Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
WaveInstaller.exe

Overview

General Information

Sample name:WaveInstaller.exe
Analysis ID:1502445
MD5:215d509bc217f7878270c161763b471e
SHA1:bfe0a2580d54cfa28d3ff5ef8dc754fdc73adcd9
SHA256:984dfc64c10f96c5350d6d9216a5d7abfece1658dfc93925f7a6b0c80817c886
Tags:exe
Infos:

Detection

Score:76
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
.NET source code contains potential unpacker
Uses Windows timers to delay execution
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Potential time zone aware malware
Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • WaveInstaller.exe (PID: 7464 cmdline: "C:\Users\user\Desktop\WaveInstaller.exe" MD5: 215D509BC217F7878270C161763B471E)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
WaveInstaller.exeJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
    SourceRuleDescriptionAuthorStrings
    00000000.00000000.1637430102.0000000000B82000.00000002.00000001.01000000.00000003.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
      00000000.00000002.2895806482.00000000031A1000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
        Process Memory Space: WaveInstaller.exe PID: 7464JoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
          SourceRuleDescriptionAuthorStrings
          0.0.WaveInstaller.exe.b80000.0.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
            No Sigma rule has matched
            No Suricata rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: https://cdn.getwave.gg/bootstrapper/WaveWindows.exe-WaveAvira URL Cloud: Label: malware
            Source: https://cdn.getwave.gg/bootstrapper/WaveWindows.exeioAvira URL Cloud: Label: malware
            Source: https://cdn.getwave.gg/bootstrapper/WaveWindows.exe-WaveVirustotal: Detection: 11%Perma Link
            Source: WaveInstaller.exeReversingLabs: Detection: 31%
            Source: WaveInstaller.exeVirustotal: Detection: 44%Perma Link
            Source: WaveInstaller.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
            Source: WaveInstaller.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: Binary string: C:\Users\imaxi\Desktop\WaveInstaller\obj\Release\WaveInstaller.pdb source: WaveInstaller.exe
            Source: Binary string: costura.costura.pdb.compressed source: WaveInstaller.exe
            Source: Binary string: costura.costura.pdb.compressed|||Costura.pdb|6C6000A5EAF8579850AB82A89BD6268776EB51AD|2608 source: WaveInstaller.exe
            Source: Binary string: costura=costura.costura.dll.compressed=costura.costura.pdb.compressed;microsoft.bcl.asyncinterfacesicostura.microsoft.bcl.asyncinterfaces.dll.compressed source: WaveInstaller.exe
            Source: WaveInstaller.exeString found in binary or memory: https://cdn.getwave.gg/bootstrapper/WaveWindows.exe-Wave
            Source: WaveInstaller.exe, 00000000.00000002.2895806482.00000000031A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://cdn.getwave.gg/bootstrapper/WaveWindows.exeio
            Source: WaveInstaller.exe, 00000000.00000002.2895806482.00000000031A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Common.124.3.8.rar
            Source: WaveInstaller.exeString found in binary or memory: https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Common.124.3.8.rar1CefSharp.Wpf.124.3.8.rar
            Source: WaveInstaller.exeString found in binary or memory: https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Wpf.124.3.8.rar
            Source: WaveInstaller.exeString found in binary or memory: https://github.com/dxgi/wave-binaries/raw/main/Luau-x64.rar
            Source: WaveInstaller.exeString found in binary or memory: https://github.com/dxgi/wave-binaries/raw/main/Wave-x64.rar
            Source: WaveInstaller.exe, 00000000.00000002.2895806482.00000000031A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.nuget.org/api/v2/package/chromiumembeddedframework.runtime.win-x86/124.3.8
            Source: WaveInstaller.exeString found in binary or memory: https://www.nuget.org/api/v2/package/chromiumembeddedframework.runtime.win-x86/124.3.87CefSharp.Comm
            Source: WaveInstaller.exe, 00000000.00000002.2894838722.000000000133E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs WaveInstaller.exe
            Source: WaveInstaller.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
            Source: WaveInstaller.exe, MainWindow.csSuspicious URL: 'https://www.nuget.org/api/v2/package/chromiumembeddedframework.runtime.win-x86/124.3.8'
            Source: classification engineClassification label: mal76.evad.winEXE@1/0@0/0
            Source: C:\Users\user\Desktop\WaveInstaller.exeMutant created: NULL
            Source: WaveInstaller.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: WaveInstaller.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
            Source: C:\Users\user\Desktop\WaveInstaller.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
            Source: WaveInstaller.exeReversingLabs: Detection: 31%
            Source: WaveInstaller.exeVirustotal: Detection: 44%
            Source: WaveInstaller.exeString found in binary or memory: :includes/images/installer.png0includes/images/logo.png
            Source: WaveInstaller.exeString found in binary or memory: Includes/Images/Installer.png
            Source: WaveInstaller.exeString found in binary or memory: The installation process will take some time. Sit back, relax and let this process finish. Please do not turn off your computer.-Installation Completed
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: mscoree.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: apphelp.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: kernel.appcore.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: version.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: uxtheme.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: cryptsp.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: rsaenh.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: cryptbase.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: dwrite.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: msvcp140_clr0400.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: windows.storage.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: wldp.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: profapi.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: iphlpapi.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: dnsapi.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: dhcpcsvc6.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: dhcpcsvc.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: winnsi.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: dwmapi.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: d3d9.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: d3d10warp.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: urlmon.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: iertutil.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: srvcli.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: netutils.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: windowscodecs.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: wtsapi32.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: winsta.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: powrprof.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: umpdc.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: textshaping.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: dataexchange.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: d3d11.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: dcomp.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: dxgi.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: twinapi.appcore.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: resourcepolicyclient.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: dxcore.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: textinputframework.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: coreuicomponents.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: coremessaging.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: ntmarta.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: coremessaging.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: wintypes.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: wintypes.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: wintypes.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: msctfui.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: uiautomationcore.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: propsys.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: winmm.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeSection loaded: d3dcompiler_47.dll
            Source: C:\Users\user\Desktop\WaveInstaller.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InprocServer32
            Source: Window RecorderWindow detected: More than 3 window changes detected
            Source: C:\Users\user\Desktop\WaveInstaller.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
            Source: WaveInstaller.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
            Source: WaveInstaller.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
            Source: WaveInstaller.exeStatic file information: File size 2377216 > 1048576
            Source: WaveInstaller.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x210c00
            Source: WaveInstaller.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: WaveInstaller.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
            Source: Binary string: C:\Users\imaxi\Desktop\WaveInstaller\obj\Release\WaveInstaller.pdb source: WaveInstaller.exe
            Source: Binary string: costura.costura.pdb.compressed source: WaveInstaller.exe
            Source: Binary string: costura.costura.pdb.compressed|||Costura.pdb|6C6000A5EAF8579850AB82A89BD6268776EB51AD|2608 source: WaveInstaller.exe
            Source: Binary string: costura=costura.costura.dll.compressed=costura.costura.pdb.compressed;microsoft.bcl.asyncinterfacesicostura.microsoft.bcl.asyncinterfaces.dll.compressed source: WaveInstaller.exe

            Data Obfuscation

            barindex
            Source: WaveInstaller.exe, AssemblyLoader.cs.Net Code: ReadFromEmbeddedResources System.Reflection.Assembly.Load(byte[])
            Source: Yara matchFile source: WaveInstaller.exe, type: SAMPLE
            Source: Yara matchFile source: 0.0.WaveInstaller.exe.b80000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000000.00000000.1637430102.0000000000B82000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2895806482.00000000031A1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: WaveInstaller.exe PID: 7464, type: MEMORYSTR
            Source: WaveInstaller.exeStatic PE information: 0x8C34F576 [Sat Jul 16 11:22:30 2044 UTC]
            Source: C:\Users\user\Desktop\WaveInstaller.exeCode function: 0_2_018A4442 push esp; retf
            Source: C:\Users\user\Desktop\WaveInstaller.exeCode function: 0_2_018A1762 pushfd ; iretd
            Source: C:\Users\user\Desktop\WaveInstaller.exeCode function: 0_2_018A3F7A pushad ; iretd
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\WaveInstaller.exeProcess information set: NOOPENFILEERRORBOX

            Malware Analysis System Evasion

            barindex
            Source: C:\Users\user\Desktop\WaveInstaller.exeUser Timer Set: Timeout: 125ms
            Source: C:\Users\user\Desktop\WaveInstaller.exeUser Timer Set: Timeout: 10ms
            Source: C:\Users\user\Desktop\WaveInstaller.exeUser Timer Set: Timeout: 1ms
            Source: C:\Users\user\Desktop\WaveInstaller.exeUser Timer Set: Timeout: 985ms
            Source: C:\Users\user\Desktop\WaveInstaller.exeUser Timer Set: Timeout: 1ms
            Source: C:\Users\user\Desktop\WaveInstaller.exeUser Timer Set: Timeout: 125ms
            Source: C:\Users\user\Desktop\WaveInstaller.exeUser Timer Set: Timeout: 1ms
            Source: C:\Users\user\Desktop\WaveInstaller.exeUser Timer Set: Timeout: 1ms
            Source: C:\Users\user\Desktop\WaveInstaller.exeUser Timer Set: Timeout: 1ms
            Source: C:\Users\user\Desktop\WaveInstaller.exeMemory allocated: 15E0000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\WaveInstaller.exeMemory allocated: 31A0000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\WaveInstaller.exeMemory allocated: 2FA0000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\WaveInstaller.exeSystem information queried: CurrentTimeZoneInformation
            Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
            Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
            Source: C:\Users\user\Desktop\WaveInstaller.exeMemory allocated: page read and write | page guard
            Source: C:\Users\user\Desktop\WaveInstaller.exeQueries volume information: C:\Users\user\Desktop\WaveInstaller.exe VolumeInformation
            Source: C:\Users\user\Desktop\WaveInstaller.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
            Source: C:\Users\user\Desktop\WaveInstaller.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
            Source: C:\Users\user\Desktop\WaveInstaller.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
            Source: C:\Users\user\Desktop\WaveInstaller.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation
            Source: C:\Users\user\Desktop\WaveInstaller.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation
            Source: C:\Users\user\Desktop\WaveInstaller.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
            Source: C:\Users\user\Desktop\WaveInstaller.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
            Source: C:\Users\user\Desktop\WaveInstaller.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
            Source: C:\Users\user\Desktop\WaveInstaller.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
            Source: C:\Users\user\Desktop\WaveInstaller.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
            Command and Scripting Interpreter
            1
            DLL Side-Loading
            1
            DLL Side-Loading
            11
            Virtualization/Sandbox Evasion
            OS Credential Dumping1
            System Time Discovery
            Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
            Disable or Modify Tools
            LSASS Memory11
            Virtualization/Sandbox Evasion
            Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
            Software Packing
            Security Account Manager12
            System Information Discovery
            SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
            Timestomp
            NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            DLL Side-Loading
            LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
            Obfuscated Files or Information
            Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            WaveInstaller.exe32%ReversingLabsWin32.Trojan.Generic
            WaveInstaller.exe45%VirustotalBrowse
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            SourceDetectionScannerLabelLink
            https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Common.124.3.8.rar0%Avira URL Cloudsafe
            https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Wpf.124.3.8.rar0%Avira URL Cloudsafe
            https://www.nuget.org/api/v2/package/chromiumembeddedframework.runtime.win-x86/124.3.80%Avira URL Cloudsafe
            https://www.nuget.org/api/v2/package/chromiumembeddedframework.runtime.win-x86/124.3.87CefSharp.Comm0%Avira URL Cloudsafe
            https://cdn.getwave.gg/bootstrapper/WaveWindows.exe-Wave100%Avira URL Cloudmalware
            https://github.com/dxgi/wave-binaries/raw/main/Wave-x64.rar0%Avira URL Cloudsafe
            https://github.com/dxgi/wave-binaries/raw/main/Luau-x64.rar0%Avira URL Cloudsafe
            https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Wpf.124.3.8.rar0%VirustotalBrowse
            https://www.nuget.org/api/v2/package/chromiumembeddedframework.runtime.win-x86/124.3.80%VirustotalBrowse
            https://cdn.getwave.gg/bootstrapper/WaveWindows.exeio100%Avira URL Cloudmalware
            https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Common.124.3.8.rar1CefSharp.Wpf.124.3.8.rar0%Avira URL Cloudsafe
            https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Common.124.3.8.rar0%VirustotalBrowse
            https://github.com/dxgi/wave-binaries/raw/main/Luau-x64.rar0%VirustotalBrowse
            https://github.com/dxgi/wave-binaries/raw/main/Wave-x64.rar0%VirustotalBrowse
            https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Common.124.3.8.rar1CefSharp.Wpf.124.3.8.rar0%VirustotalBrowse
            https://cdn.getwave.gg/bootstrapper/WaveWindows.exe-Wave11%VirustotalBrowse
            https://www.nuget.org/api/v2/package/chromiumembeddedframework.runtime.win-x86/124.3.87CefSharp.Comm0%VirustotalBrowse
            No contacted domains info
            NameSourceMaliciousAntivirus DetectionReputation
            https://cdn.getwave.gg/bootstrapper/WaveWindows.exe-WaveWaveInstaller.exefalse
            • 11%, Virustotal, Browse
            • Avira URL Cloud: malware
            unknown
            https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Wpf.124.3.8.rarWaveInstaller.exefalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            https://www.nuget.org/api/v2/package/chromiumembeddedframework.runtime.win-x86/124.3.8WaveInstaller.exe, 00000000.00000002.2895806482.00000000031A1000.00000004.00000800.00020000.00000000.sdmpfalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            https://www.nuget.org/api/v2/package/chromiumembeddedframework.runtime.win-x86/124.3.87CefSharp.CommWaveInstaller.exefalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Common.124.3.8.rarWaveInstaller.exe, 00000000.00000002.2895806482.00000000031A1000.00000004.00000800.00020000.00000000.sdmpfalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            https://github.com/dxgi/wave-binaries/raw/main/Luau-x64.rarWaveInstaller.exefalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            https://github.com/dxgi/wave-binaries/raw/main/Wave-x64.rarWaveInstaller.exefalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            https://cdn.getwave.gg/bootstrapper/WaveWindows.exeioWaveInstaller.exe, 00000000.00000002.2895806482.00000000031A1000.00000004.00000800.00020000.00000000.sdmpfalse
            • Avira URL Cloud: malware
            unknown
            https://github.com/dxgi/wave-binaries/raw/main/CefSharp.Common.124.3.8.rar1CefSharp.Wpf.124.3.8.rarWaveInstaller.exefalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            No contacted IP infos
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1502445
            Start date and time:2024-09-01 16:20:05 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 49s
            Hypervisor based Inspection enabled:false
            Report type:light
            Cookbook file name:default.jbs
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Sample name:WaveInstaller.exe
            Detection:MAL
            Classification:mal76.evad.winEXE@1/0@0/0
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 96%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • Found application associated with file extension: .exe
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
            • Execution Graph export aborted for target WaveInstaller.exe, PID 7464 because it is empty
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtProtectVirtualMemory calls found.
            • Report size getting too big, too many NtQueryValueKey calls found.
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
            Entropy (8bit):7.874597413262029
            TrID:
            • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
            • Win32 Executable (generic) a (10002005/4) 49.78%
            • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
            • Generic Win/DOS Executable (2004/3) 0.01%
            • DOS Executable Generic (2002/1) 0.01%
            File name:WaveInstaller.exe
            File size:2'377'216 bytes
            MD5:215d509bc217f7878270c161763b471e
            SHA1:bfe0a2580d54cfa28d3ff5ef8dc754fdc73adcd9
            SHA256:984dfc64c10f96c5350d6d9216a5d7abfece1658dfc93925f7a6b0c80817c886
            SHA512:68e615dfcb1b7770ad64175438a913744c14bdd3af93b339c2b526271bdd0d23334e78d049fdae8ca9fe66672a8cf252ebf891be9ab6c46a3d8f1fb00fa8c83b
            SSDEEP:49152:LinbT3qpTDQSmanAmwJAaDMg33U2pLOiniT:LinKpTJmWAmmAMP8in
            TLSH:6DB512192A3CC8CBEC3907B15AFAE15A7B39317782490748ECCCC14C62F9E56F5B6529
            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...v.4..........."...0...!..8......N+!.. ........@.. ........................$...........`................................
            Icon Hash:2340020b0bbf733f
            Entrypoint:0x612b4e
            Entrypoint Section:.text
            Digitally signed:false
            Imagebase:0x400000
            Subsystem:windows gui
            Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
            DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Time Stamp:0x8C34F576 [Sat Jul 16 11:22:30 2044 UTC]
            TLS Callbacks:
            CLR (.Net) Version:
            OS Version Major:4
            OS Version Minor:0
            File Version Major:4
            File Version Minor:0
            Subsystem Version Major:4
            Subsystem Version Minor:0
            Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
            Instruction
            jmp dword ptr [00402000h]
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            add byte ptr [eax], al
            NameVirtual AddressVirtual Size Is in Section
            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_IMPORT0x212af40x57.text
            IMAGE_DIRECTORY_ENTRY_RESOURCE0x2140000x33568.rsrc
            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
            IMAGE_DIRECTORY_ENTRY_BASERELOC0x2480000xc.reloc
            IMAGE_DIRECTORY_ENTRY_DEBUG0x212a600x38.text
            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
            .text0x20000x210b540x210c0041e0a54accebca40bf945a207af8a88funknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            .rsrc0x2140000x335680x3360032ec3b22a5cf4afe774f17b0bc6fcb20False0.5065579379562044data6.519047836554647IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
            .reloc0x2480000xc0x200b8becffedd18a9b187b1a5d4a2499a67False0.044921875MacBinary, Mon Feb 6 07:28:16 2040 INVALID date, modified Mon Feb 6 07:28:16 2040 "!"0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
            NameRVASizeTypeLanguageCountryZLIB Complexity
            RT_ICON0x2142000x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 5669 x 5669 px/m0.875
            RT_ICON0x2146780x988Device independent bitmap graphic, 24 x 48 x 32, image size 2304, resolution 5669 x 5669 px/m0.7729508196721312
            RT_ICON0x2150100x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096, resolution 5669 x 5669 px/m0.6744840525328331
            RT_ICON0x2160c80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216, resolution 5669 x 5669 px/m0.5504149377593361
            RT_ICON0x2186800x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16384, resolution 5669 x 5669 px/m0.4750236183278224
            RT_ICON0x21c8b80x5488Device independent bitmap graphic, 72 x 144 x 32, image size 20736, resolution 5669 x 5669 px/m0.4406192236598891
            RT_ICON0x221d500x94a8Device independent bitmap graphic, 96 x 192 x 32, image size 36864, resolution 5669 x 5669 px/m0.36519865461425266
            RT_ICON0x22b2080x10828Device independent bitmap graphic, 128 x 256 x 32, image size 65536, resolution 5669 x 5669 px/m0.2990949958594582
            RT_ICON0x23ba400xa9e7PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.9990343717668697
            RT_GROUP_ICON0x2464380x84data0.7272727272727273
            RT_VERSION0x2464cc0x33cdata0.41304347826086957
            RT_MANIFEST0x2468180xd4cXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.38689776733254994
            DLLImport
            mscoree.dll_CorExeMain
            No network behavior found
            No statistics
            Target ID:0
            Start time:10:20:51
            Start date:01/09/2024
            Path:C:\Users\user\Desktop\WaveInstaller.exe
            Wow64 process (32bit):true
            Commandline:"C:\Users\user\Desktop\WaveInstaller.exe"
            Imagebase:0xb80000
            File size:2'377'216 bytes
            MD5 hash:215D509BC217F7878270C161763B471E
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Yara matches:
            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000000.1637430102.0000000000B82000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.2895806482.00000000031A1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
            Reputation:low
            Has exited:false

            No disassembly