OneDriveSetup.exe

  • File Path: C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe
  • Description: Microsoft OneDrive Setup

Hashes

Type Hash
MD5 11D5E2EF5D9A0E009DF8CC61F4706982
SHA1 416771469332479A94822CD1B70B26AFC6F02DFC
SHA256 17A5F35C30B9D1DBB651686407DBF7D1BDCC685426581AF6796B364550E7FE70
SHA384 8D3D7037FA021D13FB116CF1537027F06FC8EC6AC5E6114728470251C290BAD4D57944EF09A37CC34E0089442C3F32DB
SHA512 07AE5570A8EEAC8B83B26684419B66115211E06300AE4A888B1C609C90A583121AB2DEAB736A8D584BC869587D3435C2D237F14D3FA4E1786F749A63C81A776B
SSDEEP 393216:xw5ZbDO6RGmb8hFZtxwbTNXp3YCkxJoPMAvqkWgoj6RVFK+q3HvUUw0vXL:xWO1c877xqpyovvVWJ6VFK+q3cSvXL
IMP 059AC5CD530DD28EAD72A380619D30D7
PESHA1 FA2EF04627D1617F6F437D85148EE7B072B51B05
PE256 A6FD3DDF8C4F8A8A2741396F965673A0E6FA2845D1D9986F1DDB4170235D67FD

Runtime Data

Child Processes:

OneDriveSetup.exe

Open Handles:

Path Type
(—) \FileSystem\Filters\FltMgrMsg File
(R–) C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe File
(R–) C:\Users\user\AppData\Local\Microsoft\OneDrive\logs\setup\Install-2020-10-4.1546.5276.1.aodl File
(R–) C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs\Install_2020-10-04_154618_149c-17c8.log File
(R–) C:\Users\user\AppData\Local\Temp\tmpFA2D.tmp File
(R-D) C:\Users\user\AppData\Local\Temp\wctF838.tmp File
(R-D) C:\Windows\System32\en-US\crypt32.dll.mui File
(R-D) C:\Windows\System32\en-US\KernelBase.dll.mui File
(RW-) C:\Users\user\AppData\Local\Temp\aria-debug-5276.log File
(RW-) C:\Users\user\Documents File
(RW-) C:\Windows File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627 File
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.508_none_429cdbca8a8ffa94 File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\Sessions\1\BaseNamedObjects\windows_shell_global_counters Section

Loaded Modules:

Path
C:\Program Files (x86)\Microsoft Office\root\Integration\Addons\OneDriveSetup.exe
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll

Signature

  • Status: Signature verified.
  • Serial: 33000001B1DDEDBA54E965B85F0001000001B1
  • Thumbprint: 9DC17888B5CFAD98B3CB35C1994E96227F061675
  • Issuer: CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: OneDriveSetup.exe
  • Product Name: Microsoft OneDrive
  • Company Name: Microsoft Corporation
  • File Version: 18.151.0729.0013
  • Product Version: 18.151.0729.0013
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/72
  • VirusTotal Link: https://www.virustotal.com/gui/file/17a5f35c30b9d1dbb651686407dbf7d1bdcc685426581af6796b364550e7fe70/detection/

Possible Misuse

The following table contains possible examples of OneDriveSetup.exe being misused. While OneDriveSetup.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma registry_event_asep_reg_keys_modification_currentversion.yml - '\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe' # C:\Users\*\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe DRL 1.0
sigma registry_event_asep_reg_keys_modification_currentversion.yml - 'C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.