File name:

OneDriveStandaloneUpdater.exe

Full analysis: https://app.any.run/tasks/f40e49e1-f463-46e8-a1c0-e85d2b4eed8a
Verdict: Malicious activity
Analysis date: March 01, 2024, 12:31:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9CDABFBF75FD35E615C9F85FEDAFCE8A

SHA1:

57B7FC9BF59CF09A9C19AD0CE0A159746554D682

SHA256:

969FBB03015DD9F33BAF45F2750E36B77003A7E18C3954FAB890CDDC94046673

SSDEEP:

49152:X63yWRyqw4amAiJkGrzzGWxTGdY9JPEHUxJyEl276xDeaGtkf6IUDeOCxbyvTovg:q3HRyq2mAiJ7qY93Dw/9tkketo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • OneDriveStandaloneUpdater.exe (PID: 2160)
      • OneDriveSetup.exe (PID: 4060)
    • Changes the autorun value in the registry

      • OneDriveSetup.exe (PID: 4060)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • OneDriveStandaloneUpdater.exe (PID: 2160)
      • OneDriveSetup.exe (PID: 4060)
    • Starts a Microsoft application from unusual location

      • OneDriveStandaloneUpdater.exe (PID: 2160)
    • Checks Windows Trust Settings

      • OneDriveStandaloneUpdater.exe (PID: 2160)
      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
    • Reads security settings of Internet Explorer

      • OneDriveStandaloneUpdater.exe (PID: 2160)
      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
      • OneDrive.exe (PID: 2064)
    • Reads settings of System Certificates

      • OneDriveStandaloneUpdater.exe (PID: 2160)
      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
    • Reads the Internet Settings

      • OneDriveStandaloneUpdater.exe (PID: 2160)
      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
      • OneDrive.exe (PID: 2064)
    • Application launched itself

      • OneDriveSetup.exe (PID: 3464)
    • Creates a software uninstall entry

      • OneDriveSetup.exe (PID: 4060)
    • Executable content was dropped or overwritten

      • OneDriveSetup.exe (PID: 4060)
    • The process creates files with name similar to system file names

      • OneDriveSetup.exe (PID: 4060)
    • The process drops C-runtime libraries

      • OneDriveSetup.exe (PID: 4060)
    • Write to the desktop.ini file (may be used to cloak folders)

      • FileSyncConfig.exe (PID: 956)
    • Creates/Modifies COM task schedule object

      • OneDriveSetup.exe (PID: 4060)
    • Changes Internet Explorer settings (feature browser emulation)

      • OneDriveSetup.exe (PID: 4060)
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3240)
      • OneDriveStandaloneUpdater.exe (PID: 2160)
      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
      • FileSyncConfig.exe (PID: 956)
      • OneDrive.exe (PID: 2064)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3240)
      • OneDriveStandaloneUpdater.exe (PID: 2160)
      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
      • FileSyncConfig.exe (PID: 956)
      • OneDrive.exe (PID: 2064)
    • Reads the machine GUID from the registry

      • OneDriveStandaloneUpdater.exe (PID: 2160)
      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
      • OneDrive.exe (PID: 2064)
    • Creates files or folders in the user directory

      • OneDriveStandaloneUpdater.exe (PID: 2160)
      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
      • OneDrive.exe (PID: 2064)
    • Reads the software policy settings

      • OneDriveStandaloneUpdater.exe (PID: 2160)
      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
    • Creates files in the program directory

      • OneDriveSetup.exe (PID: 3464)
    • Reads Environment values

      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
      • OneDrive.exe (PID: 2064)
    • Checks proxy server information

      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
      • OneDrive.exe (PID: 2064)
    • Create files in a temporary directory

      • OneDriveSetup.exe (PID: 3464)
      • OneDriveSetup.exe (PID: 4060)
      • OneDrive.exe (PID: 2064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2051:04:02 11:58:25+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 2272256
InitializedDataSize: 790528
UninitializedDataSize: -
EntryPoint: 0x2dc90
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 21.220.1024.5
ProductVersionNumber: 21.220.1024.5
FileFlagsMask: 0x003f
FileFlags: Special build
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Standalone Updater
InternalName: OneDriveStandaloneUpdater.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: OneDriveStandaloneUpdater.exe
ProductName: Microsoft OneDrive
FileVersion: 21.220.1024.0005
ProductVersion: 21.220.1024.0005
SpecialBuild: b/build/2c205c5c-e050-0ffd-f7d0-63786687edbc
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start onedrivestandaloneupdater.exe no specs onedrivesetup.exe onedrivesetup.exe filesyncconfig.exe no specs onedrive.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
956"C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe" C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exeOneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive Configuration Application
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\21.220.1024.0005\filesyncconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\onedrive\21.220.1024.0005\loggingplatform.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2064 /updateInstalledC:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
OneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\onedrive.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2160"C:\Users\admin\AppData\Local\Temp\OneDriveStandaloneUpdater.exe" C:\Users\admin\AppData\Local\Temp\OneDriveStandaloneUpdater.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Standalone Updater
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\temp\onedrivestandaloneupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3240"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3464"C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" /update /restart /updateSource:ODSUC:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
OneDriveStandaloneUpdater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\standaloneupdater\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wer.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
4060C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe /update /restart /updateSource:ODSU /peruser /childprocess /extractFilesWithLessThreadCount /renameReplaceOneDriveExe /renameReplaceODSUExe /removeNonCurrentVersions /enableODSUReportingMode C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
OneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\standaloneupdater\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wer.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
20 321
Read events
19 928
Write events
337
Delete events
56

Modification events

(PID) Process:(2160) OneDriveStandaloneUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\OneDrive
Operation:writeName:StandaloneUpdaterSafeMode
Value:
1
(PID) Process:(2160) OneDriveStandaloneUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\PreSignInSettingsConfigJSON
Operation:writeName:GUID
Value:
63C936A91F16C8479811B56DDB78ABBC
(PID) Process:(2160) OneDriveStandaloneUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\PreSignInSettingsConfigJSON
Operation:writeName:File
Value:
wctF82B.tmp
(PID) Process:(2160) OneDriveStandaloneUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\PreSignInSettingsConfigJSON
Operation:delete valueName:GUID
Value:
쥣ꤶᘟ䟈ᆘ涵磛벫
(PID) Process:(2160) OneDriveStandaloneUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\PreSignInSettingsConfigJSON
Operation:delete valueName:File
Value:
wctF82B.tmp
(PID) Process:(2160) OneDriveStandaloneUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\PreSignInSettingsConfigJSON
Operation:delete keyName:(default)
Value:
(PID) Process:(2160) OneDriveStandaloneUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\UpdateDescriptionXml
Operation:writeName:GUID
Value:
EFE148D38B9A0B4981D2EBC53AD74BC1
(PID) Process:(2160) OneDriveStandaloneUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\UpdateDescriptionXml
Operation:writeName:File
Value:
wct2F0B.tmp
(PID) Process:(2160) OneDriveStandaloneUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\UpdateDescriptionXml
Operation:delete valueName:GUID
Value:
퍈骋䤋튁엫휺셋
(PID) Process:(2160) OneDriveStandaloneUpdater.exeKey:HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\UpdateDescriptionXml
Operation:delete valueName:File
Value:
wct2F0B.tmp
Executable files
222
Suspicious files
16
Text files
405
Unknown types
11

Dropped files

PID
Process
Filename
Type
2160OneDriveStandaloneUpdater.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
MD5:
SHA256:
4060OneDriveSetup.exeC:\Users\admin\AppData\Local\Temp\tmpA14C.tmp
MD5:
SHA256:
2160OneDriveStandaloneUpdater.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Common\DeviceHealthSummaryConfiguration.initext
MD5:1769F0CA8F791BA888AF167FACB9CE14
SHA256:25A6C6F0D480713493D85616D304F92ACC71E8DAA1D706EBBBA70E7DD433031A
2160OneDriveStandaloneUpdater.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Common\StandaloneUpdater-2024-03-01.1231.2160.1.odlbinary
MD5:2F8F74619DC8E0F88995A8A288D88360
SHA256:5327D1507CF820EADFF4F973A5B3B06D46C0BA051E4DFB53B62A00FC70A71401
2160OneDriveStandaloneUpdater.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\PreSignInSettingsConfig.jsonbinary
MD5:E516A60BC980095E8D156B1A99AB5EEE
SHA256:543796A1B343B4EBC0285D89CB8EB70667AC7B513DA37495E38003704E9D88D7
3464OneDriveSetup.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\setup\logs\parentTelemetryCache.otc-journalbinary
MD5:F181B0892DB0AF87B8866175E1D066BE
SHA256:A1736AC2652FC3429E61705BD8A2FEBA2CBF07977059760BC70C1D7F4ECEC3B6
2160OneDriveStandaloneUpdater.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\setup\logs\StandaloneUpdate_2024-03-01_123125_2160-3656.logbinary
MD5:281032AE08AF24AB030AA77019713461
SHA256:A3E7B1E17BDF530432E2F4482C53F05688359567B5F35A492E38F75E21DE3A1B
3464OneDriveSetup.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\setup\logs\Install-2024-03-01.1232.3464.1.aodlbinary
MD5:0F703716585B72E4BB67A8063B3F52DB
SHA256:A28B70387BCADC228968682B02F5B32F32503A357100B2ADFC5A3660F036DBDD
2160OneDriveStandaloneUpdater.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\Update.xmlxml
MD5:53244E542DDF6D280A2B03E28F0646B7
SHA256:36A6BD38A8A6F5A75B73CAFFAE5AE66DFABCAEFD83DA65B493FA881EA8A64E7D
2160OneDriveStandaloneUpdater.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\Update.xmlxml
MD5:53244E542DDF6D280A2B03E28F0646B7
SHA256:36A6BD38A8A6F5A75B73CAFFAE5AE66DFABCAEFD83DA65B493FA881EA8A64E7D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
11
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3464
OneDriveSetup.exe
GET
304
23.53.42.64:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5640091f244ed244
DE
unknown
3464
OneDriveSetup.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2044
svchost.exe
239.255.255.250:1900
unknown
856
svchost.exe
68.219.88.225:443
g.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
856
svchost.exe
23.35.237.43:443
oneclient.sfx.ms
AKAMAI-AS
DE
unknown
3464
OneDriveSetup.exe
52.168.117.168:443
self.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3464
OneDriveSetup.exe
23.53.42.64:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3464
OneDriveSetup.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4060
OneDriveSetup.exe
52.168.117.168:443
self.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
g.live.com
  • 68.219.88.225
whitelisted
oneclient.sfx.ms
  • 23.35.237.43
unknown
self.events.data.microsoft.com
  • 52.168.117.168
whitelisted
ctldl.windowsupdate.com
  • 23.53.42.64
  • 23.53.41.250
  • 23.53.41.248
  • 23.53.41.243
  • 23.53.42.66
  • 23.53.42.16
  • 23.53.42.59
  • 23.53.42.67
  • 23.53.42.17
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info