File name:

OneDrive.egg

Full analysis: https://app.any.run/tasks/25de9023-02ec-4ebe-84a5-4eab466fc2c7
Verdict: Malicious activity
Analysis date: February 25, 2025, 00:28:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/octet-stream
File info: EGG archive data, version 1.0
MD5:

0F2DAB387E7BC0953AA872631A6D50A2

SHA1:

833914F60E8A2A4A157C1DE30F7B08EBEE74463C

SHA256:

0DB4FF1DDF81D38BC49EC2FFCB93B7DBB37B953835E701226934215518F9989A

SSDEEP:

24576:Hp5mTWab4w6n/8ePt2WIhyxsjSVOJpm65pnuMYoLigv:Hp5mTWab4w6n/8ePt2WIhyxsjSUJpm6H

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • OneDriveSetup.exe (PID: 5040)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • OneDrive.exe (PID: 5752)
      • OneDriveSetup.exe (PID: 6768)
      • OneDriveSetup.exe (PID: 5040)
    • Creates/Modifies COM task schedule object

      • OneDrive.exe (PID: 5752)
      • OneDriveSetup.exe (PID: 5040)
    • Reads security settings of Internet Explorer

      • OneDrive.exe (PID: 5752)
      • OneDriveSetup.exe (PID: 6768)
      • OneDriveSetup.exe (PID: 5040)
    • Application launched itself

      • OneDriveSetup.exe (PID: 6768)
    • Process drops legitimate windows executable

      • OneDriveSetup.exe (PID: 5040)
    • There is functionality for taking screenshot (YARA)

      • OneDrive.exe (PID: 5752)
    • Executable content was dropped or overwritten

      • OneDriveSetup.exe (PID: 5040)
    • Creates a software uninstall entry

      • OneDriveSetup.exe (PID: 5040)
    • The process creates files with name similar to system file names

      • OneDriveSetup.exe (PID: 5040)
    • The process drops C-runtime libraries

      • OneDriveSetup.exe (PID: 5040)
  • INFO

    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 6300)
    • Manual execution by a user

      • OneDrive.exe (PID: 5752)
    • Creates files or folders in the user directory

      • OneDrive.exe (PID: 5752)
      • OneDriveSetup.exe (PID: 6768)
      • OneDriveSetup.exe (PID: 5040)
      • OneDrive.exe (PID: 6096)
    • Checks supported languages

      • OneDrive.exe (PID: 5752)
      • OneDriveSetup.exe (PID: 6768)
      • OneDriveSetup.exe (PID: 5040)
      • OneDrive.exe (PID: 6096)
      • FileSyncConfig.exe (PID: 6868)
    • Reads the time zone

      • OneDrive.exe (PID: 5752)
    • Create files in a temporary directory

      • OneDrive.exe (PID: 5752)
      • svchost.exe (PID: 448)
      • OneDriveSetup.exe (PID: 5040)
    • Reads the computer name

      • OneDrive.exe (PID: 5752)
      • OneDriveSetup.exe (PID: 6768)
      • OneDriveSetup.exe (PID: 5040)
      • OneDrive.exe (PID: 6096)
    • Reads CPU info

      • OneDrive.exe (PID: 5752)
    • Reads the machine GUID from the registry

      • OneDrive.exe (PID: 5752)
      • OneDriveSetup.exe (PID: 6768)
      • OneDriveSetup.exe (PID: 5040)
      • OneDrive.exe (PID: 6096)
    • Checks proxy server information

      • OneDrive.exe (PID: 5752)
    • Reads the software policy settings

      • OneDrive.exe (PID: 5752)
      • OneDriveSetup.exe (PID: 6768)
      • OneDriveSetup.exe (PID: 5040)
    • Process checks computer location settings

      • OneDrive.exe (PID: 5752)
      • OneDriveSetup.exe (PID: 5040)
    • The sample compiled with english language support

      • OneDriveSetup.exe (PID: 5040)
    • Reads Environment values

      • OneDrive.exe (PID: 6096)
    • The sample compiled with portuguese language support

      • OneDriveSetup.exe (PID: 5040)
    • The sample compiled with chinese language support

      • OneDriveSetup.exe (PID: 5040)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.egg | EGG compressed archive (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start openwith.exe no specs rundll32.exe no specs onedrive.exe svchost.exe onedrivesetup.exe no specs onedrivesetup.exe filesyncconfig.exe no specs onedrive.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
448C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s BITSC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
3060C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
5040C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe /update /restart /updateSource:ODU /peruser /childprocess C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe
OneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\update\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
5752"C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive
Exit code:
0
Version:
19.043.0304.0013
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\onedrive.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
6096 /updateInstalled /backgroundC:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exeOneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive
Exit code:
2147943660
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\onedrive.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
6300"C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\AppData\Local\Temp\OneDrive.eggC:\Windows\System32\OpenWith.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Pick an app
Exit code:
2147943623
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6768"C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" /update /restart /updateSource:ODU C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exeOneDrive.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\update\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
6868"C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe" C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exeOneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive Configuration Application
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\21.220.1024.0005\filesyncconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
Total events
16 130
Read events
15 246
Write events
336
Delete events
548

Modification events

(PID) Process:(5752) OneDrive.exeKey:HKEY_CLASSES_ROOT\AppID\OneDrive.EXE
Operation:writeName:AppID
Value:
{EEABD3A3-784D-4334-AAFC-BB13234F17CF}
(PID) Process:(5752) OneDrive.exeKey:HKEY_CLASSES_ROOT\FileSyncClient.AutoPlayHandler\shell\import\DropTarget
Operation:writeName:CLSID
Value:
{5999E1EE-711E-48D2-9884-851A709F543D}
(PID) Process:(5752) OneDrive.exeKey:HKEY_CLASSES_ROOT\BannerNotificationHandler.BannerNotificationHandler\shell\import\DropTarget
Operation:writeName:CLSID
Value:
{2e7c0a19-0438-41e9-81e3-3ad3d64f55ba}
(PID) Process:(5752) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{F0AF7C30-EAE4-4644-961D-54E6E28708D6}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5752) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{F0AF7C30-EAE4-4644-961D-54E6E28708D6}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5752) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{9D613F8A-B30E-4938-8490-CB5677701EBF}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5752) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{9D613F8A-B30E-4938-8490-CB5677701EBF}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5752) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{79A2A54C-3916-41FD-9FAB-F26ED0BBA755}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5752) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{79A2A54C-3916-41FD-9FAB-F26ED0BBA755}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5752) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{0299ECA9-80B6-43C8-A79A-FB1C5F19E7D8}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
221
Suspicious files
86
Text files
401
Unknown types
0

Dropped files

PID
Process
Filename
Type
448svchost.exeC:\Users\admin\AppData\Local\Temp\BITAD1D.tmp
MD5:
SHA256:
448svchost.exeC:\Users\admin\AppData\Local\Temp\wctAD0D.tmp
MD5:
SHA256:
5752OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:D357E0613CA41F673D55C641E28DB6BA
SHA256:1F63A0DAC8BFD42F3E9BA7A360611B3B68FE7ED3A2EC59A2EE6E437C17C172CB
5752OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\telemetryCache.otc.session-journalbinary
MD5:A2C8FFE4789A25177E023DBF4D57F9D0
SHA256:FBC606D55AA6DFE9CFF84A2672A7C26CC7855FD9B732D14B457EEE2A04D68311
5752OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64Abinary
MD5:68383BBEB7D47B115A5B98B25A319B30
SHA256:DCDBCFE970E99A83D4CFEC1B6ABA9392C11E94B8558E6F7CEF317C781E9FCCEF
5752OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:DF4627737831E8101F30FAE631CDB3BA
SHA256:E35698E307BEAFA7BA7A9CFAE377115A2F21B6F1551CD92E97AD1198119252CF
5752OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.jsonbinary
MD5:E516A60BC980095E8D156B1A99AB5EEE
SHA256:543796A1B343B4EBC0285D89CB8EB70667AC7B513DA37495E38003704E9D88D7
5752OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\telemetryCache.otc.sessionbinary
MD5:580BD824DEBBA908591408D7A5A3D01F
SHA256:B3218FF93047231A34C6962C758A36D412C2EB928C33F7EE537023EB6E489974
5752OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\DeviceFailureDatagram\DeviceHealthSummaryConfiguration.initext
MD5:16A0195C8E41674D2FDF8C90624E37BC
SHA256:89F3809867D49966D6F691354A11781DB9E7339202006310054DC85BE2E6AFA9
5752OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64Abinary
MD5:5428438E985FA4EC869BF6F6A90C4E07
SHA256:BC5C398F5070189ED26854317FB42852EEE7FB980CE25BE3A5A2BB70FD95D925
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
36
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5316
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5316
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4132
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6680
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5752
OneDrive.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5752
OneDrive.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.19.96.128:443
www.bing.com
Akamai International B.V.
DE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4132
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
5472
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
2.18.97.227:443
go.microsoft.com
Akamai International B.V.
FR
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.19.96.128
  • 2.19.96.120
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.72
whitelisted
google.com
  • 142.250.186.142
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 2.23.181.156
whitelisted
login.live.com
  • 20.190.160.130
  • 40.126.32.134
  • 20.190.160.14
  • 40.126.32.76
  • 20.190.160.2
  • 40.126.32.138
  • 20.190.160.128
  • 20.190.160.66
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
go.microsoft.com
  • 2.18.97.227
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

No threats detected
No debug info