| File name: | OneDrive.egg |
| Full analysis: | https://app.any.run/tasks/25de9023-02ec-4ebe-84a5-4eab466fc2c7 |
| Verdict: | Malicious activity |
| Analysis date: | February 25, 2025, 00:28:29 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/octet-stream |
| File info: | EGG archive data, version 1.0 |
| MD5: | 0F2DAB387E7BC0953AA872631A6D50A2 |
| SHA1: | 833914F60E8A2A4A157C1DE30F7B08EBEE74463C |
| SHA256: | 0DB4FF1DDF81D38BC49EC2FFCB93B7DBB37B953835E701226934215518F9989A |
| SSDEEP: | 24576:Hp5mTWab4w6n/8ePt2WIhyxsjSVOJpm65pnuMYoLigv:Hp5mTWab4w6n/8ePt2WIhyxsjSUJpm6H |
| .egg | | | EGG compressed archive (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 448 | C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s BITS | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3060 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5040 | C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe /update /restart /updateSource:ODU /peruser /childprocess | C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe | OneDriveSetup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive (32 bit) Setup Exit code: 0 Version: 21.220.1024.0005 Modules
| |||||||||||||||
| 5752 | "C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" | C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive Exit code: 0 Version: 19.043.0304.0013 Modules
| |||||||||||||||
| 6096 | /updateInstalled /background | C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe | — | OneDriveSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive Exit code: 2147943660 Version: 21.220.1024.0005 Modules
| |||||||||||||||
| 6300 | "C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\AppData\Local\Temp\OneDrive.egg | C:\Windows\System32\OpenWith.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Pick an app Exit code: 2147943623 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6768 | "C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" /update /restart /updateSource:ODU | C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe | — | OneDrive.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive (32 bit) Setup Exit code: 0 Version: 21.220.1024.0005 Modules
| |||||||||||||||
| 6868 | "C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe" | C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe | — | OneDriveSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive Configuration Application Exit code: 0 Version: 21.220.1024.0005 Modules
| |||||||||||||||
| (PID) Process: | (5752) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\AppID\OneDrive.EXE |
| Operation: | write | Name: | AppID |
Value: {EEABD3A3-784D-4334-AAFC-BB13234F17CF} | |||
| (PID) Process: | (5752) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\FileSyncClient.AutoPlayHandler\shell\import\DropTarget |
| Operation: | write | Name: | CLSID |
Value: {5999E1EE-711E-48D2-9884-851A709F543D} | |||
| (PID) Process: | (5752) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\BannerNotificationHandler.BannerNotificationHandler\shell\import\DropTarget |
| Operation: | write | Name: | CLSID |
Value: {2e7c0a19-0438-41e9-81e3-3ad3d64f55ba} | |||
| (PID) Process: | (5752) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\Interface\{F0AF7C30-EAE4-4644-961D-54E6E28708D6}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (5752) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\Interface\{F0AF7C30-EAE4-4644-961D-54E6E28708D6}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (5752) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\Interface\{9D613F8A-B30E-4938-8490-CB5677701EBF}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (5752) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\Interface\{9D613F8A-B30E-4938-8490-CB5677701EBF}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (5752) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\Interface\{79A2A54C-3916-41FD-9FAB-F26ED0BBA755}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (5752) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\Interface\{79A2A54C-3916-41FD-9FAB-F26ED0BBA755}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (5752) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\Interface\{0299ECA9-80B6-43C8-A79A-FB1C5F19E7D8}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 448 | svchost.exe | C:\Users\admin\AppData\Local\Temp\BITAD1D.tmp | — | |
MD5:— | SHA256:— | |||
| 448 | svchost.exe | C:\Users\admin\AppData\Local\Temp\wctAD0D.tmp | — | |
MD5:— | SHA256:— | |||
| 5752 | OneDrive.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04 | binary | |
MD5:D357E0613CA41F673D55C641E28DB6BA | SHA256:1F63A0DAC8BFD42F3E9BA7A360611B3B68FE7ED3A2EC59A2EE6E437C17C172CB | |||
| 5752 | OneDrive.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\telemetryCache.otc.session-journal | binary | |
MD5:A2C8FFE4789A25177E023DBF4D57F9D0 | SHA256:FBC606D55AA6DFE9CFF84A2672A7C26CC7855FD9B732D14B457EEE2A04D68311 | |||
| 5752 | OneDrive.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A | binary | |
MD5:68383BBEB7D47B115A5B98B25A319B30 | SHA256:DCDBCFE970E99A83D4CFEC1B6ABA9392C11E94B8558E6F7CEF317C781E9FCCEF | |||
| 5752 | OneDrive.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04 | binary | |
MD5:DF4627737831E8101F30FAE631CDB3BA | SHA256:E35698E307BEAFA7BA7A9CFAE377115A2F21B6F1551CD92E97AD1198119252CF | |||
| 5752 | OneDrive.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json | binary | |
MD5:E516A60BC980095E8D156B1A99AB5EEE | SHA256:543796A1B343B4EBC0285D89CB8EB70667AC7B513DA37495E38003704E9D88D7 | |||
| 5752 | OneDrive.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\telemetryCache.otc.session | binary | |
MD5:580BD824DEBBA908591408D7A5A3D01F | SHA256:B3218FF93047231A34C6962C758A36D412C2EB928C33F7EE537023EB6E489974 | |||
| 5752 | OneDrive.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\DeviceFailureDatagram\DeviceHealthSummaryConfiguration.ini | text | |
MD5:16A0195C8E41674D2FDF8C90624E37BC | SHA256:89F3809867D49966D6F691354A11781DB9E7339202006310054DC85BE2E6AFA9 | |||
| 5752 | OneDrive.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A | binary | |
MD5:5428438E985FA4EC869BF6F6A90C4E07 | SHA256:BC5C398F5070189ED26854317FB42852EEE7FB980CE25BE3A5A2BB70FD95D925 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1176 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5316 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5316 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.120:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4132 | svchost.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6680 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5752 | OneDrive.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5752 | OneDrive.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5064 | SearchApp.exe | 2.19.96.128:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.16.164.120:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
4132 | svchost.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
5472 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1176 | svchost.exe | 20.190.160.130:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1076 | svchost.exe | 2.18.97.227:443 | go.microsoft.com | Akamai International B.V. | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |