrowser.exe (PID: 644)
      • wavebrowser.exe (PID: 3812)
      • wavebrowser.exe (PID: 1216)
      • wavebrowser.exe (PID: 240)
      • wavebrowser.exe (PID: 1964)
      • wavebrowser.exe (PID: 7056)
      • wavebrowser.exe (PID: 1184)
      • wavebrowser.exe (PID: 936)
      • wavebrowser.exe (PID: 7112)
      • wavebrowser.exe (PID: 7272)
      • wavebrowser.exe (PID: 7324)
      • wavebrowser.exe (PID: 7280)
      • wavebrowser.exe (PID: 7296)
      • wavebrowser.exe (PID: 7288)
      • wavebrowser.exe (PID: 7304)
      • wavebrowser.exe (PID: 7348)
      • wavebrowser.exe (PID: 7424)
      • wavebrowser.exe (PID: 7536)
      • wavebrowser.exe (PID: 7596)
      • wavebrowser.exe (PID: 7608)
      • wavebrowser.exe (PID: 6240)
      • wavebrowser.exe (PID: 7264)
      • wavebrowser.exe (PID: 7756)
      • wavebrowser.exe (PID: 7764)
      • wavebrowser.exe (PID: 7776)
      • wavebrowser.exe (PID: 6284)
      • wavebrowser.exe (PID: 8092)
      • wavebrowser.exe (PID: 8000)
      • wavebrowser.exe (PID: 8044)
      • wavebrowser.exe (PID: 8140)
      • wavebrowser.exe (PID: 7328)
      • wavebrowser.exe (PID: 6832)
      • wavebrowser.exe (PID: 5136)
      • wavebrowser.exe (PID: 5152)
      • wavebrowser.exe (PID: 6932)
      • wavebrowser.exe (PID: 6904)
      • wavebrowser.exe (PID: 7516)
      • wavebrowser.exe (PID: 7616)
      • wavebrowser.exe (PID: 7652)
      • wavebrowser.exe (PID: 7748)
      • wavebrowser.exe (PID: 3324)
      • wavebrowser.exe (PID: 7092)
      • wavebrowser.exe (PID: 7956)
      • wavebrowser.exe (PID: 7184)
      • wavebrowser.exe (PID: 7220)
      • wavebrowser.exe (PID: 7196)
      • wavebrowser.exe (PID: 7116)
      • wavebrowser.exe (PID: 7204)
      • wavebrowser.exe (PID: 5088)
      • wavebrowser.exe (PID: 7408)
      • wavebrowser.exe (PID: 7296)
      • wavebrowser.exe (PID: 7000)
      • wavebrowser.exe (PID: 2128)
      • wavebrowser.exe (PID: 5244)
      • wavebrowser.exe (PID: 8068)
      • wavebrowser.exe (PID: 7616)
      • wavebrowser.exe (PID: 8044)
      • wavebrowser.exe (PID: 8072)
      • wavebrowser.exe (PID: 3076)
      • wavebrowser.exe (PID: 8088)
      • wavebrowser.exe (PID: 7540)
      • wavebrowser.exe (PID: 7676)
      • wavebrowser.exe (PID: 7868)
      • wavebrowser.exe (PID: 7672)
      • wavebrowser.exe (PID: 7516)
      • wavebrowser.exe (PID: 7372)
      • wavebrowser.exe (PID: 7272)
      • wavebrowser.exe (PID: 7600)
      • wavebrowser.exe (PID: 7404)
      • wavebrowser.exe (PID: 6056)
      • wavebrowser.exe (PID: 7536)
      • wavebrowser.exe (PID: 5900)
      • wavebrowser.exe (PID: 7404)
      • wavebrowser.exe (PID: 7200)
      • wavebrowser.exe (PID: 7864)
      • wavebrowser.exe (PID: 7880)
      • wavebrowser.exe (PID: 7620)
      • wavebrowser.exe (PID: 7924)
      • wavebrowser.exe (PID: 8076)
      • wavebrowser.exe (PID: 2572)
      • wavebrowser.exe (PID: 6496)
      • wavebrowser.exe (PID: 7400)
      • wavebrowser.exe (PID: 6724)
      • wavebrowser.exe (PID: 7232)
      • wavebrowser.exe (PID: 6896)
      • wavebrowser.exe (PID: 6996)
      • wavebrowser.exe (PID: 1692)
      • wavebrowser.exe (PID: 8032)
    • Checks proxy server information

      • Wave Browser.exe (PID: 6368)
      • SWUpdater.exe (PID: 2064)
      • SWUpdater.exe (PID: 3116)
      • setup.exe (PID: 6288)
      • setup.exe (PID: 4064)
      • SWUpdater.exe (PID: 6396)
      • wavebrowser.exe (PID: 7136)
    • Reads the software policy settings

      • Wave Browser.exe (PID: 6368)
      • SWUpdater.exe (PID: 2064)
      • SWUpdater.exe (PID: 3116)
      • setup.exe (PID: 6288)
      • SWUpdater.exe (PID: 6396)
      • setup.exe (PID: 4064)
    • Reads Environment values

      • Wave Browser.exe (PID: 6368)
    • Reads the machine GUID from the registry

      • Wave Browser.exe (PID: 6368)
      • setup.exe (PID: 6288)
      • setup.exe (PID: 4064)
      • wavebrowser.exe (PID: 7136)
      • wavebrowser.exe (PID: 8032)
    • Reads the computer name

      • Wave Browser.exe (PID: 6368)
      • SWUpdater.exe (PID: 6796)
      • SWUpdater.exe (PID: 2204)
      • SWUpdater.exe (PID: 2064)
      • SWUpdater.exe (PID: 4404)
      • SWUpdater.exe (PID: 3116)
      • setup.exe (PID: 6288)
      • setup.exe (PID: 4064)
      • SWUpdater.exe (PID: 6396)
      • wavebrowser.exe (PID: 7136)
      • wavebrowser.exe (PID: 6340)
      • wavebrowser.exe (PID: 6308)
      • wavebrowser.exe (PID: 4024)
      • wavebrowser.exe (PID: 2900)
      • wavebrowser.exe (PID: 5068)
      • TextInputHost.exe (PID: 7064)
      • wavebrowser.exe (PID: 8032)
    • Creates files or folders in the user directory

      • setup.exe (PID: 6288)
      • setup.exe (PID: 4064)
      • wavebrowser.exe (PID: 6208)
      • wavebrowser.exe (PID: 7136)
      • wavebrowser.exe (PID: 6340)
      • wavebrowser.exe (PID: 8032)
    • Reads Microsoft Office registry keys

      • setup.exe (PID: 6288)
      • wavebrowser.exe (PID: 7136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2055:07:27 05:22:29+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 1087488
InitializedDataSize: 177152
UninitializedDataSize: -
EntryPoint: 0x10b64e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.3.17.2
ProductVersionNumber: 1.3.17.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: WaveBrowser
CompanyName: Wavesor Software
FileDescription: WaveBrowser
FileVersion: 1.3.17.2
InternalName: Wave Browser.exe
LegalCopyright: Copyright 2024 Wavesor Software. All rights reserved.
LegalTrademarks: -
OriginalFileName: Wave Browser.exe
ProductName: WaveBrowser
ProductVersion: 1.3.17.2
AssemblyVersion: 1.3.17.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
278
Monitored processes
139
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start wave browser.exe swupdatersetup.exe swupdater.exe swupdater.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs swupdater.exe swupdater.exe no specs swupdater.exe waveinstaller-v1.5.18.2.exe setup.exe setup.exe no specs setup.exe setup.exe no specs wavebrowser.exe wavebrowser.exe no specs swupdater.exe wavebrowser.exe no specs wavebrowser.exe wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs textinputhost.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs THREAT wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=5980,i,3299641668567431075,17877429537685823716,262144 --variations-seed-version=15 --mojo-platform-channel-handle=6020 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.2
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.2\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
644"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=7164,i,3299641668567431075,17877429537685823716,262144 --variations-seed-version=15 --mojo-platform-channel-handle=6384 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.2
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.2\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
872"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=5732,i,3299641668567431075,17877429537685823716,262144 --variations-seed-version=15 --mojo-platform-channel-handle=5784 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.2
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.2\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
888C:\Users\admin\AppData\Local\Temp\nsnA734.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\WaveBrowser\User Data\Crashpad" --annotation=channel= --annotation=plat=Win64 --annotation=prod=WaveBrowser --annotation=ver=1.5.18.2 --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x7ff7553d12d0,0x7ff7553d12dc,0x7ff7553d12e8C:\Users\admin\AppData\Local\Temp\nsnA734.tmp\setup.exesetup.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
WaveBrowser Installer
Exit code:
0
Version:
1.5.18.2
Modules
Images
c:\users\admin\appdata\local\temp\nsna734.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
936"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=6856,i,3299641668567431075,17877429537685823716,262144 --variations-seed-version=15 --mojo-platform-channel-handle=7604 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.2
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.2\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1104"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=1900,i,3299641668567431075,17877429537685823716,262144 --variations-seed-version=15 --mojo-platform-channel-handle=2400 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Version:
1.5.18.2
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.2\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1120"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=6408,i,3299641668567431075,17877429537685823716,262144 --variations-seed-version=15 --mojo-platform-channel-handle=5728 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.2
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.2\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1184"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=7768,i,3299641668567431075,17877429537685823716,262144 --variations-seed-version=15 --mojo-platform-channel-handle=7776 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.2
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.2\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1216"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=6040,i,3299641668567431075,17877429537685823716,262144 --variations-seed-version=15 --mojo-platform-channel-handle=5784 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.2
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.2\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1248"C:\Users\admin\Wavesor Software\SWUpdater\1.3.133.0\SWUpdaterComRegisterShell64.exe" /user C:\Users\admin\Wavesor Software\SWUpdater\1.3.133.0\SWUpdaterComRegisterShell64.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.133.0
Modules
Images
c:\users\admin\wavesor software\swupdater\1.3.133.0\swupdatercomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
48 465
Read events
45 915
Write events
2 455
Delete events
95

Modification events

(PID) Process:(6368) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6368) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6368) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6368) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6368) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6368) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6368) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6368) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6368) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6368) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
37
Suspicious files
630
Text files
896
Unknown types
192

Dropped files

PID
Process
Filename
Type
6368Wave Browser.exeC:\Users\admin\AppData\Local\Temp\Wave\SWUpdaterSetup.exeexecutable
MD5:18693249F3A283E83B8179E692FFBBA9
SHA256:3D828BCCCC628E7096856337B178DA5608A6C3DB99383374E6C49D50A1895E64
6816SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUMA5B1.tmp\SWUpdaterSetup.exeexecutable
MD5:18693249F3A283E83B8179E692FFBBA9
SHA256:3D828BCCCC628E7096856337B178DA5608A6C3DB99383374E6C49D50A1895E64
6816SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUMA5B1.tmp\SWUpdaterComRegisterShell64.exeexecutable
MD5:10B82DC9D9A29BC4AF224981F0E1C6FE
SHA256:00CD644354032257A39FF710DDD03E9FB98348F5323DEC31CA670C903D68274C
6816SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUMA5B1.tmp\psmachine_64.dllexecutable
MD5:19E105E099B7653CF60FF5783EC59453
SHA256:7E05780AFFFB2834EC4E2E1D67C9031616C13394CCFEB3A3C678415F19BA1104
6816SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUMA5B1.tmp\swupdater.dllexecutable
MD5:D388D67A1861F9D0CC4F6EDFA97861B4
SHA256:B21F99F14B4CCC78C5E01C269A8EBA83AE0C5912B46D8C1554F329A1076A7617
6816SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUMA5B1.tmp\psuser.dllexecutable
MD5:71DD0ABC865C9D8873E93478707A16D8
SHA256:A0439F5455EF696B70A230AB76C15F4BC3D7571AD4FBC32FDA95247789AA5822
6816SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUMA5B1.tmp\SWUpdaterOnDemand.exeexecutable
MD5:29B0571D015318EDB1C292AEA8011179
SHA256:CEA433E8FEA8DCF1705016545ABD150A2891291AE122A776CD66DDB802A17587
3116SWUpdater.exeC:\Users\admin\AppData\Local\Temp\{E4769CA8-F326-4F15-8B28-453EFEAF79BA}-WaveInstaller-v1.5.18.2.exe
MD5:
SHA256:
3116SWUpdater.exeC:\Users\admin\Wavesor Software\SWUpdater\Download\{EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}\1.5.18.2\WaveInstaller-v1.5.18.2.exe
MD5:
SHA256:
3116SWUpdater.exeC:\Users\admin\Wavesor Software\SWUpdater\Install\{76AFFB78-5834-401F-8376-17B37B306FC6}\WaveInstaller-v1.5.18.2.exe
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
140
DNS requests
120
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2616
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6884
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6924
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6288
setup.exe
GET
200
18.245.65.219:80
http://ocsp.r2m02.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRmbQtwnInkvkvr7BNFR%2BS2lTYPjAQUwDFSzVpQw4J8dHHOy%2Bmc%2BXrrguICEA12qv%2FUSBVBcTK34zqJD7U%3D
unknown
whitelisted
6288
setup.exe
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
unknown
unknown
4056
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
4056
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
4056
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
4056
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/j2hxfei2occ5siitujtlwgp6xi_3/ojhpjlocmbogdgmfpkhlaaeamibhnphh_3_all_gplutbkdljxxbjolk3siq7kive.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4040
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3164
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6368
Wave Browser.exe
3.217.70.1:443
api.wavebrowserbase.com
AMAZON-AES
US
unknown
4
System
192.168.100.255:137
whitelisted
4040
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5336
SearchApp.exe
184.86.251.4:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.110
whitelisted
api.wavebrowserbase.com
  • 3.217.70.1
  • 44.212.212.255
  • 54.91.66.17
  • 18.207.34.87
  • 3.220.179.139
  • 174.129.220.5
unknown
www.bing.com
  • 184.86.251.4
  • 184.86.251.15
  • 184.86.251.28
  • 184.86.251.20
  • 184.86.251.9
  • 184.86.251.24
  • 184.86.251.14
  • 184.86.251.10
  • 184.86.251.19
  • 184.86.251.22
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.23
  • 20.190.159.73
  • 40.126.31.71
  • 20.190.159.75
  • 40.126.31.67
  • 40.126.31.69
  • 20.190.159.71
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
th.bing.com
  • 184.86.251.4
  • 184.86.251.15
  • 184.86.251.28
  • 184.86.251.20
  • 184.86.251.9
  • 184.86.251.24
  • 184.86.251.14
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted

Threats

No threats detected
No debug info