File name:

MicrosoftEdgeSetupDev.exe

Full analysis: https://app.any.run/tasks/e6aab60e-25bb-4ddc-9835-311c59481a9d
Verdict: Malicious activity
Analysis date: January 18, 2025, 13:33:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

E6D0CFFA690424AA082D37CB6CC02E5F

SHA1:

E526F3F696A4E38C5DF1456B7DC96B7E1269C484

SHA256:

C297DD349D5DE60E2E7AE8DC6CF8DED70A97AD528331D227604516073FB5477A

SSDEEP:

49152:WTdF8NxRKYqIk0JeckN7vvWR/rO7h0JJweFFJXvzUUdHUviAjrq6HUuBcu+iWPiI:WENxRL5k0vktnryr1FxUvi0W6DBcuZWt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeSetupDev.exe (PID: 1936)
      • MicrosoftEdgeUpdate.exe (PID: 1984)
      • MicrosoftEdgeUpdateSetup.exe (PID: 2276)
      • MicrosoftEdgeUpdate.exe (PID: 2264)
    • Process drops legitimate windows executable

      • MicrosoftEdgeSetupDev.exe (PID: 1936)
      • MicrosoftEdgeUpdateSetup.exe (PID: 2276)
      • MicrosoftEdgeUpdate.exe (PID: 2264)
    • Executable content was dropped or overwritten

      • MicrosoftEdgeSetupDev.exe (PID: 1936)
      • MicrosoftEdgeUpdateSetup.exe (PID: 2276)
    • Creates a software uninstall entry

      • MicrosoftEdgeUpdate.exe (PID: 2264)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 2264)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 2264)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 2128)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 3180)
    • Reads settings of System Certificates

      • MicrosoftEdgeUpdate.exe (PID: 3180)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 3180)
    • Reads the Internet Settings

      • MicrosoftEdgeUpdate.exe (PID: 3180)
    • Executes as Windows Service

      • MicrosoftEdgeUpdate.exe (PID: 3112)
  • INFO

    • Checks supported languages

      • MicrosoftEdgeSetupDev.exe (PID: 1936)
      • MicrosoftEdgeUpdate.exe (PID: 1984)
      • MicrosoftEdgeUpdateSetup.exe (PID: 2276)
      • MicrosoftEdgeUpdate.exe (PID: 448)
      • MicrosoftEdgeUpdate.exe (PID: 2128)
      • MicrosoftEdgeUpdate.exe (PID: 2264)
      • MicrosoftEdgeUpdate.exe (PID: 3180)
      • MicrosoftEdgeUpdate.exe (PID: 3204)
      • MicrosoftEdgeUpdate.exe (PID: 3112)
      • wmpnscfg.exe (PID: 1048)
    • The sample compiled with english language support

      • MicrosoftEdgeSetupDev.exe (PID: 1936)
      • MicrosoftEdgeUpdateSetup.exe (PID: 2276)
      • MicrosoftEdgeUpdate.exe (PID: 2264)
    • Reads the computer name

      • MicrosoftEdgeUpdate.exe (PID: 1984)
      • MicrosoftEdgeUpdate.exe (PID: 2264)
      • MicrosoftEdgeUpdate.exe (PID: 448)
      • MicrosoftEdgeUpdate.exe (PID: 2128)
      • MicrosoftEdgeUpdate.exe (PID: 3204)
      • MicrosoftEdgeUpdate.exe (PID: 3180)
      • MicrosoftEdgeUpdate.exe (PID: 3112)
      • wmpnscfg.exe (PID: 1048)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 1984)
    • Create files in a temporary directory

      • MicrosoftEdgeSetupDev.exe (PID: 1936)
      • MicrosoftEdgeUpdate.exe (PID: 1984)
      • MicrosoftEdgeUpdate.exe (PID: 3180)
    • Creates files in the program directory

      • MicrosoftEdgeUpdateSetup.exe (PID: 2276)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 3180)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 3180)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 3180)
      • MicrosoftEdgeUpdate.exe (PID: 3112)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 3180)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1048)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:11:20 18:26:59+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.31
CodeSize: 110592
InitializedDataSize: 1531392
UninitializedDataSize: -
EntryPoint: 0x83f0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.195.39
ProductVersionNumber: 1.3.195.39
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge Update Setup
FileVersion: 1.3.195.39
InternalName: Microsoft Edge Update Setup
LegalCopyright: Copyright Microsoft Corporation
OriginalFileName: MicrosoftEdgeUpdateSetup.exe
ProductName: Microsoft Edge Update
ProductVersion: 1.3.195.39
UpstreamVersion: 1.3.99.0
LanguageId: en
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
10
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start microsoftedgesetupdev.exe microsoftedgeupdate.exe no specs microsoftedgeupdatesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
448"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvcC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.39
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1048"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1936"C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeSetupDev.exe" C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeSetupDev.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Version:
1.3.195.39
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgesetupdev.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1984C:\Users\admin\AppData\Local\Temp\EU8138.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}&appname=Microsoft%20Edge%20Dev&needsadmin=prefers&usagestats=0&lang=en&brand=M103"C:\Users\admin\AppData\Local\Temp\EU8138.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeSetupDev.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.195.39
Modules
Images
c:\users\admin\appdata\local\temp\eu8138.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2128"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.39
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2264"C:\Program Files\Microsoft\Temp\EU8B5A.tmp\MicrosoftEdgeUpdate.exe" /installsource taggedmi /install "appguid={0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}&appname=Microsoft%20Edge%20Dev&needsadmin=prefers&usagestats=0&lang=en&brand=M103" /installelevatedC:\Program Files\Microsoft\Temp\EU8B5A.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Version:
1.3.195.39
Modules
Images
c:\program files\microsoft\temp\eu8b5a.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2276"C:\Users\admin\AppData\Local\Temp\EU8138.tmp\MicrosoftEdgeUpdateSetup.exe" /installsource taggedmi /install "appguid={0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}&appname=Microsoft%20Edge%20Dev&needsadmin=prefers&usagestats=0&lang=en&brand=M103" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\EU8138.tmp\MicrosoftEdgeUpdateSetup.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Version:
1.3.195.39
3112"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svcC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Edge Update
Version:
1.3.195.39
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3180"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTUuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xOTUuMzkiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7RDUwRTE3NTItNEE3MC00MDRFLThDMDEtREZGOTE0QTI2QTgzfSIgdXNlcmlkPSJ7NEQ1RjZBQTEtOEYyNS00RDZBLUI1MzAtMjI1NjhFOEM0RkNCfSIgaW5zdGFsbHNvdXJjZT0idGFnZ2VkbWkiIHJlcXVlc3RpZD0iezc2NzdFQkM3LTczODUtNENFMi1CRDBGLTBGMjRDMUU3QTQ2MH0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgbG9naWNhbF9jcHVzPSI0IiBwaHlzbWVtb3J5PSIzIiBkaXNrX3R5cGU9IjAiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjI0NTQ2IiBzcD0iU2VydmljZSBQYWNrIDEiIGFyY2g9Ing4NiIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSImcXVvdDtyNDUydDErazJUZ3EvSFh6anZGTkJSaG9wQldSOXNialh4cWVVREg5dVgwPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGM0M0RkUwMC1FRkQ1LTQwM0ItOTU2OS0zOThBMjBGMUJBNEF9IiB2ZXJzaW9uPSIxLjMuMTc1LjI5IiBuZXh0dmVyc2lvbj0iMS4zLjE5NS4zOSIgbGFuZz0iZW4iIGJyYW5kPSJNMTAzIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTA4NjY3NzczNDMiIGluc3RhbGxfdGltZV9tcz0iMTIxOSIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.39
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3204"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}&appname=Microsoft%20Edge%20Dev&needsadmin=prefers&usagestats=0&lang=en&brand=M103" /installsource taggedmi /sessionid "{D50E1752-4A70-404E-8C01-DFF914A26A83}"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Version:
1.3.195.39
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
9 987
Read events
9 516
Write events
374
Delete events
97

Modification events

(PID) Process:(2264) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}
Operation:writeName:usagestats
Value:
0
(PID) Process:(2264) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}
Operation:writeName:urlstats
Value:
0
(PID) Process:(2264) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{0D50BFEC-CD6A-4F9A-964C-C7416E3ACB10}
Operation:writeName:consentcommunicated
Value:
0
(PID) Process:(2264) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(448) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
Operation:delete keyName:(default)
Value:
(PID) Process:(448) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A6B716CB-028B-404D-B72C-50E153DD68DA}
Operation:writeName:LocalService
Value:
edgeupdatem
(PID) Process:(448) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A6B716CB-028B-404D-B72C-50E153DD68DA}
Operation:writeName:ServiceParameters
Value:
/comsvc
(PID) Process:(448) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\edgeupdatem
Operation:writeName:EventMessageFile
Value:
C:\Program Files\Microsoft\EdgeUpdate\1.3.195.39\msedgeupdate.dll
(PID) Process:(448) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6B716CB-028B-404D-B72C-50E153DD68DA}\ProgID
Operation:delete keyName:(default)
Value:
(PID) Process:(448) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A6B716CB-028B-404D-B72C-50E153DD68DA}\VersionIndependentProgID
Operation:delete keyName:(default)
Value:
Executable files
303
Suspicious files
7
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
1936MicrosoftEdgeSetupDev.exeC:\Users\admin\AppData\Local\Temp\EU8138.tmp\EdgeUpdate.datbinary
MD5:369BBC37CFF290ADB8963DC5E518B9B8
SHA256:3D7EC761BEF1B1AF418B909F1C81CE577C769722957713FDAFBC8131B0A0C7D3
1936MicrosoftEdgeSetupDev.exeC:\Users\admin\AppData\Local\Temp\EU8138.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:6513BF6501B147F7A6BB78F543C4A104
SHA256:829FE05CCF8C87A8B428BAE43CAFCA9434551EE5C80718C737D22548C9E7F342
1936MicrosoftEdgeSetupDev.exeC:\Users\admin\AppData\Local\Temp\EU8138.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:D6092C49ADBE6E336129589DB40DD865
SHA256:6474D531F1B8788451F9A0D9E421DFA236279466C09D783C3E6BDADF7306B909
1936MicrosoftEdgeSetupDev.exeC:\Users\admin\AppData\Local\Temp\EU8138.tmp\MicrosoftEdgeUpdate.exeexecutable
MD5:9DA54F5A8726349124DBDCA094448A11
SHA256:F04EFEE822F9B2BAF2F9B4EA576B9908804B6990497B82C549A34BA54B1B4807
1936MicrosoftEdgeSetupDev.exeC:\Users\admin\AppData\Local\Temp\EU8138.tmp\psmachine.dllexecutable
MD5:7B2941EC175F5ABB34BE6E3F95F2E782
SHA256:32C94C3747EA83F0D880C4239911CF03796A6876C97F647EE9E798543A1889DA
1936MicrosoftEdgeSetupDev.exeC:\Users\admin\AppData\Local\Temp\EU8138.tmp\MicrosoftEdgeUpdateCore.exeexecutable
MD5:DB5CF5B7795B922A9F07561E7213BA01
SHA256:A8CE896D4E64A0246B1CFBBA3D3F39A11350C017C7DC19E5BC4DABF0109FB0EF
1936MicrosoftEdgeSetupDev.exeC:\Users\admin\AppData\Local\Temp\EU8138.tmp\NOTICE.TXTtext
MD5:6DD5BF0743F2366A0BDD37E302783BCD
SHA256:91D3FC490565DED7621FF5198960E501B6DB857D5DD45AF2FE7C3ECD141145F5
1936MicrosoftEdgeSetupDev.exeC:\Users\admin\AppData\Local\Temp\EU8138.tmp\msedgeupdate.dllexecutable
MD5:3F84AC83FA44FB5E069640648E1660E7
SHA256:17C62E9ED5BEBDCCE2AC0CB41A255C5F63F6544FB5AB148B6810617B854F6319
1936MicrosoftEdgeSetupDev.exeC:\Users\admin\AppData\Local\Temp\EU8138.tmp\psmachine_64.dllexecutable
MD5:59CD8A85A18155A5F02DD89BFE1E1B7B
SHA256:EF7A94659D525E346F0BCDB7CFE2824ED06B05418198E1E892A0FE5B9B19C894
1936MicrosoftEdgeSetupDev.exeC:\Users\admin\AppData\Local\Temp\EU8138.tmp\msedgeupdateres_bg.dllexecutable
MD5:5C4C5B2C1DFE89ADF51D753E5A83F6BD
SHA256:AC722DB8CD409584C7529B4791773B56454D91C404222C7E9BC3F8A4D4AEC448
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
10
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3180
MicrosoftEdgeUpdate.exe
GET
200
217.20.57.20:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?41bc40d0d984f203
unknown
whitelisted
3180
MicrosoftEdgeUpdate.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1108
svchost.exe
224.0.0.252:5355
whitelisted
3180
MicrosoftEdgeUpdate.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3112
MicrosoftEdgeUpdate.exe
4.245.161.190:443
msedge.api.cdp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3180
MicrosoftEdgeUpdate.exe
52.182.141.63:443
self.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
568
svchost.exe
239.255.255.250:1900
whitelisted
3180
MicrosoftEdgeUpdate.exe
217.20.57.20:80
ctldl.windowsupdate.com
US
whitelisted
3180
MicrosoftEdgeUpdate.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.212.174
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
msedge.api.cdp.microsoft.com
  • 4.245.161.190
whitelisted
self.events.data.microsoft.com
  • 52.182.141.63
whitelisted
ctldl.windowsupdate.com
  • 217.20.57.20
  • 217.20.57.18
  • 84.201.210.39
  • 217.20.57.34
  • 217.20.57.19
  • 217.20.57.36
  • 84.201.210.23
  • 217.20.57.35
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

No threats detected
No debug info