Managed XDR

c-program-files-micros...estandaloneupdater.exe — malware analysis report

File info

Filename
c-program-files-microsoft-onedrive-onedrivestandaloneupdater.exe
File type
PE32 executable (DLL) (native) Intel 80386, for MS Windows
File size
13 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
89a366a728171e101bdf2693b44b280c543d9ee5
SHA256
a0e3c52a2c99c39b70155a9115a6c74ea79f8a68111190faa45a8fd1e50f8880
MD5
1352a9210c8d9120f55f98f90fa5fc5c

Signatures

Persistence

T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
message_box: Displays a message