.. /OneDriveStandaloneUpdater.exe
Star

Download

OneDrive Standalone Updater


Paths:

Resources:
Acknowledgements:

Detection:

Download

  1. Download a file from the web address specified in HKCU\Software\Microsoft\OneDrive\UpdateOfficeConfig\UpdateRingSettingURLFromOC. ODSUUpdateXMLUrlFromOC and UpdateXMLUrlFromOC must be equal to non-empty string values in that same registry key. UpdateOfficeConfigTimestamp is a UNIX epoch time which must be set to a large QWORD such as 99999999999 (in decimal) to indicate the URL cache is good. The downloaded file will be in %localappdata%\OneDrive\StandaloneUpdater\PreSignInSettingsConfig.json

    OneDriveStandaloneUpdater
    Use case
    Download a file from the Internet without executing any anomalous executables with suspicious arguments
    Privileges required
    User
    Operating systems
    Windows 10
    ATT&CK® technique
    T1105