File name:

OneDrivePatcher.exe

Full analysis: https://app.any.run/tasks/a714456c-563f-4b04-9306-dc1fc845ace0
Verdict: Malicious activity
Analysis date: April 29, 2026, 19:20:33
OS: Windows 10 Professional (build: 19044, 64 bit)
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 8 sections
MD5:

66DB277946BCB8F35AF53B8CA2FB2346

SHA1:

EC95C33E6C2CDC99678146ABF9DF71B0959EBB2C

SHA256:

12A06CAF41711A04BDC9D4184419BA30B165964AFB445E9D27B7E40DC46566C2

SSDEEP:

98304:a7I+OFUxSKB0tyI5K7w4PsbfQojVibqlEHW7IMRk/HxP5jRzMlS:lFMRWSZV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • OneDrivePatcher.exe (PID: 7728)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • OneDrivePatcher.exe (PID: 7728)
  • INFO

    • The sample compiled with english language support

      • OneDrivePatcher.exe (PID: 6556)
    • Manual execution by a user

      • OneDrivePatcher.exe (PID: 7728)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2045:12:22 12:52:01+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.5
CodeSize: 2601472
InitializedDataSize: 938496
UninitializedDataSize: -
EntryPoint: 0xd52c0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 26.70.414.1
ProductVersionNumber: 26.70.414.1
FileFlagsMask: 0x003f
FileFlags: Special build
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Microsoft OneDrive Patcher
InternalName: Microsoft OneDrive
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: OneDrivePatcher.exe
ProductName: Microsoft OneDrive
FileVersion: 26.070.0414.0001
ProductVersion: 26.070.0414.0001
SpecialBuild: b/build/58d507b0-3939-9d95-dd4c-daf495003659
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
3
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start onedrivepatcher.exe no specs slui.exe onedrivepatcher.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
5384C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6556"C:\Users\admin\AppData\Local\Temp\OneDrivePatcher.exe" C:\Users\admin\AppData\Local\Temp\OneDrivePatcher.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive Patcher
Exit code:
3221225781
Version:
26.070.0414.0001
Modules
Images
c:\users\admin\appdata\local\temp\onedrivepatcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
7728"C:\Users\admin\AppData\Local\Temp\OneDrivePatcher.exe" C:\Users\admin\AppData\Local\Temp\OneDrivePatcher.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive Patcher
Version:
26.070.0414.0001
Modules
Images
c:\users\admin\appdata\local\temp\onedrivepatcher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
Total events
408
Read events
407
Write events
1
Delete events
0

Modification events

(PID) Process:(5384) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
13
DNS requests
8
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
8000
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7988
slui.exe
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
5208
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5384
slui.exe
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8000
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
  • 40.127.240.158
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
google.com
  • 142.251.14.113
  • 142.251.14.101
  • 142.251.14.138
  • 142.251.14.100
  • 142.251.14.102
  • 142.251.14.139
whitelisted
self.events.data.microsoft.com
  • 20.50.73.13
whitelisted

Threats

No threats detected
No debug info