URL:

wavebrowser.com

Full analysis: https://app.any.run/tasks/bec2e170-d1f7-446d-9a64-e58bdc42a3be
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 25, 2026, 14:19:35
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
Indicators:
MD5:

2600D8D2283E2E3D129206B7AEE9BD63

SHA1:

EF876BBBD6DDB180070B67C35758A5E59A55E98E

SHA256:

BF165B2B88BC57F1ACE2200037A4FFBE6613A186B635BF45BCC80F8AE14B2474

SSDEEP:

3:853yKI:VKI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • SWUpdater.exe (PID: 4796)
      • SWUpdater.exe (PID: 10632)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • Wave Browser.exe (PID: 5152)
      • setup.exe (PID: 8380)
      • Wave Browser (1).exe (PID: 10720)
      • setup.exe (PID: 10996)
      • Wave Browser - 2026-03-25T142125.818.exe (PID: 8872)
      • setup.exe (PID: 10280)
      • Wave Browser.exe (PID: 6696)
      • setup.exe (PID: 9952)
      • Wave Browser (2).exe (PID: 10648)
      • setup.exe (PID: 8096)
    • Executable content was dropped or overwritten

      • SWUpdaterSetup.exe (PID: 5168)
      • Wave Browser.exe (PID: 5152)
      • SWUpdater.exe (PID: 4796)
      • WaveInstaller-v1.5.21.10.exe (PID: 8728)
      • setup.exe (PID: 2428)
      • Wave Browser (1).exe (PID: 10720)
      • SWUpdaterSetup.exe (PID: 10928)
      • WaveInstaller-v1.5.21.10.exe (PID: 6900)
      • setup.exe (PID: 4996)
      • Wave Browser - 2026-03-25T142125.818.exe (PID: 8872)
      • SWUpdater.exe (PID: 10632)
      • SWUpdaterSetup.exe (PID: 6172)
      • WaveInstaller-v1.5.21.10.exe (PID: 11196)
      • setup.exe (PID: 5496)
      • Wave Browser.exe (PID: 6696)
      • SWUpdaterSetup.exe (PID: 6240)
      • WaveInstaller-v1.5.21.10.exe (PID: 7540)
      • setup.exe (PID: 8888)
      • Wave Browser (2).exe (PID: 10648)
      • SWUpdaterSetup.exe (PID: 5520)
      • setup.exe (PID: 6148)
      • WaveInstaller-v1.5.21.10.exe (PID: 5412)
    • Starts itself from another location

      • SWUpdater.exe (PID: 4796)
      • SWUpdater.exe (PID: 9736)
      • SWUpdater.exe (PID: 10632)
      • SWUpdater.exe (PID: 10556)
    • Creates/Modifies COM task schedule object

      • SWUpdaterComRegisterShell64.exe (PID: 8892)
      • SWUpdaterComRegisterShell64.exe (PID: 7020)
      • SWUpdaterComRegisterShell64.exe (PID: 9140)
      • SWUpdater.exe (PID: 1344)
      • SWUpdaterComRegisterShell64.exe (PID: 1784)
      • SWUpdaterComRegisterShell64.exe (PID: 8704)
      • SWUpdaterComRegisterShell64.exe (PID: 10196)
      • SWUpdater.exe (PID: 10932)
    • Searches for installed software

      • setup.exe (PID: 2428)
      • setup.exe (PID: 4996)
      • setup.exe (PID: 5496)
      • setup.exe (PID: 8888)
      • setup.exe (PID: 6148)
    • Application launched itself

      • setup.exe (PID: 2428)
      • wavebrowser.exe (PID: 8332)
      • SWUpdater.exe (PID: 8708)
      • setup.exe (PID: 8380)
      • setup.exe (PID: 4996)
      • setup.exe (PID: 10996)
      • wavebrowser.exe (PID: 10744)
      • SWUpdater.exe (PID: 8408)
      • SWUpdater.exe (PID: 9452)
      • setup.exe (PID: 5496)
      • setup.exe (PID: 10280)
      • wavebrowser.exe (PID: 10396)
      • SWUpdater.exe (PID: 2264)
      • setup.exe (PID: 8888)
      • setup.exe (PID: 9952)
      • wavebrowser.exe (PID: 7340)
      • SWUpdater.exe (PID: 7228)
      • setup.exe (PID: 6148)
      • setup.exe (PID: 8096)
      • wavebrowser.exe (PID: 3804)
      • SWUpdater.exe (PID: 9732)
  • INFO

    • Reads Environment values

      • identity_helper.exe (PID: 8968)
      • Wave Browser.exe (PID: 5152)
      • Wave Browser (1).exe (PID: 10720)
      • Wave Browser - 2026-03-25T142125.818.exe (PID: 8872)
      • Wave Browser.exe (PID: 6696)
      • Wave Browser (2).exe (PID: 10648)
    • Reads the computer name

      • identity_helper.exe (PID: 8968)
      • Wave Browser.exe (PID: 5152)
      • SWUpdater.exe (PID: 1344)
      • SWUpdater.exe (PID: 4796)
      • SWUpdater.exe (PID: 1792)
      • SWUpdater.exe (PID: 7548)
      • SWUpdater.exe (PID: 8708)
      • setup.exe (PID: 2428)
      • setup.exe (PID: 8380)
      • wavebrowser.exe (PID: 8332)
      • SWUpdater.exe (PID: 5612)
      • wavebrowser.exe (PID: 8160)
      • wavebrowser.exe (PID: 4728)
      • wavebrowser.exe (PID: 9408)
      • wavebrowser.exe (PID: 9812)
      • wavebrowser.exe (PID: 9804)
      • wavebrowser.exe (PID: 10068)
      • Wave Browser (1).exe (PID: 10720)
      • SWUpdater.exe (PID: 9744)
      • SWUpdater.exe (PID: 10940)
      • SWUpdater.exe (PID: 9764)
      • SWUpdater.exe (PID: 8408)
      • SWUpdater.exe (PID: 9736)
      • setup.exe (PID: 4996)
      • setup.exe (PID: 10996)
      • wavebrowser.exe (PID: 10744)
      • Wave Browser - 2026-03-25T142125.818.exe (PID: 8872)
      • SWUpdater.exe (PID: 9452)
      • SWUpdater.exe (PID: 7716)
      • SWUpdater.exe (PID: 10224)
      • SWUpdaterCore.exe (PID: 9872)
      • SWUpdater.exe (PID: 10632)
      • SWUpdater.exe (PID: 11188)
      • SWUpdater.exe (PID: 10932)
      • SWUpdater.exe (PID: 2264)
      • setup.exe (PID: 5496)
      • SWUpdater.exe (PID: 10532)
      • setup.exe (PID: 10280)
      • wavebrowser.exe (PID: 10396)
      • wavebrowser.exe (PID: 4484)
      • SWUpdater.exe (PID: 10980)
      • wavebrowser.exe (PID: 4468)
      • Wave Browser.exe (PID: 6696)
      • SWUpdater.exe (PID: 3212)
      • SWUpdater.exe (PID: 9808)
      • SWUpdater.exe (PID: 8412)
      • SWUpdater.exe (PID: 7228)
      • SWUpdater.exe (PID: 4552)
      • setup.exe (PID: 8888)
      • setup.exe (PID: 9952)
      • wavebrowser.exe (PID: 7340)
      • wavebrowser.exe (PID: 3400)
      • Wave Browser (2).exe (PID: 10648)
      • SWUpdater.exe (PID: 10556)
      • SWUpdater.exe (PID: 2452)
      • SWUpdater.exe (PID: 10708)
      • SWUpdater.exe (PID: 3500)
      • SWUpdater.exe (PID: 9732)
      • setup.exe (PID: 6148)
      • setup.exe (PID: 8096)
      • wavebrowser.exe (PID: 3804)
      • wavebrowser.exe (PID: 3920)
      • SWUpdater.exe (PID: 11572)
      • SWUpdater.exe (PID: 10336)
    • Disables trace logs

      • Wave Browser.exe (PID: 5152)
      • Wave Browser (1).exe (PID: 10720)
      • Wave Browser - 2026-03-25T142125.818.exe (PID: 8872)
      • Wave Browser.exe (PID: 6696)
      • Wave Browser (2).exe (PID: 10648)
    • Checks supported languages

      • identity_helper.exe (PID: 8968)
      • Wave Browser.exe (PID: 5152)
      • SWUpdaterSetup.exe (PID: 5168)
      • SWUpdater.exe (PID: 1344)
      • SWUpdater.exe (PID: 4796)
      • SWUpdater.exe (PID: 8708)
      • SWUpdaterComRegisterShell64.exe (PID: 8892)
      • SWUpdaterComRegisterShell64.exe (PID: 7020)
      • SWUpdaterComRegisterShell64.exe (PID: 9140)
      • SWUpdater.exe (PID: 1792)
      • SWUpdater.exe (PID: 7548)
      • setup.exe (PID: 2428)
      • setup.exe (PID: 9068)
      • setup.exe (PID: 8380)
      • WaveInstaller-v1.5.21.10.exe (PID: 8728)
      • setup.exe (PID: 8148)
      • wavebrowser.exe (PID: 6280)
      • wavebrowser.exe (PID: 8332)
      • SWUpdater.exe (PID: 5612)
      • wavebrowser.exe (PID: 9228)
      • wavebrowser.exe (PID: 9284)
      • wavebrowser.exe (PID: 8160)
      • wavebrowser.exe (PID: 4728)
      • wavebrowser.exe (PID: 9276)
      • wavebrowser.exe (PID: 9408)
      • wavebrowser.exe (PID: 9548)
      • wavebrowser.exe (PID: 9588)
      • wavebrowser.exe (PID: 9812)
      • wavebrowser.exe (PID: 10024)
      • wavebrowser.exe (PID: 9864)
      • wavebrowser.exe (PID: 9852)
      • wavebrowser.exe (PID: 10032)
      • wavebrowser.exe (PID: 9916)
      • wavebrowser.exe (PID: 9948)
      • wavebrowser.exe (PID: 9924)
      • wavebrowser.exe (PID: 9840)
      • wavebrowser.exe (PID: 10004)
      • wavebrowser.exe (PID: 9956)
      • wavebrowser.exe (PID: 9964)
      • wavebrowser.exe (PID: 10032)
      • wavebrowser.exe (PID: 9880)
      • wavebrowser.exe (PID: 9988)
      • wavebrowser.exe (PID: 8904)
      • wavebrowser.exe (PID: 9940)
      • wavebrowser.exe (PID: 8604)
      • wavebrowser.exe (PID: 9704)
      • wavebrowser.exe (PID: 9816)
      • wavebrowser.exe (PID: 9680)
      • wavebrowser.exe (PID: 10124)
      • wavebrowser.exe (PID: 9416)
      • wavebrowser.exe (PID: 10068)
      • wavebrowser.exe (PID: 4796)
      • wavebrowser.exe (PID: 10160)
      • wavebrowser.exe (PID: 10144)
      • wavebrowser.exe (PID: 2748)
      • wavebrowser.exe (PID: 7780)
      • wavebrowser.exe (PID: 9852)
      • wavebrowser.exe (PID: 9556)
      • wavebrowser.exe (PID: 2368)
      • wavebrowser.exe (PID: 10100)
      • wavebrowser.exe (PID: 3004)
      • wavebrowser.exe (PID: 9868)
      • wavebrowser.exe (PID: 5700)
      • wavebrowser.exe (PID: 1704)
      • wavebrowser.exe (PID: 3376)
      • wavebrowser.exe (PID: 10172)
      • wavebrowser.exe (PID: 9940)
      • wavebrowser.exe (PID: 4756)
      • wavebrowser.exe (PID: 2496)
      • wavebrowser.exe (PID: 8268)
      • wavebrowser.exe (PID: 9276)
      • wavebrowser.exe (PID: 8240)
      • wavebrowser.exe (PID: 10304)
      • wavebrowser.exe (PID: 5772)
      • wavebrowser.exe (PID: 9580)
      • wavebrowser.exe (PID: 10296)
      • wavebrowser.exe (PID: 10316)
      • wavebrowser.exe (PID: 10280)
      • wavebrowser.exe (PID: 10412)
      • wavebrowser.exe (PID: 10624)
      • wavebrowser.exe (PID: 10428)
      • wavebrowser.exe (PID: 10404)
      • wavebrowser.exe (PID: 10616)
      • wavebrowser.exe (PID: 10688)
      • wavebrowser.exe (PID: 10724)
      • wavebrowser.exe (PID: 10944)
      • wavebrowser.exe (PID: 10872)
      • wavebrowser.exe (PID: 10984)
      • wavebrowser.exe (PID: 11172)
      • wavebrowser.exe (PID: 11000)
      • wavebrowser.exe (PID: 11008)
      • wavebrowser.exe (PID: 10960)
      • wavebrowser.exe (PID: 10880)
      • wavebrowser.exe (PID: 10992)
      • wavebrowser.exe (PID: 10952)
      • wavebrowser.exe (PID: 11024)
      • wavebrowser.exe (PID: 8904)
      • wavebrowser.exe (PID: 10976)
      • wavebrowser.exe (PID: 10528)
      • wavebrowser.exe (PID: 4828)
      • wavebrowser.exe (PID: 10968)
      • wavebrowser.exe (PID: 10612)
      • wavebrowser.exe (PID: 10020)
      • wavebrowser.exe (PID: 9804)
      • wavebrowser.exe (PID: 4688)
      • wavebrowser.exe (PID: 10608)
      • wavebrowser.exe (PID: 10412)
      • Wave Browser (1).exe (PID: 10720)
      • SWUpdater.exe (PID: 9736)
      • SWUpdaterSetup.exe (PID: 10928)
      • SWUpdater.exe (PID: 9744)
      • WaveInstaller-v1.5.21.10.exe (PID: 6900)
      • SWUpdater.exe (PID: 10940)
      • SWUpdater.exe (PID: 9764)
      • SWUpdater.exe (PID: 8408)
      • setup.exe (PID: 4996)
      • setup.exe (PID: 10996)
      • setup.exe (PID: 11184)
      • wavebrowser.exe (PID: 10744)
      • setup.exe (PID: 5716)
      • wavebrowser.exe (PID: 10728)
      • wavebrowser.exe (PID: 3004)
      • wavebrowser.exe (PID: 10052)
      • wavebrowser.exe (PID: 2752)
      • wavebrowser.exe (PID: 11196)
      • wavebrowser.exe (PID: 7208)
      • wavebrowser.exe (PID: 10072)
      • wavebrowser.exe (PID: 2284)
      • wavebrowser.exe (PID: 6580)
      • wavebrowser.exe (PID: 2368)
      • wavebrowser.exe (PID: 7788)
      • wavebrowser.exe (PID: 10008)
      • wavebrowser.exe (PID: 10160)
      • wavebrowser.exe (PID: 10312)
      • SWUpdater.exe (PID: 10224)
      • SWUpdater.exe (PID: 9452)
      • SWUpdater.exe (PID: 7716)
      • Wave Browser - 2026-03-25T142125.818.exe (PID: 8872)
      • SWUpdaterCore.exe (PID: 9872)
      • SWUpdater.exe (PID: 10632)
      • SWUpdaterSetup.exe (PID: 6172)
      • SWUpdaterComRegisterShell64.exe (PID: 1784)
      • SWUpdater.exe (PID: 11188)
      • SWUpdater.exe (PID: 10532)
      • SWUpdaterComRegisterShell64.exe (PID: 10196)
      • SWUpdater.exe (PID: 10932)
      • SWUpdaterComRegisterShell64.exe (PID: 8704)
      • wavebrowser.exe (PID: 9944)
      • WaveInstaller-v1.5.21.10.exe (PID: 11196)
      • SWUpdater.exe (PID: 2264)
      • setup.exe (PID: 9800)
      • setup.exe (PID: 5496)
      • SWUpdaterCore.exe (PID: 1688)
      • setup.exe (PID: 10280)
      • setup.exe (PID: 4756)
      • wavebrowser.exe (PID: 10396)
      • wavebrowser.exe (PID: 4484)
      • wavebrowser.exe (PID: 7540)
      • wavebrowser.exe (PID: 9452)
      • wavebrowser.exe (PID: 1656)
      • wavebrowser.exe (PID: 796)
      • wavebrowser.exe (PID: 8888)
      • wavebrowser.exe (PID: 6944)
      • wavebrowser.exe (PID: 10032)
      • wavebrowser.exe (PID: 8096)
      • wavebrowser.exe (PID: 9936)
      • wavebrowser.exe (PID: 3224)
      • wavebrowser.exe (PID: 4508)
      • wavebrowser.exe (PID: 5600)
      • wavebrowser.exe (PID: 10008)
      • wavebrowser.exe (PID: 7368)
      • wavebrowser.exe (PID: 6552)
      • wavebrowser.exe (PID: 9064)
      • wavebrowser.exe (PID: 10048)
      • SWUpdater.exe (PID: 10980)
      • wavebrowser.exe (PID: 4664)
      • wavebrowser.exe (PID: 4468)
      • wavebrowser.exe (PID: 9612)
      • Wave Browser.exe (PID: 6696)
      • SWUpdaterSetup.exe (PID: 6240)
      • SWUpdater.exe (PID: 4552)
      • SWUpdater.exe (PID: 9808)
      • SWUpdater.exe (PID: 3212)
      • SWUpdater.exe (PID: 8412)
      • wavebrowser.exe (PID: 10564)
      • SWUpdater.exe (PID: 7228)
      • WaveInstaller-v1.5.21.10.exe (PID: 7540)
      • setup.exe (PID: 8888)
      • setup.exe (PID: 11208)
      • setup.exe (PID: 9952)
      • setup.exe (PID: 9576)
      • wavebrowser.exe (PID: 7340)
      • wavebrowser.exe (PID: 3400)
      • wavebrowser.exe (PID: 1572)
      • wavebrowser.exe (PID: 7544)
      • wavebrowser.exe (PID: 1492)
      • wavebrowser.exe (PID: 9900)
      • wavebrowser.exe (PID: 9512)
      • wavebrowser.exe (PID: 10852)
      • wavebrowser.exe (PID: 9800)
      • wavebrowser.exe (PID: 6512)
      • wavebrowser.exe (PID: 10112)
      • wavebrowser.exe (PID: 3584)
      • wavebrowser.exe (PID: 10228)
      • wavebrowser.exe (PID: 792)
      • wavebrowser.exe (PID: 10216)
      • wavebrowser.exe (PID: 9804)
      • wavebrowser.exe (PID: 8276)
      • wavebrowser.exe (PID: 9576)
      • wavebrowser.exe (PID: 8352)
      • wavebrowser.exe (PID: 10052)
      • SWUpdater.exe (PID: 10336)
      • wavebrowser.exe (PID: 7408)
      • SWUpdaterSetup.exe (PID: 5520)
      • Wave Browser (2).exe (PID: 10648)
      • SWUpdater.exe (PID: 2452)
      • SWUpdater.exe (PID: 3500)
      • SWUpdater.exe (PID: 10708)
      • SWUpdater.exe (PID: 10556)
      • SWUpdater.exe (PID: 9732)
      • WaveInstaller-v1.5.21.10.exe (PID: 5412)
      • setup.exe (PID: 6148)
      • setup.exe (PID: 2448)
      • setup.exe (PID: 8096)
      • setup.exe (PID: 10252)
      • wavebrowser.exe (PID: 3804)
      • wavebrowser.exe (PID: 8400)
      • wavebrowser.exe (PID: 10772)
      • wavebrowser.exe (PID: 10140)
      • wavebrowser.exe (PID: 5996)
      • wavebrowser.exe (PID: 8548)
      • wavebrowser.exe (PID: 10400)
      • wavebrowser.exe (PID: 11256)
      • wavebrowser.exe (PID: 6476)
      • wavebrowser.exe (PID: 9196)
      • wavebrowser.exe (PID: 10248)
      • wavebrowser.exe (PID: 2752)
      • wavebrowser.exe (PID: 11200)
      • wavebrowser.exe (PID: 3920)
      • wavebrowser.exe (PID: 11396)
      • wavebrowser.exe (PID: 8312)
      • wavebrowser.exe (PID: 4540)
      • wavebrowser.exe (PID: 11316)
      • SWUpdater.exe (PID: 11572)
      • wavebrowser.exe (PID: 11692)
      • wavebrowser.exe (PID: 10144)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 8036)
    • Reads the machine GUID from the registry

      • Wave Browser.exe (PID: 5152)
      • setup.exe (PID: 2428)
      • setup.exe (PID: 8380)
      • wavebrowser.exe (PID: 8332)
      • Wave Browser (1).exe (PID: 10720)
      • setup.exe (PID: 4996)
      • Wave Browser - 2026-03-25T142125.818.exe (PID: 8872)
      • setup.exe (PID: 5496)
      • wavebrowser.exe (PID: 4468)
      • Wave Browser.exe (PID: 6696)
      • setup.exe (PID: 8888)
      • Wave Browser (2).exe (PID: 10648)
      • setup.exe (PID: 6148)
    • Create files in a temporary directory

      • Wave Browser.exe (PID: 5152)
      • SWUpdaterSetup.exe (PID: 5168)
      • WaveInstaller-v1.5.21.10.exe (PID: 8728)
      • setup.exe (PID: 2428)
      • svchost.exe (PID: 3092)
      • SWUpdater.exe (PID: 8708)
      • wavebrowser.exe (PID: 9408)
      • wavebrowser.exe (PID: 8332)
      • Wave Browser (1).exe (PID: 10720)
      • SWUpdaterSetup.exe (PID: 10928)
      • SWUpdater.exe (PID: 8408)
      • WaveInstaller-v1.5.21.10.exe (PID: 6900)
      • Wave Browser - 2026-03-25T142125.818.exe (PID: 8872)
      • SWUpdaterSetup.exe (PID: 6172)
      • SWUpdater.exe (PID: 10632)
      • SWUpdater.exe (PID: 2264)
      • WaveInstaller-v1.5.21.10.exe (PID: 11196)
      • Wave Browser.exe (PID: 6696)
      • SWUpdaterSetup.exe (PID: 6240)
      • WaveInstaller-v1.5.21.10.exe (PID: 7540)
      • SWUpdater.exe (PID: 7228)
      • Wave Browser (2).exe (PID: 10648)
      • SWUpdaterSetup.exe (PID: 5520)
      • SWUpdater.exe (PID: 9732)
      • WaveInstaller-v1.5.21.10.exe (PID: 5412)
    • Reads security settings of Internet Explorer

      • Wave Browser.exe (PID: 5152)
      • SWUpdater.exe (PID: 4796)
      • setup.exe (PID: 2428)
      • setup.exe (PID: 8380)
      • SWUpdater.exe (PID: 8708)
      • Wave Browser (1).exe (PID: 10720)
      • SWUpdater.exe (PID: 9736)
      • setup.exe (PID: 4996)
      • SWUpdater.exe (PID: 8408)
      • SWUpdaterCore.exe (PID: 9872)
      • Wave Browser - 2026-03-25T142125.818.exe (PID: 8872)
      • SWUpdater.exe (PID: 10632)
      • setup.exe (PID: 5496)
      • SWUpdater.exe (PID: 2264)
      • Wave Browser.exe (PID: 6696)
      • SWUpdater.exe (PID: 4552)
      • setup.exe (PID: 8888)
      • SWUpdater.exe (PID: 7228)
      • Wave Browser (2).exe (PID: 10648)
      • SWUpdater.exe (PID: 10556)
      • setup.exe (PID: 6148)
      • SWUpdater.exe (PID: 9732)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 4292)
      • msedge.exe (PID: 8036)
    • Application launched itself

      • msedge.exe (PID: 8036)
    • The sample compiled with english language support

      • Wave Browser.exe (PID: 5152)
      • SWUpdaterSetup.exe (PID: 5168)
      • SWUpdater.exe (PID: 4796)
      • WaveInstaller-v1.5.21.10.exe (PID: 8728)
      • setup.exe (PID: 2428)
      • Wave Browser (1).exe (PID: 10720)
      • SWUpdaterSetup.exe (PID: 10928)
      • WaveInstaller-v1.5.21.10.exe (PID: 6900)
      • setup.exe (PID: 4996)
      • SWUpdaterSetup.exe (PID: 6172)
      • Wave Browser - 2026-03-25T142125.818.exe (PID: 8872)
      • SWUpdater.exe (PID: 10632)
      • WaveInstaller-v1.5.21.10.exe (PID: 11196)
      • setup.exe (PID: 5496)
      • Wave Browser.exe (PID: 6696)
      • SWUpdaterSetup.exe (PID: 6240)
      • WaveInstaller-v1.5.21.10.exe (PID: 7540)
      • setup.exe (PID: 8888)
      • Wave Browser (2).exe (PID: 10648)
      • SWUpdaterSetup.exe (PID: 5520)
      • setup.exe (PID: 6148)
      • WaveInstaller-v1.5.21.10.exe (PID: 5412)
    • Wave updater related mutex has been found

      • SWUpdater.exe (PID: 4796)
      • SWUpdater.exe (PID: 1792)
      • SWUpdater.exe (PID: 1344)
      • SWUpdater.exe (PID: 8708)
      • SWUpdater.exe (PID: 5612)
      • SWUpdater.exe (PID: 9736)
      • SWUpdater.exe (PID: 10940)
      • SWUpdater.exe (PID: 8408)
      • SWUpdater.exe (PID: 7716)
      • SWUpdater.exe (PID: 10224)
      • SWUpdater.exe (PID: 9452)
      • SWUpdater.exe (PID: 10632)
      • SWUpdater.exe (PID: 11188)
      • SWUpdater.exe (PID: 2264)
      • SWUpdater.exe (PID: 10980)
      • SWUpdater.exe (PID: 4552)
      • SWUpdater.exe (PID: 9808)
      • SWUpdater.exe (PID: 7228)
      • SWUpdater.exe (PID: 10336)
      • SWUpdater.exe (PID: 10556)
      • SWUpdater.exe (PID: 10708)
      • SWUpdater.exe (PID: 9732)
      • SWUpdater.exe (PID: 11572)
    • Launching a file from a Registry key

      • SWUpdater.exe (PID: 4796)
      • SWUpdater.exe (PID: 10632)
    • Creates files or folders in the user directory

      • setup.exe (PID: 2428)
      • setup.exe (PID: 8380)
      • wavebrowser.exe (PID: 6280)
      • wavebrowser.exe (PID: 4728)
      • wavebrowser.exe (PID: 8332)
      • wavebrowser.exe (PID: 10728)
      • wavebrowser.exe (PID: 10744)
      • setup.exe (PID: 4996)
      • wavebrowser.exe (PID: 10396)
      • wavebrowser.exe (PID: 4484)
      • setup.exe (PID: 5496)
      • wavebrowser.exe (PID: 4468)
      • setup.exe (PID: 8888)
      • wavebrowser.exe (PID: 3400)
      • wavebrowser.exe (PID: 3804)
      • wavebrowser.exe (PID: 3920)
      • setup.exe (PID: 6148)
    • Creates a software uninstall entry

      • setup.exe (PID: 2428)
      • setup.exe (PID: 4996)
      • setup.exe (PID: 5496)
      • setup.exe (PID: 8888)
      • setup.exe (PID: 6148)
    • Manual execution by a user

      • SWUpdaterCore.exe (PID: 9872)
      • SWUpdaterCore.exe (PID: 1688)
      • Wave Browser.exe (PID: 6696)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
475
Monitored processes
322
Malicious processes
3
Suspicious processes
9

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wave browser.exe swupdatersetup.exe swupdater.exe swupdater.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs swupdater.exe swupdater.exe no specs swupdater.exe msedge.exe no specs svchost.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs waveinstaller-v1.5.21.10.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setup.exe msedge.exe no specs setup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setup.exe setup.exe no specs msedge.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs msedge.exe no specs swupdater.exe wavebrowser.exe no specs wavebrowser.exe wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs slui.exe wavebrowser.exe no specs msedge.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs msedge.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs msedge.exe no specs msedge.exe no specs wavebrowser.exe no specs wave browser (1).exe msedge.exe no specs msedge.exe no specs swupdatersetup.exe swupdater.exe no specs swupdater.exe no specs swupdater.exe swupdater.exe no specs swupdater.exe waveinstaller-v1.5.21.10.exe msedge.exe no specs setup.exe setup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setup.exe no specs setup.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs msedge.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs swupdater.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs swupdatercore.exe no specs swupdater.exe no specs swupdater.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wave browser - 2026-03-25t142125.818.exe swupdatersetup.exe swupdater.exe swupdater.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs swupdatercomregistershell64.exe no specs msedge.exe no specs swupdater.exe swupdater.exe no specs swupdater.exe waveinstaller-v1.5.21.10.exe setup.exe setup.exe no specs swupdatercore.exe no specs setup.exe no specs setup.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs swupdater.exe wavebrowser.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wavebrowser.exe no specs wave browser.exe swupdatersetup.exe swupdater.exe no specs swupdater.exe no specs swupdater.exe swupdater.exe no specs wavebrowser.exe no specs swupdater.exe waveinstaller-v1.5.21.10.exe setup.exe setup.exe no specs msedge.exe no specs msedge.exe no specs setup.exe no specs setup.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs swupdater.exe wavebrowser.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wavebrowser.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wave browser (2).exe swupdatersetup.exe swupdater.exe no specs swupdater.exe no specs swupdater.exe swupdater.exe no specs swupdater.exe waveinstaller-v1.5.21.10.exe setup.exe setup.exe no specs setup.exe no specs setup.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs wavebrowser.exe no specs swupdater.exe wavebrowser.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
792"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=renderer --string-annotations=is-enterprise-managed=no --extension-process --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=136 --field-trial-handle=6008,i,17963987302792308827,16346911897243200942,262144 --variations-seed-version=15 --mojo-platform-channel-handle=9776 /prefetch:2C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.21.10
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\wavesor software\wavebrowser\1.5.21.10\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
796"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=renderer --string-annotations=is-enterprise-managed=no --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=110 --field-trial-handle=8108,i,17963987302792308827,16346911897243200942,262144 --variations-seed-version=15 --mojo-platform-channel-handle=11004 /prefetch:1C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.21.10
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\wavesor software\wavebrowser\1.5.21.10\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=22 --always-read-main-dll --field-trial-handle=8268,i,8329612573250698314,16257727094563167173,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=8284 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1172"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_collections.mojom.CollectionsDataManager --lang=en-US --service-sandbox-type=collections --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6900,i,8329612573250698314,16257727094563167173,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6944 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1344"C:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exe" /regserverC:\Users\admin\Wavesor Software\SWUpdater\SWUpdater.exeSWUpdater.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
MEDIUM
Description:
Wavesor SWUpdater
Exit code:
0
Version:
1.3.139.0
Modules
Images
c:\users\admin\wavesor software\swupdater\swupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1492"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=renderer --string-annotations=is-enterprise-managed=no --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=131 --field-trial-handle=10668,i,17963987302792308827,16346911897243200942,262144 --variations-seed-version=15 --mojo-platform-channel-handle=11096 /prefetch:1C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.21.10
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\wavesor software\wavebrowser\1.5.21.10\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1512"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=23 --always-read-main-dll --field-trial-handle=8800,i,8329612573250698314,16257727094563167173,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=8952 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1520"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=8864,i,8329612573250698314,16257727094563167173,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=8584 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1572"C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exe" --type=renderer --string-annotations=is-enterprise-managed=no --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=133 --field-trial-handle=10712,i,17963987302792308827,16346911897243200942,262144 --variations-seed-version=15 --mojo-platform-channel-handle=2196 /prefetch:1C:\Users\admin\Wavesor Software\WaveBrowser\wavebrowser.exewavebrowser.exe
User:
admin
Company:
Wavesor Software
Integrity Level:
LOW
Description:
WaveBrowser
Exit code:
0
Version:
1.5.21.10
Modules
Images
c:\users\admin\wavesor software\wavebrowser\wavebrowser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\wavesor software\wavebrowser\1.5.21.10\wavebrowser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1656"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=7008,i,8329612573250698314,16257727094563167173,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=11152 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
48 528
Read events
45 570
Write events
2 663
Delete events
295

Modification events

(PID) Process:(5152) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5152) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5152) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(5152) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(5152) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(5152) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(5152) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(5152) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5152) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5152) Wave Browser.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Wave Browser_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
195
Suspicious files
1 499
Text files
1 256
Unknown types
21

Dropped files

PID
Process
Filename
Type
8036msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1e5254.TMP
MD5:
SHA256:
8036msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1e5254.TMP
MD5:
SHA256:
8036msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1e5254.TMP
MD5:
SHA256:
8036msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
8036msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
8036msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1e5254.TMP
MD5:
SHA256:
8036msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
8036msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
8036msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1e5273.TMP
MD5:
SHA256:
8036msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1e5283.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1 816
TCP/UDP connections
451
DNS requests
546
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4292
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=66&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1774448381&lafgdate=0
US
text
4.59 Kb
whitelisted
4292
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:a50ylUsS3mqu2xVsDD4De4jtKTj2-oUNDGa9DrWUuSw&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
98 b
whitelisted
4292
msedge.exe
GET
301
13.226.244.100:80
http://wavebrowser.com/
US
html
167 b
unknown
4292
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
US
text
314 b
whitelisted
4292
msedge.exe
GET
200
13.107.246.44:443
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appId=edge-extensions&country=US
US
binary
82 b
whitelisted
4292
msedge.exe
GET
200
104.18.23.222:443
https://copilot.microsoft.com/c/api/user/eligibility
US
text
25 b
whitelisted
4292
msedge.exe
GET
200
13.226.244.100:443
https://wavebrowser.com/assets/index-021151ad.css
US
text
210 Kb
unknown
4292
msedge.exe
GET
200
13.226.244.100:443
https://wavebrowser.com/assets/index-02857969.js
US
text
606 Kb
unknown
4292
msedge.exe
GET
200
184.24.77.156:443
https://use.typekit.net/rgb4vnm.css
NL
text
4.63 Kb
whitelisted
4292
msedge.exe
GET
200
13.226.244.62:443
https://wavebrowser.com/assets/index-02857969.js
US
text
606 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5516
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
8736
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3412
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4292
msedge.exe
150.171.28.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
4292
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4292
msedge.exe
13.226.244.100:80
wavebrowser.com
AMAZON-02
US
whitelisted
4292
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
self.events.data.microsoft.com
  • 104.46.162.226
  • 20.42.73.25
whitelisted
google.com
  • 142.250.129.102
  • 142.250.129.113
  • 142.250.129.138
  • 142.250.129.100
  • 142.250.129.139
  • 142.250.129.101
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
wavebrowser.com
  • 13.226.244.100
  • 13.226.244.23
  • 13.226.244.121
  • 13.226.244.62
unknown
api.edgeoffer.microsoft.com
  • 13.107.246.44
  • 13.107.213.44
whitelisted
copilot.microsoft.com
  • 104.18.23.222
  • 104.18.22.222
whitelisted
www.bing.com
  • 2.16.204.144
  • 2.16.204.149
  • 2.16.204.145
  • 2.16.204.139
  • 2.16.204.143
  • 2.16.204.141
  • 2.16.204.147
  • 2.16.204.140
  • 2.16.204.138
  • 2.16.204.136
  • 2.16.204.142
  • 2.16.204.134
  • 2.16.204.161
  • 2.16.204.137
  • 2.16.204.135
  • 2.16.204.146
  • 2.16.204.158
  • 2.16.204.159
  • 2.16.204.160
  • 104.126.37.138
  • 104.126.37.144
  • 104.126.37.161
  • 104.126.37.168
  • 104.126.37.154
  • 104.126.37.136
  • 104.126.37.139
  • 104.126.37.153
  • 104.126.37.147
  • 184.86.251.18
  • 184.86.251.23
  • 184.86.251.19
  • 184.86.251.22
  • 184.86.251.27
  • 184.86.251.25
  • 184.86.251.24
  • 184.86.251.20
  • 184.86.251.21
  • 184.86.251.12
  • 184.86.251.14
  • 184.86.251.10
  • 184.86.251.13
  • 184.86.251.11
  • 184.86.251.15
  • 2.16.204.132
  • 2.16.204.133
whitelisted

Threats

PID
Process
Class
Message
4292
msedge.exe
Potentially Bad Traffic
ET INFO Executable served from Amazon S3
5516
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
3092
svchost.exe
Potentially Bad Traffic
ET INFO Executable served from Amazon S3
4292
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
4292
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
4292
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
4292
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com)
8380
setup.exe
Misc activity
ET INFO Observed UA-CPU Header
4292
msedge.exe
Potentially Bad Traffic
ET INFO Executable served from Amazon S3
4292
msedge.exe
Potentially Bad Traffic
ET INFO Executable served from Amazon S3
No debug info