File name:

installer.exe

Full analysis: https://app.any.run/tasks/6d871582-1db1-46f5-9e5b-6d6b88c17031
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: September 24, 2024, 18:44:43
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

43B1B2C0A77F854B3DA78DCEA07DDE13

SHA1:

3BBA28B52B62A793BBFAB4A70E086D914534C131

SHA256:

1DA656B1A5AB3D5FE578EB6BCFD078BF68DF4A7ECC570B611686B0213CB54775

SSDEEP:

98304:eKKoEh18Ack+PZAglan4WrFRk1K3KfmOmW8Y1FuNHZtZrGrUMm/97vepL1J3dA86:41BnWSyOGNSnMnu6/C7u110T22

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 6296)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • installer.exe (PID: 6768)
      • nmtcache.exe (PID: 6668)
      • MicrosoftEdgeUpdate.exe (PID: 6296)
      • svchost.exe (PID: 7004)
      • MicrosoftEdge_X64_129.0.2792.52.exe (PID: 6384)
      • setup.exe (PID: 492)
      • msedgewebview2.exe (PID: 6660)
    • Executable content was dropped or overwritten

      • installer.exe (PID: 6768)
      • nmtcache.exe (PID: 6668)
      • MicrosoftEdgeUpdate.exe (PID: 6296)
      • MicrosoftEdge_X64_129.0.2792.52.exe (PID: 6384)
      • setup.exe (PID: 492)
      • msedgewebview2.exe (PID: 6660)
    • Starts a Microsoft application from unusual location

      • nmtcache.exe (PID: 6668)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 6296)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7032)
      • MicrosoftEdgeUpdate.exe (PID: 6636)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6760)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 4976)
    • Potential Corporate Privacy Violation

      • svchost.exe (PID: 7004)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 6296)
      • MicrosoftEdgeUpdate.exe (PID: 6280)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 6280)
    • Application launched itself

      • setup.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 6280)
      • msedgewebview2.exe (PID: 5600)
  • INFO

    • Checks supported languages

      • installer.exe (PID: 6768)
      • nmtcache.exe (PID: 6668)
      • MicrosoftEdgeUpdate.exe (PID: 6296)
      • MicrosoftEdgeUpdate.exe (PID: 6636)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7032)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6760)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 4976)
      • MicrosoftEdgeUpdate.exe (PID: 6280)
      • MicrosoftEdgeUpdate.exe (PID: 5552)
      • MicrosoftEdgeUpdate.exe (PID: 1952)
      • setup.exe (PID: 492)
      • MicrosoftEdge_X64_129.0.2792.52.exe (PID: 6384)
      • setup.exe (PID: 6772)
    • Reads the computer name

      • installer.exe (PID: 6768)
      • MicrosoftEdgeUpdate.exe (PID: 6296)
      • MicrosoftEdgeUpdate.exe (PID: 6636)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7032)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6760)
      • MicrosoftEdgeUpdate.exe (PID: 6280)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 4976)
      • MicrosoftEdgeUpdate.exe (PID: 5552)
      • MicrosoftEdgeUpdate.exe (PID: 1952)
      • MicrosoftEdge_X64_129.0.2792.52.exe (PID: 6384)
      • setup.exe (PID: 492)
    • Create files in a temporary directory

      • installer.exe (PID: 6768)
      • nmtcache.exe (PID: 6668)
      • MicrosoftEdgeUpdate.exe (PID: 6296)
      • svchost.exe (PID: 7004)
    • Checks proxy server information

      • installer.exe (PID: 6768)
      • MicrosoftEdgeUpdate.exe (PID: 6280)
      • MicrosoftEdgeUpdate.exe (PID: 5552)
    • Reads the software policy settings

      • installer.exe (PID: 6768)
      • MicrosoftEdgeUpdate.exe (PID: 6280)
      • MicrosoftEdgeUpdate.exe (PID: 5552)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 6296)
      • MicrosoftEdgeUpdate.exe (PID: 6280)
      • MicrosoftEdge_X64_129.0.2792.52.exe (PID: 6384)
      • setup.exe (PID: 6772)
      • setup.exe (PID: 492)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 6280)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 6296)
      • setup.exe (PID: 492)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 5552)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:08:25 09:20:39+00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.4
CodeSize: 4732928
InitializedDataSize: 2680832
UninitializedDataSize: -
EntryPoint: 0x11404b2
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.1.0.0
ProductVersionNumber: 0.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
ProductVersion: 0.1.0
ProductName: nmt-installer
FileVersion: 0.1.0
FileDescription: A Nmt App
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
26
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start installer.exe nmtcache.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe svchost.exe microsoftedge_x64_129.0.2792.52.exe setup.exe setup.exe no specs microsoftedgeupdate.exe msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
492"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{CB683985-D6BC-4AD4-8C73-9A327564D6C3}\EDGEMITMP_54E1B.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{CB683985-D6BC-4AD4-8C73-9A327564D6C3}\MicrosoftEdge_X64_129.0.2792.52.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{CB683985-D6BC-4AD4-8C73-9A327564D6C3}\EDGEMITMP_54E1B.tmp\setup.exe
MicrosoftEdge_X64_129.0.2792.52.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
129.0.2792.52
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{cb683985-d6bc-4ad4-8c73-9a327564d6c3}\edgemitmp_54e1b.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
752"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\com.nmt.ecosystem\EBWebView" --webview-exe-name=installer.exe --webview-exe-version=0.1.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=4856,i,4262562402728440644,14846436947806891029,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=4588 /prefetch:8C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
129.0.2792.52
772"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --string-annotations=is-enterprise-managed=no --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\com.nmt.ecosystem\EBWebView" --webview-exe-name=installer.exe --webview-exe-version=0.1.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --gpu-preferences=UAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAhAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=4816,i,4262562402728440644,14846436947806891029,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=4812 /prefetch:8C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
129.0.2792.52
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\129.0.2792.52\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\129.0.2792.52\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1952"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=false" /installsource taggedmi /sessionid "{FD64593F-F6B4-4579-BC82-3848D2D36FEE}"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.19
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
1984"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTUuMTkiIHNoZWxsX3ZlcnNpb249IjEuMy4xOTUuMTkiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7RkQ2NDU5M0YtRjZCNC00NTc5LUJDODItMzg0OEQyRDM2RkVFfSIgdXNlcmlkPSJ7NkY0OEVEMzItRkE0OC00RkQyLThDN0ItNzJEOTc5MDY5MUFFfSIgaW5zdGFsbHNvdXJjZT0idGFnZ2VkbWkiIHJlcXVlc3RpZD0iezAxNzY0NDRGLTkwMzUtNERGNS05MDVBLUYwMkNEMzNDRjg2Qn0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgbG9naWNhbF9jcHVzPSI0IiBwaHlzbWVtb3J5PSI0IiBkaXNrX3R5cGU9IjIiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjEwLjAuMTkwNDUuNDA0NiIgc3A9IiIgYXJjaD0ieDY0IiBwcm9kdWN0X3R5cGU9IjQ4IiBpc193aXA9IjAiIGlzX2luX2xvY2tkb3duX21vZGU9IjAiLz48b2VtIHByb2R1Y3RfbWFudWZhY3R1cmVyPSJERUxMIiBwcm9kdWN0X25hbWU9IkRFTEwiLz48ZXhwIGV0YWc9IiZxdW90OzczU1ZaOFhJUkhjTS80a1I5YnJJMnZHNHN3ZTRiWW9VdWl4aHBZVFl4NkE9JnF1b3Q7Ii8-PGFwcCBhcHBpZD0ie0YzMDE3MjI2LUZFMkEtNDI5NS04QkRGLTAwQzNBOUE3RTRDNX0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEyOS4wLjI3OTIuNTIiIGxhbmc9ImVuIiBicmFuZD0iIiBjbGllbnQ9IiIgZXhwZXJpbWVudHM9ImNvbnNlbnQ9ZmFsc2UiIGluc3RhbGxhZ2U9Ii0xIiBpbnN0YWxsZGF0ZT0iLTEiPjx1cGRhdGVjaGVjay8-PGV2ZW50IGV2ZW50dHlwZT0iOSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMjA4OTUxNDMxNzYiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI1IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSIyMDg5NTMwMDAzMSIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIvPjxldmVudCBldmVudHR5cGU9IjEiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjIxOTAyMDE5MzIzIiBzb3VyY2VfdXJsX2luZGV4PSIwIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIiBkb3dubG9hZGVyPSJiaXRzIiB1cmw9Imh0dHA6Ly9tc2VkZ2UuZi50bHUuZGwuZGVsaXZlcnkubXAubWljcm9zb2Z0LmNvbS9maWxlc3RyZWFtaW5nc2VydmljZS9maWxlcy9lOWRjYzNkNy1kMjRhLTQwN2QtOGY3NC03NWMzZDdmZDhjZmU_UDE9MTcyNzgwODMwMyZhbXA7UDI9NDA0JmFtcDtQMz0yJmFtcDtQND1ZWkJteGtVSHFWeCUyZnJ4bTBPTFVRN0ZDeiUyYnhxUjltOVJRQ0k0WVFQa0cwT09CWVFyaUZQRnhnWUxrJTJiQW9Vd2UxamklMmIlMmZyZkE0a0ZzYTJCNEpET2tiMHclM2QlM2QiIHNlcnZlcl9pcF9oaW50PSIiIGNkbl9jaWQ9Ii0xIiBjZG5fY2NjPSIiIGNkbl9tc2VkZ2VfcmVmPSIiIGNkbl9henVyZV9yZWZfb3JpZ2luX3NoaWVsZD0iIiBjZG5fY2FjaGU9IiIgY2RuX3AzcD0iIiBkb3dubG9hZGVkPSIxNzM5MDIyODAiIHRvdGFsPSIxNzM5MDIyODAiIGRvd25sb2FkX3RpbWVfbXM9Ijk2NzAxIi8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMjE5MDIzMzI1MTciIHNvdXJjZV91cmxfaW5kZXg9IjAiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI2IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSIyMTkyMTIzNDkyMiIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIvPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjE5Njc1NyIgc3lzdGVtX3VwdGltZV90aWNrcz0iMjIzMzk5ODc5MDkiIHNvdXJjZV91cmxfaW5kZXg9IjAiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiIHVwZGF0ZV9jaGVja190aW1lX21zPSIyNjYiIGRvd25sb2FkX3RpbWVfbXM9IjEwMDcwNCIgZG93bmxvYWRlZD0iMTczOTAyMjgwIiB0b3RhbD0iMTczOTAyMjgwIiBwYWNrYWdlX2NhY2hlX3Jlc3VsdD0iMCIgaW5zdGFsbF90aW1lX21zPSI0MTg1OSIvPjwvYXBwPjwvcmVxdWVzdD4C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.19
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
3880"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --string-annotations=is-enterprise-managed=no --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\com.nmt.ecosystem\EBWebView" --webview-exe-name=installer.exe --webview-exe-version=0.1.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=4512,i,4262562402728440644,14846436947806891029,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=4560 /prefetch:8C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
129.0.2792.52
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\129.0.2792.52\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\129.0.2792.52\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3904"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exe" --type=renderer --string-annotations=is-enterprise-managed=no --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\com.nmt.ecosystem\EBWebView" --webview-exe-name=installer.exe --webview-exe-version=0.1.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --autoplay-policy=no-user-gesture-required --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=" --field-trial-handle=3592,i,4262562402728440644,14846436947806891029,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=3604 /prefetch:1C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Version:
129.0.2792.52
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\129.0.2792.52\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\129.0.2792.52\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4976"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.19\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.19\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.19
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.19\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5112"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exe" --type=gpu-process --string-annotations=is-enterprise-managed=no --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\com.nmt.ecosystem\EBWebView" --webview-exe-name=installer.exe --webview-exe-version=0.1.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --gpu-preferences=UAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=1876,i,4262562402728440644,14846436947806891029,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --mojo-platform-channel-handle=1872 /prefetch:2C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Version:
129.0.2792.52
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\129.0.2792.52\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\129.0.2792.52\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
5148C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exe --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Local\com.nmt.ecosystem\EBWebView /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\com.nmt.ecosystem\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=129.0.6668.59 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exe --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=129.0.2792.52 --initial-client-data=0x1a0,0x1a4,0x1a8,0x17c,0x1b0,0x7fffd4228ee0,0x7fffd4228eec,0x7fffd4228ef8C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\129.0.2792.52\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Version:
129.0.2792.52
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\129.0.2792.52\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\129.0.2792.52\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
14 708
Read events
10 473
Write events
4 167
Delete events
68

Modification events

(PID) Process:(6296) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(6296) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:path
Value:
C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(PID) Process:(6296) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:UninstallCmdLine
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall
(PID) Process:(6296) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.195.19
(PID) Process:(6296) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
Microsoft Edge Update
(PID) Process:(6296) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.195.19
(PID) Process:(6296) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft Edge Update
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.19\MicrosoftEdgeUpdateCore.exe"
(PID) Process:(6296) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:edgeupdate_task_name_c
Value:
MicrosoftEdgeUpdateTaskUserS-1-5-21-1693682860-607145093-2874071422-1001Core{2E64C314-10BE-49C9-ABC5-9A7E37BE51D3}
(PID) Process:(6296) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:edgeupdate_task_name_ua
Value:
MicrosoftEdgeUpdateTaskUserS-1-5-21-1693682860-607145093-2874071422-1001UA{0BD7A19D-2A47-43AE-9556-46E42ABD55A7}
(PID) Process:(7032) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
Executable files
205
Suspicious files
125
Text files
42
Unknown types
22

Dropped files

PID
Process
Filename
Type
6668nmtcache.exeC:\Users\admin\AppData\Local\Temp\EUD153.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:1D35F02C24D817CD9AE2B9BD75A4C135
SHA256:0ABF4F0FE0033A56EBDAFF875B63CC083FD9C8628D2FB2AB5826D3C0C687B262
6668nmtcache.exeC:\Users\admin\AppData\Local\Temp\EUD153.tmp\psuser.dllexecutable
MD5:33BF134B69D77316BD814D8904F27B35
SHA256:55C9EB7C7FD62B2173F2203421E85DFAD845C169B1225FF4CA1A9E0CFFEA2B0D
6668nmtcache.exeC:\Users\admin\AppData\Local\Temp\EUD153.tmp\msedgeupdate.dllexecutable
MD5:B0DA0A3975239134C6454035E5C3ED79
SHA256:C590D1AF571D75D85CFE6CB3D1AA0808C702BCEFD1B74B93EA423676859FB8BA
6668nmtcache.exeC:\Users\admin\AppData\Local\Temp\EUD153.tmp\MicrosoftEdgeUpdate.exeexecutable
MD5:B0D94FFD264B31A419E84A9B027D926B
SHA256:F471D9FF608FE58DA68A49AF83A7FD9A3D6BF5A5757D340F7B8224B6CD8BDDF6
6668nmtcache.exeC:\Users\admin\AppData\Local\Temp\EUD153.tmp\psmachine.dllexecutable
MD5:440CC4D0CE247CA6F5B9A3D30192B844
SHA256:C5EC4633F80C54FE8D77BDE05A952B11B4B647A2FFC10E43D0370154780D21F7
6668nmtcache.exeC:\Users\admin\AppData\Local\Temp\EUD153.tmp\psmachine_64.dllexecutable
MD5:AE6E84289F0264374BA3B54634FD1864
SHA256:198FAF3C4107737679C6A057F1E661B5B8A15CFD39C1BECFE2EF9062A7F2F24B
6668nmtcache.exeC:\Users\admin\AppData\Local\Temp\EUD153.tmp\psmachine_arm64.dllexecutable
MD5:26A613B3E85F99F277C72E089BA55A96
SHA256:81078F06FAE5DC44257EEFC39675449A4E8D9CEB4910750BABF0914F5361017D
6668nmtcache.exeC:\Users\admin\AppData\Local\Temp\EUD153.tmp\psuser_64.dllexecutable
MD5:72AA2974228D0D4E62A8E3C670DB1204
SHA256:632762238CDB97D88C6527AD5D2AAD7A84C61550545458F69CE5EDB504E659C0
6668nmtcache.exeC:\Users\admin\AppData\Local\Temp\EUD153.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:3234CB9CE73386F54FD0CA140CE1EA34
SHA256:CA798DAEAD23EB45E054C22D59688873710A3AEEB56AD58DFFB9DBD7DF7619AB
6668nmtcache.exeC:\Users\admin\AppData\Local\Temp\EUD153.tmp\MicrosoftEdgeUpdateOnDemand.exeexecutable
MD5:B24A7473192E02CA5A8EF0A6CDF5A7FA
SHA256:2FB732A43AF16159B58EEA7950EE63FF6ED21EE78303C584FCC580F92D997BF5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
45
DNS requests
33
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2636
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7004
svchost.exe
HEAD
200
23.50.131.72:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e9dcc3d7-d24a-407d-8f74-75c3d7fd8cfe?P1=1727808303&P2=404&P3=2&P4=YZBmxkUHqVx%2frxm0OLUQ7FCz%2bxqR9m9RQCI4YQPkG0OOBYQriFPFxgYLk%2bAoUwe1ji%2b%2frfA4kFsa2B4JDOkb0w%3d%3d
unknown
whitelisted
7004
svchost.exe
HEAD
200
84.201.210.37:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/2132f61f-f790-4ae6-a355-8cf9a1533800?P1=1727400401&P2=404&P3=2&P4=CHFl94Rvu6Xdv%2fmiyHEWoZKImh7Lp1SvmijHehVv3LdVX9bKdrVXXBCVmY%2f2GhyD1YFrZ28g%2bsG6NFov1KhsyQ%3d%3d
unknown
whitelisted
7004
svchost.exe
GET
200
23.50.131.72:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e9dcc3d7-d24a-407d-8f74-75c3d7fd8cfe?P1=1727808303&P2=404&P3=2&P4=YZBmxkUHqVx%2frxm0OLUQ7FCz%2bxqR9m9RQCI4YQPkG0OOBYQriFPFxgYLk%2bAoUwe1ji%2b%2frfA4kFsa2B4JDOkb0w%3d%3d
unknown
whitelisted
7164
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7164
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7004
svchost.exe
HEAD
200
84.201.210.37:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b22f5f18-f7ea-4290-929d-b13c03908334?P1=1727400401&P2=404&P3=2&P4=GXG80%2bsrnSAXN8dEkJrCx%2f%2frLheQRVBT%2ffCqIc5KkORMPTcRgk7tSEYjxd1rcmyPEtxHaOktwOO9Hdpm%2bviccA%3d%3d
unknown
whitelisted
7004
svchost.exe
GET
206
84.201.210.37:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b22f5f18-f7ea-4290-929d-b13c03908334?P1=1727400401&P2=404&P3=2&P4=GXG80%2bsrnSAXN8dEkJrCx%2f%2frLheQRVBT%2ffCqIc5KkORMPTcRgk7tSEYjxd1rcmyPEtxHaOktwOO9Hdpm%2bviccA%3d%3d
unknown
whitelisted
7004
svchost.exe
GET
206
84.201.210.37:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b22f5f18-f7ea-4290-929d-b13c03908334?P1=1727400401&P2=404&P3=2&P4=GXG80%2bsrnSAXN8dEkJrCx%2f%2frLheQRVBT%2ffCqIc5KkORMPTcRgk7tSEYjxd1rcmyPEtxHaOktwOO9Hdpm%2bviccA%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3888
svchost.exe
239.255.255.250:1900
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2864
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6768
installer.exe
23.218.210.69:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
6768
installer.exe
152.199.21.175:443
msedge.sf.dl.delivery.mp.microsoft.com
EDGECAST
DE
whitelisted
2636
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2636
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5552
MicrosoftEdgeUpdate.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.142
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted
login.live.com
  • 40.126.32.133
  • 40.126.32.76
  • 40.126.32.134
  • 20.190.160.22
  • 40.126.32.72
  • 40.126.32.136
  • 40.126.32.68
  • 20.190.160.20
  • 20.190.159.2
  • 20.190.159.64
  • 20.190.159.23
  • 20.190.159.71
  • 40.126.31.71
  • 40.126.31.73
  • 40.126.31.69
  • 20.190.159.4
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
msedge.api.cdp.microsoft.com
  • 4.245.161.190
whitelisted
msedge.f.tlu.dl.delivery.mp.microsoft.com
  • 23.50.131.72
  • 23.50.131.74
whitelisted

Threats

PID
Process
Class
Message
7004
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\com.nmt.ecosystem directory exists )