URL:

https://www.wacom.com/en-us/support/product-support/drivers?_gl=1*15hawf2*_ga*MTkwOTQ3MTAxNS4xNzUwMjM4MzQ2*_ga_5XHN22BY8E*czE3NTAyMzgzNDUkbzEkZzEkdDE3NTAyMzgzNTAkajU1JGwwJGgyMzQ2MDQwOTQ.

Full analysis: https://app.any.run/tasks/5179f7c8-c06d-41eb-bc59-54e8e098d1fd
Verdict: Malicious activity
Analysis date: June 19, 2025, 05:34:26
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MD5:

D66B0C18209F411559A7A09A6892BAE0

SHA1:

A7A549ABD507F30BA818DD32C870272FA00ECE6A

SHA256:

E2B6B1ABB4031E911AFB97AA64DE70CE901AB3CDFBCB6000166ABEB59A70D3EE

SSDEEP:

3:N8DSLDTQ2IK9bGRIFgBKhS/IsYEz3FdiRxn8Aq6otDXM1rgq6OX/oqUw2ihvhRiK:2OLDTQ74iRIFgBcSvpDiR6/6opXMhgKd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
      • DevInst.exe (PID: 7556)
      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 5952)
      • DevInst.exe (PID: 7368)
      • DevInst.exe (PID: 4456)
      • drvinst.exe (PID: 3688)
      • DevInst.exe (PID: 6192)
      • drvinst.exe (PID: 3624)
      • DevInst.exe (PID: 7496)
      • drvinst.exe (PID: 7936)
      • DevInst.exe (PID: 5032)
      • drvinst.exe (PID: 4080)
      • DevInst.exe (PID: 8148)
      • DevInst.exe (PID: 7720)
      • drvinst.exe (PID: 3748)
      • drvinst.exe (PID: 7680)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1480)
    • Process drops legitimate windows executable

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
      • DevInst.exe (PID: 7496)
      • drvinst.exe (PID: 7936)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1480)
      • MicrosoftEdgeUpdate.exe (PID: 5116)
    • There is functionality for taking screenshot (YARA)

      • Setup.exe (PID: 2620)
    • Reads security settings of Internet Explorer

      • Setup.exe (PID: 2620)
      • MicrosoftEdgeUpdate.exe (PID: 5116)
    • Creates a software uninstall entry

      • Setup.exe (PID: 2620)
    • The process creates files with name similar to system file names

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The process drops C-runtime libraries

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • Drops a system driver (possible attempt to evade defenses)

      • DevInst.exe (PID: 7556)
      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 5952)
      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
      • DevInst.exe (PID: 7368)
      • DevInst.exe (PID: 4456)
      • drvinst.exe (PID: 3688)
      • drvinst.exe (PID: 3624)
      • DevInst.exe (PID: 6192)
      • DevInst.exe (PID: 5032)
      • drvinst.exe (PID: 4080)
      • drvinst.exe (PID: 7680)
      • DevInst.exe (PID: 8148)
      • DevInst.exe (PID: 7720)
      • drvinst.exe (PID: 3748)
    • Uses REG/REGEDIT.EXE to modify registry

      • Setup.exe (PID: 2620)
    • Creates files in the driver directory

      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 5952)
      • drvinst.exe (PID: 3688)
      • drvinst.exe (PID: 3624)
      • drvinst.exe (PID: 1728)
      • drvinst.exe (PID: 7936)
      • drvinst.exe (PID: 4080)
      • drvinst.exe (PID: 7680)
      • drvinst.exe (PID: 3748)
    • Creates or modifies Windows services

      • Setup.exe (PID: 2620)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 5116)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 5116)
  • INFO

    • Reads Environment values

      • identity_helper.exe (PID: 7896)
      • MicrosoftEdgeUpdate.exe (PID: 5116)
    • Checks supported languages

      • identity_helper.exe (PID: 7896)
      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • WacomTablet_6.4.10-3.exe (PID: 5780)
      • Setup.exe (PID: 2620)
      • DevInst.exe (PID: 3756)
      • DevInst.exe (PID: 7344)
      • DevInst.exe (PID: 3752)
      • DevInst.exe (PID: 3488)
      • DevInst.exe (PID: 1868)
      • DevInst.exe (PID: 7556)
      • WTabletServicePro.exe (PID: 6620)
      • DevInst.exe (PID: 1808)
      • drvinst.exe (PID: 5124)
      • DevInst.exe (PID: 7368)
      • drvinst.exe (PID: 5952)
      • DevInst.exe (PID: 1472)
      • DevInst.exe (PID: 4456)
      • drvinst.exe (PID: 3688)
      • DevInst.exe (PID: 6192)
      • drvinst.exe (PID: 3624)
      • DevInst.exe (PID: 7496)
      • drvinst.exe (PID: 7936)
      • DevInst.exe (PID: 7276)
      • DevInst.exe (PID: 5032)
      • drvinst.exe (PID: 1728)
      • drvinst.exe (PID: 4080)
      • drvinst.exe (PID: 7680)
      • DevInst.exe (PID: 8148)
      • DevInst.exe (PID: 7720)
      • drvinst.exe (PID: 3748)
      • DevInst.exe (PID: 1580)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1480)
      • MicrosoftEdgeUpdate.exe (PID: 5116)
    • Reads the computer name

      • identity_helper.exe (PID: 7896)
      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
      • WTabletServicePro.exe (PID: 6620)
      • DevInst.exe (PID: 7556)
      • drvinst.exe (PID: 5124)
      • DevInst.exe (PID: 7368)
      • drvinst.exe (PID: 5952)
      • DevInst.exe (PID: 6192)
      • DevInst.exe (PID: 4456)
      • drvinst.exe (PID: 3688)
      • drvinst.exe (PID: 3624)
      • DevInst.exe (PID: 7496)
      • drvinst.exe (PID: 1728)
      • drvinst.exe (PID: 7936)
      • DevInst.exe (PID: 7276)
      • DevInst.exe (PID: 5032)
      • drvinst.exe (PID: 4080)
      • DevInst.exe (PID: 8148)
      • drvinst.exe (PID: 7680)
      • DevInst.exe (PID: 7720)
      • drvinst.exe (PID: 3748)
      • MicrosoftEdgeUpdate.exe (PID: 5116)
    • Application launched itself

      • msedge.exe (PID: 4224)
    • The sample compiled with spanish language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with Indonesian language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 4224)
    • Create files in a temporary directory

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
      • DevInst.exe (PID: 3756)
      • DevInst.exe (PID: 7368)
      • DevInst.exe (PID: 7556)
      • DevInst.exe (PID: 4456)
      • DevInst.exe (PID: 6192)
      • DevInst.exe (PID: 7496)
      • DevInst.exe (PID: 7276)
      • DevInst.exe (PID: 5032)
      • DevInst.exe (PID: 8148)
      • DevInst.exe (PID: 7720)
    • The sample compiled with english language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
      • DevInst.exe (PID: 7556)
      • drvinst.exe (PID: 5124)
      • DevInst.exe (PID: 7368)
      • drvinst.exe (PID: 5952)
      • DevInst.exe (PID: 4456)
      • drvinst.exe (PID: 3688)
      • DevInst.exe (PID: 7496)
      • drvinst.exe (PID: 7936)
      • DevInst.exe (PID: 5032)
      • drvinst.exe (PID: 4080)
      • DevInst.exe (PID: 8148)
      • drvinst.exe (PID: 3748)
      • drvinst.exe (PID: 7680)
      • DevInst.exe (PID: 7720)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1480)
      • MicrosoftEdgeUpdate.exe (PID: 5116)
    • The sample compiled with Italian language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with polish language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with korean language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with portuguese language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with russian language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • Reads the software policy settings

      • slui.exe (PID: 7756)
      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 5952)
      • drvinst.exe (PID: 3688)
      • drvinst.exe (PID: 3624)
      • drvinst.exe (PID: 7936)
      • drvinst.exe (PID: 1728)
      • drvinst.exe (PID: 4080)
      • drvinst.exe (PID: 7680)
      • drvinst.exe (PID: 3748)
      • MicrosoftEdgeUpdate.exe (PID: 5116)
    • Checks proxy server information

      • slui.exe (PID: 7756)
      • MicrosoftEdgeUpdate.exe (PID: 5116)
      • wermgr.exe (PID: 5600)
    • The sample compiled with slovak language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with swedish language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with turkish language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with chinese language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with japanese language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • Process checks computer location settings

      • Setup.exe (PID: 2620)
      • MicrosoftEdgeUpdate.exe (PID: 5116)
    • Creates files in the program directory

      • Setup.exe (PID: 2620)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1480)
    • Reads the machine GUID from the registry

      • drvinst.exe (PID: 5124)
      • drvinst.exe (PID: 5952)
      • drvinst.exe (PID: 3688)
      • drvinst.exe (PID: 3624)
      • drvinst.exe (PID: 7936)
      • drvinst.exe (PID: 1728)
      • drvinst.exe (PID: 4080)
      • drvinst.exe (PID: 7680)
      • drvinst.exe (PID: 3748)
    • The sample compiled with arabic language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with bulgarian language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with czech language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with french language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
    • The sample compiled with german language support

      • WacomTablet_6.4.10-3.exe (PID: 4808)
      • Setup.exe (PID: 2620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
225
Monitored processes
74
Malicious processes
14
Suspicious processes
1

Behavior graph

Click at the process to see the details
start msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe msedge.exe no specs wacomtablet_6.4.10-3.exe no specs wacomtablet_6.4.10-3.exe no specs wacomtablet_6.4.10-3.exe wacomtablet_6.4.10-3.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setup.exe regedit.exe no specs wtabletservicepro.exe no specs devinst.exe msedge.exe no specs devinst.exe devinst.exe devinst.exe devinst.exe devinst.exe devinst.exe drvinst.exe devinst.exe drvinst.exe devinst.exe devinst.exe drvinst.exe devinst.exe drvinst.exe devinst.exe drvinst.exe devinst.exe drvinst.exe no specs devinst.exe drvinst.exe devinst.exe drvinst.exe devinst.exe drvinst.exe devinst.exe msedge.exe no specs msedge.exe no specs microsoftedgewebview2setup.exe microsoftedgeupdate.exe wermgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
856"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=7720,i,3433298651139018355,3304879337600537045,262144 --variations-seed-version --mojo-platform-channel-handle=7936 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1204"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --extension-process --renderer-sub-type=extension --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --always-read-main-dll --field-trial-handle=4300,i,3433298651139018355,3304879337600537045,262144 --variations-seed-version --mojo-platform-channel-handle=4320 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1472"C:\Program Files\Tablet\DevInst.exe" Remove ROOT\WACOMVIRTUALROUTERC:\Program Files\Tablet\DevInst.exe
Setup.exe
User:
admin
Company:
Wacom Co. Ltd.
Integrity Level:
HIGH
Description:
DevInst helper Utility
Exit code:
0
Version:
6.4.10-3
Modules
Images
c:\program files\tablet\devinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1480"C:\Program Files\Tablet\Wacom\MicrosoftEdgeWebview2Setup.exe" /silent /installC:\Program Files\Tablet\Wacom\MicrosoftEdgeWebview2Setup.exe
Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Version:
1.3.195.19
Modules
Images
c:\program files\tablet\wacom\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1580"C:\Program Files\Tablet\DevInst.exe" Update "USB\VID_10C4&PID_EA60" "C:\Program Files\Tablet\silabser.inf"C:\Program Files\Tablet\DevInst.exe
Setup.exe
User:
admin
Company:
Wacom Co. Ltd.
Integrity Level:
HIGH
Description:
DevInst helper Utility
Exit code:
3758096907
Version:
6.4.10-3
Modules
Images
c:\program files\tablet\devinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1728DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{9aaf03ac-f287-474f-985c-e8fe5a86d5a9}\wacpaper.inf" "9" "4f9c8405f" "0000000000000200" "WinSta0\Default" "00000000000001F8" "208" "C:\Program Files\Tablet"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
1808"C:\Program Files\Tablet\DevInst.exe" Remove ROOT\WACOMVIRTUALHIDC:\Program Files\Tablet\DevInst.exe
Setup.exe
User:
admin
Company:
Wacom Co. Ltd.
Integrity Level:
HIGH
Description:
DevInst helper Utility
Exit code:
0
Version:
6.4.10-3
Modules
Images
c:\program files\tablet\devinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1868"C:\Program Files\Tablet\DevInst.exe" RemoveOEMInf wachidrouter.infC:\Program Files\Tablet\DevInst.exe
Setup.exe
User:
admin
Company:
Wacom Co. Ltd.
Integrity Level:
HIGH
Description:
DevInst helper Utility
Exit code:
0
Version:
6.4.10-3
Modules
Images
c:\program files\tablet\devinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
2028"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --always-read-main-dll --field-trial-handle=3640,i,3433298651139018355,3304879337600537045,262144 --variations-seed-version --mojo-platform-channel-handle=3660 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2368"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4336,i,3433298651139018355,3304879337600537045,262144 --variations-seed-version --mojo-platform-channel-handle=4292 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
40 694
Read events
40 298
Write events
379
Delete events
17

Modification events

(PID) Process:(4224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(4224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(4224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(4224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(4224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328462
Operation:writeName:WindowTabManagerFileMappingId
Value:
{C58754BE-88C8-49F0-A251-1938BAF211B8}
(PID) Process:(4224) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
69BD45627C962F00
(PID) Process:(4224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328462
Operation:writeName:WindowTabManagerFileMappingId
Value:
{24F3F06A-0C66-4CFD-B8C4-7250DC38FDE0}
(PID) Process:(4224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328462
Operation:writeName:WindowTabManagerFileMappingId
Value:
{1B8ED9ED-CF67-4E34-8091-A117C6716B4D}
(PID) Process:(4224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328462
Operation:writeName:WindowTabManagerFileMappingId
Value:
{A985058E-7A99-4E3F-9EEF-2F32E6F426E5}
(PID) Process:(4224) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328462
Operation:writeName:WindowTabManagerFileMappingId
Value:
{133297DD-0141-48E5-A820-32D6371F3D26}
Executable files
1 223
Suspicious files
643
Text files
2 795
Unknown types
0

Dropped files

PID
Process
Filename
Type
4224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF176978.TMP
MD5:
SHA256:
4224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
4224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF176987.TMP
MD5:
SHA256:
4224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
4224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF1769a7.TMP
MD5:
SHA256:
4224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
4224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF1769a7.TMP
MD5:
SHA256:
4224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
4224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF1769a7.TMP
MD5:
SHA256:
4224msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
30
TCP/UDP connections
160
DNS requests
152
Threats
18

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
436
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2648
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:7DDIt2ld4gAy4t9YuDSqF6Ede_er4PEdeejoK66756s&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
unknown
whitelisted
1268
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1324
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1750792216&P2=404&P3=2&P4=WjrY3729xC5gYtR9BEDNBn9GMt3MAtGSzdKa%2fERNPIYE3AzPWmHwBOk04vDxNK2Z28XGu84rFcq7OppO%2bGb9Ag%3d%3d
unknown
whitelisted
3732
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3732
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1324
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/4c4fdee0-d69c-42b7-bf5c-3ec046e9dfc9?P1=1750792219&P2=404&P3=2&P4=Zyk8nt8Ly6TiR9aONFY%2b6A9D%2fLPRLFCkCSeFSy0wcC53asd%2fydf17UB%2fal3ReGHRuroTAB55v9zuyHqHk1y0SQ%3d%3d
unknown
whitelisted
1324
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1750792216&P2=404&P3=2&P4=WjrY3729xC5gYtR9BEDNBn9GMt3MAtGSzdKa%2fERNPIYE3AzPWmHwBOk04vDxNK2Z28XGu84rFcq7OppO%2bGb9Ag%3d%3d
unknown
whitelisted
1324
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/bf8090eb-6e5c-4c51-9250-5bf9b46cf160?P1=1750792216&P2=404&P3=2&P4=WjrY3729xC5gYtR9BEDNBn9GMt3MAtGSzdKa%2fERNPIYE3AzPWmHwBOk04vDxNK2Z28XGu84rFcq7OppO%2bGb9Ag%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4380
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2648
msedge.exe
137.117.15.217:443
www.wacom.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2648
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2648
msedge.exe
150.171.28.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2648
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2648
msedge.exe
92.123.104.45:443
copilot.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.wacom.com
  • 137.117.15.217
whitelisted
copilot.microsoft.com
  • 92.123.104.45
  • 92.123.104.53
whitelisted
www.bing.com
  • 92.123.104.34
  • 92.123.104.38
  • 92.123.104.40
  • 92.123.104.47
  • 92.123.104.19
  • 92.123.104.52
  • 92.123.104.32
  • 92.123.104.28
  • 92.123.104.33
  • 2.16.241.201
  • 2.16.241.205
  • 2.16.241.218
  • 92.123.104.11
  • 92.123.104.64
whitelisted
cdn-media.wacom.com
  • 104.18.21.91
  • 104.18.20.91
whitelisted
cdnjs.cloudflare.com
  • 104.17.24.14
  • 104.17.25.14
whitelisted
vjs.zencdn.net
  • 151.101.194.217
  • 151.101.130.217
  • 151.101.2.217
  • 151.101.66.217
whitelisted
kit.fontawesome.com
  • 172.64.147.188
  • 104.18.40.68
whitelisted

Threats

PID
Process
Class
Message
2648
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2648
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2648
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2648
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
2648
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
2648
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
2648
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net)
2648
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
2648
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com)
2648
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com)
Process
Message
Setup.exe
[I] Semaphore SplitNameMap 0150525C create 5628
Setup.exe
HandleBufferedDataRead: WOW64{HKLM}\Software\WACOM\Installer, AssertsToDebugOut
Setup.exe
GetDWORD: default 1
Setup.exe
[I] Semaphore setupdebug 01505374 create 5628
Setup.exe
[I] Sending trace to file C:\Users\admin\AppData\Local\Temp\Install-pid-2620.txt
Setup.exe
HandleBufferedDataRead: lOpenRegResult: 0x2
Setup.exe
HandleBufferedDataRead: lOpenRegResult: 0x2
Setup.exe
HandleBufferedDataRead: WOW64{HKLM}\Software\WACOM\Installer, TraceFileName
Setup.exe
GetString: default
Setup.exe
Language is en