OneDriveSetup.exe

  • File Path: C:\WINDOWS\SysWOW64\OneDriveSetup.exe
  • Description: Microsoft OneDrive Setup

Hashes

Type Hash
MD5 1941AED7D47CA3A8DA33D98B6D877E88
SHA1 2D6B07ED820BFD92382D46B28CF43409867458C3
SHA256 9B1D2D09D162A0B6558828017E47A06357BA1B19FE1B0F746934692D69976CC6
SHA384 70258AB8559CBD08D2BEE7D8ED865C989428B4C12A6A29C6548392FE499664C08A528FF56317922C585818CAE3C32D22
SHA512 159D0F8A8ECFD4E95174326DB607A2FFCC77F1DDE376022E5D1A9C3FF9DEA5D1E18C1E0D42E5CCF7CC2CE5183A501D5CB767D78E344FF915EEB1F565274B6073
SSDEEP 786432:9i5ecJ5QH6G5hH/g4vx9w5rTc/it1G80kvKv9NwzdvSgHWW:9itJG9PHY4vHw5GiW80kvKv9NwZvSgB

Runtime Data

Child Processes:

OneDriveSetup.exe

Signature

  • Status: Signature verified.
  • Serial: 33000001C422B2F79B793DACB20000000001C4
  • Thumbprint: AE9C1AE54763822EEC42474983D8B635116C8452
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: OneDriveSetup.exe
  • Product Name: Microsoft OneDrive
  • Company Name: Microsoft Corporation
  • File Version: 19.002.0107.0005
  • Product Version: 19.002.0107.0005
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.

Possible Misuse

The following table contains possible examples of OneDriveSetup.exe being misused. While OneDriveSetup.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma registry_event_asep_reg_keys_modification_currentversion.yml - '\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe' # C:\Users\*\AppData\Local\Microsoft\OneDrive\Update\OneDriveSetup.exe DRL 1.0
sigma registry_event_asep_reg_keys_modification_currentversion.yml - 'C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.