File name:

wexside-new.exe

Full analysis: https://app.any.run/tasks/2325f0d9-2750-4d5f-a2ea-1734a9b6d479
Verdict: Malicious activity
Analysis date: December 21, 2025, 15:15:01
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
golang
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 9 sections
MD5:

CC6FA95D51E14E83D738A50282C28A18

SHA1:

7A5946F6A0A5827471BC884D8E02A82A42014A0A

SHA256:

4F77A5BFA119F24D84CD4AFE89540DAC06D88C9EF8CFB3DD7443FCDE18E59D49

SSDEEP:

98304:pW5ENqvl96fxejSNK8B3XaOhBJlZqUkx0KW6SPGfaFMOHgBAyHOzZUBZdzkHZSCP:o4Jan+KN9i0Cw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • wexside-new.exe (PID: 7540)
    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 7632)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • wexside-new.exe (PID: 7540)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7608)
      • MicrosoftEdgeUpdate.exe (PID: 7632)
      • setup.exe (PID: 7280)
      • MicrosoftEdge_X64_143.0.3650.96.exe (PID: 7380)
    • Process drops legitimate windows executable

      • wexside-new.exe (PID: 7540)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7608)
      • MicrosoftEdgeUpdate.exe (PID: 7632)
      • MicrosoftEdge_X64_143.0.3650.96.exe (PID: 7380)
      • setup.exe (PID: 7280)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebview2Setup.exe (PID: 7608)
      • MicrosoftEdgeUpdate.exe (PID: 7632)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 7632)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 7716)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7744)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7780)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7812)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 7632)
      • MicrosoftEdgeUpdate.exe (PID: 8064)
    • There is functionality for taking screenshot (YARA)

      • wexside-new.exe (PID: 7540)
    • Application launched itself

      • setup.exe (PID: 7280)
      • MicrosoftEdgeUpdate.exe (PID: 8064)
      • msedgewebview2.exe (PID: 4724)
    • Searches for installed software

      • setup.exe (PID: 7280)
  • INFO

    • Reads Environment values

      • wexside-new.exe (PID: 7540)
      • MicrosoftEdgeUpdate.exe (PID: 7868)
      • MicrosoftEdgeUpdate.exe (PID: 7900)
    • Checks supported languages

      • wexside-new.exe (PID: 7540)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7608)
      • MicrosoftEdgeUpdate.exe (PID: 7632)
      • MicrosoftEdgeUpdate.exe (PID: 7716)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7744)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7780)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7812)
      • MicrosoftEdgeUpdate.exe (PID: 7908)
      • MicrosoftEdgeUpdate.exe (PID: 8064)
      • MicrosoftEdge_X64_143.0.3650.96.exe (PID: 7380)
      • MicrosoftEdgeUpdate.exe (PID: 7868)
      • MicrosoftEdgeUpdate.exe (PID: 7900)
      • setup.exe (PID: 7280)
      • setup.exe (PID: 6852)
      • msedgewebview2.exe (PID: 8072)
      • msedgewebview2.exe (PID: 4724)
    • Reads the computer name

      • wexside-new.exe (PID: 7540)
      • MicrosoftEdgeUpdate.exe (PID: 7632)
      • MicrosoftEdgeUpdate.exe (PID: 7716)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7744)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7780)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7812)
      • MicrosoftEdgeUpdate.exe (PID: 7868)
      • MicrosoftEdgeUpdate.exe (PID: 7908)
      • MicrosoftEdgeUpdate.exe (PID: 8064)
      • MicrosoftEdge_X64_143.0.3650.96.exe (PID: 7380)
      • setup.exe (PID: 7280)
      • MicrosoftEdgeUpdate.exe (PID: 7900)
      • msedgewebview2.exe (PID: 4724)
    • The sample compiled with english language support

      • wexside-new.exe (PID: 7540)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7608)
      • MicrosoftEdgeUpdate.exe (PID: 7632)
      • MicrosoftEdge_X64_143.0.3650.96.exe (PID: 7380)
      • setup.exe (PID: 7280)
    • Create files in a temporary directory

      • wexside-new.exe (PID: 7540)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7608)
    • Reads the machine GUID from the registry

      • wexside-new.exe (PID: 7540)
      • MicrosoftEdgeUpdate.exe (PID: 8064)
    • Launching a file from a Registry key

      • MicrosoftEdgeUpdate.exe (PID: 7632)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 7632)
      • MicrosoftEdgeUpdate.exe (PID: 8064)
      • MicrosoftEdge_X64_143.0.3650.96.exe (PID: 7380)
      • setup.exe (PID: 6852)
      • setup.exe (PID: 7280)
      • msedgewebview2.exe (PID: 4724)
      • msedgewebview2.exe (PID: 8072)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 7632)
      • setup.exe (PID: 7280)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 7868)
      • MicrosoftEdgeUpdate.exe (PID: 8064)
      • MicrosoftEdgeUpdate.exe (PID: 7900)
    • Detects GO elliptic curve encryption (YARA)

      • wexside-new.exe (PID: 7540)
    • Application based on Golang

      • wexside-new.exe (PID: 7540)
    • Manual execution by a user

      • mspaint.exe (PID: 7216)
    • Creates a software uninstall entry

      • setup.exe (PID: 7280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 3
CodeSize: 3922944
InitializedDataSize: 623104
UninitializedDataSize: -
EntryPoint: 0x72160
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Built using Wails (https://wails.io)
CompanyName: wexside-launcher
FileDescription: wexside-launcher
LegalCopyright: Copyright.........
ProductName: wexside-launcher
ProductVersion: 1.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
161
Monitored processes
18
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wexside-new.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe mspaint.exe no specs microsoftedge_x64_143.0.3650.96.exe setup.exe setup.exe no specs slui.exe no specs microsoftedgeupdate.exe msedgewebview2.exe msedgewebview2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4724"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\143.0.3650.96\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=wexside-new.exe --webview-exe-version=1.0.0 --user-data-dir="C:\Users\admin\AppData\Roaming\wexside-new.exe\EBWebView" --noerrdialogs --embedded-browser-webview-dpi-awareness=2 --disable-features=msSmartScreenProtection --mojo-named-platform-channel-pipe=7540.6936.3542857694896675845C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\143.0.3650.96\msedgewebview2.exe
wexside-new.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Version:
143.0.3650.96
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\143.0.3650.96\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\143.0.3650.96\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
6852C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{15916F85-4540-46BC-8F0F-3B611C0A1C30}\EDGEMITMP_91B4D.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=143.0.7499.147 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{15916F85-4540-46BC-8F0F-3B611C0A1C30}\EDGEMITMP_91B4D.tmp\setup.exe --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=143.0.3650.96 --initial-client-data=0x258,0x25c,0x260,0x1dc,0x264,0x7ff62a724798,0x7ff62a7247a4,0x7ff62a7247b0C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{15916F85-4540-46BC-8F0F-3B611C0A1C30}\EDGEMITMP_91B4D.tmp\setup.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
143.0.3650.96
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{15916f85-4540-46bc-8f0f-3b611c0a1c30}\edgemitmp_91b4d.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
7216"C:\WINDOWS\system32\mspaint.exe" "C:\Users\admin\Desktop\whileunderstand.png"C:\Windows\System32\mspaint.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Paint
Exit code:
0
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mspaint.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7280"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{15916F85-4540-46BC-8F0F-3B611C0A1C30}\EDGEMITMP_91B4D.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{15916F85-4540-46BC-8F0F-3B611C0A1C30}\MicrosoftEdge_X64_143.0.3650.96.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{15916F85-4540-46BC-8F0F-3B611C0A1C30}\EDGEMITMP_91B4D.tmp\setup.exe
MicrosoftEdge_X64_143.0.3650.96.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
143.0.3650.96
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{15916f85-4540-46bc-8f0f-3b611c0a1c30}\edgemitmp_91b4d.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
7380"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{15916F85-4540-46BC-8F0F-3B611C0A1C30}\MicrosoftEdge_X64_143.0.3650.96.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{15916F85-4540-46BC-8F0F-3B611C0A1C30}\MicrosoftEdge_X64_143.0.3650.96.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
143.0.3650.96
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{15916f85-4540-46bc-8f0f-3b611c0a1c30}\microsoftedge_x64_143.0.3650.96.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7540"C:\Users\admin\AppData\Local\Temp\wexside-new.exe" C:\Users\admin\AppData\Local\Temp\wexside-new.exe
explorer.exe
User:
admin
Company:
wexside-launcher
Integrity Level:
MEDIUM
Description:
wexside-launcher
Modules
Images
c:\users\admin\appdata\local\temp\wexside-new.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
7608C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe
wexside-new.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.213.7
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7632C:\Users\admin\AppData\Local\Temp\EUF340.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EUF340.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.213.7
Modules
Images
c:\users\admin\appdata\local\temp\euf340.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
7716"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.213.7
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
7744"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.213.7\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.213.7\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.213.7
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.213.7\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
12 522
Read events
10 824
Write events
1 631
Delete events
67

Modification events

(PID) Process:(7744) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{5EA43877-C6D8-4885-B77A-C0BB27E94372}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(7744) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{D627BF09-34D0-4995-BF6F-C344772BFA2D}\InprocHandler32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(7744) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{5247F326-2FF0-4920-998E-12AA35F0883C}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(7716) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(7716) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5EA43877-C6D8-4885-B77A-C0BB27E94372}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(7716) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{D627BF09-34D0-4995-BF6F-C344772BFA2D}\InprocHandler32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(7716) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5247F326-2FF0-4920-998E-12AA35F0883C}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(7716) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(7716) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}
Operation:delete keyName:(default)
Value:
(PID) Process:(7812) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32
Operation:delete keyName:(default)
Value:
Executable files
207
Suspicious files
8
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
7608MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUF340.tmp\psmachine_arm64.dllexecutable
MD5:0010E4731F11ACF8279569B69504FC38
SHA256:920FADA66C96585ABD49EB662CAB842C2F33F64AE8E1FE910C22A56F32DBEDED
7608MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUF340.tmp\MicrosoftEdgeUpdateCore.exeexecutable
MD5:6B866AF5FB89F2E51437CD62964F2BC0
SHA256:50CD95698C2CFA2F77055B3122A24723D7FB5C2964364EB620E7519AB6291FE7
7608MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUF340.tmp\psuser_arm64.dllexecutable
MD5:5B95D476C4C1F1E378AB81978C002683
SHA256:C72EE6A7A304407EA157F49C59106DEAAAE48CC0ECEAD313C06FB756593ED3E1
7608MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUF340.tmp\msedgeupdateres_ar.dllexecutable
MD5:64EE92F5D81AF823CA53FAAF62AF124E
SHA256:8151857143B297F5ECD0877BA51AB38E175618865A8E1AE28741DA4BDFADD710
7608MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUF340.tmp\msedgeupdateres_am.dllexecutable
MD5:53FF1BE76C29ADF769DDA827D3D48D37
SHA256:6513862CBD03B5ED383B63105F14143BA5AC52BE59CB08DE390E19DD419E1FCE
7608MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUF340.tmp\msedgeupdateres_bg.dllexecutable
MD5:F91F2185C161E9BB617DFE833B61F23F
SHA256:F4A13BE042AD533BBB9A076A9027F6F3FA2AA1A064343D3112685DB339D74147
7608MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUF340.tmp\MicrosoftEdgeUpdateOnDemand.exeexecutable
MD5:1289AF5365E5554AC40A1FA3BB148567
SHA256:3B1E2521392AA4603BB6A9CAF4F993C82F2893601191185F17518E1F432CE80C
7608MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUF340.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:0AFC5E546B677C17BA56DFF791A11B9D
SHA256:1740BC1E757E401DA8108DF66EFCDE4772D450852C733FEFC84A5455078A3595
7608MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUF340.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:556199381EB17044D081FDD148D5C41E
SHA256:234C9F4A508DD59A55F639E12A2A41DB2F3E5B4C775DE8CB6A5BF94B8D5241B6
7608MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EUF340.tmp\psuser_64.dllexecutable
MD5:561F52ED51CCB8B84E3F1D059015C143
SHA256:16294FD7E353539C020AF4797A1703FE99D9D0EF2DCB73AF9FE39DCC556D213D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
32
DNS requests
22
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
1840
svchost.exe
POST
200
20.190.160.132:443
https://login.live.com/RST2.srf
US
xml
11.0 Kb
whitelisted
1840
svchost.exe
POST
200
20.190.160.132:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
whitelisted
4704
svchost.exe
GET
200
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=562&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=1&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
5.48 Kb
whitelisted
8064
MicrosoftEdgeUpdate.exe
POST
200
74.178.76.44:443
https://msedge.api.cdp.microsoft.com/api/v1.1/internal/contents/Browser/namespaces/Default/names/msedgewebview-stable-win-x64/versions/143.0.3650.96/files?action=GenerateDownloadInfo&foregroundPriority=true
US
text
9.71 Kb
whitelisted
6724
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
US
binary
419 b
whitelisted
6724
SIHClient.exe
GET
200
13.95.31.18:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
6724
SIHClient.exe
GET
200
74.179.77.204:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
6724
SIHClient.exe
GET
304
74.179.77.204:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
4704
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5480
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7540
wexside-new.exe
2.23.246.9:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
7540
wexside-new.exe
199.232.214.172:443
msedge.sf.dl.delivery.mp.microsoft.com
FASTLY
US
whitelisted
4704
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4704
svchost.exe
23.216.77.21:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
4704
svchost.exe
2.23.246.101:80
www.microsoft.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
go.microsoft.com
  • 2.23.246.9
whitelisted
msedge.sf.dl.delivery.mp.microsoft.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
crl.microsoft.com
  • 23.216.77.21
  • 23.216.77.16
  • 23.216.77.31
  • 23.216.77.12
  • 23.216.77.19
  • 23.216.77.30
  • 23.216.77.26
  • 23.216.77.20
  • 23.216.77.8
  • 23.216.77.22
  • 23.216.77.18
  • 23.216.77.28
  • 23.216.77.32
  • 23.216.77.29
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 88.221.169.152
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
msedge.api.cdp.microsoft.com
  • 74.178.76.44
whitelisted
msedge.f.tlu.dl.delivery.mp.microsoft.com
  • 217.195.193.60
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
8152
svchost.exe
Misc activity
ET INFO Packed Executable Download
Process
Message
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Roaming directory exists )