drweb-12.0-ss-win.exe

by DOCTOR WEB, LTD

Sources: observed in the EchoTrail lab on Windows 11.

Summary

Dr.Web Security Space (Dr.Web Security Space, Doctor Web, Ltd.)

drweb-12.0-ss-win.exe is not in the 2025 snapshot. It was observed in EchoTrail's behavior lab on Windows 11 24H2 on 2026-09-24 installed from manual_url package https://cdn-download.drweb.com/pub/drweb/windows/workstation/12.0/drweb-12.0-ss-win.exe.

Get this in your tools

The same record for drweb-12.0-ss-win.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/drweb-12.0-ss-win.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

n/a
most commonly executed Windows program
n/a
observed endpoint executions

Behavior

Top Paths

  • C:\lab\in

Top Hashes (SHA256)

  • d0ab23daa56ba69427348e54ea38531cedeb0c2644d9bd47298e7c0bdc9f20b0

Process Ancestry

Top Grandparents

Top Parents

Top Children

Lab record

Installed from
manual_url https://cdn-download.drweb.com/pub/drweb/windows/workstation/12.0/drweb-12.0-ss-win.exe
Publisher
DOCTOR WEB, LTD
Persistence
none
Network
none
Command lines
1 pattern (1 launch)
DLL loads
34 patterns (34 loads)
Registry writes
16 patterns (16 writes)
File writes
5 patterns (9 writes)
HTTP requests
0 patterns (0 requests)
TLS connections
0 patterns (0 handshakes)
Named pipes
0 patterns (0 events)
Process access
0 patterns (0 events)
Driver loads
0 patterns (0 loads)
PowerShell blocks
0 patterns (0 blocks)
Remote threads
0 patterns (0 events)
Audit events
1 pattern (1 event)

Full record on Team.

Ask Rocky about drweb-12.0-ss-win.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for drweb-12.0-ss-win.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.