analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

MicrosoftEdgeSetup.exe

Full analysis: https://app.any.run/tasks/6e708cfc-f792-4f95-886f-93411c4fa8aa
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 24, 2022, 21:56:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

24586F227490B2F7117D221A5D77E384

SHA1:

E0699DB67007497F7959E78A878B060B99CD82F1

SHA256:

E3A0F4C20282164F9ED480BAD46290D18254DB3A6D8F810C178EF079AF0AFE44

SSDEEP:

49152:lSm3cZDbdjZtN8vVruf5ka1FtQImQQHrQhFwCg0H:lSrZZad6fX1FTXT3g0H

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeSetup.exe (PID: 2824)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
    • Loads the Task Scheduler COM API

      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
    • Loads dropped or rewritten executable

      • MicrosoftEdgeUpdate.exe (PID: 1304)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 2568)
      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 524)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
    • Application was dropped or rewritten from another process

      • MicrosoftEdgeUpdate.exe (PID: 1304)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 2568)
      • MicrosoftEdgeUpdate.exe (PID: 524)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • setup.exe (PID: 3208)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • setup.exe (PID: 2212)
    • Actions looks like stealing of personal data

      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • msedge.exe (PID: 3976)
    • Changes the autorun value in the registry

      • setup.exe (PID: 3208)
  • SUSPICIOUS

    • Reads the computer name

      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 1304)
      • MicrosoftEdgeUpdate.exe (PID: 524)
      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 2568)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 2600)
      • msedge.exe (PID: 1652)
      • msedge.exe (PID: 540)
      • setup.exe (PID: 2212)
      • msedge.exe (PID: 2220)
      • msedge.exe (PID: 5428)
      • msedge.exe (PID: 5492)
      • msedge.exe (PID: 3004)
    • Checks supported languages

      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 1304)
      • MicrosoftEdgeSetup.exe (PID: 2824)
      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeUpdate.exe (PID: 524)
      • MicrosoftEdgeUpdate.exe (PID: 2568)
      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 4040)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 1700)
      • msedge.exe (PID: 2600)
      • msedge.exe (PID: 1652)
      • msedge.exe (PID: 2724)
      • msedge.exe (PID: 3272)
      • msedge.exe (PID: 1284)
      • msedge.exe (PID: 3016)
      • msedge.exe (PID: 2888)
      • msedge.exe (PID: 3044)
      • msedge.exe (PID: 3560)
      • msedge.exe (PID: 2964)
      • msedge.exe (PID: 472)
      • msedge.exe (PID: 540)
      • msedge.exe (PID: 3592)
      • msedge.exe (PID: 3572)
      • msedge.exe (PID: 1368)
      • msedge.exe (PID: 1508)
      • msedge.exe (PID: 1220)
      • msedge.exe (PID: 628)
      • msedge.exe (PID: 1592)
      • msedge.exe (PID: 2236)
      • msedge.exe (PID: 2096)
      • msedge.exe (PID: 1588)
      • msedge.exe (PID: 1936)
      • setup.exe (PID: 2212)
      • msedge.exe (PID: 1544)
      • msedge.exe (PID: 872)
      • msedge.exe (PID: 3184)
      • msedge.exe (PID: 4348)
      • msedge.exe (PID: 4784)
      • msedge.exe (PID: 5448)
      • msedge.exe (PID: 5756)
      • msedge.exe (PID: 6056)
      • msedge.exe (PID: 4332)
      • msedge.exe (PID: 5136)
      • msedge.exe (PID: 4916)
      • msedge.exe (PID: 4620)
      • msedge.exe (PID: 4984)
      • msedge.exe (PID: 744)
      • msedge.exe (PID: 2220)
      • msedge.exe (PID: 3396)
      • msedge.exe (PID: 5428)
      • msedge.exe (PID: 5492)
      • msedge.exe (PID: 4876)
      • msedge.exe (PID: 5856)
      • msedge.exe (PID: 3004)
      • msedge.exe (PID: 5584)
      • msedge.exe (PID: 276)
    • Creates a directory in Program Files

      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
    • Creates files in the program directory

      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 492)
    • Executable content was dropped or overwritten

      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdgeSetup.exe (PID: 2824)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
    • Drops a file that was compiled in debug mode

      • MicrosoftEdgeSetup.exe (PID: 2824)
      • MicrosoftEdgeUpdateSetup.exe (PID: 2148)
      • MicrosoftEdgeUpdate.exe (PID: 492)
      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 524)
      • setup.exe (PID: 3208)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 492)
    • Creates a software uninstall entry

      • MicrosoftEdgeUpdate.exe (PID: 492)
      • setup.exe (PID: 3208)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 2220)
    • Executed as Windows Service

      • MicrosoftEdgeUpdate.exe (PID: 3028)
    • Removes files from Windows directory

      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
    • Application launched itself

      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 2220)
    • Creates files in the Windows directory

      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
    • Drops a file with a compile date too recent

      • MicrosoftEdge_X86_97.0.1072.69.exe (PID: 2740)
      • setup.exe (PID: 3208)
    • Changes default file association

      • setup.exe (PID: 3208)
    • Creates files in the user directory

      • msedge.exe (PID: 3976)
    • Reads Microsoft Outlook installation path

      • msedge.exe (PID: 3976)
    • Reads the date of Windows installation

      • msedge.exe (PID: 3976)
    • Reads internet explorer settings

      • msedge.exe (PID: 3976)
  • INFO

    • Reads settings of System Certificates

      • MicrosoftEdgeUpdate.exe (PID: 276)
      • MicrosoftEdgeUpdate.exe (PID: 2528)
      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 2220)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 3028)
      • MicrosoftEdgeUpdate.exe (PID: 4020)
      • msedge.exe (PID: 3976)
    • Manual execution by user

      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 2220)
    • Reads the hosts file

      • msedge.exe (PID: 3976)
      • msedge.exe (PID: 1652)
      • msedge.exe (PID: 2220)
      • msedge.exe (PID: 5492)
    • Dropped object may contain Bitcoin addresses

      • msedge.exe (PID: 3976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:11:24 01:02:57+01:00
PEType: PE32
LinkerVersion: 14.26
CodeSize: 105472
InitializedDataSize: 1694720
UninitializedDataSize: -
EntryPoint: 0x746a
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.153.55
ProductVersionNumber: 1.3.153.55
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge Update Setup
FileVersion: 1.3.153.55
InternalName: Microsoft Edge Update Setup
LegalCopyright: Copyright Microsoft Corporation
OriginalFileName: MicrosoftEdgeUpdateSetup.exe
ProductName: Microsoft Edge Update
ProductVersion: 1.3.153.55
UpstreamVersion: 1.3.99.0
LanguageId: en

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 24-Nov-2021 00:02:57
Detected languages:
  • Afrikaans - South Africa
  • Albanian - Albania
  • Arabic - Saudi Arabia
  • Azeri - Azerbaijan (Latin)
  • Basque - Spain
  • Bulgarian - Bulgaria
  • Catalan - Spain
  • Chinese - PRC
  • Chinese - Taiwan
  • Croatian - Croatia
  • Czech - Czech Republic
  • Danish - Denmark
  • Dutch - Netherlands
  • English - United Kingdom
  • English - United States
  • Estonian - Estonia
  • F.Y.R.O. Macedonia - F.Y.R.O. Macedonia
  • Farsi - Iran
  • Finnish - Finland
  • French - Canada
  • French - France
  • Galician - Spain
  • Georgian - Georgia
  • German - Germany
  • Greek - Greece
  • Gujarati - India
  • Hebrew - Israel
  • Hindi - India
  • Hungarian - Hungary
  • Icelandic - Iceland
  • Indonesian - Indonesia (Bahasa)
  • Italian - Italy
  • Japanese - Japan
  • Kannada - India (Kannada script)
  • Kazakh - Kazakstan
  • Konkani - India
  • Korean - Korea
  • Latvian - Latvia
  • Lithuanian - Lithuania
  • Malay - Malaysia
  • Marathi - India
  • Norwegian - Norway (Bokmal)
  • Norwegian - Norway (Nynorsk)
  • Polish - Poland
  • Portuguese - Brazil
  • Portuguese - Portugal
  • Punjabi - India (Gurmukhi script)
  • Romanian - Romania
  • Russian - Russia
  • Serbian - Serbia (Latin)
  • Slovak - Slovakia
  • Slovenian - Slovenia
  • Spanish - Mexico
  • Spanish - Spain (International sort)
  • Swedish - Sweden
  • Tamil - India
  • Tatar - Tatarstan
  • Telugu - India (Telugu script)
  • Thai - Thailand
  • Turkish - Turkey
  • Ukrainian - Ukraine
  • Urdu - Pakistan
  • Vietnamese - Viet Nam
Debug artifacts:
  • mi_exe_stub.pdb
CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge Update Setup
FileVersion: 1.3.153.55
InternalName: Microsoft Edge Update Setup
LegalCopyright: Copyright Microsoft Corporation
OriginalFilename: MicrosoftEdgeUpdateSetup.exe
ProductName: Microsoft Edge Update
ProductVersion: 1.3.153.55
UpstreamVersion: 1.3.99.0
LanguageId: en

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000118

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 24-Nov-2021 00:02:57
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00019A8F
0x00019C00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.66667
.rdata
0x0001B000
0x000086F2
0x00008800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.09144
.data
0x00024000
0x0000145C
0x00000A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.31641
.rsrc
0x00026000
0x00193328
0x00193400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.98746
.reloc
0x001BA000
0x0000147C
0x00001600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.43194

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.24273
1196
Latin 1 / Western European
UNKNOWN
RT_MANIFEST
2
4.13669
1384
Latin 1 / Western European
English - United States
RT_ICON
3
3.91985
744
Latin 1 / Western European
English - United States
RT_ICON
4
4.83772
2216
Latin 1 / Western European
English - United States
RT_ICON
5
3.68656
1640
Latin 1 / Western European
English - United States
RT_ICON
6
4.50268
3752
Latin 1 / Western European
English - United States
RT_ICON
101
2.86669
90
Latin 1 / Western European
English - United States
RT_GROUP_ICON
102
7.99988
1607019
Latin 1 / Western European
UNKNOWN
B
1223
3.7326
378
Latin 1 / Western European
UNKNOWN
RT_STRING

Imports

ADVAPI32.dll
KERNEL32.dll
SHELL32.dll
SHLWAPI.dll (delay-loaded)
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
104
Monitored processes
62
Malicious processes
15
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start microsoftedgesetup.exe microsoftedgeupdate.exe no specs microsoftedgeupdatesetup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe microsoftedge_x86_97.0.1072.69.exe setup.exe microsoftedgeupdate.exe msedge.exe msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs setup.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2824"C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeSetup.exe" C:\Users\admin\AppData\Local\Temp\MicrosoftEdgeSetup.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.153.55
Modules
Images
c:\users\admin\appdata\local\temp\microsoftedgesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\lpk.dll
1304C:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeUpdate.exe /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&lang=uk"C:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeUpdate.exeMicrosoftEdgeSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.153.55
Modules
Images
c:\users\admin\appdata\local\temp\eue7b4.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2148"C:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeUpdateSetup.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&lang=uk" /installelevated /nomitagC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeUpdateSetup.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.153.55
Modules
Images
c:\users\admin\appdata\local\temp\eue7b4.tmp\microsoftedgeupdatesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
492"C:\Program Files\Microsoft\Temp\EUEB6D.tmp\MicrosoftEdgeUpdate.exe" /installsource taggedmi /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&lang=uk" /installelevatedC:\Program Files\Microsoft\Temp\EUEB6D.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdateSetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\microsoft\temp\eueb6d.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2568"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvcC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.153.55
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
524"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.153.55
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
276"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNTMuNTUiIHNoZWxsX3ZlcnNpb249IjEuMy4xNTMuNTUiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7M0FDNkZFNUUtNjU4Mi00NkEzLTkzRjMtNzQxQUQzQkIzMThBfSIgaW5zdGFsbHNvdXJjZT0idGFnZ2VkbWkiIHJlcXVlc3RpZD0iezQ3MTY5OUExLTI2NTMtNDZBNi1BMEE3LUExQTkwQkQzQTc5NH0iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgbG9naWNhbF9jcHVzPSI0IiBwaHlzbWVtb3J5PSIzIiBkaXNrX3R5cGU9IjAiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjI0NTQ2IiBzcD0iU2VydmljZSBQYWNrIDEiIGFyY2g9Ing4NiIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9IkRFTEwiIHByb2R1Y3RfbmFtZT0iREVMTCIvPjxleHAgZXRhZz0iIi8-PGFwcCBhcHBpZD0ie0YzQzRGRTAwLUVGRDUtNDAzQi05NTY5LTM5OEEyMEYxQkE0QX0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEuMy4xNTMuNTUiIGxhbmc9InVrIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgaW5zdGFsbF90aW1lX21zPSI4MTIiLz48L2FwcD48L3JlcXVlc3Q-C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.153.55
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
4040"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft%20Edge&needsadmin=prefers&lang=uk" /installsource taggedmi /sessionid "{3AC6FE5E-6582-46A3-93F3-741AD3BB318A}"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.153.55
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
3028"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svcC:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.153.55
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2528"C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNTMuNTUiIHNoZWxsX3ZlcnNpb249IjEuMy4xNTMuNTUiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7M0FDNkZFNUUtNjU4Mi00NkEzLTkzRjMtNzQxQUQzQkIzMThBfSIgaW5zdGFsbHNvdXJjZT0idGFnZ2VkbWkiIHJlcXVlc3RpZD0iezNFQTQzMzlCLTA2OEMtNDFDNy05RTJCLTlCMkZBQUYxMDI5N30iIGRlZHVwPSJjciIgZG9tYWluam9pbmVkPSIwIj48aHcgbG9naWNhbF9jcHVzPSI0IiBwaHlzbWVtb3J5PSIzIiBkaXNrX3R5cGU9IjAiIHNzZT0iMSIgc3NlMj0iMSIgc3NlMz0iMSIgc3NzZTM9IjEiIHNzZTQxPSIxIiBzc2U0Mj0iMSIgYXZ4PSIxIi8-PG9zIHBsYXRmb3JtPSJ3aW4iIHZlcnNpb249IjYuMS43NjAxLjI0NTQ2IiBzcD0iU2VydmljZSBQYWNrIDEiIGFyY2g9Ing4NiIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9IkRFTEwiIHByb2R1Y3RfbmFtZT0iREVMTCIvPjxleHAgZXRhZz0iIi8-PGFwcCBhcHBpZD0iezhBNjlEMzQ1LUQ1NjQtNDYzYy1BRkYxLUE2OUQ5RTUzMEY5Nn0iIHZlcnNpb249Ijg2LjAuNDI0MC4xOTgiIG5leHR2ZXJzaW9uPSI4Ni4wLjQyNDAuMTk4IiBsYW5nPSJlbiIgYnJhbmQ9IkdDRUEiIGNsaWVudD0iIiBpbnN0YWxsYWdlPSIxMjQ1IiBpbnN0YWxsZGF0ZT0iNDI1NiIgaW5zdGFsbGRhdGV0aW1lPSIxNTM1NDU0NjM4Ij48ZXZlbnQgZXZlbnR0eXBlPSIzMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMyIvPjwvYXBwPjwvcmVxdWVzdD4C:\Program Files\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.153.55
Modules
Images
c:\program files\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
46 137
Read events
42 745
Write events
0
Delete events
0

Modification events

No data
Executable files
303
Suspicious files
783
Text files
230
Unknown types
91

Dropped files

PID
Process
Filename
Type
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeUpdateBroker.exeexecutable
MD5:F352CD29284A54A3B1ED4775A322D8B5
SHA256:EBC307E4A4213DD3DF7F5AEFC283160AEB7CD481A604376333950A1D6CE64B83
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\msedgeupdateres_bn.dllexecutable
MD5:D4978790923AFACF4E02C22F0CF5F9D3
SHA256:C90F7978609001570B7EDE8A0FE861C64FAE10E7E43E36092AA36213E28E2123
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\psuser_64.dllexecutable
MD5:7DFD881D1B14E6F1756AB63AEA4838EC
SHA256:4C2A48BF220F06B1B1286071D9E0B1B2E622D4CDE0563D641D753A4C73337061
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeexecutable
MD5:9E1984814DAC4A464F347AB013D1EACA
SHA256:4705DD0AF182B39A62ABC1DD2812044611F9691D0D949D33A66D8D5D5B252E9E
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\psmachine_64.dllexecutable
MD5:8FEEFF7C0EFAA38A81B6780E74DC8C30
SHA256:0D02F68CCB7B8882DF412A2FABC086E3D153DC8977A9D8942E86524E07D74740
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\msedgeupdateres_bg.dllexecutable
MD5:203057DE88067CD87AB45DEF5FA63640
SHA256:EC004651F5A5FC793A170DB4F32902F70ACD348A8032AA12BEFBA3BC58D16264
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\psuser_arm64.dllexecutable
MD5:9DF19D652048EBC995DBC7F0160CAD8D
SHA256:2DBA11BE045E569E4CCB7336E10FE99531348BF8B25535B4141E6143467ECE92
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\psmachine.dllexecutable
MD5:1224CA427925BDB0736342669ED1ABB8
SHA256:FC4AB90171879A356092933FE4918311918CDC620A2FD0E31B68591CBDD9B3D6
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\psmachine_arm64.dllexecutable
MD5:263894F5010CC27AC3A2908A4D83E715
SHA256:AFF9FA15E729CBACA20930E7F1594BBA4D04F0298F0E4BC425499ACA6533C3F6
2824MicrosoftEdgeSetup.exeC:\Users\admin\AppData\Local\Temp\EUE7B4.tmp\MicrosoftEdgeUpdateCore.exeexecutable
MD5:0E6873CBC239632B3747164BB9F4582D
SHA256:6A86F78FC801BB3662380652EB1208EC032A736D1129A4187FF0B227BD0AA7C6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
221
DNS requests
212
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
924
svchost.exe
HEAD
200
2.16.107.73:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7c0fd069-0ded-4c8f-bf7c-42264882bc36?P1=1643666234&P2=404&P3=2&P4=mzvARJwdLNal45PipxtBtqqtWUgTxEzEBPJQ74Sx%2feIbgQehHJz%2b1WXehA78006HgKlf41uD%2b9PG2zu6ptJLVQ%3d%3d
unknown
whitelisted
3976
msedge.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQN1VoiX40jVOMldh7uDThi9DqeewQU1cFnOsKjnfR3UltZEjgp5lVou6UCEzMAIvvuRE0H7U6%2FXlgAAAAi%2B%2B4%3D
US
der
1.72 Kb
whitelisted
3976
msedge.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRyOb3oPpcJ3XHZgxJCfx%2BuZbC%2FbAQUx7KcfxzjuFrv6WgaqF2UwSZSamgCEzMAI9XkHMozuwLLr0oAAAAj1eQ%3D
US
der
1.69 Kb
whitelisted
3976
msedge.exe
GET
200
88.221.62.197:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQnuEQcScL%2FkljKed%2BRzpzFYOq9kwQUw%2FfQtSowra8NkSFwOVTdvIlwxzoCEBqzQrgKMEgb7iTLStVaX3c%3D
unknown
der
1.55 Kb
whitelisted
3976
msedge.exe
GET
200
88.221.62.197:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQnuEQcScL%2FkljKed%2BRzpzFYOq9kwQUw%2FfQtSowra8NkSFwOVTdvIlwxzoCEA%2FQdmqNdih7FJzMMqTLTtg%3D
unknown
der
1.55 Kb
whitelisted
3976
msedge.exe
GET
200
88.221.62.197:80
http://ocsp.entrust.net/MEUwQzBBMD8wPTAJBgUrDgMCGgUABBQsSqZpWQuWOxHU9pAda%2B7Lf6V20AQUaJDkZ6SmU4DHhmak8fdLQ%2FuEvW0CBFHTQEQ%3D
unknown
der
1.53 Kb
whitelisted
924
svchost.exe
GET
200
2.16.107.73:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/7c0fd069-0ded-4c8f-bf7c-42264882bc36?P1=1643666234&P2=404&P3=2&P4=mzvARJwdLNal45PipxtBtqqtWUgTxEzEBPJQ74Sx%2feIbgQehHJz%2b1WXehA78006HgKlf41uD%2b9PG2zu6ptJLVQ%3d%3d
unknown
executable
100 Mb
whitelisted
3976
msedge.exe
GET
200
88.221.62.197:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQnuEQcScL%2FkljKed%2BRzpzFYOq9kwQUw%2FfQtSowra8NkSFwOVTdvIlwxzoCED9oBrECNE%2F6ubtDkdfZl30%3D
unknown
der
1.55 Kb
whitelisted
3976
msedge.exe
GET
200
88.221.62.197:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQnuEQcScL%2FkljKed%2BRzpzFYOq9kwQUw%2FfQtSowra8NkSFwOVTdvIlwxzoCEHXW69CTLgVTY4KE9WperCg%3D
unknown
der
1.55 Kb
whitelisted
3976
msedge.exe
GET
200
88.221.62.197:80
http://ocsp.entrust.net/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQnuEQcScL%2FkljKed%2BRzpzFYOq9kwQUw%2FfQtSowra8NkSFwOVTdvIlwxzoCEGwbq%2BVSTTxnMMagAJ4LQng%3D
unknown
der
1.55 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
276
MicrosoftEdgeUpdate.exe
13.107.42.16:443
config.edge.skype.com
Microsoft Corporation
US
whitelisted
1652
msedge.exe
131.253.33.203:443
ntp.msn.com
Microsoft Corporation
US
whitelisted
4020
MicrosoftEdgeUpdate.exe
52.168.117.170:443
self.events.data.microsoft.com
Microsoft Corporation
US
suspicious
1652
msedge.exe
2.16.186.185:443
assets.msn.com
Akamai International B.V.
whitelisted
1652
msedge.exe
13.107.21.200:443
www.bing.com
Microsoft Corporation
US
whitelisted
3976
msedge.exe
92.123.194.121:80
ctldl.windowsupdate.com
Akamai International B.V.
malicious
4020
MicrosoftEdgeUpdate.exe
92.123.194.121:80
ctldl.windowsupdate.com
Akamai International B.V.
malicious
1652
msedge.exe
13.107.42.16:443
config.edge.skype.com
Microsoft Corporation
US
whitelisted
3976
msedge.exe
20.82.250.189:443
nav.smartscreen.microsoft.com
US
whitelisted
4020
MicrosoftEdgeUpdate.exe
13.107.42.16:443
config.edge.skype.com
Microsoft Corporation
US
whitelisted

DNS requests

Domain
IP
Reputation
config.edge.skype.com
  • 13.107.42.16
whitelisted
self.events.data.microsoft.com
  • 20.50.201.200
  • 52.168.117.170
whitelisted
msedge.api.cdp.microsoft.com
  • 40.125.120.53
whitelisted
msedge.f.tlu.dl.delivery.mp.microsoft.com
  • 2.16.107.73
  • 2.16.107.32
whitelisted
nav.smartscreen.microsoft.com
  • 20.82.250.189
  • 20.73.130.64
  • 20.67.219.150
whitelisted
ntp.msn.com
  • 131.253.33.203
whitelisted
ctldl.windowsupdate.com
  • 92.123.194.121
  • 92.123.194.108
whitelisted
www.bing.com
  • 13.107.21.200
  • 204.79.197.200
whitelisted
arc.msn.com
  • 20.82.209.183
whitelisted
assets.msn.com
  • 2.16.186.185
  • 2.16.186.171
  • 2.16.186.186
  • 2.16.186.184
  • 2.16.186.176
  • 2.16.186.179
  • 2.16.186.170
  • 2.16.186.178
  • 2.16.186.177
whitelisted

Threats

PID
Process
Class
Message
924
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
msedge.exe
[0124/215834.222:ERROR:settings.cc(433)] Settings version is not 5