| File name: | MicrosoftEdgeSetup.exe |
| Full analysis: | https://app.any.run/tasks/d067df92-808f-48ce-9afb-707280830773 |
| Verdict: | Malicious activity |
| Analysis date: | January 17, 2025, 23:30:25 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | 8A1E57A4BAE81CECE2C1F9294A020D94 |
| SHA1: | 4DDED75C56FEFF2C02F32AC5F1047B8E0AA680C2 |
| SHA256: | 9DCDA0281AD5BAA5EFAAC20733B6D4B5C4A8BA93A70711A6B4C4384885E9F4E7 |
| SSDEEP: | 49152:GTOFoz6EUfZ/Oyvib0ecH8gMytm4Wo0khNsWlEF5CTOmBG2KPtjJb8wDyzHHCm/I:GhznUh/c0eq3Mytm4WoNY+AoOUGjXmit |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:12:17 19:06:15+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.31 |
| CodeSize: | 110592 |
| InitializedDataSize: | 1532416 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x83f0 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.195.43 |
| ProductVersionNumber: | 1.3.195.43 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft Edge Update Setup |
| FileVersion: | 1.3.195.43 |
| InternalName: | Microsoft Edge Update Setup |
| LegalCopyright: | Copyright Microsoft Corporation |
| OriginalFileName: | MicrosoftEdgeUpdateSetup.exe |
| ProductName: | Microsoft Edge Update |
| ProductVersion: | 1.3.195.43 |
| UpstreamVersion: | 1.3.99.0 |
| LanguageId: | en |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 5876 | "C:\WINDOWS\system32\wermgr.exe" "-outproc" "0" "6616" "1028" "720" "1068" "0" "0" "0" "0" "0" "0" "0" "0" | C:\Windows\SysWOW64\wermgr.exe | — | MicrosoftEdgeUpdate.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Problem Reporting Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6320 | "C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeSetup.exe" | C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeSetup.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Update Setup Version: 1.3.195.43 Modules
| |||||||||||||||
| 6360 | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&lang=en&brand=M100" | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\MicrosoftEdgeUpdate.exe | — | MicrosoftEdgeSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Update Version: 1.3.195.43 Modules
| |||||||||||||||
| 6516 | "C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\MicrosoftEdgeUpdateSetup.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&lang=en&brand=M100" /installelevated /nomitag | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\MicrosoftEdgeUpdateSetup.exe | MicrosoftEdgeUpdate.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Update Setup Version: 1.3.195.43 Modules
| |||||||||||||||
| 6616 | "C:\Program Files (x86)\Microsoft\Temp\EU710D.tmp\MicrosoftEdgeUpdate.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&lang=en&brand=M100" /installelevated | C:\Program Files (x86)\Microsoft\Temp\EU710D.tmp\MicrosoftEdgeUpdate.exe | MicrosoftEdgeUpdateSetup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Edge Update Version: 1.3.195.43 Modules
| |||||||||||||||
| (PID) Process: | (6616) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe |
| Operation: | write | Name: | DisableExceptionChainValidation |
Value: 0 | |||
| (PID) Process: | (6616) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{C94C30E9-86D9-4024-AAB2-4E78D26EFC39} |
| Operation: | write | Name: | PersistedPingString |
Value: <?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.195.43" shell_version="1.3.147.37" ismachine="1" sessionid="{14BC893C-35A5-471F-9EC1-86F2B48D7190}" userid="{FD984739-A122-4DB0-BE5B-46E3E09D84E4}" installsource="taggedmi" requestid="{C94C30E9-86D9-4024-AAB2-4E78D26EFC39}" dedup="cr" domainjoined="0"><hw logical_cpus="4" physmemory="4" disk_type="2" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="10.0.19045.4046" sp="" arch="x64" product_type="48" is_wip="0" is_in_lockdown_mode="0"/><oem product_manufacturer="DELL" product_name="DELL"/><exp etag=""r452t1+k2Tgq/HXzjvFNBRhopBWR9sbjXxqeUDH9uX0=""/><app appid="{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}" version="1.3.185.17" nextversion="1.3.195.43" lang="en" brand="M100" client=""><event eventtype="2" eventresult="1" errorcode="0" extracode1="0" system_uptime_ticks="12767026158" install_time_ms="656"/></app></request> | |||
| (PID) Process: | (6616) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\proxy |
| Operation: | write | Name: | source |
Value: auto | |||
| (PID) Process: | (6616) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{C94C30E9-86D9-4024-AAB2-4E78D26EFC39} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (6616) MicrosoftEdgeUpdate.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{C94C30E9-86D9-4024-AAB2-4E78D26EFC39} |
| Operation: | write | Name: | PersistedPingTime |
Value: 133816302389592944 | |||
| (PID) Process: | (6616) MicrosoftEdgeUpdate.exe | Key: | \REGISTRY\A\{a3b08049-f165-1d73-d972-3812902a43e0}\Root\InventoryApplicationFile |
| Operation: | write | Name: | WritePermissionsCheck |
Value: 1 | |||
| (PID) Process: | (6616) MicrosoftEdgeUpdate.exe | Key: | \REGISTRY\A\{a3b08049-f165-1d73-d972-3812902a43e0}\Root\InventoryApplicationFile\PermissionsCheckTestKey |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (5876) wermgr.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData |
| Operation: | write | Name: | ClockTimeSeconds |
Value: 25E88A6700000000 | |||
| (PID) Process: | (5876) wermgr.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IdentityCRL\ClockData |
| Operation: | write | Name: | TickCount |
Value: 9294130000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6320 | MicrosoftEdgeSetup.exe | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\MicrosoftEdgeUpdate.exe | executable | |
MD5:70CC35C7FB88D650902E7A5611219931 | SHA256:7ECA199201273F0BCFF1E26778CB535E69C74A69064E7759FF8DAD86954D42B1 | |||
| 6320 | MicrosoftEdgeSetup.exe | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\msedgeupdate.dll | executable | |
MD5:40CD707DD3011A9845FF9C42256EA7E3 | SHA256:9F4C7072716E0BE1BE08207A7024A5E41162E288E677D805BE8E5469A8BD4909 | |||
| 6320 | MicrosoftEdgeSetup.exe | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\MicrosoftEdgeUpdateBroker.exe | executable | |
MD5:E5DE2B67B2B629859949DB28D614FAAB | SHA256:8C86A415557DA686214675A02A94964F07C2166C811C61542776F4BF920555CA | |||
| 6320 | MicrosoftEdgeSetup.exe | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\MicrosoftEdgeComRegisterShellARM64.exe | executable | |
MD5:8F7C44E937ECC243D05EAB5BB218440B | SHA256:BC3CDD57A892CE1841787061E23E526AD46575460CD66C1DC6DCF0F811563D59 | |||
| 6320 | MicrosoftEdgeSetup.exe | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | executable | |
MD5:714C34FE6098B45A3303C611C4323EAE | SHA256:FBF495968C4A385FF0790E6B65D26610EF917A2B36A5387EFF7AE79D7A980AC5 | |||
| 6320 | MicrosoftEdgeSetup.exe | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\psmachine_arm64.dll | executable | |
MD5:EC69BFAF00836707975CC8ADB1E8F000 | SHA256:744860280846486104FFFECF012F1502F024B142FC3FCE17BCA581B7D50DAAF0 | |||
| 6320 | MicrosoftEdgeSetup.exe | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\MicrosoftEdgeUpdateCore.exe | executable | |
MD5:C8B26176E536E1BCE918AE8B1AF951A2 | SHA256:BE6AB7DD506E44A0A9EB0DD531929BD8AA0796D85A0353E6944BC6BF1630B717 | |||
| 6320 | MicrosoftEdgeSetup.exe | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\msedgeupdateres_bn.dll | executable | |
MD5:ABC20DF0545611A835DCD895D2832CCA | SHA256:75D8C2E259B4D113C0967615AF61E8F54EAFB49C498767291627FAAE9FCF504B | |||
| 6320 | MicrosoftEdgeSetup.exe | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\msedgeupdateres_am.dll | executable | |
MD5:BD175CB3DFC1D43944223BD5D7177539 | SHA256:BF0D65CEBE0C29F15A616A0DDA2F1A414E3F96FE7A28FF7876E811855BE6621B | |||
| 6320 | MicrosoftEdgeSetup.exe | C:\Users\admin\AppData\Local\Temp\EU5B81.tmp\msedgeupdateres_bg.dll | executable | |
MD5:5887CD452245DC7BD0389A0AD5DB98E0 | SHA256:922A102CAE4E74BFC0B402BBB136116EDDC71A8ADCF7F1268D48006C858D1D60 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.164.49:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 2.16.164.49:80 | crl.microsoft.com | Akamai International B.V. | NL | unknown |
— | — | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | unknown |
3220 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3976 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
6616 | MicrosoftEdgeUpdate.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
5064 | SearchApp.exe | 2.23.227.215:443 | www.bing.com | Ooredoo Q.S.C. | QA | unknown |
5064 | SearchApp.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | unknown |
1176 | svchost.exe | 40.126.31.71:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| unknown |
crl.microsoft.com |
| unknown |
www.microsoft.com |
| unknown |
settings-win.data.microsoft.com |
| unknown |
config.edge.skype.com |
| unknown |
www.bing.com |
| unknown |
ocsp.digicert.com |
| unknown |
login.live.com |
| unknown |
go.microsoft.com |
| unknown |