URL:

https://ps.yuuki.me/app/yuukips-launcher/download/windows

Full analysis: https://app.any.run/tasks/18bb0af4-91a7-480e-8eb1-91a6d90cfbe7
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: February 23, 2026, 14:08:24
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
Indicators:
MD5:

5B88A6C5F1FC49F29EC747AEEF04A8C3

SHA1:

5C8E446C050C4F4ED120D3E5D3CFCE7EFCC94683

SHA256:

41940D1345363AC5A92358DC7A091E0CB56E52FBC1A9B83AF9BE4E1E3874FC7D

SSDEEP:

3:N8SUIyO6LaAR4JkdY:2SUIyO6J4AY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 3388)
    • Potential DLL hijacking behavior detected

      • msedgewebview2.exe (PID: 4224)
      • msedgewebview2.exe (PID: 5528)
    • Scans artifacts that could help determine the target

      • msedgewebview2.exe (PID: 2144)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 1044)
      • MicrosoftEdgeUpdate.exe (PID: 3388)
      • MicrosoftEdgeWebview_X64_145.0.3800.70.exe (PID: 8080)
      • setup.exe (PID: 7924)
      • YuukiPS_2.0.15_x64-setup.exe (PID: 1836)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 3388)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 3388)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2912)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6296)
      • MicrosoftEdgeUpdate.exe (PID: 4200)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 9088)
    • Application launched itself

      • setup.exe (PID: 7924)
      • MicrosoftEdgeUpdate.exe (PID: 6484)
      • msedgewebview2.exe (PID: 2764)
      • msedgewebview2.exe (PID: 2144)
    • Searches for installed software

      • setup.exe (PID: 7924)
    • The process creates files with name similar to system file names

      • YuukiPS_2.0.15_x64-setup.exe (PID: 1836)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • YuukiPS_2.0.15_x64-setup.exe (PID: 1836)
  • INFO

    • Drops script file

      • msedge.exe (PID: 9064)
      • setup.exe (PID: 7924)
    • Application launched itself

      • msedge.exe (PID: 9064)
    • Reads Environment values

      • identity_helper.exe (PID: 2284)
      • MicrosoftEdgeUpdate.exe (PID: 6232)
      • MicrosoftEdgeUpdate.exe (PID: 7972)
      • msedgewebview2.exe (PID: 2764)
      • msedgewebview2.exe (PID: 2144)
    • Checks supported languages

      • identity_helper.exe (PID: 2284)
      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 1044)
      • MicrosoftEdgeUpdate.exe (PID: 3388)
      • MicrosoftEdgeUpdate.exe (PID: 4200)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2912)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6296)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 9088)
      • MicrosoftEdgeUpdate.exe (PID: 8816)
      • MicrosoftEdgeUpdate.exe (PID: 6484)
      • MicrosoftEdgeWebview_X64_145.0.3800.70.exe (PID: 8080)
      • MicrosoftEdgeUpdate.exe (PID: 6232)
      • setup.exe (PID: 7924)
      • setup.exe (PID: 1488)
      • MicrosoftEdgeUpdate.exe (PID: 7972)
      • YuukiPS_2.0.15_x64-setup.exe (PID: 1836)
      • yuukips-launcher.exe (PID: 7524)
      • msedgewebview2.exe (PID: 2764)
      • msedgewebview2.exe (PID: 4992)
      • msedgewebview2.exe (PID: 4332)
      • msedgewebview2.exe (PID: 4224)
      • msedgewebview2.exe (PID: 6036)
      • msedgewebview2.exe (PID: 7036)
      • msedgewebview2.exe (PID: 4312)
      • msedgewebview2.exe (PID: 7056)
      • msedgewebview2.exe (PID: 2144)
      • yuukips-launcher.exe (PID: 2148)
      • msedgewebview2.exe (PID: 7760)
      • msedgewebview2.exe (PID: 5528)
      • msedgewebview2.exe (PID: 6224)
    • Reads the computer name

      • identity_helper.exe (PID: 2284)
      • MicrosoftEdgeUpdate.exe (PID: 3388)
      • MicrosoftEdgeUpdate.exe (PID: 4200)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2912)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6296)
      • MicrosoftEdgeUpdate.exe (PID: 6484)
      • MicrosoftEdgeWebview_X64_145.0.3800.70.exe (PID: 8080)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 9088)
      • MicrosoftEdgeUpdate.exe (PID: 6232)
      • MicrosoftEdgeUpdate.exe (PID: 8816)
      • setup.exe (PID: 7924)
      • MicrosoftEdgeUpdate.exe (PID: 7972)
      • YuukiPS_2.0.15_x64-setup.exe (PID: 1836)
      • yuukips-launcher.exe (PID: 7524)
      • msedgewebview2.exe (PID: 2764)
      • msedgewebview2.exe (PID: 4332)
      • msedgewebview2.exe (PID: 4224)
      • yuukips-launcher.exe (PID: 2148)
      • msedgewebview2.exe (PID: 5528)
      • msedgewebview2.exe (PID: 2144)
      • msedgewebview2.exe (PID: 4312)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 9064)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 9064)
      • msedge.exe (PID: 3516)
    • The sample compiled with english language support

      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 1044)
      • MicrosoftEdgeUpdate.exe (PID: 3388)
      • MicrosoftEdgeWebview_X64_145.0.3800.70.exe (PID: 8080)
      • setup.exe (PID: 7924)
    • Create files in a temporary directory

      • MicrosoftEdgeWebView2RuntimeInstallerX64.exe (PID: 1044)
      • YuukiPS_2.0.15_x64-setup.exe (PID: 1836)
      • msedgewebview2.exe (PID: 2764)
      • msedgewebview2.exe (PID: 2144)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 3388)
      • MicrosoftEdgeUpdate.exe (PID: 6484)
      • MicrosoftEdgeWebview_X64_145.0.3800.70.exe (PID: 8080)
      • setup.exe (PID: 7924)
      • setup.exe (PID: 1488)
      • YuukiPS_2.0.15_x64-setup.exe (PID: 1836)
      • yuukips-launcher.exe (PID: 7524)
      • msedgewebview2.exe (PID: 2764)
      • msedgewebview2.exe (PID: 4992)
      • msedgewebview2.exe (PID: 4332)
      • msedgewebview2.exe (PID: 2144)
      • yuukips-launcher.exe (PID: 2148)
      • msedgewebview2.exe (PID: 4312)
    • Launching a file from a Registry key

      • MicrosoftEdgeUpdate.exe (PID: 3388)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 6232)
      • MicrosoftEdgeUpdate.exe (PID: 7972)
      • slui.exe (PID: 7208)
      • msedgewebview2.exe (PID: 2764)
      • msedgewebview2.exe (PID: 2144)
      • reg.exe (PID: 7588)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 3388)
      • MicrosoftEdgeUpdate.exe (PID: 6484)
      • msedgewebview2.exe (PID: 2764)
      • msedgewebview2.exe (PID: 2144)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 3388)
      • setup.exe (PID: 7924)
      • msedgewebview2.exe (PID: 2764)
      • msedgewebview2.exe (PID: 2144)
      • msedgewebview2.exe (PID: 7036)
      • msedgewebview2.exe (PID: 6224)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 6484)
      • msedgewebview2.exe (PID: 2764)
      • msedgewebview2.exe (PID: 2144)
    • Creates a software uninstall entry

      • setup.exe (PID: 7924)
      • YuukiPS_2.0.15_x64-setup.exe (PID: 1836)
    • Manual execution by a user

      • yuukips-launcher.exe (PID: 7524)
      • yuukips-launcher.exe (PID: 2148)
    • Creates files in the program directory

      • YuukiPS_2.0.15_x64-setup.exe (PID: 1836)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
230
Monitored processes
73
Malicious processes
3
Suspicious processes
4

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs microsoftedgewebview2runtimeinstallerx64.exe slui.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs msedge.exe no specs msedge.exe no specs microsoftedgewebview_x64_145.0.3800.70.exe msedge.exe no specs setup.exe setup.exe no specs msedge.exe no specs msedge.exe no specs microsoftedgeupdate.exe msedge.exe no specs yuukips_2.0.15_x64-setup.exe no specs yuukips_2.0.15_x64-setup.exe msedge.exe no specs msedge.exe no specs yuukips-launcher.exe no specs msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedge.exe no specs yuukips-launcher.exe msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs msedge.exe no specs msedgewebview2.exe msedgewebview2.exe no specs msedgewebview2.exe no specs reg.exe no specs conhost.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
524"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=22 --always-read-main-dll --field-trial-handle=8016,i,2568320797008187827,14706332333488120037,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=7948 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1044"C:\Users\admin\Downloads\MicrosoftEdgeWebView2RuntimeInstallerX64.exe" C:\Users\admin\Downloads\MicrosoftEdgeWebView2RuntimeInstallerX64.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.221.3
Modules
Images
c:\users\admin\downloads\microsoftedgewebview2runtimeinstallerx64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1172"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_xpay_wallet.mojom.EdgeXPayWalletService --lang=en-US --service-sandbox-type=utility --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6804,i,2568320797008187827,14706332333488120037,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=7216 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1388"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=18 --always-read-main-dll --field-trial-handle=7224,i,2568320797008187827,14706332333488120037,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=7372 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1488C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{6C88C205-6ACF-4CD7-82CB-BFD36E67EF13}\EDGEMITMP_43101.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=145.0.7632.110 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{6C88C205-6ACF-4CD7-82CB-BFD36E67EF13}\EDGEMITMP_43101.tmp\setup.exe --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=145.0.3800.70 --initial-client-data=0x230,0x234,0x238,0x20c,0x23c,0x7ff6d639cc68,0x7ff6d639cc74,0x7ff6d639cc80C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{6C88C205-6ACF-4CD7-82CB-BFD36E67EF13}\EDGEMITMP_43101.tmp\setup.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
145.0.3800.70
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{6c88c205-6acf-4cd7-82cb-bfd36e67ef13}\edgemitmp_43101.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1520"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=20 --always-read-main-dll --field-trial-handle=7300,i,2568320797008187827,14706332333488120037,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=7700 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1708"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --pdf-upsell-enabled --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=12 --always-read-main-dll --field-trial-handle=6020,i,2568320797008187827,14706332333488120037,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=6112 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1784"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5900,i,2568320797008187827,14706332333488120037,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version --mojo-platform-channel-handle=5952 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
1836"C:\Users\admin\Downloads\YuukiPS_2.0.15_x64-setup.exe" C:\Users\admin\Downloads\YuukiPS_2.0.15_x64-setup.exe
msedge.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\downloads\yuukips_2.0.15_x64-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1856\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exereg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
15 578
Read events
14 408
Write events
1 101
Delete events
69

Modification events

(PID) Process:(3388) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(3388) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:edgeupdate_task_name_c
Value:
MicrosoftEdgeUpdateTaskUserS-1-5-21-1693682860-607145093-2874071422-1001Core{3F4799E8-B801-4FD7-8A96-4C8260A57D16}
(PID) Process:(3388) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:edgeupdate_task_name_ua
Value:
MicrosoftEdgeUpdateTaskUserS-1-5-21-1693682860-607145093-2874071422-1001UA{C382C885-8A23-41AD-AB3A-AE1D7DBA8097}
(PID) Process:(4200) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{72808691-AF2A-4539-8B4A-3CDBA21C32F9}\InprocHandler32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(4200) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{BCF99248-58CE-4562-B227-14D1E171B49D}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(6296) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(6296) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}
Operation:delete keyName:(default)
Value:
(PID) Process:(6296) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(6296) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{5EA43877-C6D8-4885-B77A-C0BB27E94372}\InprocServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(6296) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{5EA43877-C6D8-4885-B77A-C0BB27E94372}
Operation:delete keyName:(default)
Value:
Executable files
258
Suspicious files
637
Text files
276
Unknown types
150

Dropped files

PID
Process
Filename
Type
9064msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1e55fd.TMP
MD5:
SHA256:
9064msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
9064msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF1e55fd.TMP
MD5:
SHA256:
9064msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1e55fd.TMP
MD5:
SHA256:
9064msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
9064msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1e55fd.TMP
MD5:
SHA256:
9064msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
9064msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF1e562c.TMP
MD5:
SHA256:
9064msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
9064msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF1e563c.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
543
TCP/UDP connections
140
DNS requests
146
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3516
msedge.exe
GET
304
150.171.28.11:443
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
unknown
whitelisted
3516
msedge.exe
GET
304
2.16.10.183:443
https://assets.msn.com/staticsb/statics/latest/oneTrust/2.3/scripttemplates/otSDKStub.js
unknown
whitelisted
3516
msedge.exe
GET
304
2.16.10.183:443
https://assets.msn.com/staticsb/statics/latest/oneTrust/2.3/scripttemplates/202501.2.0/otBannerSdk.js
unknown
whitelisted
3516
msedge.exe
GET
304
2.16.10.183:443
https://assets.msn.com/staticsb/statics/latest/oneTrust/2.3/consent/55a804ab-e5c6-4b97-9319-86263d365d28/55a804ab-e5c6-4b97-9319-86263d365d28.json
unknown
whitelisted
3516
msedge.exe
GET
200
150.171.27.11:443
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
unknown
text
295 b
whitelisted
3516
msedge.exe
GET
200
104.18.23.222:443
https://copilot.microsoft.com/c/api/user/eligibility
unknown
binary
25 b
whitelisted
3516
msedge.exe
GET
200
150.171.27.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:h9imOPKGjidv8dbUeRk84J-sQhOxFM6ZQX-gNgSpPJ4&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
3516
msedge.exe
GET
200
13.107.246.45:443
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appId=edge-extensions&country=US
unknown
binary
82 b
whitelisted
3516
msedge.exe
GET
302
104.26.0.170:443
https://ps.yuuki.me/app/yuukips-launcher/download/windows
unknown
text
134 b
unknown
3516
msedge.exe
GET
200
52.123.243.186:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=Edge%2CEdgeConfig%2CEdgeServices%2CEdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=66&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0
unknown
text
4.30 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
8400
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
7004
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3516
msedge.exe
150.171.27.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3516
msedge.exe
52.123.243.186:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3516
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3516
msedge.exe
104.26.0.170:443
ps.yuuki.me
CLOUDFLARENET
US
whitelisted
3516
msedge.exe
104.18.23.222:443
copilot.microsoft.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
self.events.data.microsoft.com
  • 52.182.143.214
  • 52.182.143.213
whitelisted
google.com
  • 216.58.206.46
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 52.123.243.186
  • 52.123.243.184
  • 52.123.243.181
  • 52.123.243.177
  • 52.123.243.93
  • 52.123.224.71
  • 52.123.224.69
  • 52.123.243.90
  • 52.123.243.207
  • 52.123.243.208
  • 52.123.243.205
  • 52.123.243.73
  • 52.123.224.74
  • 52.123.242.233
  • 52.123.242.230
  • 52.123.242.242
  • 52.123.242.240
  • 52.123.224.64
whitelisted
ps.yuuki.me
  • 104.26.0.170
  • 104.26.1.170
  • 172.67.68.147
unknown
api.edgeoffer.microsoft.com
  • 13.107.246.45
  • 13.107.213.45
whitelisted
copilot.microsoft.com
  • 104.18.23.222
  • 104.18.22.222
whitelisted
git.yuuki.me
  • 104.26.0.170
  • 104.26.1.170
  • 172.67.68.147
unknown
update.googleapis.com
  • 172.217.168.67
whitelisted
www.bing.com
  • 104.126.37.160
  • 104.126.37.179
  • 104.126.37.178
  • 104.126.37.154
  • 104.126.37.177
  • 104.126.37.146
  • 104.126.37.155
  • 104.126.37.136
  • 104.126.37.137
  • 92.123.104.6
  • 92.123.104.9
  • 92.123.104.17
  • 92.123.104.13
  • 92.123.104.16
  • 92.123.104.14
  • 92.123.104.18
  • 92.123.104.5
  • 92.123.104.12
  • 92.123.104.62
  • 92.123.104.56
  • 92.123.104.61
  • 92.123.104.60
  • 92.123.104.66
  • 92.123.104.65
  • 92.123.104.55
  • 92.123.104.52
  • 92.123.104.58
whitelisted

Threats

PID
Process
Class
Message
3516
msedge.exe
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
3516
msedge.exe
Misc activity
ET INFO EXE - Served Inline HTTP
8400
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
3516
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
3516
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
3516
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
3516
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
3516
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
3516
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
3516
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Azure Front Door domain observed in TLS SNI ( .azurefd .net)
Process
Message
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\com.yuukips.launcher directory exists )
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\com.yuukips.launcher\EBWebView directory exists )