File name:

MicrosoftEdgeWebview2Setup.exe

Full analysis: https://app.any.run/tasks/f833d8a0-cf83-4628-a70c-758b2fc7f6d7
Verdict: Malicious activity
Analysis date: December 09, 2023, 05:06:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

2FBE10E4233824FBEA08DDF085D7DF96

SHA1:

17068C55B3C15E1213436BA232BBD79D90985B31

SHA256:

5B01D964CED28C1FF850B4DE05A71F386ADDD815A30C4A9EE210EF90619DF58E

SSDEEP:

49152:9tZFIA1VBxblu2XFTLqjlu9d3Df1WKbRwBbs9DyoV6j9XL9/g41fk3UOT3M1lqWN:9+oVBxBpTLIlu9pr1WKlwBbMDnVU9LhP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MicrosoftEdgeWebview2Setup.exe (PID: 1864)
      • MicrosoftEdgeUpdate.exe (PID: 2920)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 2072)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • MicrosoftEdgeWebview2Setup.exe (PID: 1864)
      • MicrosoftEdgeUpdate.exe (PID: 2920)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 2072)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 2920)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 2632)
    • Reads settings of System Certificates

      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 2292)
    • Reads the Internet Settings

      • MicrosoftEdgeUpdate.exe (PID: 2292)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 2292)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 2292)
  • INFO

    • Checks supported languages

      • MicrosoftEdgeWebview2Setup.exe (PID: 1864)
      • MicrosoftEdgeUpdate.exe (PID: 2920)
      • MicrosoftEdgeUpdate.exe (PID: 2632)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 1352)
      • MicrosoftEdgeUpdate.exe (PID: 2292)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 2072)
      • setup.exe (PID: 2548)
      • wmpnscfg.exe (PID: 2764)
    • Create files in a temporary directory

      • MicrosoftEdgeUpdate.exe (PID: 2920)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1864)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 2920)
      • MicrosoftEdgeUpdate.exe (PID: 2292)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 2072)
      • setup.exe (PID: 2548)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
    • Reads the computer name

      • MicrosoftEdgeUpdate.exe (PID: 2920)
      • MicrosoftEdgeUpdate.exe (PID: 2632)
      • MicrosoftEdgeUpdate.exe (PID: 2292)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 1352)
      • wmpnscfg.exe (PID: 2764)
      • MicrosoftEdge_X86_109.0.1518.140.exe (PID: 2072)
      • setup.exe (PID: 2548)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 1352)
      • MicrosoftEdgeUpdate.exe (PID: 2292)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 2920)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 2528)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 2528)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2764)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:19 20:55:57+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.31
CodeSize: 108032
InitializedDataSize: 1492480
UninitializedDataSize: -
EntryPoint: 0x7d20
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.181.5
ProductVersionNumber: 1.3.181.5
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge Update Setup
FileVersion: 1.3.181.5
InternalName: Microsoft Edge Update Setup
LegalCopyright: Copyright Microsoft Corporation
OriginalFileName: MicrosoftEdgeUpdateSetup.exe
ProductName: Microsoft Edge Update
ProductVersion: 1.3.181.5
UpstreamVersion: 1.3.99.0
LanguageId: en
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
9
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start microsoftedgewebview2setup.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe wmpnscfg.exe no specs microsoftedge_x86_109.0.1518.140.exe no specs setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1352"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=false" /installsource taggedmi /sessionid "{7EA8BB2F-5238-4EE7-865B-D4A651715B9E}"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1864"C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe" C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2072"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{10431E27-5DF3-44C3-AF5F-B4AEF34C587F}\MicrosoftEdge_X86_109.0.1518.140.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{10431E27-5DF3-44C3-AF5F-B4AEF34C587F}\MicrosoftEdge_X86_109.0.1518.140.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
109.0.1518.140
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{10431e27-5df3-44c3-af5f-b4aef34c587f}\microsoftedge_x86_109.0.1518.140.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2292"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2528"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xODEuNSIgc2hlbGxfdmVyc2lvbj0iMS4zLjE4MS41IiBpc21hY2hpbmU9IjAiIHNlc3Npb25pZD0iezdFQThCQjJGLTUyMzgtNEVFNy04NjVCLUQ0QTY1MTcxNUI5RX0iIGluc3RhbGxzb3VyY2U9InRhZ2dlZG1pIiByZXF1ZXN0aWQ9IntCNzExRTAyNC00NjBDLTQ2NTItODYyMi1EMDAzNkI3NDlBOTl9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iMyIgZGlza190eXBlPSIwIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4yNDU0NiIgc3A9IlNlcnZpY2UgUGFjayAxIiBhcmNoPSJ4ODYiIHByb2R1Y3RfdHlwZT0iNDgiIGlzX3dpcD0iMCIgaXNfaW5fbG9ja2Rvd25fbW9kZT0iMCIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9IkRFTEwiIHByb2R1Y3RfbmFtZT0iREVMTCIvPjxleHAgZXRhZz0iIi8-PGFwcCBhcHBpZD0ie0YzQzRGRTAwLUVGRDUtNDAzQi05NTY5LTM5OEEyMEYxQkE0QX0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4xODEuNSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMjE2NDg4MjgxMjUiIGluc3RhbGxfdGltZV9tcz0iNDg1Ii8-PC9hcHA-PC9yZXF1ZXN0PgC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2548"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{10431E27-5DF3-44C3-AF5F-B4AEF34C587F}\EDGEMITMP_DB534.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{10431E27-5DF3-44C3-AF5F-B4AEF34C587F}\MicrosoftEdge_X86_109.0.1518.140.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{10431E27-5DF3-44C3-AF5F-B4AEF34C587F}\EDGEMITMP_DB534.tmp\setup.exeMicrosoftEdge_X86_109.0.1518.140.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
109.0.1518.140
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{10431e27-5df3-44c3-af5f-b4aef34c587f}\edgemitmp_db534.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
2632"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2764"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2920C:\Users\admin\AppData\Local\Temp\EU3D7.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EU3D7.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.181.5
Modules
Images
c:\users\admin\appdata\local\temp\eu3d7.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
12 429
Read events
10 064
Write events
2 351
Delete events
14

Modification events

(PID) Process:(2632) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(2632) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}
Operation:delete keyName:(default)
Value:
(PID) Process:(2632) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\CLSID\{5EA43877-C6D8-4885-B77A-C0BB27E94372}\InprocServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(2632) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\CLSID\{5EA43877-C6D8-4885-B77A-C0BB27E94372}
Operation:delete keyName:(default)
Value:
(PID) Process:(2632) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\CLSID\{E988995E-B6FE-4E69-AAAA-6A6BE5E5A016}\InprocHandler32
Operation:delete keyName:(default)
Value:
(PID) Process:(2632) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\CLSID\{E988995E-B6FE-4E69-AAAA-6A6BE5E5A016}
Operation:delete keyName:(default)
Value:
(PID) Process:(2632) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\CLSID\{E3D57E77-FE71-4D06-BD34-D48820074909}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(2920) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\PersistedPings\{B711E024-460C-4652-8622-D0036B749A99}
Operation:delete keyName:(default)
Value:
(PID) Process:(2528) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2292) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\PersistedPings\{B3ECAC58-9578-4C8F-86EE-A376D979D57B}
Operation:delete keyName:(default)
Value:
Executable files
202
Suspicious files
7
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
1864MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU3D7.tmp\MicrosoftEdgeUpdate.exeexecutable
MD5:11FE091ACE9D03B9ADA6D5A22D12C0D0
SHA256:50F4ED60A507CE9DD1F3F4E7D53053D923CB71594374A25251746A9B2271E4EE
1864MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU3D7.tmp\psmachine_64.dllexecutable
MD5:A1E69165B66D05938AB8FC8232EDC866
SHA256:5B7345DE0B70B8D0CEFD4140ACF428A5B0FFE5A147ADF8A75D981B37FBD81E3A
1864MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU3D7.tmp\psuser_arm64.dllexecutable
MD5:ACC156733D09FBDAFED0536A168F6395
SHA256:EC15FA8D58E7AE39DF65C607D08135C656A09BADDB0CCF061B9F3A76F897A21D
1864MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU3D7.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:7750D94E4719BA69F5F83213444C0015
SHA256:1AB31694FF0B6283FBB6EC062D6EAB9FFB26DF9D6D1BA140CF60A8E7A4CB9FE5
1864MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU3D7.tmp\MicrosoftEdgeUpdateOnDemand.exeexecutable
MD5:532D470DA7523ABBB2ADE51CBD6CF1BD
SHA256:611225DCD25B3DAB7D331CE187F3589D83C80EFC543B971D96DD5357363EC827
1864MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU3D7.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:9540AD83A08605BA1F52196424CE3067
SHA256:B0B5D9EB6F4B176BDFBE4DA0A060AD1B76C813186FAE3D9A6E1B1DD9EE0D01D1
1864MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU3D7.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:4FDA82E4E5DB7141350CDDCEF7DB07A4
SHA256:48EFBB4780A6BE7EADC26DCC6D2C2B16DACCE447E53A3E2725AD4B1318A34E68
1864MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU3D7.tmp\psmachine_arm64.dllexecutable
MD5:581BC2D275F8B2E23C2C8BEEDA8471AD
SHA256:28F2F1AC5189A07B59110946509B7C61CC7F2935AF96B000278A5C5952C4B7C3
1864MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU3D7.tmp\EdgeUpdate.datbinary
MD5:369BBC37CFF290ADB8963DC5E518B9B8
SHA256:3D7EC761BEF1B1AF418B909F1C81CE577C769722957713FDAFBC8131B0A0C7D3
1864MicrosoftEdgeWebview2Setup.exeC:\Users\admin\AppData\Local\Temp\EU3D7.tmp\psmachine.dllexecutable
MD5:56C1A9EC314B41CE4BF20AAE41E94078
SHA256:A82DB4F2EC83020B2BA31A96D214D4EE207173A8B4206432C765DEE870120917
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
11
DNS requests
7
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
868
svchost.exe
HEAD
200
23.50.131.72:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/d87a3bbd-7fe5-4ec3-b806-293cca78b363?P1=1702703198&P2=404&P3=2&P4=Do7ONkK6grkUvsbXsE5E7zIOBdlcOY6n4yw0VWw%2fT96vftwctQuImnEK2YJyfztre%2bYF6RvSE73QcBH57hiEIA%3d%3d
unknown
unknown
2528
MicrosoftEdgeUpdate.exe
GET
200
23.216.77.80:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?18241ea87a8a2a56
unknown
compressed
4.66 Kb
unknown
2528
MicrosoftEdgeUpdate.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
unknown
1080
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?20da42ca9bb40799
unknown
compressed
65.2 Kb
unknown
868
svchost.exe
GET
200
23.50.131.72:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/d87a3bbd-7fe5-4ec3-b806-293cca78b363?P1=1702703198&P2=404&P3=2&P4=Do7ONkK6grkUvsbXsE5E7zIOBdlcOY6n4yw0VWw%2fT96vftwctQuImnEK2YJyfztre%2bYF6RvSE73QcBH57hiEIA%3d%3d
unknown
executable
122 Mb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
2528
MicrosoftEdgeUpdate.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2292
MicrosoftEdgeUpdate.exe
20.114.58.89:443
msedge.api.cdp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2528
MicrosoftEdgeUpdate.exe
52.168.112.66:443
self.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2528
MicrosoftEdgeUpdate.exe
23.216.77.80:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2528
MicrosoftEdgeUpdate.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
868
svchost.exe
23.50.131.72:80
msedge.f.tlu.dl.delivery.mp.microsoft.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
msedge.api.cdp.microsoft.com
  • 20.114.58.89
whitelisted
self.events.data.microsoft.com
  • 52.168.112.66
whitelisted
ctldl.windowsupdate.com
  • 23.216.77.80
  • 23.216.77.69
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
msedge.f.tlu.dl.delivery.mp.microsoft.com
  • 23.50.131.72
  • 23.50.131.74
whitelisted

Threats

PID
Process
Class
Message
868
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info