File name: | OneDriveStandaloneUpdater.exe |
Full analysis: | https://app.any.run/tasks/da6f8742-662b-4ec5-ab72-3f7d3c5e31f2 |
Verdict: | Malicious activity |
Analysis date: | December 25, 2023, 04:05:45 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | A747FA4161FE3C00C3FBB4BF391D4D4E |
SHA1: | 04A71B457F2C2BB29F2E8D9BA3E28A4F5779272D |
SHA256: | B7BA59428AF7AE08C5BF927B57E326D5259E6ED31BD4237AA6A44378177364C1 |
SSDEEP: | 49152:1ieknwMxRoqaQfNH7EDEbiv8Cpn0lSsqVW8hGAzbD1BpYBNTsk7SxdHbiRDVTC3g:1fknwMxRoqaO7EDWOsqEdRVTC3YzL |
.exe | | | Win32 Executable Borland Delphi 6 (85.5) |
---|---|---|
.exe | | | Win32 Executable Delphi generic (4.6) |
.scr | | | Windows screen saver (4.2) |
.dll | | | Win32 Dynamic Link Library (generic) (2.1) |
.exe | | | Win32 Executable (generic) (1.4) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 1992:06:20 00:22:17+02:00 |
ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 29696 |
InitializedDataSize: | 10752 |
UninitializedDataSize: | - |
EntryPoint: | 0x80e4 |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
120 | "C:\Users\admin\Desktop\OneDriveStandaloneUpdater.exe" | C:\Users\admin\Desktop\OneDriveStandaloneUpdater.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
844 | "C:\Windows\svchost.com" "C:\Users\admin\AppData\Local\MICROS~1\OneDrive\STANDA~1\ONEDRI~1.EXE" /update /selfrepair | C:\Windows\svchost.com | — | OneDriveStandaloneUpdater.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
1732 | C:\Users\admin\AppData\Local\MICROS~1\OneDrive\STANDA~1\ONEDRI~1.EXE /update /updateSource:ODSU | C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe | — | svchost.com | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft OneDrive (32 bit) Setup Exit code: 0 Version: 21.220.1024.0005 Modules
| |||||||||||||||
1796 | "C:\Windows\svchost.com" "C:\Users\admin\AppData\Local\MICROS~1\OneDrive\STANDA~1\ONEDRI~1.EXE" /update /updateSource:ODSU | C:\Windows\svchost.com | — | OneDriveStandaloneUpdater.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2080 | "C:\Users\admin\Desktop\OneDriveStandaloneUpdater.exe" | C:\Users\admin\Desktop\OneDriveStandaloneUpdater.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2168 | C:\Users\admin\AppData\Local\MICROS~1\OneDrive\STANDA~1\ONEDRI~1.EXE /update /selfrepair | C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe | svchost.com | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft OneDrive (32 bit) Setup Exit code: 2147747478 Version: 21.220.1024.0005 Modules
| |||||||||||||||
2416 | "C:\Users\admin\AppData\Local\Temp\3582-490\OneDriveStandaloneUpdater.exe" | C:\Users\admin\AppData\Local\Temp\3582-490\OneDriveStandaloneUpdater.exe | — | OneDriveStandaloneUpdater.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Standalone Updater Exit code: 0 Version: 19.043.0304.0013 Modules
|
(PID) Process: | (2080) OneDriveStandaloneUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (2080) OneDriveStandaloneUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (2080) OneDriveStandaloneUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (2080) OneDriveStandaloneUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (2416) OneDriveStandaloneUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\PreSignInSettingsConfigJSON |
Operation: | delete value | Name: | GUID |
Value: EC771EDE6F86FE4E8F68B0D566DCAC5A | |||
(PID) Process: | (2416) OneDriveStandaloneUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\PreSignInSettingsConfigJSON |
Operation: | delete value | Name: | File |
Value: wctFF30.tmp | |||
(PID) Process: | (2416) OneDriveStandaloneUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\PreSignInSettingsConfigJSON |
Operation: | delete key | Name: | (default) |
Value: | |||
(PID) Process: | (2416) OneDriveStandaloneUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\UpdateDescriptionXml |
Operation: | delete value | Name: | GUID |
Value: E2A5ADCC3101B34F9CC0B10369E999AD | |||
(PID) Process: | (2416) OneDriveStandaloneUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\UpdateDescriptionXml |
Operation: | delete value | Name: | File |
Value: wct859.tmp | |||
(PID) Process: | (2416) OneDriveStandaloneUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\OneDrive\Installer\BITS\UpdateDescriptionXml |
Operation: | delete key | Name: | (default) |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
2080 | OneDriveStandaloneUpdater.exe | C:\Users\admin\AppData\Local\Temp\3582-490\OneDriveStandaloneUpdater.exe | executable | |
MD5:BDFF068C4C23E586A2013708D6A75C9A | SHA256:7C965138CD0AAC6920C9C7E2E68F2432A0F32F6B6CC0210E44E4CE7CA4B2C59B | |||
2080 | OneDriveStandaloneUpdater.exe | C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\DW20.EXE | executable | |
MD5:02EE6A3424782531461FB2F10713D3C1 | SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC | |||
2080 | OneDriveStandaloneUpdater.exe | C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe | executable | |
MD5:566ED4F62FDC96F175AFEDD811FA0370 | SHA256:E17CD94C08FC0E001A49F43A0801CEA4625FB9AEE211B6DFEBEBEC446C21F460 | |||
2080 | OneDriveStandaloneUpdater.exe | C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\ose.exe | executable | |
MD5:58B58875A50A0D8B5E7BE7D6AC685164 | SHA256:2A0AA0763FDEF9C38C5DD4D50703F0C7E27F4903C139804EC75E55F8388139AE | |||
2080 | OneDriveStandaloneUpdater.exe | C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\dwtrig20.exe | executable | |
MD5:CF6C595D3E5E9667667AF096762FD9C4 | SHA256:593E60CC30AE0789448547195AF77F550387F6648D45847EA244DD0DD7ABF03D | |||
2080 | OneDriveStandaloneUpdater.exe | C:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\dwtrig20.exe | executable | |
MD5:CF6C595D3E5E9667667AF096762FD9C4 | SHA256:593E60CC30AE0789448547195AF77F550387F6648D45847EA244DD0DD7ABF03D | |||
2080 | OneDriveStandaloneUpdater.exe | C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\dwtrig20.exe | executable | |
MD5:CF6C595D3E5E9667667AF096762FD9C4 | SHA256:593E60CC30AE0789448547195AF77F550387F6648D45847EA244DD0DD7ABF03D | |||
2080 | OneDriveStandaloneUpdater.exe | C:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\DW20.EXE | executable | |
MD5:02EE6A3424782531461FB2F10713D3C1 | SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC | |||
2080 | OneDriveStandaloneUpdater.exe | C:\MSOCache\All Users\{90140000-006E-0410-0000-0000000FF1CE}-C\dwtrig20.exe | executable | |
MD5:CF6C595D3E5E9667667AF096762FD9C4 | SHA256:593E60CC30AE0789448547195AF77F550387F6648D45847EA244DD0DD7ABF03D | |||
2080 | OneDriveStandaloneUpdater.exe | C:\MSOCache\All Users\{90140000-006E-0410-0000-0000000FF1CE}-C\DW20.EXE | executable | |
MD5:02EE6A3424782531461FB2F10713D3C1 | SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2168 | OneDriveSetup.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | binary | 471 b | — |
2168 | OneDriveSetup.exe | GET | 200 | 23.32.238.219:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?829dc20ce0c61145 | unknown | compressed | 4.66 Kb | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1652 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
856 | svchost.exe | 68.219.88.225:443 | g.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
856 | svchost.exe | 184.30.17.30:443 | oneclient.sfx.ms | AKAMAI-AS | DE | unknown |
2168 | OneDriveSetup.exe | 20.189.173.8:443 | self.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2168 | OneDriveSetup.exe | 23.32.238.219:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
2168 | OneDriveSetup.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | unknown |
Domain | IP | Reputation |
---|---|---|
g.live.com |
| unknown |
oneclient.sfx.ms |
| unknown |
self.events.data.microsoft.com |
| unknown |
ctldl.windowsupdate.com |
| unknown |
ocsp.digicert.com |
| unknown |