msedgewebview2.exe file report

MD5 17b527521f722cb0bfde9f3b485ab133
Latest seen 2023-07-30 23:20:07 (2 years ago)
First seen 2023-07-30 23:08:52 (2 years ago)
Size 3 MB

Why it matters

Evidence available for this file

Detection

Latest status is clean for this hash.

Timeline

First seen 2023-07-30 23:08:52 (2 years ago); latest analysis 2023-07-30 23:20:07 (2 years ago).

Publisher context

Company metadata: Microsoft Corporation. Product metadata: Microsoft Edge WebView2.

Digital signature

Signed by Microsoft Corporation. ThreatInfo marks this publisher as trusted for this record.

Recommended action

What to do next

  1. Confirm the hash and publisher match the expected software.
  2. Review the observed locations and signature information below.
  3. Rescan if the file was downloaded from an unknown source or appears in an unusual path.

msedgewebview2.exe is a Windows file recorded in the ThreatInfo database. It is associated with Microsoft Edge WebView2. The reported company name is Microsoft Corporation. The current detection status is Clean, based on the latest analysis from 2023-07-30 23:20:07 (2 years ago).

This record is currently marked as clean, but file reputation can depend on the exact path, hash, and source. Compare the MD5 and publisher data below with the file on your system.

Product Name: Microsoft Edge WebView2
Company Name: Microsoft Corporation
MD5: 17b527521f722cb0bfde9f3b485ab133
Size: 3 MB
First Published: 2023-07-30 23:08:52 (2 years ago)
Latest Published: 2023-07-30 23:20:07 (2 years ago)
Status: Clean (on last analysis)
Analysis Date: 2023-07-30 23:20:07 (2 years ago)
Signed By: Microsoft Corporation
Status: Trusted Publisher

ThreatInfo marks this publisher as trusted for this record, but the file hash and source should still match the expected software distribution.

100.0%

The strongest geographic signal for this file is Russia with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for msedgewebview2.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

msedgewebview2.exe is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x0013da40

PE Sections:

Name Size of data MD5
.text 2842112 ddd6a29a8c32879c4e43de6a9a72a0b2
.rdata 457728 99bb8c95074da94288dc3ed2af761db6
.data 69120 f3b7c2dad2d3cfb0a6226aa834ac157d
.pdata 87552 9b82ca1075f4dc760c3c759ea27f782e
.00cfg 512 e1821d9600f0cf812745da6a62f3f591
.gxfg 13312 ba333cc9aef30340e6ee7066ec52cc8d
.retplne 512 7db70a26a62dfe8a2350c6a58ee2c42f
.tls 1024 ab167f3847844a83d147ff7d8e3111ba
CPADinfo 512 60d3ea61d541c9be2e845d2787fb9574
LZMADEC 4608 05e9eab8428a551a281ab278073669fa
_RDATA 512 367c61287ecc7bf3af13f8f5538e329a
.rsrc 125952 a7c613d7e19ed0ceda35cb33351f013e
.reloc 12800 44e8c2086f2ca24435832d6f4cc0b7aa

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: