URL:

https://volt.bz/

Full analysis: https://app.any.run/tasks/25a619aa-b9b7-4612-9acc-8808619a946e
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: December 17, 2025, 10:53:28
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
rust
Indicators:
MD5:

05FC8F53DD272C98A271E25F345D8AFD

SHA1:

273AA3B1A9AD4C839E2C516876BC0972F2100BED

SHA256:

787370E4576D7D1FECFC307FB499C944A9FF1F03530AF826A6BBB4C7D4CCF13A

SSDEEP:

3:N8B:2B

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 7828)
    • Potential DLL hijacking behavior detected

      • msedgewebview2.exe (PID: 7468)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • volt.exe (PID: 6056)
      • MicrosoftEdgeWebview2Setup.exe (PID: 888)
      • MicrosoftEdgeUpdate.exe (PID: 7828)
      • MicrosoftEdge_X64_143.0.3650.80.exe (PID: 424)
      • setup.exe (PID: 7664)
      • msedgewebview2.exe (PID: 1872)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • volt.exe (PID: 6056)
    • Process drops legitimate windows executable

      • volt.exe (PID: 6056)
      • MicrosoftEdgeWebview2Setup.exe (PID: 888)
      • MicrosoftEdgeUpdate.exe (PID: 7828)
      • setup.exe (PID: 7664)
      • MicrosoftEdge_X64_143.0.3650.80.exe (PID: 424)
      • msedgewebview2.exe (PID: 1872)
    • The process creates files with name similar to system file names

      • volt.exe (PID: 6056)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebview2Setup.exe (PID: 888)
      • MicrosoftEdgeUpdate.exe (PID: 7828)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2900)
      • MicrosoftEdgeUpdate.exe (PID: 7736)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1172)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2672)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 7828)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 7828)
      • MicrosoftEdgeUpdate.exe (PID: 7120)
      • msedgewebview2.exe (PID: 6548)
    • There is functionality for taking screenshot (YARA)

      • volt.exe (PID: 6056)
      • tauri-app.exe (PID: 752)
    • Application launched itself

      • setup.exe (PID: 7664)
      • MicrosoftEdgeUpdate.exe (PID: 7120)
      • msedgewebview2.exe (PID: 6548)
  • INFO

    • Application launched itself

      • msedge.exe (PID: 7680)
    • The sample compiled with english language support

      • msedge.exe (PID: 7912)
      • msedge.exe (PID: 7680)
      • volt.exe (PID: 6056)
      • MicrosoftEdgeWebview2Setup.exe (PID: 888)
      • MicrosoftEdgeUpdate.exe (PID: 7828)
      • MicrosoftEdge_X64_143.0.3650.80.exe (PID: 424)
      • setup.exe (PID: 7664)
      • msedgewebview2.exe (PID: 1872)
    • Launching a file from the Downloads directory

      • msedge.exe (PID: 7680)
    • Reads Environment values

      • identity_helper.exe (PID: 7660)
      • MicrosoftEdgeUpdate.exe (PID: 424)
      • MicrosoftEdgeUpdate.exe (PID: 2220)
      • msedgewebview2.exe (PID: 6548)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 7680)
      • msedge.exe (PID: 7912)
    • Checks supported languages

      • volt.exe (PID: 6056)
      • identity_helper.exe (PID: 7660)
      • MicrosoftEdgeWebview2Setup.exe (PID: 888)
      • MicrosoftEdgeUpdate.exe (PID: 7828)
      • MicrosoftEdgeUpdate.exe (PID: 7736)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2900)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1172)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2672)
      • MicrosoftEdgeUpdate.exe (PID: 5020)
      • MicrosoftEdgeUpdate.exe (PID: 7120)
      • MicrosoftEdgeUpdate.exe (PID: 424)
      • MicrosoftEdge_X64_143.0.3650.80.exe (PID: 424)
      • setup.exe (PID: 412)
      • setup.exe (PID: 7664)
      • MicrosoftEdgeUpdate.exe (PID: 2220)
      • tauri-app.exe (PID: 752)
      • msedgewebview2.exe (PID: 148)
      • msedgewebview2.exe (PID: 6548)
      • msedgewebview2.exe (PID: 7468)
      • msedgewebview2.exe (PID: 1908)
      • msedgewebview2.exe (PID: 7844)
      • msedgewebview2.exe (PID: 3400)
      • msedgewebview2.exe (PID: 5040)
      • msedgewebview2.exe (PID: 5592)
      • msedgewebview2.exe (PID: 2360)
      • msedgewebview2.exe (PID: 936)
      • TextInputHost.exe (PID: 7460)
      • msedgewebview2.exe (PID: 2284)
      • msedgewebview2.exe (PID: 1872)
    • Reads the computer name

      • volt.exe (PID: 6056)
      • identity_helper.exe (PID: 7660)
      • MicrosoftEdgeUpdate.exe (PID: 7828)
      • MicrosoftEdgeUpdate.exe (PID: 7736)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2900)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1172)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2672)
      • MicrosoftEdgeUpdate.exe (PID: 424)
      • MicrosoftEdgeUpdate.exe (PID: 5020)
      • MicrosoftEdgeUpdate.exe (PID: 7120)
      • MicrosoftEdge_X64_143.0.3650.80.exe (PID: 424)
      • setup.exe (PID: 7664)
      • MicrosoftEdgeUpdate.exe (PID: 2220)
      • tauri-app.exe (PID: 752)
      • msedgewebview2.exe (PID: 6548)
      • TextInputHost.exe (PID: 7460)
      • msedgewebview2.exe (PID: 1908)
      • msedgewebview2.exe (PID: 7468)
      • msedgewebview2.exe (PID: 936)
    • Checks proxy server information

      • volt.exe (PID: 6056)
      • MicrosoftEdgeUpdate.exe (PID: 424)
      • MicrosoftEdgeUpdate.exe (PID: 7120)
      • MicrosoftEdgeUpdate.exe (PID: 2220)
      • msedgewebview2.exe (PID: 6548)
      • slui.exe (PID: 7316)
      • tauri-app.exe (PID: 752)
    • Create files in a temporary directory

      • volt.exe (PID: 6056)
      • MicrosoftEdgeWebview2Setup.exe (PID: 888)
      • msedgewebview2.exe (PID: 6548)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 7828)
      • MicrosoftEdgeUpdate.exe (PID: 7120)
      • MicrosoftEdge_X64_143.0.3650.80.exe (PID: 424)
      • setup.exe (PID: 412)
      • setup.exe (PID: 7664)
      • volt.exe (PID: 6056)
      • msedgewebview2.exe (PID: 6548)
      • msedgewebview2.exe (PID: 148)
      • msedgewebview2.exe (PID: 1908)
      • msedgewebview2.exe (PID: 936)
    • Launching a file from a Registry key

      • MicrosoftEdgeUpdate.exe (PID: 7828)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 7828)
      • setup.exe (PID: 7664)
      • msedgewebview2.exe (PID: 6548)
      • msedgewebview2.exe (PID: 3400)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 7120)
      • msedgewebview2.exe (PID: 6548)
      • msedgewebview2.exe (PID: 936)
    • Creates a software uninstall entry

      • setup.exe (PID: 7664)
      • volt.exe (PID: 6056)
    • Manual execution by a user

      • tauri-app.exe (PID: 752)
    • Application based on Rust

      • tauri-app.exe (PID: 752)
    • Reads CPU info

      • msedgewebview2.exe (PID: 6548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
214
Monitored processes
63
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
148C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\143.0.3650.80\msedgewebview2.exe --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Local\com.volt.editor\EBWebView /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\com.volt.editor\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=143.0.7499.110 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\143.0.3650.80\msedgewebview2.exe --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=143.0.3650.80 --initial-client-data=0x188,0x18c,0x190,0x160,0x198,0x7ffd70a262b8,0x7ffd70a262c4,0x7ffd70a262d0C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\143.0.3650.80\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
143.0.3650.80
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\143.0.3650.80\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\143.0.3650.80\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
412C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{35CAFEDA-66FA-4120-92D4-2DAED771BD60}\EDGEMITMP_7B41E.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=143.0.7499.110 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{35CAFEDA-66FA-4120-92D4-2DAED771BD60}\EDGEMITMP_7B41E.tmp\setup.exe --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=143.0.3650.80 --initial-client-data=0x248,0x24c,0x250,0x224,0x254,0x7ff7a2b96798,0x7ff7a2b967a4,0x7ff7a2b967b0C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{35CAFEDA-66FA-4120-92D4-2DAED771BD60}\EDGEMITMP_7B41E.tmp\setup.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
143.0.3650.80
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{35cafeda-66fa-4120-92d4-2daed771bd60}\edgemitmp_7b41e.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
424"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4yMTMuNyIgc2hlbGxfdmVyc2lvbj0iMS4zLjIxMy43IiBpc21hY2hpbmU9IjAiIHNlc3Npb25pZD0ie0Q0MUQ1NEE0LUJBN0MtNEQ3OC1BQzNDLThCMUI5RDc3MTQ1N30iIHVzZXJpZD0iezAwMEI5RTJBLUM3MjktNDk4Ny04NzQ5LTEwODQ2NjBDOEFBQn0iIGluc3RhbGxzb3VyY2U9Im90aGVyaW5zdGFsbGNtZCIgcmVxdWVzdGlkPSJ7MjRERjI2RUItRkU4QS00QUU4LTlGM0EtMTU4QzE3MERGQjM3fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBsb2dpY2FsX2NwdXM9IjYiIHBoeXNtZW1vcnk9IjYiIGRpc2tfdHlwZT0iMiIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iMTAuMC4xOTA0NS40MDQ2IiBzcD0iIiBhcmNoPSJ4NjQiIHByb2R1Y3RfdHlwZT0iNDgiIGlzX3dpcD0iMCIgaXNfaW5fbG9ja2Rvd25fbW9kZT0iMCIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9IkRFTEwiIHByb2R1Y3RfbmFtZT0iREVMTCIvPjxleHAgZXRhZz0iIi8-PGFwcCBhcHBpZD0ie0YzQzRGRTAwLUVGRDUtNDAzQi05NTY5LTM5OEEyMEYxQkE0QX0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4yMTMuNyIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTA3MTY4MTcwMjAiIGluc3RhbGxfdGltZV9tcz0iNTQ0Ii8-PC9hcHA-PC9yZXF1ZXN0PgC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.213.7
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\ole32.dll
c:\windows\syswow64\ucrtbase.dll
424"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{35CAFEDA-66FA-4120-92D4-2DAED771BD60}\MicrosoftEdge_X64_143.0.3650.80.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{35CAFEDA-66FA-4120-92D4-2DAED771BD60}\MicrosoftEdge_X64_143.0.3650.80.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
143.0.3650.80
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{35cafeda-66fa-4120-92d4-2daed771bd60}\microsoftedge_x64_143.0.3650.80.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shell32.dll
752"C:\Users\admin\AppData\Local\Volt\tauri-app.exe"C:\Users\admin\AppData\Local\Volt\tauri-app.exe
explorer.exe
User:
admin
Company:
volt
Integrity Level:
MEDIUM
Description:
Volt
Exit code:
0
Version:
0.1.0
Modules
Images
c:\users\admin\appdata\local\volt\tauri-app.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
888C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe /silent /installC:\Users\admin\AppData\Local\Temp\MicrosoftEdgeWebview2Setup.exe
volt.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.213.7
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
936"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=7468,i,10806504233978947691,1527993920479394577,262144 --variations-seed-version --mojo-platform-channel-handle=6892 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
936"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\143.0.3650.80\msedgewebview2.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\com.volt.editor\EBWebView" --webview-exe-name=tauri-app.exe --webview-exe-version=0.1.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --force-high-res-timeticks=disabled --gpu-preferences=SAAAAAAAAADoAAAEAAAAAAAAAAAAAGAAAQAAAAAAAAAAAAAAAAAAAEIAAAAAAAAAAAAAAAAAAAAQAAAAAAAAABAAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --skip-read-main-dll --metrics-shmem-handle=4864,i,7909430697360816779,5253537154654429891,262144 --field-trial-handle=1884,i,7004269813204218680,7568051164931292196,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --trace-process-track-uuid=3190708995682289984 --mojo-platform-channel-handle=784 /prefetch:8C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\143.0.3650.80\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
143.0.3650.80
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\143.0.3650.80\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\143.0.3650.80\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1172"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.213.7\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.213.7\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.213.7
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.213.7\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
1872"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\143.0.3650.80\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\com.volt.editor\EBWebView" --webview-exe-name=tauri-app.exe --webview-exe-version=0.1.0 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --force-high-res-timeticks=disabled --skip-read-main-dll --metrics-shmem-handle=4932,i,12587707451482042310,16033797145222248047,524288 --field-trial-handle=1884,i,7004269813204218680,7568051164931292196,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --trace-process-track-uuid=3190708996619331833 --mojo-platform-channel-handle=4928 /prefetch:8C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\143.0.3650.80\msedgewebview2.exe
msedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
143.0.3650.80
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\143.0.3650.80\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\143.0.3650.80\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
Total events
20 281
Read events
18 710
Write events
1 486
Delete events
85

Modification events

(PID) Process:(2624) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}\/SLS/{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:Expires
Value:
2025-12-19 10:54:01
(PID) Process:(2624) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}\/SLS/{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:LastModified
Value:
2001-01-01 00:00:00
(PID) Process:(2624) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}\/SLS/{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:PotentialFailover
Value:
0
(PID) Process:(2624) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}\/SLS/{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:Data
Value:
<?xml version="1.0" encoding="utf-8"?><ServiceEnvironment ServiceID="522D76A4-93E1-47F8-B8CE-07C937AD1A1E" ID="DNSResiliency-CloudFlare-Live" Revision="3"><DNSConfigData><DNSconfigs elementVersion="1"><DNSconfig hostname="slscr.update.microsoft.com" pingtest="/sls/ping" domain=".update.microsoft.com" dnsserver="162.159.36.2"></DNSconfig><DNSconfig hostname="fe3cr.delivery.mp.microsoft.com" pingtest="/clientwebservice/ping" domain=".delivery.mp.microsoft.com" dnsserver="162.159.36.2"></DNSconfig></DNSconfigs><Flags elementVersion="1"><FeatureSwitchOn>1</FeatureSwitchOn><EnforceNRPTRule>0</EnforceNRPTRule><EnforceDomain>0</EnforceDomain><SkipDefaultDNSResolver>0</SkipDefaultDNSResolver></Flags></DNSConfigData></ServiceEnvironment>
(PID) Process:(2624) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}\/SLS/{522D76A4-93E1-47F8-B8CE-07C937AD1A1E}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:ETag
Value:
"A120uxaY5n7tg8IXsZbjQtyKuLtqzjwpYPQTor+rMVg=_2880"
(PID) Process:(2624) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\dns
Operation:writeName:Data
Value:
<?xml version="1.0" encoding="utf-8"?><ServiceEnvironment ServiceID="522D76A4-93E1-47F8-B8CE-07C937AD1A1E" ID="DNSResiliency-CloudFlare-Live" Revision="3"><DNSConfigData><DNSconfigs elementVersion="1"><DNSconfig hostname="slscr.update.microsoft.com" pingtest="/sls/ping" domain=".update.microsoft.com" dnsserver="162.159.36.2"></DNSconfig><DNSconfig hostname="fe3cr.delivery.mp.microsoft.com" pingtest="/clientwebservice/ping" domain=".delivery.mp.microsoft.com" dnsserver="162.159.36.2"></DNSconfig></DNSconfigs><Flags elementVersion="1"><FeatureSwitchOn>1</FeatureSwitchOn><EnforceNRPTRule>0</EnforceNRPTRule><EnforceDomain>0</EnforceDomain><SkipDefaultDNSResolver>0</SkipDefaultDNSResolver></Flags></DNSConfigData></ServiceEnvironment>
(PID) Process:(2624) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{E7A50285-D08D-499D-9FF8-180FDC2332BC}\/SLS/{E7A50285-D08D-499D-9FF8-180FDC2332BC}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:Expires
Value:
2025-12-18 22:54:03
(PID) Process:(2624) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{E7A50285-D08D-499D-9FF8-180FDC2332BC}\/SLS/{E7A50285-D08D-499D-9FF8-180FDC2332BC}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:LastModified
Value:
2001-01-01 00:00:00
(PID) Process:(2624) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{E7A50285-D08D-499D-9FF8-180FDC2332BC}\/SLS/{E7A50285-D08D-499D-9FF8-180FDC2332BC}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:PotentialFailover
Value:
0
(PID) Process:(2624) SIHClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\sih\sls\{E7A50285-D08D-499D-9FF8-180FDC2332BC}\/SLS/{E7A50285-D08D-499D-9FF8-180FDC2332BC}/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
Operation:writeName:Data
Value:
<?xml version="1.0" encoding="UTF-8"?><ServiceEnvironment ServiceID="E7A50285-D08D-499D-9FF8-180FDC2332BC" ID="SIHProd" Revision="2"><WUClientData /><StoreClientData /><SIHClientData><Engine elementVersion="1" /><Actions elementVersion="1" /></SIHClientData></ServiceEnvironment>
Executable files
237
Suspicious files
390
Text files
101
Unknown types
1

Dropped files

PID
Process
Filename
Type
7680msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RFfde12.TMP
MD5:
SHA256:
7680msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7680msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFfde22.TMP
MD5:
SHA256:
7680msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
7680msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFfde31.TMP
MD5:
SHA256:
7680msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RFfde41.TMP
MD5:
SHA256:
7680msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
7680msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
7680msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFfde41.TMP
MD5:
SHA256:
7680msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
170
TCP/UDP connections
99
DNS requests
87
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7912
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:3tahK07FMFjDWXdBom7GLJvgPyFz8zUBgqnlOc8LEmE&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
101 b
unknown
7912
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/133.0.3065.92?clientId=4489578223053569932&agents=EdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=65&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1741678270&lafgdate=0
US
binary
768 b
malicious
7912
msedge.exe
GET
200
188.114.97.3:443
https://volt.bz/_next/static/css/081a0afca5a9bd20.css
US
text
2.07 Kb
malicious
7912
msedge.exe
GET
200
188.114.97.3:443
https://volt.bz/
US
html
18.5 Kb
malicious
7912
msedge.exe
GET
200
188.114.97.3:443
https://volt.bz/_next/static/css/0544b53a697e1f53.css
US
text
84.7 Kb
malicious
7912
msedge.exe
GET
200
188.114.97.3:443
https://volt.bz/_next/static/chunks/webpack-81e2cf33ef1c6917.js
US
binary
3.51 Kb
malicious
7912
msedge.exe
GET
200
188.114.97.3:443
https://volt.bz/_next/static/chunks/87c73c54-d993bf2ba9d94b24.js
US
binary
128 Kb
malicious
7912
msedge.exe
GET
200
188.114.97.3:443
https://volt.bz/_next/static/chunks/315-ad3ae083767a738a.js
US
binary
128 Kb
malicious
7912
msedge.exe
GET
200
188.114.97.3:443
https://volt.bz/_next/static/chunks/main-app-eabac1076ea26dac.js
US
text
506 b
malicious
7912
msedge.exe
GET
200
188.114.97.3:443
https://volt.bz/_next/static/chunks/516-dd916c7b0e634061.js
US
binary
7.18 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
508
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6300
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7912
msedge.exe
150.171.28.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7912
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7912
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7912
msedge.exe
188.114.97.3:443
volt.bz
CLOUDFLARENET
US
whitelisted
7912
msedge.exe
104.18.22.222:443
copilot.microsoft.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 142.251.141.110
whitelisted
volt.bz
  • 188.114.97.3
  • 188.114.96.3
unknown
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
  • 52.123.243.146
  • 52.123.243.147
  • 52.123.226.99
  • 52.123.243.157
  • 52.123.243.152
  • 52.123.243.148
  • 52.123.243.156
  • 52.123.243.158
whitelisted
copilot.microsoft.com
  • 104.18.22.222
  • 104.18.23.222
whitelisted
www.bing.com
  • 2.16.241.219
  • 2.16.241.218
  • 2.16.241.209
  • 2.16.241.222
  • 2.16.241.212
  • 2.16.241.200
  • 2.16.241.214
  • 2.16.241.203
  • 2.16.241.220
whitelisted
api.volt.bz
  • 188.114.97.3
  • 188.114.96.3
unknown
a.nel.cloudflare.com
  • 35.190.80.1
whitelisted
xpaywalletcdn.azureedge.net
  • 13.107.246.45
  • 13.107.213.45
whitelisted

Threats

PID
Process
Class
Message
7912
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
7912
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
7912
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare R2 Storage (r2 .cloudflarestorage .com)
7912
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare R2 Storage (r2 .cloudflarestorage .com)
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
6056
volt.exe
Misc activity
ET INFO Packed Executable Download
6096
svchost.exe
Misc activity
ET INFO Packed Executable Download
1908
msedgewebview2.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
1908
msedgewebview2.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
Process
Message
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\com.volt.editor directory exists )