wasp.exe file report

MD5 356d10895b0eb6cd1220764c1bf6b42c
Latest seen 2024-10-09 23:00:48 (2 years ago)
First seen 2020-04-11 08:23:26 (6 years ago)
Size 5 MB
Publisher WaspAce
Product WaspAce wasp
Signed by WaspAce Service

Why it matters

Evidence available for this file

Detection

No final classification is available yet.

Timeline

First seen 2020-04-11 08:23:26 (6 years ago); latest analysis 2024-10-09 23:00:48 (2 years ago).

Publisher context

Company metadata: WaspAce. Product metadata: WaspAce wasp.

Digital signature

Signed by WaspAce Service. The signature is reported as valid, but signed files can still be bundled or abused.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Use the hash and metadata below to verify the exact file identity.
  2. Review publisher, signature, paths, and PE details for inconsistencies.
  3. Run a local scan if the file appears unexpectedly or starts with Windows.

wasp.exe is a Windows file recorded in the ThreatInfo database. It is associated with WaspAce wasp. The reported company name is WaspAce. The current detection status is Undefined, based on the latest analysis from 2024-10-09 23:00:48 (2 years ago).

ThreatInfo does not have a final classification for this file yet. Use the technical details below to compare the hash, size, signature, and observed locations with the copy found on your device.

Product Name: WaspAce wasp
Company Name: WaspAce
MD5: 356d10895b0eb6cd1220764c1bf6b42c
Size: 5 MB
First Published: 2020-04-11 08:23:26 (6 years ago)
Latest Published: 2024-10-09 23:00:48 (2 years ago)
Status: Undefined (on last analysis)
Analysis Date: 2024-10-09 23:00:48 (2 years ago)
Signed By: WaspAce Service
Status: Valid

The signature on wasp.exe is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%commonappdata%\windows
%commonappdata%\windows
%commonappdata%\windows
%commonappdata%\windows
%commonappdata%\windows
%commonappdata%\windows
%commonappdata%\windows
%commonappdata%\windows
%commonappdata%\windows
%commonappdata%\windows

ThreatInfo has observed wasp.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

36.4%
21.2%
15.2%
9.1%
3.0%
3.0%
3.0%
3.0%
3.0%
3.0%

The strongest geographic signal for this file is Russian Federation with 36.4% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 70.6%
Windows 7 26.5%
Windows 8.1 2.9%

The most common operating system signal for wasp.exe is Windows 10 with 70.6% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

wasp.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0051f228

PE Sections:

Name Size of data MD5
.text 5326848 b053e794c96b4cf6cf7fdcb1844a6a07
.itext 38400 b0fad9436fe753778f95d720c7a33420
.data 122880 6459b189b0e2941f5dfd6e22020ae9e5
.bss 0 00000000000000000000000000000000
.idata 18944 74b753e9b2172ff6a7fa4c5d20ebc21b
.didata 25600 4e19dadeb035e2b16c5dde5e6d19d55a
.edata 1024 1d3f30c6a5bce568b77b3406fe1db3c7
.tls 0 00000000000000000000000000000000
.rdata 512 af99e47a7283320cf2e2b73d1952cf8c
.reloc 0 00000000000000000000000000000000
.rsrc 651264 8090d5bc8c8e18227bbde6b729d6972c

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: