s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-2b2cf3626f4d79fa2b10001f024b86677c63e2381f0923331924d26b1ee676ba high

📛 Threat Title

Unknown: msedge.exe

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 1122816 bytes. Tags: exe, lodarat, rat, upx. Reporter: TannerFilip. First seen: 2026-08-04 23:21:30.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 2b2cf3626f4d79fa2b10001f024b86677c63e2381f0923331924d26b1ee676ba

IOC database

Type
hash_sha256
Value
2b2cf3626f4d79fa2b10001f024b86677c63e2381f0923331924d26b1ee676ba
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 8b78edc4466399b0a4158f018f614dcf01f255c4

IOC database

Type
hash_sha1
Value
8b78edc4466399b0a4158f018f614dcf01f255c4
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 61e7b67b3ca5412726f99a469d54c545

IOC database

Type
hash_md5
Value
61e7b67b3ca5412726f99a469d54c545
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_imphash ef471c0edf1877cd5a881a6a8bf647b9

IOC database

Type
hash_imphash
Value
ef471c0edf1877cd5a881a6a8bf647b9
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 1122816 bytes. Tags: exe, lodarat, rat, upx. Reporter: TannerFilip. First seen: 2026-08-04 23:21:30.

Remediations (10)

  • web:cybersecuritynews.com

    A sophisticated backdoor campaign in which attackers cleverly disguised remote access malware as a legitimate Microsoft Edge service. The malicious Mesh agent, masquerading under the path C:\Program Files\Microsoft\MicrosoftEdge\msedge.exe, was found running on multiple computers and servers across the affected network.

  • web:learn.microsoft.com

    Look for entries related to msedge.exe or any other system errors around the time of the crash. Reinstall Microsoft Edge: If none of the above steps work, consider uninstalling and then reinstalling Microsoft Edge. This can help resolve any corrupted files associated with the browser.

  • web:learn.microsoft.com

    Learn how to troubleshoot and resolve installation, update, or roll back failures for Microsoft Edge and Edge WebView2.

  • web:malwaretips.com

    Learn what msedge.exe is, its purpose, and whether you should remove it from your system. Get all the essential information in this guide.

  • web:sslinsights.com

    Msedge.exe errors crashing Microsoft Edge? Learn what causes them and how to fix them fast with proven Windows 10 and 11 troubleshooting steps.

  • web:undercodetesting.com

    In a recent incident response case, a cleverly hidden backdoor was discovered masquerading as a Microsoft Edge service. The malicious agent was running under the path:

  • web:windowsforum.com

    Records which Edge build (s) include the upstream patch, giving administrators a clear remediation target for inventory and compliance. Avoids the common misconception that a Chrome update automatically protects Edge; Edge requires Microsoft to integrate and ship the Chromium fix on Microsoft's own schedule after testing and validation.

  • web:www.bleepingcomputer.com

    Security mitigation messages re: Win32k.sys - posted in Virus, Trojan, Spyware, and Malware Removal Help: On event viewer I am getting this message: windows 11 security- mitigation PID was blocked ...

  • web:www.reddit.com

    There are several files in the folder: 103..1264.71, SetupMetrics, delegatedWebFeatures.sccd, msedge (this is the one I'm suspicious of, it has the edge logo, no .exe extension, and is labeled as an application), msedge.VisualElementsManifest, msedge_proxy, and pwahelper. Reply reply More repliesMore replies drainedgamer19 •

  • web:www.sentinelone.com

    CVE-2026-57986 is a use-after-free vulnerability in Microsoft Edge Chromium. Learn about its impact, affected versions, and mitigation methods.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.