| File name: | OneDriveStandaloneUpdater.exe.zip |
| Full analysis: | https://app.any.run/tasks/43b75c1f-55da-4227-a145-27bd361f5aed |
| Verdict: | Malicious activity |
| Analysis date: | July 16, 2024, 09:58:03 |
| OS: | Windows 11 Professional (build: 22000, 64 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | CCC1A331FE9F70325FF3ED7C45669B38 |
| SHA1: | 0F66841DF9DEAD30D19C7EEF26004E6DAC9A675F |
| SHA256: | FD91F9B0648CBF44EC61FAFEC5C98742AEEB41AB89A9E7AD0C852941C023B38A |
| SSDEEP: | 49152:4lVqU8VSiZzorqUxIjAI40vdSE+9rCvlON/3ew8muGvUyQxB30t/aNHoXxBu9h8W:W4UQSWzoJIj5Xlr+pN//lxp6301aCPuB |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2024:07:16 09:38:36 |
| ZipCRC: | 0xe6b2b3d6 |
| ZipCompressedSize: | 1709334 |
| ZipUncompressedSize: | 4209056 |
| ZipFileName: | OneDriveStandaloneUpdater.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 252 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\OneDriveStandaloneUpdater.exe.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 432 | "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.77\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\Microsoft\OneDrive\EBWebView" --webview-exe-name=OneDrive.exe --webview-exe-version=24.128.0625.0001 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=1 --mojo-platform-channel-handle=2372 --field-trial-handle=1892,i,1582774147777350670,5190960477022882854,131072 --disable-features=msEnhancedTrackingPreventionEnabled /prefetch:8 | C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.77\msedgewebview2.exe | — | msedgewebview2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge WebView2 Exit code: 0 Version: 103.0.1264.77 Modules
| |||||||||||||||
| 1048 | "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.77\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\Microsoft\OneDrive\EBWebView" --webview-exe-name=OneDrive.exe --webview-exe-version=24.128.0625.0001 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=1 --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1972 --field-trial-handle=1892,i,1582774147777350670,5190960477022882854,131072 --disable-features=msEnhancedTrackingPreventionEnabled /prefetch:2 | C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.77\msedgewebview2.exe | — | msedgewebview2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge WebView2 Exit code: 0 Version: 103.0.1264.77 Modules
| |||||||||||||||
| 1328 | "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.77\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Local\Microsoft\OneDrive\EBWebView /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\Microsoft\OneDrive\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=103.0.5060.134 "--annotation=exe=C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.77\msedgewebview2.exe" --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=103.0.1264.77 --initial-client-data=0x128,0x12c,0x130,0x104,0x138,0x7ff9c0f1a0b8,0x7ff9c0f1a0c8,0x7ff9c0f1a0d8 | C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.77\msedgewebview2.exe | — | msedgewebview2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge WebView2 Exit code: 0 Version: 103.0.1264.77 Modules
| |||||||||||||||
| 1524 | /silentConfig | C:\Program Files\Microsoft OneDrive\24.128.0625.0001\Microsoft.SharePoint.exe | OneDriveSetup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft SharePoint Exit code: 0 Version: 24.128.0625.0001 Modules
| |||||||||||||||
| 1584 | "C:\Program Files\Microsoft OneDrive\OneDrive.exe" /client=Personal /background | C:\Program Files\Microsoft OneDrive\OneDrive.exe | OneDrive.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive Version: 24.128.0625.0001 Modules
| |||||||||||||||
| 2788 | "C:\Program Files\Microsoft OneDrive\24.128.0625.0001\FileSyncConfig.exe" /allusers | C:\Program Files\Microsoft OneDrive\24.128.0625.0001\FileSyncConfig.exe | — | OneDriveSetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft OneDrive Configuration Application Exit code: 0 Version: 24.128.0625.0001 Modules
| |||||||||||||||
| 3344 | "C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe" /update /restart /updateSource:ODSU | C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe | — | OneDriveStandaloneUpdater.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive (64 bit) Setup Exit code: 0 Version: 24.128.0625.0001 Modules
| |||||||||||||||
| 4228 | "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.77\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=OneDrive.exe --webview-exe-version=24.128.0625.0001 --user-data-dir="C:\Users\admin\AppData\Local\Microsoft\OneDrive\EBWebView" --noerrdialogs --embedded-browser-webview-dpi-awareness=1 --disable-features=msEnhancedTrackingPreventionEnabled --mojo-named-platform-channel-pipe=4248.3064.15023526274655039146 | C:\Program Files (x86)\Microsoft\EdgeWebView\Application\103.0.1264.77\msedgewebview2.exe | OneDrive.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge WebView2 Exit code: 0 Version: 103.0.1264.77 Modules
| |||||||||||||||
| 4248 | /updateInstalled /background | C:\Program Files\Microsoft OneDrive\OneDrive.exe | OneDriveSetup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft OneDrive Exit code: 3011 Version: 24.128.0625.0001 Modules
| |||||||||||||||
| (PID) Process: | (252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | VerInfo |
Value: 005B0500AF8954AA66D7DA01 | |||
| (PID) Process: | (252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\OneDriveStandaloneUpdater.exe.zip | |||
| (PID) Process: | (252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (252) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
| (PID) Process: | (4356) OneDriveStandaloneUpdater.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\OneDrive |
| Operation: | write | Name: | StandaloneUpdaterSafeMode |
Value: 2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4356 | OneDriveStandaloneUpdater.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe | — | |
MD5:— | SHA256:— | |||
| 3344 | OneDriveSetup.exe | — | ||
MD5:— | SHA256:— | |||
| 6088 | OneDriveSetup.exe | C:\Windows\TEMP\tmp3A43.tmp | — | |
MD5:— | SHA256:— | |||
| 252 | WinRAR.exe | C:\Users\admin\Desktop\OneDriveStandaloneUpdater.exe | executable | |
MD5:AF274FDDAD0022CB4C01212614D2951C | SHA256:DFFB728A6A95A20E98B509805419C171C1C4FFF6E7F161CBDE32AE6F042FE629 | |||
| 252 | WinRAR.exe | C:\USERS\ADMIN\APPDATA\ROAMING\WINRAR\VERSION.DAT | binary | |
MD5:5297F9F4493539C30862448C18AF7E7E | SHA256:48740A77B1E37B54F3E6BC5FB34B126F2C4131AD97BBA54E881A47F95C6AFCFA | |||
| 252 | WinRAR.exe | C:\Users\admin\Desktop\checksums.txt | text | |
MD5:14CE700A4C749EAF1352CC80CF279AC3 | SHA256:1BD8AF98D4ED95454D9A8F8FAC120B82EB2182F5E5CE93CF1BFAE85407C7BA41 | |||
| 4356 | OneDriveStandaloneUpdater.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\Update.xml | xml | |
MD5:95DBBD688A7A2948A5BE4744F616B710 | SHA256:D60DFD51E7EC89C0007ECA1A9C887AE271D3089CD8179A828A7853951DF514A5 | |||
| 4356 | OneDriveStandaloneUpdater.exe | C:\Users\admin\AppData\Local\Temp\wct8CFC.tmp | binary | |
MD5:63672C40304E4EFAC6F079964748FD8B | SHA256:824EDDBD43047CA616FE82D3F187DCDAF36F111994B7A7FE6FA369167E778FE4 | |||
| 4356 | OneDriveStandaloneUpdater.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\setup\logs\StandaloneUpdate_2024-07-16_095823_4356-4696.log | binary | |
MD5:EA0D00AD9522DE45F2D484C900F80235 | SHA256:99A90243E381EFEB3177EDA10D3BB5FF5A8DAB9E68797B5485A3006B0751F8F6 | |||
| 4356 | OneDriveStandaloneUpdater.exe | C:\Users\admin\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\ECSConfig.json | binary | |
MD5:63672C40304E4EFAC6F079964748FD8B | SHA256:824EDDBD43047CA616FE82D3F187DCDAF36F111994B7A7FE6FA369167E778FE4 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3984 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?7bc59fe8a71b279c | unknown | — | — | whitelisted |
1332 | svchost.exe | GET | 200 | 88.221.110.216:80 | http://www.msftconnecttest.com/connecttest.txt | unknown | — | — | whitelisted |
3984 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1088 | svchost.exe | POST | 403 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409 | unknown | — | — | unknown |
1088 | svchost.exe | POST | 403 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409 | unknown | — | — | unknown |
1088 | svchost.exe | POST | 403 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409 | unknown | — | — | unknown |
1088 | svchost.exe | POST | 403 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409 | unknown | — | — | unknown |
1088 | svchost.exe | POST | 403 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409 | unknown | — | — | unknown |
1088 | svchost.exe | POST | 403 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409 | unknown | — | — | unknown |
1088 | svchost.exe | POST | 403 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkID=252669&clcid=0x409 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4552 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1332 | svchost.exe | 88.221.110.147:80 | — | Akamai International B.V. | DE | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4332 | svchost.exe | 23.35.236.109:443 | fs.microsoft.com | AKAMAI-AS | DE | unknown |
4332 | svchost.exe | 13.74.129.92:443 | g.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4332 | svchost.exe | 23.35.237.43:443 | oneclient.sfx.ms | AKAMAI-AS | DE | unknown |
1332 | svchost.exe | 88.221.110.216:80 | — | Akamai International B.V. | DE | unknown |
3984 | svchost.exe | 40.126.32.72:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
3984 | svchost.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
4356 | OneDriveStandaloneUpdater.exe | 52.113.194.132:443 | ecs.office.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
fs.microsoft.com |
| whitelisted |
g.live.com |
| whitelisted |
oneclient.sfx.ms |
| unknown |
login.live.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ecs.office.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
v10.events.data.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1332 | svchost.exe | Misc activity | ET INFO Microsoft Connection Test |
Process | Message |
|---|---|
msedgewebview2.exe | RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\Microsoft\OneDrive directory exists )
|