URL:

https://install.convertwithwave.com/hh/bgb-convert-files-ty

Full analysis: https://app.any.run/tasks/7dd9c439-53d5-404a-bfb7-e6115398924b
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: September 03, 2025, 17:27:34
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
anti-evasion
Indicators:
MD5:

7995F1A37F225BCC7E9EE87FCFA2F03C

SHA1:

5AF0261A090C0250A23B2C1CA471B4849A418E3D

SHA256:

93C971D1C8CE03951B6764356301B79CF1FD4C59EEE776B7CE11EFFF3A037923

SSDEEP:

3:N8LREJFdnAXbNaGTWNzunYApcn:2lgbn2ntpc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • SWUpdater.exe (PID: 1660)
    • Actions looks like stealing of personal data

      • wavebrowser.exe (PID: 7532)
      • wavebrowser.exe (PID: 4476)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Wave Browser.exe (PID: 2728)
      • SWUpdaterSetup.exe (PID: 5712)
      • SWUpdater.exe (PID: 1660)
      • setup.exe (PID: 7968)
      • WaveInstaller-v1.5.21.11.exe (PID: 440)
    • Reads the date of Windows installation

      • Wave Browser.exe (PID: 2728)
      • setup.exe (PID: 4412)
    • Reads security settings of Internet Explorer

      • Wave Browser.exe (PID: 2728)
      • SWUpdater.exe (PID: 1660)
      • setup.exe (PID: 7968)
      • setup.exe (PID: 4412)
      • SWUpdater.exe (PID: 7800)
    • Creates/Modifies COM task schedule object

      • SWUpdaterComRegisterShell64.exe (PID: 7524)
      • SWUpdater.exe (PID: 7552)
      • SWUpdaterComRegisterShell64.exe (PID: 7632)
      • SWUpdaterComRegisterShell64.exe (PID: 7504)
    • Starts itself from another location

      • SWUpdater.exe (PID: 1660)
    • Creates a software uninstall entry

      • setup.exe (PID: 7968)
    • Searches for installed software

      • setup.exe (PID: 7968)
    • Application launched itself

      • setup.exe (PID: 7968)
      • setup.exe (PID: 4412)
      • wavebrowser.exe (PID: 7532)
      • SWUpdater.exe (PID: 7800)
      • wavebrowser.exe (PID: 7264)
    • The process checks if it is being run in the virtual environment

      • wavebrowser.exe (PID: 7532)
  • INFO

    • Checks supported languages

      • identity_helper.exe (PID: 7512)
      • Wave Browser.exe (PID: 2728)
      • SWUpdaterSetup.exe (PID: 5712)
      • SWUpdater.exe (PID: 1660)
      • SWUpdaterComRegisterShell64.exe (PID: 7524)
      • SWUpdaterComRegisterShell64.exe (PID: 7504)
      • SWUpdaterComRegisterShell64.exe (PID: 7632)
      • SWUpdater.exe (PID: 4544)
      • SWUpdater.exe (PID: 7552)
      • SWUpdater.exe (PID: 4944)
      • SWUpdater.exe (PID: 7800)
      • setup.exe (PID: 7516)
      • setup.exe (PID: 7968)
      • WaveInstaller-v1.5.21.11.exe (PID: 440)
      • setup.exe (PID: 4412)
      • setup.exe (PID: 7632)
      • wavebrowser.exe (PID: 7532)
      • SWUpdater.exe (PID: 7240)
      • wavebrowser.exe (PID: 4112)
      • wavebrowser.exe (PID: 7852)
      • wavebrowser.exe (PID: 6228)
      • wavebrowser.exe (PID: 7292)
      • wavebrowser.exe (PID: 5576)
      • wavebrowser.exe (PID: 4700)
      • wavebrowser.exe (PID: 1096)
      • wavebrowser.exe (PID: 4476)
      • wavebrowser.exe (PID: 7260)
      • wavebrowser.exe (PID: 7264)
      • wavebrowser.exe (PID: 7724)
      • wavebrowser.exe (PID: 1100)
      • wavebrowser.exe (PID: 1660)
      • wavebrowser.exe (PID: 8304)
      • wavebrowser.exe (PID: 6796)
      • wavebrowser.exe (PID: 8220)
      • wavebrowser.exe (PID: 8312)
      • wavebrowser.exe (PID: 8268)
      • wavebrowser.exe (PID: 8348)
      • wavebrowser.exe (PID: 8288)
      • wavebrowser.exe (PID: 7152)
      • wavebrowser.exe (PID: 8452)
      • wavebrowser.exe (PID: 8296)
      • wavebrowser.exe (PID: 1872)
      • wavebrowser.exe (PID: 8252)
      • wavebrowser.exe (PID: 8468)
      • wavebrowser.exe (PID: 8200)
      • wavebrowser.exe (PID: 8260)
      • wavebrowser.exe (PID: 8328)
      • wavebrowser.exe (PID: 8208)
      • wavebrowser.exe (PID: 8320)
      • wavebrowser.exe (PID: 8336)
      • wavebrowser.exe (PID: 8716)
      • wavebrowser.exe (PID: 8924)
      • wavebrowser.exe (PID: 8860)
      • wavebrowser.exe (PID: 9412)
      • wavebrowser.exe (PID: 9272)
      • wavebrowser.exe (PID: 9420)
      • wavebrowser.exe (PID: 9732)
      • wavebrowser.exe (PID: 9528)
      • wavebrowser.exe (PID: 9628)
      • wavebrowser.exe (PID: 9784)
      • wavebrowser.exe (PID: 9836)
      • wavebrowser.exe (PID: 8484)
      • wavebrowser.exe (PID: 7972)
      • wavebrowser.exe (PID: 5184)
      • wavebrowser.exe (PID: 8516)
      • wavebrowser.exe (PID: 9168)
      • wavebrowser.exe (PID: 10004)
      • wavebrowser.exe (PID: 10020)
      • wavebrowser.exe (PID: 10012)
      • wavebrowser.exe (PID: 10028)
      • wavebrowser.exe (PID: 9416)
      • wavebrowser.exe (PID: 10036)
      • wavebrowser.exe (PID: 10044)
      • wavebrowser.exe (PID: 10052)
      • wavebrowser.exe (PID: 9972)
      • wavebrowser.exe (PID: 9492)
      • wavebrowser.exe (PID: 9480)
      • wavebrowser.exe (PID: 7264)
      • wavebrowser.exe (PID: 9412)
      • wavebrowser.exe (PID: 9464)
      • wavebrowser.exe (PID: 9620)
      • wavebrowser.exe (PID: 9628)
      • wavebrowser.exe (PID: 9980)
      • wavebrowser.exe (PID: 9988)
      • wavebrowser.exe (PID: 9996)
      • wavebrowser.exe (PID: 9732)
      • wavebrowser.exe (PID: 2324)
      • wavebrowser.exe (PID: 9896)
      • wavebrowser.exe (PID: 9696)
      • wavebrowser.exe (PID: 9864)
      • wavebrowser.exe (PID: 10144)
      • wavebrowser.exe (PID: 4032)
      • wavebrowser.exe (PID: 5928)
      • wavebrowser.exe (PID: 9288)
      • wavebrowser.exe (PID: 9280)
      • wavebrowser.exe (PID: 9928)
      • wavebrowser.exe (PID: 3960)
      • wavebrowser.exe (PID: 10060)
      • wavebrowser.exe (PID: 10112)
      • wavebrowser.exe (PID: 9744)
      • wavebrowser.exe (PID: 9456)
      • wavebrowser.exe (PID: 9768)
      • wavebrowser.exe (PID: 9604)
      • wavebrowser.exe (PID: 8028)
      • wavebrowser.exe (PID: 10020)
      • wavebrowser.exe (PID: 9776)
      • wavebrowser.exe (PID: 8516)
      • wavebrowser.exe (PID: 9772)
      • wavebrowser.exe (PID: 8508)
      • wavebrowser.exe (PID: 10180)
      • wavebrowser.exe (PID: 10232)
      • wavebrowser.exe (PID: 5904)
      • wavebrowser.exe (PID: 9272)
      • wavebrowser.exe (PID: 9888)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 3844)
      • msedge.exe (PID: 5240)
    • Application launched itself

      • msedge.exe (PID: 3844)
    • Reads the machine GUID from the registry

      • Wave Browser.exe (PID: 2728)
      • setup.exe (PID: 7968)
      • setup.exe (PID: 4412)
      • wavebrowser.exe (PID: 7532)
    • Reads Environment values

      • identity_helper.exe (PID: 7512)
      • Wave Browser.exe (PID: 2728)
    • Reads the computer name

      • identity_helper.exe (PID: 7512)
      • Wave Browser.exe (PID: 2728)
      • SWUpdater.exe (PID: 1660)
      • SWUpdater.exe (PID: 4544)
      • SWUpdater.exe (PID: 7552)
      • SWUpdater.exe (PID: 7800)
      • SWUpdater.exe (PID: 4944)
      • setup.exe (PID: 7968)
      • setup.exe (PID: 4412)
      • wavebrowser.exe (PID: 7532)
      • SWUpdater.exe (PID: 7240)
      • wavebrowser.exe (PID: 7852)
      • wavebrowser.exe (PID: 6228)
      • wavebrowser.exe (PID: 4476)
      • wavebrowser.exe (PID: 7264)
      • wavebrowser.exe (PID: 7152)
      • wavebrowser.exe (PID: 1660)
      • wavebrowser.exe (PID: 9836)
    • Disables trace logs

      • Wave Browser.exe (PID: 2728)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 3844)
    • Checks proxy server information

      • Wave Browser.exe (PID: 2728)
      • SWUpdater.exe (PID: 7800)
      • SWUpdater.exe (PID: 4544)
      • setup.exe (PID: 7968)
      • setup.exe (PID: 4412)
      • SWUpdater.exe (PID: 7240)
      • wavebrowser.exe (PID: 7532)
    • Reads the software policy settings

      • Wave Browser.exe (PID: 2728)
      • SWUpdater.exe (PID: 7800)
      • SWUpdater.exe (PID: 4544)
      • setup.exe (PID: 7968)
      • setup.exe (PID: 4412)
      • SWUpdater.exe (PID: 7240)
    • The sample compiled with english language support

      • SWUpdaterSetup.exe (PID: 5712)
      • Wave Browser.exe (PID: 2728)
      • SWUpdater.exe (PID: 1660)
      • setup.exe (PID: 7968)
      • WaveInstaller-v1.5.21.11.exe (PID: 440)
    • Create files in a temporary directory

      • SWUpdaterSetup.exe (PID: 5712)
      • Wave Browser.exe (PID: 2728)
      • setup.exe (PID: 7968)
      • SWUpdater.exe (PID: 7800)
      • svchost.exe (PID: 7856)
      • WaveInstaller-v1.5.21.11.exe (PID: 440)
      • wavebrowser.exe (PID: 7532)
      • wavebrowser.exe (PID: 4476)
    • Process checks computer location settings

      • Wave Browser.exe (PID: 2728)
      • SWUpdater.exe (PID: 1660)
      • SWUpdater.exe (PID: 7800)
      • wavebrowser.exe (PID: 7532)
      • wavebrowser.exe (PID: 7292)
      • wavebrowser.exe (PID: 4476)
      • wavebrowser.exe (PID: 7260)
      • wavebrowser.exe (PID: 8268)
      • wavebrowser.exe (PID: 5576)
      • wavebrowser.exe (PID: 8304)
      • wavebrowser.exe (PID: 8296)
      • wavebrowser.exe (PID: 8220)
      • wavebrowser.exe (PID: 8348)
      • wavebrowser.exe (PID: 7724)
      • wavebrowser.exe (PID: 8260)
      • wavebrowser.exe (PID: 8716)
      • wavebrowser.exe (PID: 6796)
      • wavebrowser.exe (PID: 8328)
      • wavebrowser.exe (PID: 8924)
      • wavebrowser.exe (PID: 8336)
      • wavebrowser.exe (PID: 8208)
      • wavebrowser.exe (PID: 8320)
      • wavebrowser.exe (PID: 8252)
      • wavebrowser.exe (PID: 8860)
      • wavebrowser.exe (PID: 8288)
      • wavebrowser.exe (PID: 8200)
      • wavebrowser.exe (PID: 9168)
      • wavebrowser.exe (PID: 1872)
      • wavebrowser.exe (PID: 10020)
      • wavebrowser.exe (PID: 9772)
      • wavebrowser.exe (PID: 9768)
      • wavebrowser.exe (PID: 9456)
      • wavebrowser.exe (PID: 9604)
      • wavebrowser.exe (PID: 10232)
      • wavebrowser.exe (PID: 9928)
      • wavebrowser.exe (PID: 9776)
      • wavebrowser.exe (PID: 5904)
      • wavebrowser.exe (PID: 8028)
      • wavebrowser.exe (PID: 8508)
      • wavebrowser.exe (PID: 9888)
      • wavebrowser.exe (PID: 9272)
    • Wave updater related mutex has been found

      • SWUpdater.exe (PID: 7552)
      • SWUpdater.exe (PID: 1660)
      • SWUpdater.exe (PID: 4544)
      • SWUpdater.exe (PID: 7800)
      • SWUpdater.exe (PID: 7240)
    • Launching a file from a Registry key

      • SWUpdater.exe (PID: 1660)
    • Creates files or folders in the user directory

      • setup.exe (PID: 7968)
      • setup.exe (PID: 4412)
      • wavebrowser.exe (PID: 4112)
      • wavebrowser.exe (PID: 7532)
      • wavebrowser.exe (PID: 6228)
      • wavebrowser.exe (PID: 1100)
      • wavebrowser.exe (PID: 7264)
    • Manual execution by a user

      • wavebrowser.exe (PID: 7264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
282
Monitored processes
143
Malicious processes
7
Suspicious processes
3

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
424"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=24 --always-read-main-dll --field-trial-handle=7212,i,11789201055038686098,3513894753777817760,262144 --variations-seed-version --mojo-platform-channel-handle=5836 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
440"C:\Users\admin\Wavesor Software\SWUpdater\Install\{6152C850-F1E0-4447-8C83-F7C7D5B8BB5E}\WaveInstaller-v1.5.21.11.exe" /installerdata="C:\Users\admin\AppData\Local\Temp\gui402C.tmp"C:\Users\admin\Wavesor Software\SWUpdater\Install\{6152C850-F1E0-4447-8C83-F7C7D5B8BB5E}\WaveInstaller-v1.5.21.11.exe
SWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Installer of Wave Browser
Exit code:
0
Version:
1.5.21.11
Modules
Images
c:\users\admin\wavesor software\swupdater\install\{6152c850-f1e0-4447-8c83-f7c7d5b8bb5e}\waveinstaller-v1.5.21.11.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1096"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --field-trial-handle=2384,i,2757045604077903172,10590540543050005536,262144 --variations-seed-version=15 --mojo-platform-channel-handle=2396 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Version:
1.5.21.11
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\wavesor software\wavebrowser\1.5.21.11\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1100"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\WaveBrowser\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\WaveBrowser\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\WaveBrowser\User Data" --annotation=channel= --annotation=plat=Win64 --annotation=prod=WaveBrowser --annotation=ver=1.5.21.11 --initial-client-data=0x17c,0x180,0x184,0x158,0x188,0x7ffc42497c48,0x7ffc42497c54,0x7ffc42497c60C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
WaveBrowser
Exit code:
0
Version:
1.5.21.11
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\wavesor software\wavebrowser\1.5.21.11\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
1288"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=8324,i,11789201055038686098,3513894753777817760,262144 --variations-seed-version --mojo-platform-channel-handle=7460 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1508"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x304,0x308,0x30c,0x2fc,0x314,0x7ffc43cef208,0x7ffc43cef214,0x7ffc43cef220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1660C:\Users\admin\AppData\Local\Temp\GUM16AB.tmp\SWUpdater.exe /install "bundlename=WaveBrowser&appguid={EB149AD2-CE4E-4F51-B7FC-A149FAA4CCAF}&appname=WaveBrowser&needsadmin=False&lang=en&usagestats=1&installdataindex=1"C:\Users\admin\AppData\Local\Temp\GUM16AB.tmp\SWUpdater.exe
SWUpdaterSetup.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.139.0
Modules
Images
c:\users\admin\appdata\local\temp\gum16ab.tmp\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1660"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=4900,i,2757045604077903172,10590540543050005536,262144 --variations-seed-version=15 --mojo-platform-channel-handle=4768 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
WaveBrowser
Exit code:
0
Version:
1.5.21.11
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\wavesor software\wavebrowser\1.5.21.11\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1872"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=renderer --string-annotations=is-enterprise-managed=no --enable-dinosaur-easter-egg-alt-images --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=15 --field-trial-handle=5056,i,2757045604077903172,10590540543050005536,262144 --variations-seed-version=15 --mojo-platform-channel-handle=5320 /prefetch:1C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Version:
1.5.21.11
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\wavesor software\wavebrowser\1.5.21.11\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2324"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --field-trial-handle=11944,i,2757045604077903172,10590540543050005536,262144 --variations-seed-version=15 --mojo-platform-channel-handle=11996 /prefetch:8C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.21.11
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\wavesor software\wavebrowser\1.5.21.11\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
22 944
Read events
21 900
Write events
973
Delete events
71

Modification events

(PID) Process:(3844) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3844) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3844) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(3844) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(3844) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3844) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(3844) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328510
Operation:writeName:WindowTabManagerFileMappingId
Value:
{1087989C-2087-415B-89F1-B2DCF49C7520}
(PID) Process:(3844) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
9C2282347F9C2F00
(PID) Process:(3844) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328510
Operation:writeName:WindowTabManagerFileMappingId
Value:
{DFB0EECB-5611-46B6-962A-AD5DA647B66C}
(PID) Process:(3844) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328510
Operation:writeName:WindowTabManagerFileMappingId
Value:
{6DF3CA73-459E-4FB7-A4A8-403329F69CB6}
Executable files
45
Suspicious files
751
Text files
534
Unknown types
0

Dropped files

PID
Process
Filename
Type
3844msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF18d220.TMP
MD5:
SHA256:
3844msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
3844msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF18d22f.TMP
MD5:
SHA256:
3844msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
3844msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF18d22f.TMP
MD5:
SHA256:
3844msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
3844msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF18d25e.TMP
MD5:
SHA256:
3844msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
3844msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF18d25e.TMP
MD5:
SHA256:
3844msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF18d25e.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
201
DNS requests
184
Threats
113

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
5240
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:WsulCASCZTv0PHMGVnieedRi5z_ykVpfeLb-g7a6W_k&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
99 b
whitelisted
1268
svchost.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
6936
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
3844
msedge.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAnXekXBwJdVrj56UVOYPAM%3D
DE
binary
727 b
whitelisted
7968
setup.exe
GET
200
18.173.160.201:80
http://ocsp.r2m02.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRmbQtwnInkvkvr7BNFR%2BS2lTYPjAQUwDFSzVpQw4J8dHHOy%2Bmc%2BXrrguICEAzNhCMvqqerLFbI47OQv1Q%3D
US
binary
471 b
whitelisted
7968
setup.exe
GET
200
18.173.189.168:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D
US
binary
1.40 Kb
whitelisted
5328
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
313 b
whitelisted
8000
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
8000
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5884
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5240
msedge.exe
150.171.28.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5240
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5240
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5240
msedge.exe
92.123.104.53:443
copilot.microsoft.com
Akamai International B.V.
DE
whitelisted
5240
msedge.exe
54.243.230.75:443
install.convertwithwave.com
AMAZON-AES
US
suspicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.142
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
install.convertwithwave.com
  • 54.243.230.75
  • 54.210.221.155
  • 50.16.165.178
  • 3.232.205.63
  • 54.166.211.159
  • 50.16.18.190
unknown
copilot.microsoft.com
  • 92.123.104.53
  • 92.123.104.45
whitelisted
use.typekit.net
  • 184.24.77.152
  • 184.24.77.156
whitelisted
p.typekit.net
  • 184.24.77.154
  • 184.24.77.146
whitelisted
fonts.gstatic.com
  • 216.58.206.67
whitelisted
www.bing.com
  • 92.123.104.32
  • 92.123.104.34
  • 92.123.104.18
  • 92.123.104.31
  • 92.123.104.33
  • 92.123.104.26
  • 92.123.104.17
  • 92.123.104.29
  • 92.123.104.21
  • 92.123.104.55
  • 92.123.104.52
  • 92.123.104.49
  • 92.123.104.50
  • 92.123.104.47
  • 92.123.104.53
  • 92.123.104.46
  • 92.123.104.57
  • 92.123.104.45
whitelisted

Threats

PID
Process
Class
Message
5240
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5240
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
5240
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
6228
wavebrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6228
wavebrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6228
wavebrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6228
wavebrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6228
wavebrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6228
wavebrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
6228
wavebrowser.exe
Generic Protocol Command Decode
SURICATA QUIC failed decrypt
No debug info