Adding file paths (#416)

This commit is contained in:
ciwen3
2025-01-14 07:12:42 -08:00
committed by GitHub
parent b9a6cd6a87
commit e62749f81a
5 changed files with 8 additions and 0 deletions

View File

@@ -13,6 +13,8 @@ Commands:
OperatingSystem: Windows 10
Full_Path:
- Path: 'C:\Users\<username>\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe'
- Path: C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe
- Path: C:\Program Files (x86)\Microsoft OneDrive\OneDriveStandaloneUpdater.exe
Detection:
- IOC: HKCU\Software\Microsoft\OneDrive\UpdateOfficeConfig\UpdateRingSettingURLFromOC being set to a suspicious non-Microsoft controlled URL
- IOC: Reports of downloading from suspicious URLs in %localappdata%\OneDrive\setup\logs\StandaloneUpdate_*.log files