File name:

979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898

Full analysis: https://app.any.run/tasks/92804ec5-0075-43a6-a760-d5da81693b3f
Verdict: Malicious activity
Analysis date: June 13, 2025, 20:10:38
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
delphi
inno
installer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

56A771336CBE0A3AA0049DC1306EAFF5

SHA1:

013EB70916260A36D4AACBF57D35FBCDEBCB6042

SHA256:

979ED241AC85B0B19E20C63106A3F83BF8DF0A8480FC637042696C580AA55898

SSDEEP:

98304:3LVIF8P3n1BLHxtD59KEKjSvDQgokZWtKsovt0FcN2TFOMR8gW6rijUNG2KOYGcz:BsYr3t/m7qoEJ+mBZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • OneDriveSetup.exe (PID: 1508)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 1760)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 6012)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDriveSetup.exe (PID: 1508)
    • Reads security settings of Internet Explorer

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
      • OneDriveSetup.exe (PID: 1508)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 4960)
    • Reads the Windows owner or organization settings

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
    • Creates/Modifies COM task schedule object

      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 1508)
    • Application launched itself

      • OneDriveSetup.exe (PID: 4960)
    • There is functionality for taking screenshot (YARA)

      • OneDrive.exe (PID: 3620)
    • The process creates files with name similar to system file names

      • OneDriveSetup.exe (PID: 1508)
    • The process drops C-runtime libraries

      • OneDriveSetup.exe (PID: 1508)
    • Creates a software uninstall entry

      • OneDriveSetup.exe (PID: 1508)
    • Process drops legitimate windows executable

      • OneDriveSetup.exe (PID: 1508)
  • INFO

    • Checks supported languages

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 1760)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 6012)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 4960)
      • OneDriveSetup.exe (PID: 1508)
      • FileSyncConfig.exe (PID: 1964)
      • OneDrive.exe (PID: 2072)
    • Create files in a temporary directory

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 1760)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 6012)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 1508)
    • Reads the computer name

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 6012)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 4960)
      • OneDriveSetup.exe (PID: 1508)
      • OneDrive.exe (PID: 2072)
    • Process checks computer location settings

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 1508)
    • Detects InnoSetup installer (YARA)

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 1760)
    • Compiled with Borland Delphi (YARA)

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 3936)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe (PID: 1760)
    • Reads the time zone

      • OneDrive.exe (PID: 3620)
    • Reads CPU info

      • OneDrive.exe (PID: 3620)
    • Reads the machine GUID from the registry

      • OneDrive.exe (PID: 3620)
      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDriveSetup.exe (PID: 4960)
      • OneDriveSetup.exe (PID: 1508)
      • OneDrive.exe (PID: 2072)
    • Reads the software policy settings

      • 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp (PID: 5348)
      • OneDriveSetup.exe (PID: 1508)
      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 4960)
    • Manual execution by a user

      • OneDrive.exe (PID: 3620)
    • Creates files or folders in the user directory

      • OneDrive.exe (PID: 3620)
      • OneDriveSetup.exe (PID: 4960)
      • OneDriveSetup.exe (PID: 1508)
      • OneDrive.exe (PID: 2072)
    • Checks proxy server information

      • OneDrive.exe (PID: 3620)
    • The sample compiled with portuguese language support

      • OneDriveSetup.exe (PID: 1508)
    • The sample compiled with chinese language support

      • OneDriveSetup.exe (PID: 1508)
    • Reads Environment values

      • OneDrive.exe (PID: 2072)
    • Launching a file from a Registry key

      • OneDriveSetup.exe (PID: 1508)
    • The sample compiled with english language support

      • OneDriveSetup.exe (PID: 1508)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:05:03 14:45:36+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 2.25
CodeSize: 704512
InitializedDataSize: 162304
UninitializedDataSize: -
EntryPoint: 0xacfe0
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 2.0.40.78
ProductVersionNumber: 2.0.40.78
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Kopetra Ltd.
FileVersion: 2.0.40.78
LegalCopyright: ©2023 Kopetra Ltd.
OriginalFileName: Kopetra Ltd..exe
ProductName: Kopetra Ltd.
ProductVersion: 2.0.40.78
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
11
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp no specs 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe 979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp rundll32.exe no specs slui.exe onedrive.exe onedrivesetup.exe no specs onedrivesetup.exe filesyncconfig.exe no specs onedrive.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1508C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe /update /restart /updateSource:ODU /peruser /childprocess C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe
OneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\update\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1760"C:\Users\admin\AppData\Local\Temp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe" C:\Users\admin\AppData\Local\Temp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Kopetra Ltd.
Exit code:
1
Version:
2.0.40.78
Modules
Images
c:\users\admin\appdata\local\temp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
1964"C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe" C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exeOneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive Configuration Application
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\21.220.1024.0005\filesyncconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
2072 /updateInstalled /backgroundC:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exeOneDriveSetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive
Exit code:
2147943660
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\onedrive.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
2612C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3620"C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive
Exit code:
0
Version:
19.043.0304.0013
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\onedrive.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3936"C:\Users\admin\AppData\Local\Temp\is-4ID5I.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp" /SL5="$80230,4079177,867840,C:\Users\admin\AppData\Local\Temp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe" C:\Users\admin\AppData\Local\Temp\is-4ID5I.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-4id5i.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4036C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4960"C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" /update /restart /updateSource:ODU C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exeOneDrive.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneDrive (32 bit) Setup
Exit code:
0
Version:
21.220.1024.0005
Modules
Images
c:\users\admin\appdata\local\microsoft\onedrive\update\onedrivesetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
5348"C:\Users\admin\AppData\Local\Temp\is-285RN.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp" /SL5="$6025A,4079177,867840,C:\Users\admin\AppData\Local\Temp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe" /SPAWNWND=$40302 /NOTIFYWND=$80230 C:\Users\admin\AppData\Local\Temp\is-285RN.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp
979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-285rn.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
Total events
16 246
Read events
15 363
Write events
335
Delete events
548

Modification events

(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\FileSyncClient.AutoPlayHandler\shell\import\DropTarget
Operation:writeName:CLSID
Value:
{5999E1EE-711E-48D2-9884-851A709F543D}
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\BannerNotificationHandler.BannerNotificationHandler\shell\import\DropTarget
Operation:writeName:CLSID
Value:
{2e7c0a19-0438-41e9-81e3-3ad3d64f55ba}
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{F0AF7C30-EAE4-4644-961D-54E6E28708D6}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{F0AF7C30-EAE4-4644-961D-54E6E28708D6}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{9D613F8A-B30E-4938-8490-CB5677701EBF}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{9D613F8A-B30E-4938-8490-CB5677701EBF}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{79A2A54C-3916-41FD-9FAB-F26ED0BBA755}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{79A2A54C-3916-41FD-9FAB-F26ED0BBA755}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\Interface\{0299ECA9-80B6-43C8-A79A-FB1C5F19E7D8}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(3620) OneDrive.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\Interface\{0299ECA9-80B6-43C8-A79A-FB1C5F19E7D8}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
224
Suspicious files
87
Text files
401
Unknown types
0

Dropped files

PID
Process
Filename
Type
6012979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.exeC:\Users\admin\AppData\Local\Temp\is-285RN.tmp\979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmpexecutable
MD5:0C60F097BD2E52EB6EAC7F6503A0E514
SHA256:3CDC4C27C131FEC93270BB1E9666121D3500E2E5883AB6C439099EA585383145
5348979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmpC:\Users\admin\AppData\Local\Temp\is-E5KLL.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
3620OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\TraceArchive.0304.0013-36.etlbinary
MD5:97596EEBD1886A7637AEC1F4739959FC
SHA256:43A342C94BDA9B236D3D1F45711C0B2FB9FA179CF7E0C9252E6DB0EE1930811F
3620OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\telemetryCache.otc.sessionbinary
MD5:580BD824DEBBA908591408D7A5A3D01F
SHA256:B3218FF93047231A34C6962C758A36D412C2EB928C33F7EE537023EB6E489974
3620OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\SyncEngine-2025-06-13.2011.3620.1.aodlbinary
MD5:28DCA2FF4B34B5A52A2E59DF202A6ED3
SHA256:33BACCB7296F1ED1F995FC77A23049F261CF391AC0388F9E8DD161F8C17B7F94
3620OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:CABF6D1E824711EB4725174A9E48BA6F
SHA256:0E96D9DF3EBB4ACBF03BC3DBEF55C3CAA10A66E0D985F46D2E7A7AE61D33E4FA
3620OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:C006D2261A9E4692140D8E4381FB3403
SHA256:6A932AE9D47F22933661D71C921107122B327E4F0B4F7D1601018879B354A1FD
3620OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:400B065B0CD793090EC25BC9E898790E
SHA256:665480CC2ACA0A5588C9A73EE4D86AC9F035EE143EF05096DC58327CEF71440C
3620OneDrive.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:2AF438423129843CBFB69C7065F11070
SHA256:B7CDE3438E7E78EAD8179C5CDDF4D4E40F326DA3E6C7E4211F564E617BB22711
3620OneDrive.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\PreSignInSettingsConfig[1].jsonbinary
MD5:E516A60BC980095E8D156B1A99AB5EEE
SHA256:543796A1B343B4EBC0285D89CB8EB70667AC7B513DA37495E38003704E9D88D7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
29
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
92.123.102.81:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
92.123.102.81:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
92.122.17.157:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
92.122.17.157:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
436
svchost.exe
GET
200
2.16.70.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6516
SIHClient.exe
GET
200
92.122.17.157:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6516
SIHClient.exe
GET
200
92.122.17.157:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3620
OneDrive.exe
GET
200
2.16.70.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
3620
OneDrive.exe
GET
200
2.16.70.4:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
2940
svchost.exe
GET
200
92.122.17.28:80
http://x1.c.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
92.123.102.81:80
crl.microsoft.com
Akamai International B.V.
RO
whitelisted
5944
MoUsoCoreWorker.exe
92.123.102.81:80
crl.microsoft.com
Akamai International B.V.
RO
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
92.122.17.157:80
www.microsoft.com
AKAMAI-AS
RO
whitelisted
92.122.17.157:80
www.microsoft.com
AKAMAI-AS
RO
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6024
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5348
979ed241ac85b0b19e20c63106a3f83bf8df0a8480fc637042696c580aa55898.tmp
18.165.71.33:443
d3salkcn7s3fki.cloudfront.net
US
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 92.123.102.81
whitelisted
google.com
  • 216.58.209.46
whitelisted
www.microsoft.com
  • 92.122.17.157
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
d3salkcn7s3fki.cloudfront.net
  • 18.165.71.33
whitelisted
login.live.com
  • 20.190.181.6
whitelisted
ocsp.digicert.com
  • 2.16.70.4
whitelisted
client.wns.windows.com
  • 98.66.133.185
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.48
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted

Threats

No threats detected
No debug info