Low signal — weak indicators present
Only weak/low-confidence indicators were found. May be benign — use context.
"msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --startup-read-main-dll --metrics-shmem-handle=2536,i,16744024644676696995,18080054063203715497,524288 --field-trial-handle=2464,i,7129805286018773235,14097306451518073526,262144 --variations-seed-version --pseudonymization-salt-handle=2468,i,6673955790337792718,14547343720472287054,4 --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=2672 /prefetch:11
Runs `msedge.exe` with arguments: `--type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --se…`.
The command leverages Msedge.exe, a Windows binary catalogued in LOLBAS as commonly abused for living-off-the-land attacks — known abuse categories: Execute and Download.
While the detected binaries have legitimate administrative uses, their presence in an investigation warrants scrutiny of process lineage, network connections made during execution, and any files created or modified.
North Korean state-sponsored group linked to the $81M Bangladesh Bank heist, WannaCry ransomware, and Sony Pictures breach. The most prolific nation-state financial threat actor.
Attribution based on MITRE ATT&CK technique overlap. Confidence reflects TTP match depth — not a definitive attribution.