SUSPICIOUS — MicrosoftEdgeComRegisterShellARM64.exe
SUSPICIOUS — MicrosoftEdgeComRegisterShellARM64.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (43/100), attributed to the Clipbanker family. 2 of 55 detection engines flagged it.
Identification
- SHA-256:
35ec821fadfa8209de2886509ae03a1aa6fb7920add0bee5220476bfde0b0f64 - SHA-1:
2e0c0052db4b871d800b60f9fea198ae5989e86c - MD5:
c8fb64141b60230a7ef05d31d7486e2c - imphash:
fa8fe285fba3aed744468d91fe9feb19 - ssdeep:
3072:Y8czwCMkW94/RVRbKEyDAAatVnATarLdM45jj0x:EwRkWW/RVVx4c5Pb8 - TLSH:
T1A442F814041C1E63C2B6D9A96D74FE6E49E3A4FC0F78F049264756B1F0938AB4C50AF6 - Submitted as: MicrosoftEdgeComRegisterShellARM64.exe
- File type: pe · Size: 199000 bytes
- Verdict: suspicious (43/100) · Family: Clipbanker
Detections (2 of 55 engines)
- YARA: bartblaze: BB_Clipbanker
- YARA: Yara-Rules community: YR_AntiDebug_Checks
Why this verdict
The suspicious score of 43/100 is the fusion of 2 weighted signals:
- YARA: bartblaze flagged BB_Clipbanker (rule
BB_Clipbanker) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
This sample is built for arm64, which no sandbox guest in our fleet executes, so it was not detonated. The absence of runtime behaviour here is a coverage gap on our side, not a finding about the sample.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- https://www.microsoft.com
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
Embedded domains
- logging.cc
- schemas.microsoft.com
- www.microsoft.com
- crl.microsoft.com
- corp.microsoft.com
Registry keys
- HKLM\Software\Microsoft\Windows\CurrentVersion\MicrosoftEdge
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft
- HKLM\Software\Policies\Microsoft\EdgeUpdate\
- HKLM\SOFTWARE\Policies\Microsoft\Copilot
More Clipbanker samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report