| File name: | OneDrive.exe |
| Full analysis: | https://app.any.run/tasks/1d2936cd-efa1-4fb4-9c3f-142dfdcce053 |
| Verdict: | Malicious activity |
| Analysis date: | December 28, 2021, 15:49:23 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C2938EB5FF932C2540A1514CC82C197C |
| SHA1: | 2D7DA1C3BFA4755BA0EFEC5317260D239CBB51C3 |
| SHA256: | 5D8273BF98397E4C5053F8F154E5F838C7E8A798B125FCAD33CAB16E2515B665 |
| SSDEEP: | 49152:YwcM40vky++ia4lw4XyTtsBP/OlsLzFmNfW6FJKxxfZA4XFrF:YwcMpiacw4XzBP/OlsLzFmNfW6FJKxxl |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| SpecialBuild: | b/build/2c205c5c-e050-0ffd-f7d0-63786687edbc |
|---|---|
| ProductVersion: | 21.220.1024.0005 |
| FileVersion: | 21.220.1024.0005 |
| ProductName: | Microsoft OneDrive |
| OriginalFileName: | OneDrive.exe |
| LegalCopyright: | © Microsoft Corporation. All rights reserved. |
| InternalName: | Client Application |
| FileDescription: | Microsoft OneDrive |
| CompanyName: | Microsoft Corporation |
| CharacterSet: | Unicode |
| LanguageCode: | English (U.S.) |
| FileSubtype: | - |
| ObjectFileType: | Executable application |
| FileOS: | Win32 |
| FileFlags: | Special build |
| FileFlagsMask: | 0x003f |
| ProductVersionNumber: | 21.220.1024.5 |
| FileVersionNumber: | 21.220.1024.5 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 6 |
| ImageVersion: | - |
| OSVersion: | 6 |
| EntryPoint: | 0x4f7e0 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 1858560 |
| CodeSize: | 503296 |
| LinkerVersion: | 14.29 |
| PEType: | PE32 |
| TimeStamp: | 1981:04:03 19:12:31+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 03-Apr-1981 17:12:31 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft OneDrive |
| InternalName: | Client Application |
| LegalCopyright: | © Microsoft Corporation. All rights reserved. |
| OriginalFilename: | OneDrive.exe |
| ProductName: | Microsoft OneDrive |
| FileVersion: | 21.220.1024.0005 |
| ProductVersion: | 21.220.1024.0005 |
| SpecialBuild: | b/build/2c205c5c-e050-0ffd-f7d0-63786687edbc |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000118 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 03-Apr-1981 17:12:31 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0007AC6B | 0x0007AE00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.61708 |
.rdata | 0x0007C000 | 0x00022986 | 0x00022A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.9513 |
.data | 0x0009F000 | 0x00004AA8 | 0x00003C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.26669 |
.rsrc | 0x000A4000 | 0x00197E80 | 0x00198000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.66682 |
.reloc | 0x0023C000 | 0x000064D4 | 0x00006600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.57825 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.2504 | 1788 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 2.70242 | 38056 | UNKNOWN | English - United States | RT_ICON |
3 | 2.74875 | 26600 | UNKNOWN | English - United States | RT_ICON |
4 | 2.79868 | 16936 | UNKNOWN | English - United States | RT_ICON |
5 | 2.8831 | 9640 | UNKNOWN | English - United States | RT_ICON |
6 | 2.95039 | 6760 | UNKNOWN | English - United States | RT_ICON |
7 | 3.03593 | 4264 | UNKNOWN | English - United States | RT_ICON |
8 | 3.08927 | 3288 | UNKNOWN | English - United States | RT_ICON |
9 | 3.2205 | 2440 | UNKNOWN | English - United States | RT_ICON |
10 | 3.25169 | 1720 | UNKNOWN | English - United States | RT_ICON |
ADVAPI32.dll |
CRYPT32.dll |
KERNEL32.dll |
OLEAUT32.dll |
RPCRT4.dll |
SHELL32.dll |
SHLWAPI.dll |
Secur32.dll |
USER32.dll |
USERENV.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 592 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2376.20.760090226\763680849" -childID 3 -isForBrowser -prefsHandle 1900 -prefMapHandle 1856 -prefsLen 7307 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2376 "\\.\pipe\gecko-crash-server-pipe.2376" 1884 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 612 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 1468 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\parentchoice.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 2208 | "C:\Users\admin\Desktop\OneDrive.exe" | C:\Users\admin\Desktop\OneDrive.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive Exit code: 3223650531 Version: 21.220.1024.0005 Modules
| |||||||||||||||
| 2336 | C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503} | C:\Windows\system32\DllHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2376 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 2532 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2376.6.816169194\247994965" -childID 1 -isForBrowser -prefsHandle 3288 -prefMapHandle 3284 -prefsLen 245 -prefMapSize 238726 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2376 "\\.\pipe\gecko-crash-server-pipe.2376" 3300 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 83.0 Modules
| |||||||||||||||
| 2724 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\ministerwatch.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 2732 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\sameitems.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 2768 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2376.0.570325910\169367098" -parentBuildID 20201112153044 -prefsHandle 1088 -prefMapHandle 820 -prefsLen 1 -prefMapSize 238726 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2376 "\\.\pipe\gecko-crash-server-pipe.2376" 1184 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 83.0 Modules
| |||||||||||||||
| (PID) Process: | (3212) OneDrive.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\OneDrive |
| Operation: | write | Name: | RepairAttempted |
Value: 1 | |||
| (PID) Process: | (2208) OneDrive.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\OneDrive |
| Operation: | write | Name: | RepairAttempted |
Value: 2 | |||
| (PID) Process: | (612) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: BDA1D6062B000000 | |||
| (PID) Process: | (2376) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: F9ACD6062B000000 | |||
| (PID) Process: | (2376) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (2376) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (2376) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (2376) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
| (PID) Process: | (2376) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|ServicesSettingsServer |
Value: https://firefox.settings.services.mozilla.com/v1 | |||
| (PID) Process: | (2376) firefox.exe | Key: | HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|SecurityContentSignatureRootHash |
Value: 97:E8:BA:9C:F1:2F:B3:DE:53:CC:42:A4:E6:57:7E:D6:4D:F4:93:C2:47:B4:14:FE:A0:36:81:8D:38:23:56:0E | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2376 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 2376 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2376 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\urlCache-current.bin | binary | |
MD5:994A33896BB41A278A315D0D796422B6 | SHA256:54EC50A20FFF8CC016710E49437CF6A11D3FE5EE7B28C185E4A9AAFEE2908B63 | |||
| 2376 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 2376 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4 | jsonlz4 | |
MD5:— | SHA256:— | |||
| 2376 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite-journal | binary | |
MD5:— | SHA256:— | |||
| 2376 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-wal | — | |
MD5:— | SHA256:— | |||
| 2376 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\recovery.jsonlz4.tmp | jsonlz4 | |
MD5:— | SHA256:— | |||
| 2376 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite-journal | binary | |
MD5:— | SHA256:— | |||
| 2376 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite-wal | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2376 | firefox.exe | POST | 200 | 142.250.179.163:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
2376 | firefox.exe | POST | 200 | 93.184.220.29:80 | http://ocsp.digicert.com/ | US | der | 471 b | whitelisted |
2376 | firefox.exe | POST | 200 | 142.250.179.163:80 | http://ocsp.pki.goog/gts1c3 | US | der | 472 b | whitelisted |
2376 | firefox.exe | POST | — | 142.250.179.163:80 | http://ocsp.pki.goog/gts1c3 | US | — | — | whitelisted |
2376 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | US | text | 8 b | whitelisted |
2376 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt | US | text | 8 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2376 | firefox.exe | 142.251.36.36:443 | www.google.com | Google Inc. | US | whitelisted |
2376 | firefox.exe | 172.217.168.202:443 | safebrowsing.googleapis.com | Google Inc. | US | whitelisted |
2376 | firefox.exe | 142.250.179.163:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
2376 | firefox.exe | 13.227.219.5:443 | content-signature-2.cdn.mozilla.net | — | US | unknown |
2376 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | — | US | whitelisted |
2376 | firefox.exe | 65.9.83.77:443 | firefox.settings.services.mozilla.com | AT&T Services, Inc. | US | unknown |
2376 | firefox.exe | 52.36.14.43:443 | push.services.mozilla.com | Amazon.com, Inc. | US | unknown |
2376 | firefox.exe | 93.184.220.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2376 | firefox.exe | 65.9.83.38:443 | firefox-settings-attachments.cdn.mozilla.net | AT&T Services, Inc. | US | unknown |
2376 | firefox.exe | 142.250.179.195:443 | www.gstatic.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
detectportal.firefox.com |
| whitelisted |
firefox.settings.services.mozilla.com |
| whitelisted |
location.services.mozilla.com |
| whitelisted |
safebrowsing.googleapis.com |
| whitelisted |
push.services.mozilla.com |
| whitelisted |
www.google.com |
| malicious |
www.youtube.com |
| whitelisted |
www.facebook.com |
| whitelisted |
www.ebay.de |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2376 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |
2376 | firefox.exe | Potentially Bad Traffic | ET INFO Terse Request for .txt - Likely Hostile |