| File name: | OneDrive.exe |
| Full analysis: | https://app.any.run/tasks/0415f774-da52-45be-aa99-f2163dea2890 |
| Verdict: | Malicious activity |
| Analysis date: | August 09, 2024, 13:20:47 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows |
| MD5: | 52C22670F89DBB434CC24532E1BE3C33 |
| SHA1: | 5FA630B3B3C4A187590AC717578CC09F636225DF |
| SHA256: | E4EFF86A543E63621D7419ED2D46C90D8803F5D606CA4C904BA0B9107F86430D |
| SSDEEP: | 98304:yipxrS0iKMApTSBprc6thcFopJwlw73UlSKC+qvc2NMDzsjFhXpr528L8YpGMw4H:BjYwc |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2089:09:28 15:52:53+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.33 |
| CodeSize: | 671232 |
| InitializedDataSize: | 4249088 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x74ff0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 24.141.714.3 |
| ProductVersionNumber: | 24.141.714.3 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Special build |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft OneDrive |
| InternalName: | Client Application |
| LegalCopyright: | © Microsoft Corporation. All rights reserved. |
| OriginalFileName: | OneDrive.exe |
| ProductName: | Microsoft OneDrive |
| FileVersion: | 24.141.0714.0003 |
| ProductVersion: | 24.141.0714.0003 |
| SpecialBuild: | b/build/12f970f4-c552-6903-8ed5-7c3628165aad |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 640 | C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe /update /restart /updateSource:ODU /peruser /childprocess | C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe | OneDriveSetup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive (32 bit) Setup Version: 21.220.1024.0005 Modules
| |||||||||||||||
| 2464 | /updateInstalled /background | C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe | — | OneDriveSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive Exit code: 2147943660 Version: 21.220.1024.0005 | |||||||||||||||
| 4436 | "C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe" /update /restart /updateSource:ODU | C:\Users\admin\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe | — | OneDrive.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive (32 bit) Setup Version: 21.220.1024.0005 Modules
| |||||||||||||||
| 5196 | "C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca | C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Version: 123.26505.0.0 Modules
| |||||||||||||||
| 5980 | "C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe" | C:\Users\admin\AppData\Local\Microsoft\OneDrive\21.220.1024.0005\FileSyncConfig.exe | — | OneDriveSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive Configuration Application Exit code: 0 Version: 21.220.1024.0005 Modules
| |||||||||||||||
| 6516 | "C:\Users\admin\AppData\Local\Temp\OneDrive.exe" | C:\Users\admin\AppData\Local\Temp\OneDrive.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive Exit code: 0 Version: 24.141.0714.0003 Modules
| |||||||||||||||
| 7220 | "C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" | C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive Exit code: 0 Version: 19.043.0304.0013 Modules
| |||||||||||||||
| (PID) Process: | (7220) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} |
| Operation: | write | Name: | ContextMenuOptIn |
Value: | |||
| (PID) Process: | (7220) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\Interface\{31508CC7-9BC7-494B-9D0F-7B1C7F144182}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7220) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\Interface\{31508CC7-9BC7-494B-9D0F-7B1C7F144182}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7220) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\Interface\{466F31F7-9892-477E-B189-FA5C59DE3603}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7220) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\Interface\{466F31F7-9892-477E-B189-FA5C59DE3603}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7220) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\Interface\{869BDA08-7ACF-42B8-91AE-4D8D597C0B33}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7220) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\Interface\{869BDA08-7ACF-42B8-91AE-4D8D597C0B33}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7220) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\Interface\{679EC955-75AA-4FB2-A7ED-8C0152ECF409}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7220) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\Interface\{679EC955-75AA-4FB2-A7ED-8C0152ECF409}\TypeLib |
| Operation: | write | Name: | Version |
Value: 1.0 | |||
| (PID) Process: | (7220) OneDrive.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{4410DC33-BC7C-496B-AA84-4AEA3EEE75F7}\InProcServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7220 | OneDrive.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\DeviceFailureDatagram\DeviceHealthSummaryConfiguration.ini | text | |
MD5:EC11527958588ABE60A78BD1EF2CDE36 | SHA256:4BCB69B814365DC9D84EC0C938DD2E71A79330E4C7126F3ABE2603258E743AD3 | |||
| 7220 | OneDrive.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\telemetryCache.otc.session | sqlite | |
MD5:580BD824DEBBA908591408D7A5A3D01F | SHA256:B3218FF93047231A34C6962C758A36D412C2EB928C33F7EE537023EB6E489974 | |||
| 7220 | OneDrive.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A | der | |
MD5:34F8138A6FADB2F66238D113044AE449 | SHA256:A01A38D75E991F6F165833FD0003F28C3909344DF0D84F2160CB7D0BCEAC0453 | |||
| 7220 | OneDrive.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\Install_2017-09-07_021906_8a8-14d8.loggz | compressed | |
MD5:3FD9A485C3978A39655CF91806C9B100 | SHA256:3B61785C24B3F6FCF1441D5F39156337C628D7691854E81C017D2C03C5DC1E82 | |||
| 7220 | OneDrive.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04 | der | |
MD5:2C48D78B2AE297D1C4A77C26F8E3DA5C | SHA256:CEB8F54E3D4E734B242559100D8C2A7E7E749B35F2147EC6E42E65368783FA6C | |||
| 7220 | OneDrive.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04 | binary | |
MD5:BA0952D41981009CD77E3B14546097F6 | SHA256:F59878256BB122B07CC3341DDD49C8AE7127FFA951758B39D0902E27835208A8 | |||
| 7220 | OneDrive.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\TraceArchive.0304.0013-36.etl | abr | |
MD5:97596EEBD1886A7637AEC1F4739959FC | SHA256:43A342C94BDA9B236D3D1F45711C0B2FB9FA179CF7E0C9252E6DB0EE1930811F | |||
| 7220 | OneDrive.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\logs\Personal\Update_2017-09-07_010539_1444-edc.loggz | compressed | |
MD5:A5134A2CF48AC6170A85C6617F4CA4BA | SHA256:4BAAEADAFE8336613F668EE5A90011FD531C3792D0F6A2E2460C9567D7B7CDC5 | |||
| 7220 | OneDrive.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\settings\PreSignInSettingsConfig.json | binary | |
MD5:E516A60BC980095E8D156B1A99AB5EEE | SHA256:543796A1B343B4EBC0285D89CB8EB70667AC7B513DA37495E38003704E9D88D7 | |||
| 7220 | OneDrive.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A | binary | |
MD5:36E0DB9116A6AC9F8D8E8B52D8F3E54D | SHA256:A2B1F15B06BD020B2E1D9146BE316AE560646A05178F3B3800C552DEC0AE2583 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6808 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7220 | OneDrive.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
2456 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6868 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
7220 | OneDrive.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2532 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2680 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2532 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5336 | SearchApp.exe | 184.86.251.28:443 | www.bing.com | Akamai International B.V. | DE | unknown |
5336 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
2456 | svchost.exe | 40.126.31.71:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
th.bing.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
r.bing.com |
| whitelisted |