File name:

MicrosoftEdgeSetup.exe

Full analysis: https://app.any.run/tasks/6e708cfc-f792-4f95-886f-93411c4fa8aa
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 24, 2022, 21:56:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

24586F227490B2F7117D221A5D77E384

SHA1:

E0699DB67007497F7959E78A878B060B99CD82F1

SHA256:

E3A0F4C20282164F9ED480BAD46290D18254DB3A6D8F810C178EF079AF0AFE44

SSDEEP:

49152:lSm3cZDbdjZtN8vVruf5ka1FtQImQQHrQhFwCg0H:lSrZZad6fX1FTXT3g0H

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeSetup.exe (PID: 2824)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
    • Loads the Task Scheduler COM API

      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
    • Loads dropped or rewritten executable

      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 524)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 1304)
      • MicrosoftEdgeUpdate.exe (PID: 2568)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
    • Application was dropped or rewritten from another process

      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 1304)
      • MicrosoftEdgeUpdate.exe (PID: 2568)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 524)
      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • setup.exe (PID: 3208)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • setup.exe (PID: 2212)
    • Actions looks like stealing of personal data

      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • msedge.exe (PID: 3976)
    • Changes the autorun value in the registry

      • setup.exe (PID: 3208)
  • SUSPICIOUS

    • Checks supported languages

      • MicrosoftEdgeSetup.exe (PID: 2824)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 1304)
      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeUpdate.exe (PID: 2568)
      • MicrosoftEdgeUpdate.exe (PID: 524)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • setup.exe (PID: 3208)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 1700)
      • msedge.exe (PID: 2600)
      • msedge.exe (PID: 1652)
      • msedge.exe (PID: 3272)
      • msedge.exe (PID: 472)
      • msedge.exe (PID: 2724)
      • msedge.exe (PID: 3016)
      • msedge.exe (PID: 3044)
      • msedge.exe (PID: 3560)
      • msedge.exe (PID: 2964)
      • msedge.exe (PID: 1284)
      • msedge.exe (PID: 3572)
      • msedge.exe (PID: 3592)
      • msedge.exe (PID: 2888)
      • msedge.exe (PID: 540)
      • msedge.exe (PID: 1368)
      • msedge.exe (PID: 1508)
      • msedge.exe (PID: 1220)
      • msedge.exe (PID: 1936)
      • msedge.exe (PID: 1592)
      • msedge.exe (PID: 2096)
      • msedge.exe (PID: 2236)
      • msedge.exe (PID: 628)
      • msedge.exe (PID: 1588)
      • msedge.exe (PID: 872)
      • msedge.exe (PID: 1544)
      • msedge.exe (PID: 3184)
      • setup.exe (PID: 2212)
      • msedge.exe (PID: 5448)
      • msedge.exe (PID: 5756)
      • msedge.exe (PID: 4348)
      • msedge.exe (PID: 4984)
      • msedge.exe (PID: 4784)
      • msedge.exe (PID: 744)
      • msedge.exe (PID: 4332)
      • msedge.exe (PID: 5136)
      • msedge.exe (PID: 4620)
      • msedge.exe (PID: 4916)
      • msedge.exe (PID: 2220)
      • msedge.exe (PID: 3396)
      • msedge.exe (PID: 5492)
      • msedge.exe (PID: 5428)
      • msedge.exe (PID: 4876)
      • msedge.exe (PID: 5856)
      • msedge.exe (PID: 5584)
      • msedge.exe (PID: 3004)
      • msedge.exe (PID: 276)
      • msedge.exe (PID: 6056)
    • Drops a file that was compiled in debug mode

      • MicrosoftEdgeSetup.exe (PID: 2824)
      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
    • Executable content was dropped or overwritten

      • MicrosoftEdgeSetup.exe (PID: 2824)
      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
    • Creates a directory in Program Files

      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
    • Reads the computer name

      • MicrosoftEdgeUpdate.exe (PID: 1304)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 2568)
      • MicrosoftEdgeUpdate.exe (PID: 524)
      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 1652)
      • msedge.exe (PID: 2600)
      • msedge.exe (PID: 540)
      • setup.exe (PID: 2212)
      • msedge.exe (PID: 2220)
      • msedge.exe (PID: 5492)
      • msedge.exe (PID: 5428)
      • msedge.exe (PID: 3004)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 492)
    • Creates files in the program directory

      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • setup.exe (PID: 3208)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 492)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 524)
      • setup.exe (PID: 3208)
    • Creates a software uninstall entry

      • MicrosoftEdgeUpdate.exe (PID: 492)
      • setup.exe (PID: 3208)
    • Application launched itself

      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 2220)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 2220)
    • Executed as Windows Service

      • MicrosoftEdgeUpdate.exe (PID: 3028)
    • Removes files from Windows directory

      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
    • Creates files in the Windows directory

      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
    • Drops a file with a compile date too recent

      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
    • Changes default file association

      • setup.exe (PID: 3208)
    • Creates files in the user directory

      • msedge.exe (PID: 3976)
    • Reads the date of Windows installation

      • msedge.exe (PID: 3976)
    • Reads Microsoft Outlook installation path

      • msedge.exe (PID: 3976)
    • Reads internet explorer settings

      • msedge.exe (PID: 3976)
  • INFO

    • Reads settings of System Certificates

      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 2220)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • msedge.exe (PID: 3976)
    • Manual execution by user

      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 2220)
    • Reads the hosts file

      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 1652)
      • msedge.exe (PID: 2220)
      • msedge.exe (PID: 5492)
    • Dropped object may contain Bitcoin addresses

      • msedge.exe (PID: 3976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

LanguageId: en
UpstreamVersion: 1.3.99.0
ProductVersion: 1.3.153.55
ProductName: Microsoft Edge Update
OriginalFileName: MicrosoftEdgeUpdateSetup.exe
LegalCopyright: Copyright Microsoft Corporation
InternalName: Microsoft Edge Update Setup
FileVersion: 1.3.153.55
FileDescription: Microsoft Edge Update Setup
CompanyName: Microsoft Corporation
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 1.3.153.55
FileVersionNumber: 1.3.153.55
Subsystem: Windows GUI
SubsystemVersion: 5.1
ImageVersion: -
OSVersion: 5.1
EntryPoint: 0x746a
UninitializedDataSize: -
InitializedDataSize: 1694720
CodeSize: 105472
LinkerVersion: 14.26
PEType: PE32
TimeStamp: 2021:11:24 01:02:57+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 24-Nov-2021 00:02:57
Detected languages:
  • Afrikaans - South Africa
  • Albanian - Albania
  • Arabic - Saudi Arabia
  • Azeri - Azerbaijan (Latin)
  • Basque - Spain
  • Bulgarian - Bulgaria
  • Catalan - Spain
  • Chinese - PRC
  • Chinese - Taiwan
  • Croatian - Croatia
  • Czech - Czech Republic
  • Danish - Denmark
  • Dutch - Netherlands
  • English - United Kingdom
  • English - United States
  • Estonian - Estonia
  • F.Y.R.O. Macedonia - F.Y.R.O. Macedonia
  • Farsi - Iran
  • Finnish - Finland
  • French - Canada
  • French - France
  • Galician - Spain
  • Georgian - Georgia
  • German - Germany
  • Greek - Greece
  • Gujarati - India
  • Hebrew - Israel
  • Hindi - India
  • Hungarian - Hungary
  • Icelandic - Iceland
  • Indonesian - Indonesia (Bahasa)
  • Italian - Italy
  • Japanese - Japan
  • Kannada - India (Kannada script)
  • Kazakh - Kazakstan
  • Konkani - India
  • Korean - Korea
  • Latvian - Latvia
  • Lithuanian - Lithuania
  • Malay - Malaysia
  • Marathi - India
  • Norwegian - Norway (Bokmal)
  • Norwegian - Norway (Nynorsk)
  • Polish - Poland
  • Portuguese - Brazil
  • Portuguese - Portugal
  • Punjabi - India (Gurmukhi script)
  • Romanian - Romania
  • Russian - Russia
  • Serbian - Serbia (Latin)
  • Slovak - Slovakia
  • Slovenian - Slovenia
  • Spanish - Mexico
  • Spanish - Spain (International sort)
  • Swedish - Sweden
  • Tamil - India
  • Tatar - Tatarstan
  • Telugu - India (Telugu script)
  • Thai - Thailand
  • Turkish - Turkey
  • Ukrainian - Ukraine
  • Urdu - Pakistan
  • Vietnamese - Viet Nam
Debug artifacts:
  • mi_exe_stub.pdb
CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge Update Setup
FileVersion: 1.3.153.55
InternalName: Microsoft Edge Update Setup
LegalCopyright: Copyright Microsoft Corporation
OriginalFilename: MicrosoftEdgeUpdateSetup.exe
ProductName: Microsoft Edge Update
ProductVersion: 1.3.153.55
UpstreamVersion: 1.3.99.0
LanguageId: en

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000118

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 24-Nov-2021 00:02:57
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00019A8F
0x00019C00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.66667
.rdata
0x0001B000
0x000086F2
0x00008800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.09144
.data
0x00024000
0x0000145C
0x00000A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.31641
.rsrc
0x00026000
0x00193328
0x00193400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.98746
.reloc
0x001BA000
0x0000147C
0x00001600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.43194

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.24273
1196
Latin 1 / Western European
UNKNOWN
RT_MANIFEST
2
4.13669
1384
Latin 1 / Western European
English - United States
RT_ICON
3
3.91985
744
Latin 1 / Western European
English - United States
RT_ICON
4
4.83772
2216
Latin 1 / Western European
English - United States
RT_ICON
5
3.68656
1640
Latin 1 / Western European
English - United States
RT_ICON
6
4.50268
3752
Latin 1 / Western European
English - United States
RT_ICON
101
2.86669
90
Latin 1 / Western European
English - United States
RT_GROUP_ICON
102
7.99988
1607019
Latin 1 / Western European
UNKNOWN
B
1223
3.7326
378
Latin 1 / Western European
UNKNOWN
RT_STRING

Imports

ADVAPI32.dll
KERNEL32.dll
SHELL32.dll
SHLWAPI.dll (delay-loaded)
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
104
Monitored processes
62
Malicious processes
15
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start microsoftedgesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdatesetup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe microsoftedge_x86_97.0.1072.69.exe setup.exe microsoftedgeupdate.exe msedge.exe msedge.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
276"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNTMuNTUiIHNoZWxsX3ZlcnNpb249IjEuMy4xNTMuNTUiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7M0FDNkZFNUUtNjU4Mi00NkEzLTkzRjMtNzQxQUQzQkIzMThBfSIgaW5zdGFsbHNvdXJjZT0idGFnZ2VkbWkiIHJlcXVlc3RpZD0iezQ3MTY5OUExLTI2NTMtNDZBNi1BMEE3LUExQTkwQkQzQTc5NH0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgbG9naWNhbF9jcHVzPSI0IiBwaHlzbWVtb3J5PSIzIiBkaXNrX3R5cGU9IjAiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjI0NTQ2IiBzcD0iU2VydmljZSBQYWNrIDEiIGFyY2g9Ing4NiIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9IkRFTEwiIHByb2R1Y3RfbmFtZT0iREVMTCIvPjxleHAgZXRhZz0iIi8-PGFwcCBhcHBpZD0ie0YzQzRGRTAwLUVGRDUtNDAzQi05NTY5LTM5OEEyMEYxQkE0QX0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4xNTMuNTUiIGxhbmc9InVrIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSI4MTIiLz48L2FwcD48L3JlcXVlc3Q-C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.153.55
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
276"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --field-trial-handle=1388,4548220571273214546,14864221897511198025,131072 --disable-gpu-compositing --lang=uk --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=3004 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
97.0.1072.69
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\97.0.1072.69\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
472"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-client-side-phishing-detection --instant-process --display-capture-permissions-policy-allowed --field-trial-handle=1340,3395796850238897415,5416449641129650494,131072 --lang=uk --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2432 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
97.0.1072.69
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\97.0.1072.69\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cryptbase.dll
492"C:\Program Files\Microsoft\Temp\EUEB6D.tmp\MicrosoftEdgeUpdate.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&lang=uk" /installelevatedC:\Program Files\Microsoft\Temp\EUEB6D.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdateSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\microsoft\temp\eueb6d.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
524"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.153.55
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
540"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --field-trial-handle=1340,3395796850238897415,5416449641129650494,131072 --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1644 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
97.0.1072.69
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\97.0.1072.69\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
628"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --field-trial-handle=1340,3395796850238897415,5416449641129650494,131072 --disable-gpu-compositing --lang=uk --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=22 --mojo-platform-channel-handle=6376 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
97.0.1072.69
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\97.0.1072.69\msedge_elf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
744"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --field-trial-handle=1340,3395796850238897415,5416449641129650494,131072 --disable-gpu-compositing --lang=uk --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=39 --mojo-platform-channel-handle=10052 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
97.0.1072.69
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\97.0.1072.69\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
872"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --field-trial-handle=1340,3395796850238897415,5416449641129650494,131072 --disable-gpu-compositing --lang=uk --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=19 --mojo-platform-channel-handle=4776 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
97.0.1072.69
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\97.0.1072.69\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1220"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-client-side-phishing-detection --display-capture-permissions-policy-allowed --field-trial-handle=1340,3395796850238897415,5416449641129650494,131072 --disable-gpu-compositing --lang=uk --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=20 --mojo-platform-channel-handle=6204 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
97.0.1072.69
Modules
Images
c:\program files\microsoft\edge\application\97.0.1072.69\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msctf.dll
Total events
46 137
Read events
42 745
Write events
3 362
Delete events
30

Modification events

(PID) Process:(492) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:path
Value:
C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(PID) Process:(492) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:UninstallCmdLine
Value:
"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall
(PID) Process:(492) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.153.55
(PID) Process:(492) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
????????? Microsoft Edge
(PID) Process:(492) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.153.55
(PID) Process:(492) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(2568) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
Operation:writeName:(default)
Value:
ServiceModule
(PID) Process:(2568) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\MicrosoftEdgeUpdate.exe
Operation:writeName:AppID
Value:
{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
(PID) Process:(2568) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
Operation:writeName:LocalService
Value:
edgeupdate
(PID) Process:(2568) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CECDDD22-2E72-4832-9606-A9B0E5E344B2}
Operation:writeName:ServiceParameters
Value:
/comsvc
Executable files
303
Suspicious files
783
Text files
230
Unknown types
91

Dropped files

PID
Process
Filename
Type
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\msedgeupdate.dllexecutable
MD5:CA84B04F5E9B4694633B8386F2AF0301
SHA256:8AFF7E70101A439DAC15391F8EBC6B657BF8E4209846D51580FA12E8E921D504
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:F352CD29284A54A3B1ED4775A322D8B5
SHA256:EBC307E4A4213DD3DF7F5AEFC283160AEB7CD481A604376333950A1D6CE64B83
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeUpdateOnDemand.exeexecutable
MD5:5AA5CCE5143CB3AA3C8EE1C2A716E8E3
SHA256:ECDFFA137AF66A4FC951D45D9AEC81F0CDBAA38FB6B914CDC3AD95A6D626B31C
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeComRegisterShellARM64.exeexecutable
MD5:6BCEA89A433041B2C6BD4E511D6BC9A7
SHA256:86D4517D87A5A8071F2F23F97852F7C6FEF17826062152ED9B85B873615CCEEE
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeUpdate.exeexecutable
MD5:8744E59DBBFD2870A30C2F4A1FCBF682
SHA256:F16F6F309C2C9C39ED62CCF84D2CD3C2C1BFBBA8721274277665535B6AD07E25
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\psmachine_64.dllexecutable
MD5:8FEEFF7C0EFAA38A81B6780E74DC8C30
SHA256:0D02F68CCB7B8882DF412A2FABC086E3D153DC8977A9D8942E86524E07D74740
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\psmachine_arm64.dllexecutable
MD5:263894F5010CC27AC3A2908A4D83E715
SHA256:AFF9FA15E729CBACA20930E7F1594BBA4D04F0298F0E4BC425499ACA6533C3F6
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\msedgeupdateres_bn.dllexecutable
MD5:D4978790923AFACF4E02C22F0CF5F9D3
SHA256:C90F7978609001570B7EDE8A0FE861C64FAE10E7E43E36092AA36213E28E2123
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:9E1984814DAC4A464F347AB013D1EACA
SHA256:4705DD0AF182B39A62ABC1DD2812044611F9691D0D949D33A66D8D5D5B252E9E
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\NOTICE.TXTtext
MD5:6DD5BF0743F2366A0BDD37E302783BCD
SHA256:91D3FC490565DED7621FF5198960E501B6DB857D5DD45AF2FE7C3ECD141145F5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
221
DNS requests
212
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
924
svchost.exe
HEAD
200
2.16.107.73:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7c0fd069-0ded-4c8f-bf7c-42264882bc36?P1=1643666234&P2=404&P3=2&P4=mzvARJwdLNal45PipxtBtqqtWUgTxEzEBPJQ74Sx%2feIbgQehHJz%2b1WXehA78006HgKlf41uD%2b9PG2zu6ptJLVQ%3d%3d
unknown
whitelisted
4020
MicrosoftEdgeUpdate.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D
US
der
471 b
whitelisted
3976
msedge.exe
GET
200
88.221.62.197:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQnuEQcScL%2FkljKed%2BRzpzFYOq9kwQUw%2FfQtSowra8NkSFwOVTdvIlwxzoCEBqzQrgKMEgb7iTLStVaX3c%3D
unknown
der
1.55 Kb
whitelisted
3976
msedge.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQN1VoiX40jVOMldh7uDThi9DqeewQU1cFnOsKjnfR3UltZEjgp5lVou6UCEzMAIvvuRE0H7U6%2FXlgAAAAi%2B%2B4%3D
US
der
1.72 Kb
whitelisted
3976
msedge.exe
GET
200
88.221.62.197:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQnuEQcScL%2FkljKed%2BRzpzFYOq9kwQUw%2FfQtSowra8NkSFwOVTdvIlwxzoCEHXW69CTLgVTY4KE9WperCg%3D
unknown
der
1.55 Kb
whitelisted
3976
msedge.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEALnkXH7gCHpP%2BLZg4NMUMA%3D
US
der
471 b
whitelisted
3976
msedge.exe
GET
200
88.221.62.197:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQnuEQcScL%2FkljKed%2BRzpzFYOq9kwQUw%2FfQtSowra8NkSFwOVTdvIlwxzoCED9oBrECNE%2F6ubtDkdfZl30%3D
unknown
der
1.55 Kb
whitelisted
3976
msedge.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
US
der
471 b
whitelisted
924
svchost.exe
GET
200
2.16.107.73:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7c0fd069-0ded-4c8f-bf7c-42264882bc36?P1=1643666234&P2=404&P3=2&P4=mzvARJwdLNal45PipxtBtqqtWUgTxEzEBPJQ74Sx%2feIbgQehHJz%2b1WXehA78006HgKlf41uD%2b9PG2zu6ptJLVQ%3d%3d
unknown
executable
100 Mb
whitelisted
3976
msedge.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRyOb3oPpcJ3XHZgxJCfx%2BuZbC%2FbAQUx7KcfxzjuFrv6WgaqF2UwSZSamgCEzMAI9XkHMozuwLLr0oAAAAj1eQ%3D
US
der
1.69 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
276
MicrosoftEdgeUpdate.exe
13.107.42.16:443
config.edge.skype.com
Microsoft Corporation
US
whitelisted
2528
MicrosoftEdgeUpdate.exe
13.107.42.16:443
config.edge.skype.com
Microsoft Corporation
US
whitelisted
2528
MicrosoftEdgeUpdate.exe
20.50.201.200:443
self.events.data.microsoft.com
US
suspicious
276
MicrosoftEdgeUpdate.exe
20.50.201.200:443
self.events.data.microsoft.com
US
suspicious
924
svchost.exe
2.16.107.73:80
msedge.f.tlu.dl.delivery.mp.microsoft.com
Akamai International B.V.
suspicious
3028
MicrosoftEdgeUpdate.exe
40.125.120.53:443
msedge.api.cdp.microsoft.com
Microsoft Corporation
US
suspicious
4020
MicrosoftEdgeUpdate.exe
13.107.42.16:443
config.edge.skype.com
Microsoft Corporation
US
whitelisted
1652
msedge.exe
131.253.33.203:443
ntp.msn.com
Microsoft Corporation
US
malicious
3976
msedge.exe
92.123.194.121:80
ctldl.windowsupdate.com
Akamai International B.V.
malicious
4020
MicrosoftEdgeUpdate.exe
92.123.194.121:80
ctldl.windowsupdate.com
Akamai International B.V.
malicious

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
malicious
self.events.data.microsoft.com
  • 20.50.201.200
  • 52.168.117.170
whitelisted
msedge.api.cdp.microsoft.com
  • 40.125.120.53
whitelisted
msedge.f.tlu.dl.delivery.mp.microsoft.com
  • 2.16.107.73
  • 2.16.107.32
whitelisted
nav.smartscreen.microsoft.com
  • 20.82.250.189
  • 20.73.130.64
  • 20.67.219.150
whitelisted
ntp.msn.com
  • 131.253.33.203
whitelisted
ctldl.windowsupdate.com
  • 92.123.194.121
  • 92.123.194.108
whitelisted
www.bing.com
  • 13.107.21.200
  • 204.79.197.200
whitelisted
arc.msn.com
  • 20.82.209.183
whitelisted
assets.msn.com
  • 2.16.186.185
  • 2.16.186.171
  • 2.16.186.186
  • 2.16.186.184
  • 2.16.186.176
  • 2.16.186.179
  • 2.16.186.170
  • 2.16.186.178
  • 2.16.186.177
whitelisted

Threats

PID
Process
Class
Message
924
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
msedge.exe
[0124/215834.222:ERROR:settings.cc(433)] Settings version is not 5