File name:

Wave Browser.exe

Full analysis: https://app.any.run/tasks/dce66ded-dd26-4534-8d33-c1b678395e23
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: October 06, 2024, 17:06:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
pup
adware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

C9DB6B5C84BE13A43AD23CC204E4BC52

SHA1:

94BD6634303205715FD04F8AA10D75158390E4D9

SHA256:

77200156D4773175D341AAD11AB23BD52445065CD95060348DA17D083DC27688

SSDEEP:

49152:co3U1o4h7r7eEhwDP6jGU0cIme87ofHR1wvaP35dQlUl48GmGDYFSCdibzJoOU12:TE1o4h77Xq2374Pwv8k+l48BGDY7dims

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • SWUpdater.exe (PID: 4712)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Wave Browser.exe (PID: 608)
      • SWUpdater.exe (PID: 4712)
      • SWUpdaterSetup.exe (PID: 6828)
      • WaveInstaller-v1.5.18.3.exe (PID: 2424)
      • setup.exe (PID: 2368)
      • wavebrowser.exe (PID: 5584)
    • Reads security settings of Internet Explorer

      • Wave Browser.exe (PID: 608)
      • SWUpdater.exe (PID: 4712)
    • Reads the date of Windows installation

      • Wave Browser.exe (PID: 608)
    • Starts itself from another location

      • SWUpdater.exe (PID: 4712)
    • Creates/Modifies COM task schedule object

      • SWUpdaterComRegisterShell64.exe (PID: 3148)
      • SWUpdater.exe (PID: 4044)
      • SWUpdaterComRegisterShell64.exe (PID: 4744)
      • SWUpdaterComRegisterShell64.exe (PID: 7052)
    • Application launched itself

      • setup.exe (PID: 4720)
      • setup.exe (PID: 2368)
      • wavebrowser.exe (PID: 4276)
      • SWUpdater.exe (PID: 2628)
  • INFO

    • Reads the computer name

      • Wave Browser.exe (PID: 608)
      • SWUpdater.exe (PID: 4712)
      • SWUpdater.exe (PID: 4044)
      • SWUpdater.exe (PID: 2868)
      • SWUpdater.exe (PID: 2056)
      • SWUpdater.exe (PID: 2628)
    • Checks supported languages

      • Wave Browser.exe (PID: 608)
      • SWUpdater.exe (PID: 4712)
      • SWUpdaterSetup.exe (PID: 6828)
      • SWUpdater.exe (PID: 4044)
      • SWUpdaterComRegisterShell64.exe (PID: 4744)
      • SWUpdaterComRegisterShell64.exe (PID: 3148)
      • SWUpdater.exe (PID: 2628)
      • SWUpdaterComRegisterShell64.exe (PID: 7052)
      • SWUpdater.exe (PID: 2868)
      • SWUpdater.exe (PID: 2056)
    • Reads the machine GUID from the registry

      • Wave Browser.exe (PID: 608)
    • Disables trace logs

      • Wave Browser.exe (PID: 608)
    • Reads the software policy settings

      • Wave Browser.exe (PID: 608)
      • SWUpdater.exe (PID: 2628)
      • SWUpdater.exe (PID: 2868)
    • Reads Environment values

      • Wave Browser.exe (PID: 608)
    • Checks proxy server information

      • Wave Browser.exe (PID: 608)
      • SWUpdater.exe (PID: 2868)
      • SWUpdater.exe (PID: 2628)
    • Create files in a temporary directory

      • Wave Browser.exe (PID: 608)
      • SWUpdaterSetup.exe (PID: 6828)
    • Process checks computer location settings

      • Wave Browser.exe (PID: 608)
      • SWUpdater.exe (PID: 4712)
    • The process uses the downloaded file

      • Wave Browser.exe (PID: 608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2068:01:14 19:44:07+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 1101312
InitializedDataSize: 177152
UninitializedDataSize: -
EntryPoint: 0x10ed5a
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.5.18.3
ProductVersionNumber: 1.5.18.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: WaveBrowser
CompanyName: Wavesor Software
FileDescription: WaveBrowser
FileVersion: 1.5.18.3
InternalName: Wave Browser.exe
LegalCopyright: Copyright 2024 Wavesor Software. All rights reserved.
LegalTrademarks: -
OriginalFileName: Wave Browser.exe
ProductName: WaveBrowser
ProductVersion: 1.5.18.3
AssemblyVersion: 1.5.18.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
289
Monitored processes
148
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wave browser.exe swupdatersetup.exe swupdater.exe swupdater.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs swupdater.exe swupdater.exe no specs swupdater.exe waveinstaller-v1.5.18.3.exe setup.exe setup.exe no specs setup.exe setup.exe no specs wavebrowser.exe wavebrowser.exe no specs swupdater.exe wavebrowser.exe no specs wavebrowser.exe wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs systemsettings.exe wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
188"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=6584,i,5996771732775977948,13299356523998392139,262144 --variations-seed-version=15 --mojo-platform-channel-handle=7032 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.3
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.3\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
188"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=6268,i,5996771732775977948,13299356523998392139,262144 --variations-seed-version=15 --mojo-platform-channel-handle=8108 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.3
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.3\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
608"C:\Users\admin\AppData\Local\Temp\Wave Browser.exe" C:\Users\admin\AppData\Local\Temp\Wave Browser.exe
explorer.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.3
Modules
Images
c:\users\admin\appdata\local\temp\wave browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
640"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=4636,i,5996771732775977948,13299356523998392139,262144 --variations-seed-version=15 --mojo-platform-channel-handle=10088 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.3
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.3\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1152"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=117 --field-trial-handle=8076,i,5996771732775977948,13299356523998392139,262144 --variations-seed-version=15 --mojo-platform-channel-handle=11288 /prefetch:1C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Version:
1.5.18.3
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.3\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1300"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=renderer --instant-process --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=118 --field-trial-handle=11232,i,5996771732775977948,13299356523998392139,262144 --variations-seed-version=15 --mojo-platform-channel-handle=11600 /prefetch:1C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Version:
1.5.18.3
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.3\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1336C:\Users\admin\AppData\Local\Temp\nssDADD.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\WaveBrowser\User Data\Crashpad" --annotation=channel= --annotation=plat=Win64 --annotation=prod=WaveBrowser --annotation=ver=1.5.18.3 --initial-client-data=0x29c,0x2a0,0x2a4,0x278,0x2a8,0x7ff6f154b370,0x7ff6f154b37c,0x7ff6f154b388C:\Users\admin\AppData\Local\Temp\nssDADD.tmp\setup.exesetup.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
WaveBrowser Installer
Exit code:
0
Version:
1.5.18.3
Modules
Images
c:\users\admin\appdata\local\temp\nssdadd.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1372"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=4332,i,5996771732775977948,13299356523998392139,262144 --variations-seed-version=15 --mojo-platform-channel-handle=4328 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.3
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.3\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1372"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=6704,i,5996771732775977948,13299356523998392139,262144 --variations-seed-version=15 --mojo-platform-channel-handle=7632 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.3
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.3\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
1404"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --field-trial-handle=7224,i,5996771732775977948,13299356523998392139,262144 --variations-seed-version=15 --mojo-platform-channel-handle=6992 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.18.3
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.18.3\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
Total events
17 909
Read events
16 496
Write events
1 340
Delete events
73

Modification events

(PID) Process:(608) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(608) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(608) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(608) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(608) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(608) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(608) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(608) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(608) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(608) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
40
Suspicious files
605
Text files
863
Unknown types
21

Dropped files

PID
Process
Filename
Type
6828SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM6CE0.tmp\SWUpdaterComRegisterShell64.exeexecutable
MD5:B483BB4C375468CFDAE4A2ED4E40D056
SHA256:DF80D9477A45EB1FF233F3D361A1D82729C368987DE14C09747DF0F959184902
6828SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM6CE0.tmp\swupdaterres_en.dllexecutable
MD5:4C638B6D2D9E243EE521EC29297728D2
SHA256:4DF4CF6C745EE927376AC7B1CC6BAA9B7A749F60CE20E27B3BED209295849D6F
6828SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM6CE0.tmp\psuser_64.dllexecutable
MD5:7F956DD9AE7C4D18789C62F545E21295
SHA256:9362A40DA1C9EE1B600311EB2AA0F732299DD68E693254ED118A4DC5273B813E
6828SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM6CE0.tmp\SWUpdaterBroker.exeexecutable
MD5:C209D2A5F427B8DBD6EC71D6E57C7E61
SHA256:76A54D6C150E7F38A08032A260EB5396C8DF89CE9CEF27F99A2A2BDF23D9F381
6828SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM6CE0.tmp\psmachine_64.dllexecutable
MD5:D75403C05D96BED42E8E27D1E735E6E5
SHA256:04DD87E70D8CDEFAE35953763A23AC30FD9D8B5EBCF424173F001E2C1889C08E
4712SWUpdater.exeC:\Users\admin\Wavesor Software\SWUpdater\1.3.135.0\SWUpdaterCore.exeexecutable
MD5:C2540F15C66D32D867F8205E39BA5C2F
SHA256:9B296F4894F4A969F2F3CE0C5C2DDB8EEA503DEB4919B23555FC3F04FA0AED41
6828SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM6CE0.tmp\SWUpdaterCore.exeexecutable
MD5:C2540F15C66D32D867F8205E39BA5C2F
SHA256:9B296F4894F4A969F2F3CE0C5C2DDB8EEA503DEB4919B23555FC3F04FA0AED41
2628SWUpdater.exeC:\Users\admin\Wavesor Software\SWUpdater\Download\{EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}\1.5.18.3\WaveInstaller-v1.5.18.3.exe
MD5:
SHA256:
2628SWUpdater.exeC:\Users\admin\Wavesor Software\SWUpdater\Install\{7AF5DFBE-FE1E-47CE-A020-8F9A2F915D05}\WaveInstaller-v1.5.18.3.exe
MD5:
SHA256:
6828SWUpdaterSetup.exeC:\Users\admin\AppData\Local\Temp\GUM6CE0.tmp\psuser.dllexecutable
MD5:DB8B356AB2314B130B4B85593576DE14
SHA256:8A412A690343346783C19967ED0AD7E1D8A1E6E31015C62828E792FB0A5EA626
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
150
DNS requests
128
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4080
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5880
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2368
setup.exe
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
unknown
unknown
4080
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2368
setup.exe
GET
200
18.245.65.219:80
http://ocsp.r2m02.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRmbQtwnInkvkvr7BNFR%2BS2lTYPjAQUwDFSzVpQw4J8dHHOy%2Bmc%2BXrrguICEAdC4QyEgUNnqtiNTeKlhaI%3D
unknown
whitelisted
1768
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1028
SystemSettings.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6020
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/fb65ahwxmyjeiy7pxajl6ah4ci_9183/hfnkpimlhhgieaddgfemjhofmfblmnib_9183_all_gvjn4jnhilcvrwetai3fkxbvsa.crx3
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2120
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
608
Wave Browser.exe
23.20.9.225:443
api.wavebrowserbase.com
AMAZON-AES
US
suspicious
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2868
SWUpdater.exe
44.217.0.154:443
swupdater.com
AMAZON-AES
US
unknown
2628
SWUpdater.exe
44.217.0.154:443
swupdater.com
AMAZON-AES
US
unknown
6020
svchost.exe
18.173.154.55:443
cdn.swupdater.com
US
suspicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 184.30.21.171
whitelisted
google.com
  • 142.250.186.110
whitelisted
api.wavebrowserbase.com
  • 23.20.9.225
  • 34.202.209.221
  • 34.199.236.63
  • 35.169.210.21
  • 3.213.6.12
  • 44.218.117.40
unknown
swupdater.com
  • 44.217.0.154
  • 54.167.126.60
unknown
cdn.swupdater.com
  • 18.173.154.55
  • 18.173.154.125
  • 18.173.154.69
  • 18.173.154.102
unknown
login.live.com
  • 40.126.31.73
  • 20.190.159.68
  • 20.190.159.64
  • 20.190.159.4
  • 20.190.159.0
  • 20.190.159.75
  • 20.190.159.2
  • 40.126.31.69
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted

Threats

No threats detected
No debug info