File name:

MicrosoftEdgeSetup.exe

Full analysis: https://app.any.run/tasks/123e2e18-5244-4770-a7d1-ebfd7c4f1136
Verdict: Malicious activity
Analysis date: November 14, 2024, 18:26:03
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

5ACD878FCD5831747814E657703BAC4E

SHA1:

F92F97A9ADA50DD23E9F307D4F442E890B7AF811

SHA256:

89627C56CB615D8405A1881FCF0566CA2367C17716378D04944C0CFF14ED609F

SSDEEP:

49152:RT5F5Iuyzubxpj3f1qoM8TG13ly0XNdacjKVkQ1E5LRkaC6BuBAxkYIY1aHXBhyw:RFI5u9qoM8TI3THacGs+a57DJYXBhhSi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeSetup.exe (PID: 1732)
      • MicrosoftEdgeUpdateSetup.exe (PID: 6640)
      • MicrosoftEdgeUpdate.exe (PID: 6364)
    • Process drops legitimate windows executable

      • MicrosoftEdgeSetup.exe (PID: 1732)
      • MicrosoftEdgeUpdateSetup.exe (PID: 6640)
      • MicrosoftEdgeUpdate.exe (PID: 6784)
    • Executable content was dropped or overwritten

      • MicrosoftEdgeUpdateSetup.exe (PID: 6640)
      • MicrosoftEdgeSetup.exe (PID: 1732)
  • INFO

    • Create files in a temporary directory

      • MicrosoftEdgeUpdate.exe (PID: 6364)
      • MicrosoftEdgeSetup.exe (PID: 1732)
    • Checks supported languages

      • MicrosoftEdgeSetup.exe (PID: 1732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:11:04 18:40:04+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.31
CodeSize: 110592
InitializedDataSize: 1513984
UninitializedDataSize: -
EntryPoint: 0x83f0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.195.35
ProductVersionNumber: 1.3.195.35
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge Update Setup
FileVersion: 1.3.195.35
InternalName: Microsoft Edge Update Setup
LegalCopyright: Copyright Microsoft Corporation
OriginalFileName: MicrosoftEdgeUpdateSetup.exe
ProductName: Microsoft Edge Update
ProductVersion: 1.3.195.35
UpstreamVersion: 1.3.99.0
LanguageId: en
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start microsoftedgesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdatesetup.exe microsoftedgeupdate.exe wermgr.exe wermgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
1732"C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeSetup.exe" C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeSetup.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
2147747592
Version:
1.3.195.35
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5584"C:\WINDOWS\system32\wermgr.exe" "-outproc" "0" "6784" "896" "1008" "736" "0" "0" "0" "0" "0" "0" "0" "0" C:\Windows\SysWOW64\wermgr.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wermgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6364C:\Users\admin\AppData\Local\Temp\EUB251.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&lang=es&brand=M100"C:\Users\admin\AppData\Local\Temp\EUB251.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
2147747592
Version:
1.3.195.35
Modules
Images
c:\users\admin\appdata\local\temp\eub251.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6408"C:\WINDOWS\system32\wermgr.exe" "-outproc" "0" "6364" "1612" "1260" "1616" "0" "0" "0" "0" "0" "0" "0" "0" C:\Windows\SysWOW64\wermgr.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wermgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6640"C:\Users\admin\AppData\Local\Temp\EUB251.tmp\MicrosoftEdgeUpdateSetup.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&lang=es&brand=M100" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\EUB251.tmp\MicrosoftEdgeUpdateSetup.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Exit code:
2147747592
Version:
1.3.195.35
Modules
Images
c:\users\admin\appdata\local\temp\eub251.tmp\microsoftedgeupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6784"C:\Program Files (x86)\Microsoft\Temp\EUBEF3.tmp\MicrosoftEdgeUpdate.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&lang=es&brand=M100" /installelevatedC:\Program Files (x86)\Microsoft\Temp\EUBEF3.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdateSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
2147747592
Modules
Images
c:\program files (x86)\microsoft\temp\eubef3.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
Total events
6 902
Read events
6 867
Write events
33
Delete events
2

Modification events

(PID) Process:(6784) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(6784) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{24F2E78A-E129-4C1E-86E9-047EBD7C75DF}
Operation:writeName:PersistedPingString
Value:
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.195.35" shell_version="1.3.147.37" ismachine="1" sessionid="{DF75E1EA-E85B-4A47-B171-EC22B49DA146}" userid="{FD984739-A122-4DB0-BE5B-46E3E09D84E4}" installsource="taggedmi" requestid="{24F2E78A-E129-4C1E-86E9-047EBD7C75DF}" dedup="cr" domainjoined="0"><hw logical_cpus="4" physmemory="4" disk_type="2" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="10.0.19045.4046" sp="" arch="x64" product_type="48" is_wip="0" is_in_lockdown_mode="0"/><oem product_manufacturer="DELL" product_name="DELL"/><exp etag="&quot;r452t1+k2Tgq/HXzjvFNBRhopBWR9sbjXxqeUDH9uX0=&quot;"/><app appid="{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}" version="1.3.185.17" nextversion="1.3.195.35" lang="es" brand="M100" client=""><event eventtype="2" eventresult="1" errorcode="0" extracode1="0" system_uptime_ticks="5750324734" install_time_ms="391"/></app></request>
(PID) Process:(6784) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{24F2E78A-E129-4C1E-86E9-047EBD7C75DF}
Operation:writeName:PersistedPingTime
Value:
133760823724051330
(PID) Process:(6784) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\proxy
Operation:writeName:source
Value:
auto
(PID) Process:(6784) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{24F2E78A-E129-4C1E-86E9-047EBD7C75DF}
Operation:delete keyName:(default)
Value:
(PID) Process:(6784) MicrosoftEdgeUpdate.exeKey:\REGISTRY\A\{0e8e1e1c-2f99-f599-e87d-8c689f9a6f74}\Root\InventoryApplicationFile
Operation:writeName:WritePermissionsCheck
Value:
1
(PID) Process:(6784) MicrosoftEdgeUpdate.exeKey:\REGISTRY\A\{0e8e1e1c-2f99-f599-e87d-8c689f9a6f74}\Root\InventoryApplicationFile\PermissionsCheckTestKey
Operation:delete keyName:(default)
Value:
(PID) Process:(5584) wermgr.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
Operation:writeName:ClockTimeSeconds
Value:
C740366700000000
(PID) Process:(5584) wermgr.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData
Operation:writeName:TickCount
Value:
62D1080000000000
(PID) Process:(6784) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\UsageStats\Daily\Counts
Operation:writeName:setup_uac_succeeded
Value:
0300000000000000
Executable files
300
Suspicious files
4
Text files
9
Unknown types
3

Dropped files

PID
Process
Filename
Type
1732MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUB251.tmp\MicrosoftEdgeUpdate.exeexecutable
MD5:DB1ACD5625C82435C72DFE120E0FDDD7
SHA256:F8CBC120B6D4536300838FFB510B0A4DBFF19086065D0DDD015386A73BCB5A09
1732MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUB251.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:EA174FB3C3C34F477AAB3F38B754B86E
SHA256:50EEF6AB090C50774B8676B340530A34ACA40FC8C67689FD1E76FDBA508CD5B3
1732MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUB251.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:67BCF8D877953C1FDB8732942D0AF1AC
SHA256:CB390E9EF56C02F0DDEDBA962A22EBFB6C9B8F75291C0A7B3BD2A6B01C097644
1732MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUB251.tmp\EdgeUpdate.dathiv
MD5:369BBC37CFF290ADB8963DC5E518B9B8
SHA256:3D7EC761BEF1B1AF418B909F1C81CE577C769722957713FDAFBC8131B0A0C7D3
1732MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUB251.tmp\msedgeupdate.dllexecutable
MD5:396FE7495EC53D354CC4383E3590C296
SHA256:66DD98D249287E7707B8F1EE181BFB7AB1E2D1D96A5A8A4605D2CC4065A516EC
1732MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUB251.tmp\psuser_64.dllexecutable
MD5:AC593E94A7F235FB0A9F6C766714A835
SHA256:9BF8A61EA1768483A17DE3D3C7632D8F668E826D59C2896A23C331A61EBA946A
1732MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUB251.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:F4F2DE0A3710012E2EA5E64232F1C869
SHA256:B0993EBB535F4E399489FF9456CE33F929597D246A46E89B7300595FC449CD7C
1732MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUB251.tmp\psmachine_64.dllexecutable
MD5:0E4545DF4C1AB2A463C0990AC77EEF76
SHA256:E693CA793918BEEF2AC99884901139D4653C79911624019A11CABB07E35EF4CF
1732MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUB251.tmp\NOTICE.TXTtext
MD5:6DD5BF0743F2366A0BDD37E302783BCD
SHA256:91D3FC490565DED7621FF5198960E501B6DB857D5DD45AF2FE7C3ECD141145F5
1732MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUB251.tmp\psuser_arm64.dllexecutable
MD5:33D1742C9F8AE4949BA65AF8B768FF8A
SHA256:1C629D6A97C6A92871A62248AD70AAA6B909026027E8B3164D2BB94ECEFAC444
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
44
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5584
wermgr.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4376
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5584
wermgr.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6488
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4448
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4448
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.9:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
2.23.209.185:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
6784
MicrosoftEdgeUpdate.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.97
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
google.com
  • 142.250.185.206
whitelisted
www.bing.com
  • 2.23.209.185
  • 2.23.209.189
  • 2.23.209.135
  • 2.23.209.130
  • 2.23.209.182
  • 2.23.209.133
  • 2.23.209.179
  • 2.23.209.187
  • 2.23.209.140
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
login.live.com
  • 20.190.159.0
  • 40.126.31.73
  • 40.126.31.67
  • 20.190.159.64
  • 20.190.159.23
  • 20.190.159.75
  • 20.190.159.71
  • 40.126.31.71
whitelisted
th.bing.com
  • 2.23.209.189
  • 2.23.209.135
  • 2.23.209.133
  • 2.23.209.140
  • 2.23.209.130
  • 2.23.209.182
  • 2.23.209.185
  • 2.23.209.149
  • 2.23.209.187
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted

Threats

No threats detected
No debug info