drweb-12.0-ss-win.exe
Sources: observed in the EchoTrail lab on Windows 11.
Summary
Dr.Web Security Space (Dr.Web Security Space, Doctor Web, Ltd.)
drweb-12.0-ss-win.exe is not in the 2025 snapshot. It was observed in EchoTrail's behavior lab on Windows 11 24H2 on 2026-09-24 installed from manual_url package https://cdn-download.drweb.com/pub/drweb/windows/workstation/12.0/drweb-12.0-ss-win.exe.
Get this in your tools
The same record for drweb-12.0-ss-win.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/drweb-12.0-ss-win.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\lab\in
Top Hashes (SHA256)
- d0ab23daa56ba69427348e54ea38531cedeb0c2644d9bd47298e7c0bdc9f20b0
Process Ancestry
Top Grandparents
Top Parents
Top Children
Lab record
- Installed from
- manual_url https://cdn-download.drweb.com/pub/drweb/windows/workstation/12.0/drweb-12.0-ss-win.exe
- Publisher
- DOCTOR WEB, LTD
- Persistence
- none
- Network
- none
- Command lines
- 1 pattern (1 launch)
- DLL loads
- 34 patterns (34 loads)
- Registry writes
- 16 patterns (16 writes)
- File writes
- 5 patterns (9 writes)
- HTTP requests
- 0 patterns (0 requests)
- TLS connections
- 0 patterns (0 handshakes)
- Named pipes
- 0 patterns (0 events)
- Process access
- 0 patterns (0 events)
- Driver loads
- 0 patterns (0 loads)
- PowerShell blocks
- 0 patterns (0 blocks)
- Remote threads
- 0 patterns (0 events)
- Audit events
- 1 pattern (1 event)
Full record on Team.
Ask Rocky about drweb-12.0-ss-win.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for drweb-12.0-ss-win.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.