Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
onedrive.bat.exe

Overview

General Information

Sample Name:onedrive.bat.exe
Analysis ID:829696
MD5:c32ca4acfcc635ec1ea6ed8a34df5fac
SHA1:f5ee89bb1e4a0b1c3c7f1e8d05d0677f2b2b5919
SHA256:73a3c4aef5de385875339fc2eb7e58a9e8a47b6161bdc6436bf78a763537be70
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:true
Confidence:100%

Signatures

Uses 32bit PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Tries to load missing DLLs
Uses code obfuscation techniques (call, push, ret)
Queries the installation date of Windows
Detected potential crypto function
Sample execution stops while process was sleeping (likely an evasion)
Enables debug privileges

Classification

  • System is w10x64native
  • onedrive.bat.exe (PID: 4720 cmdline: C:\Users\user\Desktop\onedrive.bat.exe MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC)
    • conhost.exe (PID: 6244 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: onedrive.bat.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: onedrive.bat.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: Binary string: powershell.pdbUGP source: onedrive.bat.exe
Source: Binary string: powershell.pdb source: onedrive.bat.exe
Source: onedrive.bat.exe, 00000002.00000003.103961663238.0000000002954000.00000004.00000020.00020000.00000000.sdmp, onedrive.bat.exe, 00000002.00000002.105188091472.000000000295D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: onedrive.bat.exe, 00000002.00000003.103961663238.0000000002954000.00000004.00000020.00020000.00000000.sdmp, onedrive.bat.exe, 00000002.00000002.105188091472.000000000295D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048D3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048D3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/pscore6LR
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/pscore6lB
Source: onedrive.bat.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048C5000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamePowerShell.EXEj% vs onedrive.bat.exe
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048C5000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: q,\\StringFileInfo\\040904B0\\OriginalFilename vs onedrive.bat.exe
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048B2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Management.Automation.dllv+ vs onedrive.bat.exe
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048B2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: q,\\StringFileInfo\\000004B0\\OriginalFilename vs onedrive.bat.exe
Source: onedrive.bat.exe, 00000002.00000000.103939392812.0000000000564000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamePowerShell.EXEj% vs onedrive.bat.exe
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048A1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSystem.Management.Automation.dllv+ vs onedrive.bat.exe
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048A1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs onedrive.bat.exe
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048A1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: q,\\StringFileInfo\\000004B0\\OriginalFilename vs onedrive.bat.exe
Source: onedrive.bat.exe, 00000002.00000002.105188091472.00000000028B6000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs onedrive.bat.exe
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000049F8000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFileName vs onedrive.bat.exe
Source: onedrive.bat.exeBinary or memory string: OriginalFilenamePowerShell.EXEj% vs onedrive.bat.exe
Source: C:\Users\user\Desktop\onedrive.bat.exeSection loaded: edgegdi.dll
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_047DEBC8
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_047DEBB8
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CB81B8
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CB81B1
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CF6D18
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CFEAC8
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CF9150
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CFEABD
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07EE7DA8
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07EE2478
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07EE8ED0
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07EE5E90
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07EE4678
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07EE3C60
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07EEB240
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07EE3218
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07F00040
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07F0ED92
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07F052C0
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07F052B8
Source: onedrive.bat.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\onedrive.bat.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\onedrive.bat.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\e4a1c9189d2b01f018b953e46c80d120\mscorlib.ni.dll
Source: unknownProcess created: C:\Users\user\Desktop\onedrive.bat.exe C:\Users\user\Desktop\onedrive.bat.exe
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\onedrive.bat.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\InProcServer32
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6244:304:WilStaging_02
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6244:120:WilError_03
Source: onedrive.bat.exeJoe Sandbox Cloud Basic: Detection: clean Score: 6Perma Link
Source: C:\Users\user\Desktop\onedrive.bat.exeFile created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_tw0strn3.bud.ps1Jump to behavior
Source: classification engineClassification label: clean5.winEXE@2/2@0/0
Source: C:\Users\user\Desktop\onedrive.bat.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
Source: onedrive.bat.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: onedrive.bat.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: onedrive.bat.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: onedrive.bat.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: onedrive.bat.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: onedrive.bat.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: onedrive.bat.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: onedrive.bat.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: powershell.pdbUGP source: onedrive.bat.exe
Source: Binary string: powershell.pdb source: onedrive.bat.exe
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CB3798 push esi; retf 0007h
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CB3787 push ebx; retf 0007h
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CB57B0 push esp; retf 0007h
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CB3C10 push edi; retf 0007h
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CFDA58 push 0807CA01h; retn 076Ah
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CFE659 push es; retf 0007h
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CFE8FD push 00000007h; ret
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CFF589 push cs; retf 0007h
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CF7380 push 00000007h; ret
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CF9022 push eax; retf
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07EEAA6A push 8B059113h; iretd
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\onedrive.bat.exeWindow / User API: threadDelayed 7690
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess information queried: ProcessInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeProcess token adjusted: Debug
Source: C:\Users\user\Desktop\onedrive.bat.exeMemory allocated: page read and write | page guard
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\onedrive.bat.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion InstallDate
Source: C:\Users\user\Desktop\onedrive.bat.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
Source: C:\Users\user\Desktop\onedrive.bat.exeCode function: 2_2_07CFDE0C CreateNamedPipeW,
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management Instrumentation1
DLL Side-Loading
2
Process Injection
1
Disable or Modify Tools
OS Credential Dumping1
Process Discovery
Remote Services1
Archive Collected Data
Exfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
2
Process Injection
LSASS Memory1
Application Window Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account Manager22
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
Obfuscated Files or Information
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 829696 Sample: onedrive.bat.exe Startdate: 19/03/2023 Architecture: WINDOWS Score: 0 5 onedrive.bat.exe 8 2->5         started        process3 7 conhost.exe 5->7         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.