CLEAN — MicrosoftEdgeUpdateComRegisterShell64.exe
CLEAN — MicrosoftEdgeUpdateComRegisterShell64.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (25/100). 1 of 55 detection engines flagged it.
Identification
- SHA-256:
26141f72749fafe473f67bb250b1483900c19b8845e74b69ba46e6c3e443a377 - SHA-1:
99091d74dac7e92da38d37b416c334ff2c1be8cc - MD5:
d238ec07744a0e7caafa2cfc59e5a73f - imphash:
9e27fcbe18d7548b61654824a77a7a51 - ssdeep:
3072:5NTstGEbpb0pnVeLGt5kLDydCYDZxRgwoY46ZKjRBrgFTZ9UT2:bo8Ebpb8neE5kHlYJohHg6C - TLSH:
T19E43F75645090A33D6B3C8B45C74F9BE18E3F0F81EB9B5182603E6797093CB79861AB1 - Submitted as: MicrosoftEdgeUpdateComRegisterShell64.exe
- File type: pe · Size: 232792 bytes
- Verdict: clean (25/100)
Detections (1 of 55 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
Why this verdict
The clean score of 25/100 is the fusion of 1 weighted signal:
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.microsoft.com
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
Embedded domains
- logging.cc
- schemas.microsoft.com
- www.microsoft.com
- crl.microsoft.com
Registry keys
- HKLM\Software\Microsoft\Windows\CurrentVersion\MicrosoftEdge
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\
- HKLM\Software\Policies\Microsoft\EdgeUpdate\
- HKLM\SOFTWARE\Policies\Microsoft\Copilot
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report