File name:

MicrosoftEdgeSetup.exe

Full analysis: https://app.any.run/tasks/93d75352-94c5-4ed3-97b3-b9b1cd15348f
Verdict: Malicious activity
Analysis date: February 03, 2026, 15:43:08
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

AB2BEC7BDD015E579A5372A549912C00

SHA1:

1DA95CB5A5211CFFE48B7B1FDE5544E327BF0F20

SHA256:

AB97E486F239A1F5698963FDB5B7EB29D80F9C75D472ABE2D1B346E385D13B67

SSDEEP:

49152:P49F8pttdVTeJMJ08+HQlfv9HNrRVJok0m/bBvdsKNSky3WFx8vyZJwEZKVnL2k0:PfPtvm8jhVHNr2m/bddtN+rOJuVixL7X

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • setup.exe (PID: 7344)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 8864)
      • MicrosoftEdgeUpdateSetup.exe (PID: 9092)
      • MicrosoftEdgeUpdate.exe (PID: 6348)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 6348)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 6348)
      • setup.exe (PID: 7344)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 8716)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8132)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8980)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2760)
      • setup.exe (PID: 7344)
    • Process drops legitimate windows executable

      • MicrosoftEdgeSetup.exe (PID: 1840)
      • MicrosoftEdgeUpdateSetup.exe (PID: 9092)
      • MicrosoftEdgeUpdate.exe (PID: 6348)
      • MicrosoftEdge_X64_144.0.3719.104.exe (PID: 7292)
      • setup.exe (PID: 7344)
    • Application launched itself

      • MicrosoftEdgeUpdate.exe (PID: 7272)
      • setup.exe (PID: 7344)
      • setup.exe (PID: 5796)
      • setup.exe (PID: 5600)
      • setup.exe (PID: 5224)
    • Executes as Windows Service

      • MicrosoftEdgeUpdate.exe (PID: 7272)
  • INFO

    • Checks supported languages

      • MicrosoftEdgeSetup.exe (PID: 1840)
      • MicrosoftEdgeUpdate.exe (PID: 8864)
      • MicrosoftEdgeUpdateSetup.exe (PID: 9092)
      • MicrosoftEdgeUpdate.exe (PID: 6828)
      • MicrosoftEdgeUpdate.exe (PID: 8716)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8132)
      • MicrosoftEdgeUpdate.exe (PID: 6348)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8980)
      • MicrosoftEdgeUpdate.exe (PID: 7868)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2760)
      • MicrosoftEdgeUpdate.exe (PID: 5536)
      • MicrosoftEdge_X64_144.0.3719.104.exe (PID: 7292)
      • MicrosoftEdgeUpdate.exe (PID: 7272)
      • setup.exe (PID: 7344)
      • setup.exe (PID: 5548)
      • MicrosoftEdgeUpdate.exe (PID: 8324)
      • setup.exe (PID: 5796)
      • setup.exe (PID: 1000)
      • setup.exe (PID: 5600)
      • setup.exe (PID: 5224)
      • setup.exe (PID: 6540)
      • setup.exe (PID: 8660)
      • MicrosoftEdgeUpdate.exe (PID: 5304)
      • identity_helper.exe (PID: 7820)
    • The sample compiled with english language support

      • MicrosoftEdgeSetup.exe (PID: 1840)
      • MicrosoftEdgeUpdateSetup.exe (PID: 9092)
      • MicrosoftEdgeUpdate.exe (PID: 6348)
      • MicrosoftEdge_X64_144.0.3719.104.exe (PID: 7292)
      • setup.exe (PID: 7344)
    • Reads the computer name

      • MicrosoftEdgeUpdate.exe (PID: 8864)
      • MicrosoftEdgeUpdate.exe (PID: 6828)
      • MicrosoftEdgeUpdate.exe (PID: 8716)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8132)
      • MicrosoftEdgeUpdate.exe (PID: 6348)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8980)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2760)
      • MicrosoftEdgeUpdate.exe (PID: 7868)
      • MicrosoftEdgeUpdate.exe (PID: 5536)
      • MicrosoftEdgeUpdate.exe (PID: 8324)
      • MicrosoftEdgeUpdate.exe (PID: 7272)
      • MicrosoftEdge_X64_144.0.3719.104.exe (PID: 7292)
      • setup.exe (PID: 7344)
      • setup.exe (PID: 5796)
      • setup.exe (PID: 5600)
      • setup.exe (PID: 5224)
      • MicrosoftEdgeUpdate.exe (PID: 5304)
      • identity_helper.exe (PID: 7820)
    • Create files in a temporary directory

      • MicrosoftEdgeSetup.exe (PID: 1840)
      • MicrosoftEdgeUpdate.exe (PID: 6348)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 8864)
      • MicrosoftEdgeUpdate.exe (PID: 6348)
      • setup.exe (PID: 5600)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 8864)
      • MicrosoftEdgeUpdate.exe (PID: 6348)
      • setup.exe (PID: 5796)
      • setup.exe (PID: 7344)
    • Creates files in the program directory

      • MicrosoftEdgeUpdateSetup.exe (PID: 9092)
      • MicrosoftEdge_X64_144.0.3719.104.exe (PID: 7292)
      • setup.exe (PID: 7344)
      • setup.exe (PID: 5796)
      • setup.exe (PID: 5224)
      • setup.exe (PID: 5600)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 7868)
      • MicrosoftEdgeUpdate.exe (PID: 5536)
      • MicrosoftEdgeUpdate.exe (PID: 5304)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 7868)
      • slui.exe (PID: 824)
    • Drops script file

      • setup.exe (PID: 7344)
      • msedge.exe (PID: 5016)
    • Launching a file from a Registry key

      • setup.exe (PID: 7344)
    • Reads Microsoft Office registry keys

      • setup.exe (PID: 7344)
    • Application launched itself

      • msedge.exe (PID: 7748)
      • msedge.exe (PID: 2336)
    • Manual execution by a user

      • msedge.exe (PID: 2336)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2026:01:20 23:46:33+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.31
CodeSize: 110592
InitializedDataSize: 1552384
UninitializedDataSize: -
EntryPoint: 0x8400
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.217.3
ProductVersionNumber: 1.3.217.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge Update Setup
FileVersion: 1.3.217.3
InternalName: Microsoft Edge Update Setup
LegalCopyright: Copyright Microsoft Corporation
OriginalFileName: MicrosoftEdgeUpdateSetup.exe
ProductName: Microsoft Edge Update
ProductVersion: 1.3.217.3
UpstreamVersion: 1.3.99.0
LanguageId: en
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
201
Monitored processes
51
Malicious processes
3
Suspicious processes
4

Behavior graph

Click at the process to see the details
start microsoftedgesetup.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdatesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe microsoftedge_x64_144.0.3719.104.exe no specs setup.exe setup.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs setup.exe no specs slui.exe microsoftedgeupdate.exe msedge.exe no specs msedge.exe msedge.exe no specs elevation_service.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs elevation_service.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
792"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=SAAAAAAAAADgAAAEAAAAAAAAAAAAAGAAAQAAAAAAAAAAAAAAAAAAAAIAAAAAAAAAAAAAAAAAAAAQAAAAAAAAABAAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --startup-read-main-dll --metrics-shmem-handle=1472,i,17764188302779023446,17863606912550609488,262144 --field-trial-handle=2520,i,3054111289072473760,4650834442277851984,262144 --variations-seed-version --trace-process-track-uuid=3190708988185955192 --mojo-platform-channel-handle=2516 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
144.0.3719.104
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\144.0.3719.104\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
824C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1000"C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{0D22FB59-9C46-476F-9CE9-3073969716CA}\EDGEMITMP_BACA0.tmp\setup.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\WINDOWS\SystemTemp\MsEdgeCrashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=144.0.7559.110 "--annotation=exe=C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{0D22FB59-9C46-476F-9CE9-3073969716CA}\EDGEMITMP_BACA0.tmp\setup.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=144.0.3719.104 --initial-client-data=0x224,0x228,0x22c,0x200,0x230,0x7ff69abe2118,0x7ff69abe2124,0x7ff69abe2130C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{0D22FB59-9C46-476F-9CE9-3073969716CA}\EDGEMITMP_BACA0.tmp\setup.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Installer
Exit code:
0
Version:
144.0.3719.104
Modules
Images
c:\program files (x86)\microsoft\edgeupdate\install\{0d22fb59-9c46-476f-9ce9-3073969716ca}\edgemitmp_baca0.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1084"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=10 --skip-read-main-dll --metrics-shmem-handle=4536,i,17780475601090375957,10004503147791343962,2097152 --field-trial-handle=2520,i,3054111289072473760,4650834442277851984,262144 --variations-seed-version --trace-process-track-uuid=3190708995682289984 --mojo-platform-channel-handle=4568 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
144.0.3719.104
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\144.0.3719.104\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1560"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=144.0.7559.110 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=144.0.3719.104 --initial-client-data=0x264,0x268,0x26c,0x260,0x274,0x7ffd6fc42c98,0x7ffd6fc42ca4,0x7ffd6fc42cb0C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
144.0.3719.104
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\144.0.3719.104\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1600"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --startup-read-main-dll --metrics-shmem-handle=2316,i,14850778438429339980,8143669761057733392,524288 --field-trial-handle=2520,i,3054111289072473760,4650834442277851984,262144 --variations-seed-version --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=2624 /prefetch:3C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
144.0.3719.104
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\144.0.3719.104\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1840"C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeSetup.exe" C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeSetup.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.217.3
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1860"C:\Program Files (x86)\Microsoft\Edge\Application\144.0.3719.104\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --skip-read-main-dll --metrics-shmem-handle=6372,i,660007843643093161,7377199694944508418,524288 --field-trial-handle=2520,i,3054111289072473760,4650834442277851984,262144 --variations-seed-version --trace-process-track-uuid=3190708999430457380 --mojo-platform-channel-handle=6380 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\144.0.3719.104\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
144.0.3719.104
Modules
Images
c:\program files (x86)\microsoft\edge\application\144.0.3719.104\identity_helper.exe
c:\windows\system32\ntdll.dll
2336"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --from-installerC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
144.0.3719.104
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\144.0.3719.104\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
2496"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --pdf-upsell-enabled --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=8 --skip-read-main-dll --metrics-shmem-handle=4344,i,4575094714753820271,13170814327490073718,2097152 --field-trial-handle=2520,i,3054111289072473760,4650834442277851984,262144 --variations-seed-version --trace-process-track-uuid=3190708993808206286 --mojo-platform-channel-handle=4352 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
144.0.3719.104
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
Total events
13 803
Read events
11 968
Write events
1 719
Delete events
116

Modification events

(PID) Process:(6348) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(8716) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9E8F1B36-249F-4FC3-9994-974AFAA07B26}\InprocServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(8716) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9E8F1B36-249F-4FC3-9994-974AFAA07B26}
Operation:delete keyName:(default)
Value:
(PID) Process:(8716) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9E8F1B36-249F-4FC3-9994-974AFAA07B26}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(8716) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{A2F5CB38-265F-4A02-9D1E-F25B664968AB}\InprocServer32
Operation:delete keyName:(default)
Value:
(PID) Process:(8716) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{A2F5CB38-265F-4A02-9D1E-F25B664968AB}
Operation:delete keyName:(default)
Value:
(PID) Process:(8716) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{A2F5CB38-265F-4A02-9D1E-F25B664968AB}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(8716) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3693B209-AE17-43E4-ADA0-22E97D760318}\InprocHandler32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(8716) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F5333F94-4CB2-4C8E-A3B0-79B5648DEC33}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(8716) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3693B209-AE17-43E4-ADA0-22E97D760318}\InprocHandler32
Operation:delete keyName:(default)
Value:
Executable files
335
Suspicious files
274
Text files
303
Unknown types
1

Dropped files

PID
Process
Filename
Type
1840MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EU511B.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:229AF2A53A7B3741BE616C1648637D47
SHA256:BC8A862A95852B7D102C99910DABE38DD053E54D7ED8C40743AEB9B6A82AC4E5
1840MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EU511B.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:0F03C139157B7EB1800B348ED6AA8EE2
SHA256:F6380AA1F4694AD5B413504E326C06EA72C2F9A2398FD30E0CE99A5F21479DD9
1840MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EU511B.tmp\psuser_64.dllexecutable
MD5:F13C21C6B21D6A68A084719B1E0482B2
SHA256:A1597AB64EC15ADB499684A22C7BD9C495BCFDC8EAAACD7AE952360EE1DF0D3B
1840MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EU511B.tmp\psmachine_arm64.dllexecutable
MD5:917C6192F341DA1A08B6BCD8063117DF
SHA256:A8C21485D5112107B6B321BD1F9A309EF4D315924E8C6308022DD675BE8FE09C
1840MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EU511B.tmp\psuser.dllexecutable
MD5:4E22B0A23523217E8583E6A4D2454C56
SHA256:F9E9F725DED923C144BB836BD96B15C9A22004B130DACADAB236534C2F3AE456
1840MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EU511B.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:36C60AC823BFF242FA1D4242D3FF6142
SHA256:3CD8B4669F1E9EB22CBA842E79CE8A35F19E278D38E2D042D66752AD8EA75317
1840MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EU511B.tmp\msedgeupdate.dllexecutable
MD5:05A084F88F628C5EAD832619EB9E5E77
SHA256:275F6BF9750EDED145E37B11DFA7C0580C88036E80C21395E8A4A77C66D51090
1840MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EU511B.tmp\psmachine_64.dllexecutable
MD5:44C4D5971CE5F0ADA5E02650022157D0
SHA256:B102A42AB18D6E029123B1B3C994E4B52EE459FDA5C88D79861820FF7D798373
1840MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EU511B.tmp\psmachine.dllexecutable
MD5:843CAB3CD6A42071AA35D685F641D0AC
SHA256:6EF9B52D37339FAD9C7933C4D70D223EA54474AC9698A068EA5D139A7281CED6
1840MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EU511B.tmp\MicrosoftEdgeUpdateOnDemand.exeexecutable
MD5:AFF93DDDA4796969CCC666B27FFEBC2E
SHA256:C0FA7B89F6A590D27AF4EE253920663CE9B10B0384DCE16AF666B0186B165F9C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
356
TCP/UDP connections
96
DNS requests
83
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4256
svchost.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
7236
SIHClient.exe
GET
304
74.179.77.204:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
7236
SIHClient.exe
GET
200
13.95.31.18:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
7236
SIHClient.exe
GET
200
74.179.77.204:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
7236
SIHClient.exe
GET
304
74.179.77.204:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5824
svchost.exe
GET
200
23.216.77.15:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5824
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
US
binary
1.05 Kb
whitelisted
5304
MicrosoftEdgeUpdate.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.217.3?clientId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&appBrandCode_stable=M100&appChannel_stable=4&appConsentState_stable=2&appDayOfInstall_stable=0&appInactivityBadgeApplied_stable=0&appInactivityBadgeCleared_stable=0&appInactivityBadgeDuration_stable=0&appInstallTimeDiffSec_stable=0&appIsPinnedSystem_stable=false&appLang_stable=de&appLastLaunchCount_stable=1&appLastLaunchTime_stable=13410608837114362&appLastLaunchTimeJson_stable=2025-12-19t09:07:17.114z&appLastLaunchTimeDaysAgo_stable=46&appVersion_stable=144.0.3719.104&appUpdateCheckIsUpdateDisabled_stable=false&appUpdatesAllowedForMeteredNetworks_stable=false&hwDiskType=2&hwHasSsse3=true&hwLogicalCpus=6&hwPhysmemory=6&isCTADevice=false&isMsftDomainJoined=false&oemProductManufacturer=DELL&oemProductName=DELL&osArch=x64&osIsDefaultNetworkConnectionMetered=false&osIsInLockdownMode=false&osIsWIP=false&osPlatform=win&osProductType=48&osVersion=10.0.19045.4046&requestCheckPeriodSec=-1&requestDomainJoined=false&requestInstallSource=taggedmi&requestIsMachine=true&requestOmahaShellVersion=1.3.217.3&requestOmahaVersion=1.3.217.3
US
text
430 b
unknown
1600
msedge.exe
GET
200
150.171.22.17:443
https://config.edge.skype.com/config/v1/Edge/144.0.3719.104?clientid=4489578223053569932&agents=EdgeFirstRun%2CEdgeFirstRunConfig&osname=win&client=edge&channel=stable&osarch=x86_64&osver=10.0.19045&devicefamily=desktop&uma=0&sessionid=66&mngd=0&installdate=1661339457&edu=0&vm=0&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0&aad=0&ad=0&cm=0
US
text
1.29 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
4256
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8068
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2.16.204.156:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7868
MicrosoftEdgeUpdate.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5536
MicrosoftEdgeUpdate.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7272
MicrosoftEdgeUpdate.exe
135.233.95.80:443
msedge.api.cdp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3140
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 20.73.194.208
whitelisted
www.bing.com
  • 2.16.204.156
  • 2.16.204.138
  • 2.16.204.158
  • 2.16.204.160
  • 2.16.204.134
  • 2.16.204.161
  • 2.16.204.141
  • 2.16.204.139
  • 2.16.204.143
  • 2.16.241.219
  • 2.16.241.205
  • 2.16.241.218
  • 2.16.241.207
  • 2.16.241.203
  • 2.16.241.222
  • 2.16.241.200
  • 2.16.241.223
  • 2.16.241.206
whitelisted
self.events.data.microsoft.com
  • 52.178.17.232
whitelisted
google.com
  • 142.251.208.174
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
msedge.api.cdp.microsoft.com
  • 135.233.95.80
whitelisted
msedge.f.tlu.dl.delivery.mp.microsoft.com
  • 23.53.40.11
  • 23.53.40.34
whitelisted
crl.microsoft.com
  • 95.101.54.128
  • 95.101.54.122
  • 23.216.77.15
  • 23.216.77.26
  • 23.216.77.29
  • 23.216.77.31
  • 23.216.77.11
  • 23.216.77.21
  • 23.216.77.8
  • 23.216.77.32
  • 23.216.77.25
  • 23.216.77.22
  • 23.216.77.42
  • 23.216.77.35
  • 23.216.77.41
  • 23.216.77.20
  • 23.216.77.37
  • 23.216.77.38
  • 23.216.77.28
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.17
  • 20.190.160.66
  • 20.190.160.4
  • 40.126.32.68
  • 40.126.32.133
  • 20.190.160.2
  • 20.190.160.64
  • 40.126.32.74
  • 40.126.31.128
  • 20.190.159.75
  • 40.126.31.73
  • 20.190.159.23
  • 20.190.159.73
  • 20.190.159.128
  • 40.126.31.130
  • 20.190.159.4
whitelisted

Threats

PID
Process
Class
Message
2788
svchost.exe
Misc activity
ET INFO Packed Executable Download
4256
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info