File name:

OneDriveLauncher.exe.zip

Full analysis: https://app.any.run/tasks/02ab5df3-2387-4248-b50d-0a45a8eb7ff0
Verdict: Malicious activity
Analysis date: May 28, 2025, 18:43:59
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

2A049B7B93B1C29818C9862F9AF267C6

SHA1:

48997B365307D0DE5DC915BC1EA41286BA8C88EF

SHA256:

07BA6457D7F389F8AE24A8AC7238C257B74D09DEEC417317BB3CA71C1767EB93

SSDEEP:

6144:jRs/H6Jx+BLPLy4bRu8jv13qjnkn7ck8Xj/vXlLrdZJdCsla2naqUP23aFC:jySL+BLPX0SAjkn7WXjv9rnJdVDsuqFC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7348)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • OneDriveLauncher.exe (PID: 6268)
      • OneDriveLauncher.exe (PID: 7296)
      • OneDriveLauncher.exe (PID: 4688)
      • OneDriveLauncher.exe (PID: 1228)
      • OneDriveLauncher.exe (PID: 4988)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 7348)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7348)
    • Start notepad (likely ransomware note)

      • WinRAR.exe (PID: 7348)
  • INFO

    • Reads the software policy settings

      • slui.exe (PID: 7520)
      • slui.exe (PID: 7344)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 7348)
    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 7348)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7348)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 1764)
      • notepad.exe (PID: 6712)
    • Checks proxy server information

      • slui.exe (PID: 7344)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2025:05:28 18:43:14
ZipCRC: 0xa6c92b3c
ZipCompressedSize: 290462
ZipUncompressedSize: 684856
ZipFileName: OneDriveLauncher.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
11
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe onedrivelauncher.exe no specs onedrivelauncher.exe no specs slui.exe onedrivelauncher.exe no specs notepad.exe no specs onedrivelauncher.exe no specs onedrivelauncher.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1228"C:\Users\admin\AppData\Local\Temp\Rar$EXa7348.24353\OneDriveLauncher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7348.24353\OneDriveLauncher.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
OneDriveLauncher
Exit code:
3221225781
Version:
25.085.0504.0002
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7348.24353\onedrivelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1764"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa7348.23208\checksums.txtC:\Windows\System32\notepad.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4688"C:\Users\admin\AppData\Local\Temp\Rar$EXa7348.22611\OneDriveLauncher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7348.22611\OneDriveLauncher.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
OneDriveLauncher
Exit code:
3221225781
Version:
25.085.0504.0002
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7348.22611\onedrivelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4988"C:\Users\admin\AppData\Local\Temp\Rar$EXa7348.24914\OneDriveLauncher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7348.24914\OneDriveLauncher.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
OneDriveLauncher
Exit code:
3221225781
Version:
25.085.0504.0002
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7348.24914\onedrivelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6268"C:\Users\admin\AppData\Local\Temp\Rar$EXa7348.21911\OneDriveLauncher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7348.21911\OneDriveLauncher.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
OneDriveLauncher
Exit code:
3221225781
Version:
25.085.0504.0002
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7348.21911\onedrivelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6712"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\Rar$DIa7348.25642\checksums.txtC:\Windows\System32\notepad.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
7296"C:\Users\admin\AppData\Local\Temp\Rar$EXa7348.21953\OneDriveLauncher.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7348.21953\OneDriveLauncher.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
OneDriveLauncher
Exit code:
3221225781
Version:
25.085.0504.0002
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7348.21953\onedrivelauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7344C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7348"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\OneDriveLauncher.exe.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7488C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
4 101
Read events
4 091
Write events
10
Delete events
0

Modification events

(PID) Process:(7348) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7348) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7348) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7348) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\OneDriveLauncher.exe.zip
(PID) Process:(7348) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7348) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7348) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7348) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7348) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithProgids
Operation:writeName:txtfile
Value:
Executable files
5
Suspicious files
0
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
7348WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7348.21911\checksums.txttext
MD5:52800BE9774187547D22DB8D0FC4A0AE
SHA256:F8DC1B2E0C2FE0DBDF81E15459209F193BAFE8AF7415268280D3BFFE29BB405B
7348WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7348.21911\OneDriveLauncher.exeexecutable
MD5:F8ECFA3E013988F5F5BCD1D5CE649F4B
SHA256:3673AE89113D76F0FD62C2F214A14EA9116E6D7AE5A3675C6AA982B1533390B0
7348WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7348.21953\OneDriveLauncher.exeexecutable
MD5:F8ECFA3E013988F5F5BCD1D5CE649F4B
SHA256:3673AE89113D76F0FD62C2F214A14EA9116E6D7AE5A3675C6AA982B1533390B0
7348WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7348.21953\checksums.txttext
MD5:52800BE9774187547D22DB8D0FC4A0AE
SHA256:F8DC1B2E0C2FE0DBDF81E15459209F193BAFE8AF7415268280D3BFFE29BB405B
7348WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7348.22611\OneDriveLauncher.exeexecutable
MD5:F8ECFA3E013988F5F5BCD1D5CE649F4B
SHA256:3673AE89113D76F0FD62C2F214A14EA9116E6D7AE5A3675C6AA982B1533390B0
7348WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7348.24353\OneDriveLauncher.exeexecutable
MD5:F8ECFA3E013988F5F5BCD1D5CE649F4B
SHA256:3673AE89113D76F0FD62C2F214A14EA9116E6D7AE5A3675C6AA982B1533390B0
7348WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7348.24353\checksums.txttext
MD5:52800BE9774187547D22DB8D0FC4A0AE
SHA256:F8DC1B2E0C2FE0DBDF81E15459209F193BAFE8AF7415268280D3BFFE29BB405B
7348WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7348.24914\OneDriveLauncher.exeexecutable
MD5:F8ECFA3E013988F5F5BCD1D5CE649F4B
SHA256:3673AE89113D76F0FD62C2F214A14EA9116E6D7AE5A3675C6AA982B1533390B0
7348WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7348.22611\checksums.txttext
MD5:52800BE9774187547D22DB8D0FC4A0AE
SHA256:F8DC1B2E0C2FE0DBDF81E15459209F193BAFE8AF7415268280D3BFFE29BB405B
7348WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa7348.23208\checksums.txttext
MD5:52800BE9774187547D22DB8D0FC4A0AE
SHA256:F8DC1B2E0C2FE0DBDF81E15459209F193BAFE8AF7415268280D3BFFE29BB405B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
22
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8104
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8104
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6392
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
5496
MoUsoCoreWorker.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
6544
svchost.exe
40.126.31.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
23.63.118.230:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.110
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted
login.live.com
  • 40.126.31.0
  • 20.190.159.129
  • 20.190.159.0
  • 40.126.31.130
  • 40.126.31.131
  • 40.126.31.2
  • 20.190.159.128
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 23.63.118.230
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info