File name:

BrowserUpdater.exe

Full analysis: https://app.any.run/tasks/8b6136da-631e-4f90-bf43-d014025d10d4
Verdict: Malicious activity
Analysis date: September 04, 2024, 01:59:03
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
antivm
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
MD5:

601C10036F779D66D51D041DB843527F

SHA1:

5231F97233076AF0846590D7D0386BF78797BD22

SHA256:

2181C60E8727D5CFE7E713AA9731018168660AD2C96F31B08A729D1503DFC19A

SSDEEP:

196608:t3NkYY4MSikP9Z6puMKCFqFNNrnvHb7ixlgw:t3KmiYXM5MNBnvXixN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • MicrosoftEdgeWebview2Setup.exe (PID: 6264)
      • BrowserUpdater.exe (PID: 6720)
      • MicrosoftEdgeUpdateSetup.exe (PID: 7164)
      • MicrosoftEdgeUpdate.exe (PID: 6816)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebview2Setup.exe (PID: 6264)
      • MicrosoftEdgeUpdate.exe (PID: 32)
      • MicrosoftEdgeUpdateSetup.exe (PID: 7164)
      • MicrosoftEdgeUpdate.exe (PID: 6816)
    • Executable content was dropped or overwritten

      • BrowserUpdater.exe (PID: 6720)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6264)
      • MicrosoftEdgeUpdateSetup.exe (PID: 7164)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 32)
      • MicrosoftEdgeUpdate.exe (PID: 6816)
    • Reads the date of Windows installation

      • MicrosoftEdgeUpdate.exe (PID: 32)
      • MicrosoftEdgeUpdate.exe (PID: 6816)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 6816)
    • Creates a software uninstall entry

      • MicrosoftEdgeUpdate.exe (PID: 6816)
    • There is functionality for VM detection (antiVM strings)

      • BrowserUpdater.exe (PID: 6720)
  • INFO

    • Checks supported languages

      • BrowserUpdater.exe (PID: 6720)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6264)
      • MicrosoftEdgeUpdate.exe (PID: 32)
      • MicrosoftEdgeUpdateSetup.exe (PID: 7164)
      • MicrosoftEdgeUpdate.exe (PID: 6816)
    • Reads Environment values

      • BrowserUpdater.exe (PID: 6720)
      • MicrosoftEdgeUpdate.exe (PID: 6816)
      • MicrosoftEdgeUpdate.exe (PID: 32)
    • Reads the machine GUID from the registry

      • BrowserUpdater.exe (PID: 6720)
      • MicrosoftEdgeUpdate.exe (PID: 32)
    • Reads the computer name

      • BrowserUpdater.exe (PID: 6720)
      • MicrosoftEdgeUpdate.exe (PID: 32)
      • MicrosoftEdgeUpdate.exe (PID: 6816)
    • Create files in a temporary directory

      • MicrosoftEdgeUpdate.exe (PID: 32)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6264)
      • BrowserUpdater.exe (PID: 6720)
      • MicrosoftEdgeUpdate.exe (PID: 6816)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 32)
      • MicrosoftEdgeUpdate.exe (PID: 6816)
    • Creates files in the program directory

      • MicrosoftEdgeUpdateSetup.exe (PID: 7164)
      • MicrosoftEdgeUpdate.exe (PID: 32)
    • Checks proxy server information

      • wermgr.exe (PID: 6184)
      • wermgr.exe (PID: 4732)
    • Reads the software policy settings

      • wermgr.exe (PID: 6184)
      • wermgr.exe (PID: 4732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 2.41
CodeSize: 27655680
InitializedDataSize: 67828224
UninitializedDataSize: 716800
EntryPoint: 0x13e0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
122
Monitored processes
7
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT browserupdater.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe no specs microsoftedgeupdatesetup.exe microsoftedgeupdate.exe no specs wermgr.exe wermgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
32C:\Users\admin\AppData\Local\Temp\EU4C6.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=true"C:\Users\admin\AppData\Local\Temp\EU4C6.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
2147747592
Version:
1.3.143.57
Modules
Images
c:\users\admin\appdata\local\temp\eu4c6.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4732"C:\WINDOWS\system32\wermgr.exe" "-outproc" "0" "32" "1604" "1588" "1608" "0" "0" "0" "0" "0" "0" "0" "0" C:\Windows\SysWOW64\wermgr.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wermgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6184"C:\WINDOWS\system32\wermgr.exe" "-outproc" "0" "6816" "1556" "1404" "1424" "0" "0" "0" "0" "0" "0" "0" "0" C:\Windows\SysWOW64\wermgr.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wermgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6264C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe
BrowserUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
2147747592
Version:
1.3.143.57
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6720"C:\Users\admin\AppData\Local\Temp\BrowserUpdater.exe" C:\Users\admin\AppData\Local\Temp\BrowserUpdater.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
2
Modules
Images
c:\users\admin\appdata\local\temp\browserupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
6816"C:\Program Files (x86)\Microsoft\Temp\EU15EC.tmp\MicrosoftEdgeUpdate.exe" /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=true" /installelevatedC:\Program Files (x86)\Microsoft\Temp\EU15EC.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
2147747592
Version:
1.3.143.57
Modules
Images
c:\program files (x86)\microsoft\temp\eu15ec.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
7164"C:\Users\admin\AppData\Local\Temp\EU4C6.tmp\MicrosoftEdgeUpdateSetup.exe" /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=true" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\EU4C6.tmp\MicrosoftEdgeUpdateSetup.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Exit code:
2147747592
Version:
1.3.143.57
Modules
Images
c:\users\admin\appdata\local\temp\eu4c6.tmp\microsoftedgeupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
13 256
Read events
12 955
Write events
292
Delete events
9

Modification events

(PID) Process:(6816) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(6816) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate
Operation:writeName:path
Value:
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(PID) Process:(6816) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate
Operation:writeName:UninstallCmdLine
Value:
"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall
(PID) Process:(6816) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.143.57
(PID) Process:(6816) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
Microsoft Edge Update
(PID) Process:(6816) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.143.57
(PID) Process:(6816) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(6816) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate
Operation:writeName:IsMSIHelperRegistered
Value:
0
(PID) Process:(6816) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate
Operation:writeName:LastOSVersion
Value:
1C0100000A00000000000000654A000002000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010100
(PID) Process:(6816) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate
Operation:writeName:version
Value:
1.3.143.57
Executable files
301
Suspicious files
4
Text files
9
Unknown types
1

Dropped files

PID
Process
Filename
Type
6264MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU4C6.tmp\psmachine.dllexecutable
MD5:460FE68C5A8EBFAC911CCD7E859A8C9A
SHA256:7998424877C98F049023391ADF0B494B9BFA0194B9ABE9161F74A256A50BB45B
6264MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU4C6.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:2F6C55219295B8FB852D0250407DCD39
SHA256:8F53160721CBB335C5B48C0418ADDF228019FDF8BABEC80FB4C3D895F15B7E06
6264MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU4C6.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:8B6401915E92E8DD7C1B08FD7C936240
SHA256:C1346AC1F12D9B2D8ED4A34390498911ED87656AC8723208105ECBB84A6D4368
6720BrowserUpdater.exeC:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exeexecutable
MD5:60366CBF515774FFDE2B49297C3D2E9B
SHA256:7EBC4CE80143EF89CEA86A61EA151502868DB6CAAA678B8B43660A66ACE11C3A
6264MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU4C6.tmp\MicrosoftEdgeUpdateOnDemand.exeexecutable
MD5:069FCF4DD89F4BC2F96E06E559E5B2CF
SHA256:8E110A20684C92438B3EEFE4731DD5D4070D1E936D6FE3C8456628FD76B5009A
6264MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU4C6.tmp\msedgeupdate.dllexecutable
MD5:2141E11F0E1AAED7BDBCADF58FAD0357
SHA256:7D3F4E7A5ECFA260582B80D5A04C118320274A5E421D99E6C39D875FF8A80B9C
6264MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU4C6.tmp\MicrosoftEdgeUpdate.exeexecutable
MD5:5492E3D3E8E5C13E057D323029AAE7B3
SHA256:BD9699E3DA3DE952145565D1825DA68C3880C7E92AF1D5EA94589D0A5820F668
6264MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU4C6.tmp\psmachine_64.dllexecutable
MD5:2B8028B854468A64FF7EB4A3B1C8AFE9
SHA256:D6E8D613617A703FDA04CEF34D909D27CC9B2E3AE38749E1B313D082AD3F4206
6264MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU4C6.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:682CBD01731AD16EE3F89A66757FEDE6
SHA256:784D1DF23F232B5E4D40477D4ED9D61792D30B3EF28DE8D40F681C858EF36D0F
6264MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU4C6.tmp\psmachine_arm64.dllexecutable
MD5:8D0A79C5A41BE9A0175087D6CE8E3610
SHA256:3C210E6E21FF1C18716ED92DD63FE8D5E8CA0A5F01895A81073C2AD30460B261
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
34
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7152
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
407 b
whitelisted
6344
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
7152
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
239.255.255.250:1900
whitelisted
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6344
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7152
SIHClient.exe
20.114.59.183:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7152
SIHClient.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
7152
SIHClient.exe
20.166.126.56:443
fe3cr.delivery.mp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 172.217.23.110
whitelisted
login.live.com
  • 20.190.159.23
  • 40.126.31.69
  • 20.190.159.0
  • 20.190.159.4
  • 20.190.159.71
  • 40.126.31.71
  • 20.190.159.64
  • 20.190.159.2
  • 20.190.159.68
  • 20.190.159.75
  • 20.190.159.73
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.103.199
  • 40.113.110.67
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted
watson.events.data.microsoft.com
  • 20.42.73.29
whitelisted

Threats

No threats detected
No debug info