| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Aug-02 23:02:39 |
| Detected languages |
English - United States
|
| TLS Callbacks | 2 callback(s) detected. |
| Debug artifacts |
Embedded COFF debugging symbols
|
| CompanyName | Microsoft Corporation |
| FileDescription | Microsoft OneDrive |
| FileVersion | 23.246.1126.0002 |
| InternalName | OneDrive |
| LegalCopyright | Copyright (c) Microsoft Corporation. All rights reserved. |
| OriginalFilename | OneDrive.exe |
| ProductName | Microsoft OneDrive |
| ProductVersion | 23.246.1126.0002 |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: | Uses constants related to CRC32 |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .buildid
Unusual section name found: /4 Unusual section name found: /18 Unusual section name found: /58 Unusual section name found: /70 Unusual section name found: /82 Unusual section name found: /33 Unusual section name found: /47 |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | The file contains overlay data. | 134656 bytes of data starting at offset 0x11fa00. |
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x78 |
| e_cp | 0x1 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0 |
| e_ss | 0 |
| e_sp | 0 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x78 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 15 |
| TimeDateStamp | 2026-Aug-02 23:02:39 |
| PointerToSymbolTable | 0x11fa00 |
| NumberOfSymbols | 2488 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xd5e00 |
| SizeOfInitializedData | 0x49800 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000001000 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x12f000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| d3d11.dll |
D3D11CreateDeviceAndSwapChain
|
|---|---|
| D3DCOMPILER_47.dll |
D3DCompile
|
| dwmapi.dll |
DwmEnableBlurBehindWindow
DwmGetColorizationColor DwmIsCompositionEnabled DwmSetWindowAttribute |
| KERNEL32.dll |
CloseHandle
CreateFileW CreateProcessW CreateToolhelp32Snapshot DeleteCriticalSection EnterCriticalSection FileTimeToLocalFileTime FileTimeToSystemTime FreeLibrary GetCurrentProcess GetFileAttributesA GetFileTime GetLastError GetLocaleInfoA GetModuleFileNameW GetModuleHandleA GetModuleHandleW GetProcAddress GetStartupInfoW GetTempPathW GlobalAlloc GlobalFree GlobalLock GlobalUnlock InitializeCriticalSection LeaveCriticalSection LoadLibraryA LocalFileTimeToFileTime Module32NextW MultiByteToWideChar OpenThread QueryPerformanceCounter QueryPerformanceFrequency ResumeThread SetFileTime SetUnhandledExceptionFilter Sleep SuspendThread SystemTimeToFileTime Thread32First Thread32Next TlsGetValue VerSetConditionMask VirtualProtect VirtualQuery WideCharToMultiByte WriteFile |
| USER32.dll |
ClientToScreen
CloseClipboard CreateWindowExW DefWindowProcW DestroyWindow DispatchMessageW EmptyClipboard GetCapture GetClientRect GetClipboardData GetCursorPos GetDC GetForegroundWindow GetKeyState GetKeyboardLayout GetMessageExtraInfo IsWindowUnicode LoadCursorA MessageBoxW MonitorFromWindow OpenClipboard PeekMessageW PostQuitMessage RegisterClassExW ReleaseCapture ReleaseDC ScreenToClient SendMessageW SetCapture SetClipboardData SetCursor SetCursorPos SetFocus SetForegroundWindow SetProcessDPIAware SetWindowRgn ShowWindow TrackMouseEvent TranslateMessage UnregisterClassW UpdateWindow |
| GDI32.dll |
CreateRectRgn
CreateRoundRectRgn DeleteObject GetDeviceCaps |
| SHELL32.dll |
DragAcceptFiles
DragFinish DragQueryFileW ShellExecuteA |
| comdlg32.dll |
GetOpenFileNameW
|
| ADVAPI32.dll |
AdjustTokenPrivileges
CloseServiceHandle LookupPrivilegeValueW OpenProcessToken OpenSCManagerW OpenServiceW QueryServiceStatusEx RegCloseKey RegDeleteValueW RegEnumValueW RegOpenKeyExW |
| libc++.dll |
_ZNSt11logic_errorC2EPKc
_ZNSt12length_errorD1Ev _ZNSt12out_of_rangeD1Ev _ZNSt20bad_array_new_lengthC1Ev _ZNSt20bad_array_new_lengthD1Ev _ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKc _ZNSt3__112basic_stringIwNS_11char_traitsIwEENS_9allocatorIwEEE6appendEPKw _ZNSt3__112basic_stringIwNS_11char_traitsIwEENS_9allocatorIwEEE6insertEyPKw _ZNSt3__112basic_stringIwNS_11char_traitsIwEENS_9allocatorIwEEEaSERKS5_ _ZSt9terminatev _ZTVN10__cxxabiv117__class_type_infoE _ZTVN10__cxxabiv120__si_class_type_infoE _ZTVSt12length_error _ZTVSt12out_of_range _ZdlPv _Znwy __cxa_allocate_exception __cxa_begin_catch __cxa_free_exception __cxa_guard_abort __cxa_guard_acquire __cxa_guard_release __cxa_throw __gxx_personality_seh0 |
| libunwind.dll |
_Unwind_Resume
|
| api-ms-win-crt-stdio-l1-1-0.dll |
__acrt_iob_func
__p__commode __p__fmode __stdio_common_vfprintf __stdio_common_vsprintf __stdio_common_vsscanf fclose fflush fopen fread fseek ftell fwrite setvbuf |
| api-ms-win-crt-string-l1-1-0.dll |
_wcsicmp
memset strcmp strlen strncmp strncpy toupper towlower towupper wcslen |
| api-ms-win-crt-runtime-l1-1-0.dll |
__p___argc
__p___wargv __p__wcmdln _cexit _configure_wide_argv _crt_atexit _exit _initialize_wide_environment _initterm _initterm_e _seh_filter_exe _set_app_type _set_invalid_parameter_handler abort exit |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| api-ms-win-crt-math-l1-1-0.dll |
__setusermatherr
acosf atan2f ceilf cosf floorf fmodf log logf pow powf sinf sqrtf |
| api-ms-win-crt-convert-l1-1-0.dll |
atof
atoi |
| api-ms-win-crt-heap-l1-1-0.dll |
_set_new_mode
calloc free malloc |
| api-ms-win-crt-private-l1-1-0.dll |
memchr
memcmp memcpy memmove strchr strstr |
| api-ms-win-crt-utility-l1-1-0.dll |
qsort
|
| api-ms-win-crt-environment-l1-1-0.dll |
__p__wenviron
|
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 23.246.1126.2 |
| ProductVersion | 23.246.1126.2 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Microsoft OneDrive |
| FileVersion (#2) | 23.246.1126.0002 |
| InternalName | OneDrive |
| LegalCopyright | Copyright (c) Microsoft Corporation. All rights reserved. |
| OriginalFilename | OneDrive.exe |
| ProductName | Microsoft OneDrive |
| ProductVersion (#2) | 23.246.1126.0002 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Aug-02 23:02:39 |
| Version | 0.0 |
| SizeofData | 25 |
| AddressOfRawData | 0x10501c |
| PointerToRawData | 0x103e1c |
| StartAddressOfRawData | 0x140115000 |
|---|---|
| EndAddressOfRawData | 0x140115008 |
| AddressOfIndex | 0x140111c20 |
| AddressOfCallbacks | 0x1400fb7b8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_8BYTES
|
| Callbacks |
0x00000001400D4E10
0x00000001400D4E90 |
| Size | 0x138 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0 |
No comments yet.