MB-2b2cf3626f4d79fa2b10001f024b86677c63e2381f0923331924d26b1ee676ba
high
📛 Threat Title
Unknown: msedge.exe
Description
File type: exe. Size: 1122816 bytes. Tags: exe, lodarat, rat, upx. Reporter: TannerFilip. First seen: 2026-08-04 23:21:30.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
2b2cf3626f4d79fa2b10001f024b86677c63e2381f0923331924d26b1ee676ba
IOC database
- Type
- hash_sha256
- Value
2b2cf3626f4d79fa2b10001f024b86677c63e2381f0923331924d26b1ee676ba- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
8b78edc4466399b0a4158f018f614dcf01f255c4
IOC database
- Type
- hash_sha1
- Value
8b78edc4466399b0a4158f018f614dcf01f255c4- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
61e7b67b3ca5412726f99a469d54c545
IOC database
- Type
- hash_md5
- Value
61e7b67b3ca5412726f99a469d54c545- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_imphash
ef471c0edf1877cd5a881a6a8bf647b9
IOC database
- Type
- hash_imphash
- Value
ef471c0edf1877cd5a881a6a8bf647b9- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 1122816 bytes. Tags: exe, lodarat, rat, upx. Reporter: TannerFilip. First seen: 2026-08-04 23:21:30.
Remediations (10)
-
web:cybersecuritynews.com
A sophisticated backdoor campaign in which attackers cleverly disguised remote access malware as a legitimate Microsoft Edge service. The malicious Mesh agent, masquerading under the path C:\Program Files\Microsoft\MicrosoftEdge\msedge.exe, was found running on multiple computers and servers across the affected network.
-
web:learn.microsoft.com
Look for entries related to msedge.exe or any other system errors around the time of the crash. Reinstall Microsoft Edge: If none of the above steps work, consider uninstalling and then reinstalling Microsoft Edge. This can help resolve any corrupted files associated with the browser.
-
web:learn.microsoft.com
Learn how to troubleshoot and resolve installation, update, or roll back failures for Microsoft Edge and Edge WebView2.
-
web:malwaretips.com
Learn what msedge.exe is, its purpose, and whether you should remove it from your system. Get all the essential information in this guide.
-
web:sslinsights.com
Msedge.exe errors crashing Microsoft Edge? Learn what causes them and how to fix them fast with proven Windows 10 and 11 troubleshooting steps.
-
web:undercodetesting.com
In a recent incident response case, a cleverly hidden backdoor was discovered masquerading as a Microsoft Edge service. The malicious agent was running under the path:
-
web:windowsforum.com
Records which Edge build (s) include the upstream patch, giving administrators a clear remediation target for inventory and compliance. Avoids the common misconception that a Chrome update automatically protects Edge; Edge requires Microsoft to integrate and ship the Chromium fix on Microsoft's own schedule after testing and validation.
-
web:www.bleepingcomputer.com
Security mitigation messages re: Win32k.sys - posted in Virus, Trojan, Spyware, and Malware Removal Help: On event viewer I am getting this message: windows 11 security- mitigation PID was blocked ...
-
web:www.reddit.com
There are several files in the folder: 103..1264.71, SetupMetrics, delegatedWebFeatures.sccd, msedge (this is the one I'm suspicious of, it has the edge logo, no .exe extension, and is labeled as an application), msedge.VisualElementsManifest, msedge_proxy, and pwahelper. Reply reply More repliesMore replies drainedgamer19 •
-
web:www.sentinelone.com
CVE-2026-57986 is a use-after-free vulnerability in Microsoft Edge Chromium. Learn about its impact, affected versions, and mitigation methods.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.