File name:

979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898

Full analysis: https://app.any.run/tasks/92804ec5-0075-43a6-a760-d5da81693b3f
Verdict: Malicious activity
Analysis date: June 13, 2025, 20:10:38
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
delphi
inno
installer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

56A771336CBE0A3AA0049DC1306EAFF5

SHA1:

013EB70916260A36D4AACBF57D35FBCDEBCB6042

SHA256:

979ED241AC85B0B19E20C63106A3F83BF8DF0A8480FC637042696C580AA55898

SSDEEP:

98304:3LVIF8P3n1BLHxtD59KEKjSvDQgokZWtKsovt0FcN2TFOMR8gW6rijUNG2KOYGcz:BsYr3t/m7qoEJ+mBZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • OneDriveSetup.exe (PID: 1508)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 1760)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 6012)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDriveSetup.exe (PID: 1508)
    • Reads security settings of Internet Explorer

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 4960)
      • OneDriveSetup.exe (PID: 1508)
    • Reads the Windows owner or organization settings

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
    • Creates/Modifies COM task schedule object

      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 1508)
    • There is functionality for taking screenshot (YARA)

      • OneDrive.exe (PID: 3620)
    • Application launched itself

      • OneDriveSetup.exe (PID: 4960)
    • Process drops legitimate windows executable

      • OneDriveSetup.exe (PID: 1508)
    • The process drops C-runtime libraries

      • OneDriveSetup.exe (PID: 1508)
    • The process creates files with name similar to system file names

      • OneDriveSetup.exe (PID: 1508)
    • Creates a software uninstall entry

      • OneDriveSetup.exe (PID: 1508)
  • INFO

    • Checks supported languages

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 1760)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 6012)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 4960)
      • OneDriveSetup.exe (PID: 1508)
      • FileSyncConfig.exe (PID: 1964)
      • OneDrive.exe (PID: 2072)
    • Create files in a temporary directory

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 1760)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 6012)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 1508)
    • Reads the computer name

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 6012)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 4960)
      • OneDriveSetup.exe (PID: 1508)
      • OneDrive.exe (PID: 2072)
    • Process checks computer location settings

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 1508)
    • Reads the software policy settings

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 4960)
      • OneDriveSetup.exe (PID: 1508)
    • Reads the machine GUID from the registry

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 4960)
      • OneDriveSetup.exe (PID: 1508)
      • OneDrive.exe (PID: 2072)
    • Detects InnoSetup installer (YARA)

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 1760)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
    • Compiled with Borland Delphi (YARA)

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 1760)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
    • Manual execution by a user

      • OneDrive.exe (PID: 3620)
    • Reads CPU info

      • OneDrive.exe (PID: 3620)
    • Creates files or folders in the user directory

      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 4960)
      • OneDriveSetup.exe (PID: 1508)
      • OneDrive.exe (PID: 2072)
    • Reads the time zone

      • OneDrive.exe (PID: 3620)
    • Checks proxy server information

      • OneDrive.exe (PID: 3620)
    • The sample compiled with english language support

      • OneDriveSetup.exe (PID: 1508)
    • The sample compiled with portuguese language support

      • OneDriveSetup.exe (PID: 1508)
    • The sample compiled with chinese language support

      • OneDriveSetup.exe (PID: 1508)
    • Launching a file from a Registry key

      • OneDriveSetup.exe (PID: 1508)
    • Reads Environment values

      • OneDrive.exe (PID: 2072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:05:03 14:45:36+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 704512
InitializedDataSize: 162304
UninitializedDataSize: -
EntryPoint: 0xacfe0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 2.0.40.78
ProductVersionNumber: 2.0.40.78
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Kopetra Ltd.
FileVersion: 2.0.40.78
LegalCopyright: ©2023 Kopetra Ltd.
OriginalFileName: Kopetra Ltd..exe
ProductName: Kopetra Ltd.
ProductVersion: 2.0.40.78
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
11
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp no specs 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp rundll32.exe no specs slui.exe onedrive.exe onedrivesetup.exe no specs onedrivesetup.exe filesyncconfig.exe no specs onedrive.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1508C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe /update /restart /updateSource:ODU /peruser /childprocess C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe
OneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\update\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1760"C:\Users\admin\AppData\Local\Temp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe" C:\Users\admin\AppData\Local\Temp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Kopetra Ltd.
Exit code:
1
Version:
2.0.40.78
Modules
Images
c:\users\admin\appdata\local\temp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
1964"C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe" C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exeOneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive Configuration Application
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\21.220.1024.0005\filesyncconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
2072 /updateInstalled /backgroundC:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exeOneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive
Exit code:
2147943660
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\onedrive.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
2612C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3620"C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive
Exit code:
0
Version:
19.043.0304.0013
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\onedrive.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3936"C:\Users\admin\AppData\Local\Temp\is-4ID5I.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp" /SL5="$80230,4079177,867840,C:\Users\admin\AppData\Local\Temp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe" C:\Users\admin\AppData\Local\Temp\is-4ID5I.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-4id5i.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4036C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4960"C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" /update /restart /updateSource:ODU C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exeOneDrive.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\update\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
5348"C:\Users\admin\AppData\Local\Temp\is-285RN.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp" /SL5="$6025A,4079177,867840,C:\Users\admin\AppData\Local\Temp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe" /SPAWNWND=$40302 /NOTIFYWND=$80230 C:\Users\admin\AppData\Local\Temp\is-285RN.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp
979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-285rn.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
Total events
16 246
Read events
15 363
Write events
335
Delete events
548

Modification events

(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\FileSyncClient.AutoPlayHandler\shell\import\DropTarget
Operation:writeName:CLSID
Value:
{5999E1EE-711E-48D2-9884-851A709F543D}
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\BannerNotificationHandler.BannerNotificationHandler\shell\import\DropTarget
Operation:writeName:CLSID
Value:
{2e7c0a19-0438-41e9-81e3-3ad3d64f55ba}
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{F0AF7C30-EAE4-4644-961D-54E6E28708D6}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{F0AF7C30-EAE4-4644-961D-54E6E28708D6}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{9D613F8A-B30E-4938-8490-CB5677701EBF}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{9D613F8A-B30E-4938-8490-CB5677701EBF}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{79A2A54C-3916-41FD-9FAB-F26ED0BBA755}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{79A2A54C-3916-41FD-9FAB-F26ED0BBA755}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{0299ECA9-80B6-43C8-A79A-FB1C5F19E7D8}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{0299ECA9-80B6-43C8-A79A-FB1C5F19E7D8}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
224
Suspicious files
87
Text files
401
Unknown types
0

Dropped files

PID
Process
Filename
Type
1760979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exeC:\Users\admin\AppData\Local\Temp\is-4ID5I.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmpexecutable
MD5:0C60F097BD2E52EB6EAC7F6503A0E514
SHA256:3CDC4C27C131FEC93270BB1E9666121D3500E2E5883AB6C439099EA585383145
6012979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exeC:\Users\admin\AppData\Local\Temp\is-285RN.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmpexecutable
MD5:0C60F097BD2E52EB6EAC7F6503A0E514
SHA256:3CDC4C27C131FEC93270BB1E9666121D3500E2E5883AB6C439099EA585383145
5348979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmpC:\Users\admin\AppData\Local\Temp\is-E5KLL.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
3620OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\Update_2017-09-07_010539_1444-edc.loggzcompressed
MD5:A5134A2CF48AC6170A85C6617F4CA4BA
SHA256:4BAAEADAFE8336613F668EE5A90011FD531C3792D0F6A2E2460C9567D7B7CDC5
3620OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\update100[1].xmlxml
MD5:53244E542DDF6D280A2B03E28F0646B7
SHA256:36A6BD38A8A6F5A75B73CAFFAE5AE66DFABCAEFD83DA65B493FA881EA8A64E7D
3620OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.jsonbinary
MD5:E516A60BC980095E8D156B1A99AB5EEE
SHA256:543796A1B343B4EBC0285D89CB8EB70667AC7B513DA37495E38003704E9D88D7
3620OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\Update_2017-09-07_010407_115c-16f4.loggzcompressed
MD5:0B1B6AEA14319C877AEB7E12E25B6105
SHA256:3B921684D40475A24D4862C1BEC2DC8762542C9AF566ACD514BE023C69093FB3
3620OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\update.xmlxml
MD5:53244E542DDF6D280A2B03E28F0646B7
SHA256:36A6BD38A8A6F5A75B73CAFFAE5AE66DFABCAEFD83DA65B493FA881EA8A64E7D
3620OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\settings\Personal\logUploaderSettings_temp.inibinary
MD5:0C24CB5454D302369C680FAEC849269D
SHA256:73891ADAE04E702F5815A0B874909A6CCD151AEABD221874CD87155E00E4FE9B
3620OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\SyncEngine-2025-06-13.2011.3620.1.aodlbinary
MD5:28DCA2FF4B34B5A52A2E59DF202A6ED3
SHA256:33BACCB7296F1ED1F995FC77A23049F261CF391AC0388F9E8DD161F8C17B7F94
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
29
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5944
MoUsoCoreWorker.exe
GET
200
92.123.102.81:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
92.123.102.81:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
92.122.17.157:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
92.122.17.157:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
436
svchost.exe
GET
200
2.16.70.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6516
SIHClient.exe
GET
200
92.122.17.157:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6516
SIHClient.exe
GET
200
92.122.17.157:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3620
OneDrive.exe
GET
200
2.16.70.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3620
OneDrive.exe
GET
200
2.16.70.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
2940
svchost.exe
GET
200
92.122.17.28:80
http://x1.c.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
92.123.102.81:80
crl.microsoft.com
Akamai International B.V.
RO
whitelisted
5944
MoUsoCoreWorker.exe
92.123.102.81:80
crl.microsoft.com
Akamai International B.V.
RO
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
92.122.17.157:80
www.microsoft.com
AKAMAI-AS
RO
whitelisted
92.122.17.157:80
www.microsoft.com
AKAMAI-AS
RO
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6024
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5348
979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp
18.165.71.33:443
d3salkcn7s3fki.cloudfront.net
US
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 92.123.102.81
whitelisted
google.com
  • 216.58.209.46
whitelisted
www.microsoft.com
  • 92.122.17.157
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
d3salkcn7s3fki.cloudfront.net
  • 18.165.71.33
whitelisted
login.live.com
  • 20.190.181.6
whitelisted
ocsp.digicert.com
  • 2.16.70.4
whitelisted
client.wns.windows.com
  • 98.66.133.185
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.48
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted

Threats

No threats detected
No debug info