1c81ca0a865841dd19ba65eff895f68004d8470c89309070c1620847941ea846

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2026-Aug-02 23:02:39
Detected languages English - United States
TLS Callbacks 2 callback(s) detected.
Debug artifacts Embedded COFF debugging symbols
CompanyName Microsoft Corporation
FileDescription Microsoft OneDrive
FileVersion 23.246.1126.0002
InternalName OneDrive
LegalCopyright Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFilename OneDrive.exe
ProductName Microsoft OneDrive
ProductVersion 23.246.1126.0002

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Miscellaneous malware strings:
  • cmd.exe
Contains domain names:
  • dearimgui.com
  • github.com
  • https://github.com
  • https://www.dearimgui.com
  • https://www.dearimgui.com/faq/
  • www.dearimgui.com
Info Cryptographic algorithms detected in the binary: Uses constants related to CRC32
Suspicious The PE is possibly packed. Unusual section name found: .buildid
Unusual section name found: /4
Unusual section name found: /18
Unusual section name found: /58
Unusual section name found: /70
Unusual section name found: /82
Unusual section name found: /33
Unusual section name found: /47
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryA
Functions which can be used for anti-debugging purposes:
  • CreateToolhelp32Snapshot
Can access the registry:
  • RegCloseKey
  • RegDeleteValueW
  • RegEnumValueW
  • RegOpenKeyExW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteA
Can create temporary files:
  • CreateFileW
  • GetTempPathW
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Interacts with services:
  • OpenSCManagerW
  • OpenServiceW
  • QueryServiceStatusEx
Reads the contents of the clipboard:
  • GetClipboardData
Suspicious The file contains overlay data. 134656 bytes of data starting at offset 0x11fa00.
Suspicious No VirusTotal score. This file has never been scanned on VirusTotal.

Hashes

MD5 c74d6015a35bc87f106666901cc81b81
SHA1 ec717c5726b7535fed3214f05d6ada3f30f09891
SHA256 1c81ca0a865841dd19ba65eff895f68004d8470c89309070c1620847941ea846
SHA3 a4bf3f078d45d22baec431a97d87a2fc84d9f78c07c239bc978d7df452a8a048
SSDeep 24576:7n7KKvE/IBBBfabnmU+0LbW5umXmwlcW+BQ8up0JlzS6lKu:7WKvE/iBD70LbW572scW+BQ8up0TO6l
Imports Hash cdf939f55b9f25f747d86d9c404eecea

DOS Header

e_magic MZ
e_cblp 0x78
e_cp 0x1
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0
e_ss 0
e_sp 0
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0x78

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 15
TimeDateStamp 2026-Aug-02 23:02:39
PointerToSymbolTable 0x11fa00
NumberOfSymbols 2488
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xd5e00
SizeOfInitializedData 0x49800
SizeOfUninitializedData 0
AddressOfEntryPoint 0x0000000000001000 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 6.0
ImageVersion 0.0
SubsystemVersion 6.0
Win32VersionValue 0
SizeOfImage 0x12f000
SizeOfHeaders 0x400
Checksum 0
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 8392f292bfb7a7a61b4c43185bace1d3
SHA1 04506ffd50323fec32216efa441f51374bf17468
SHA256 278ee2d5ebf4f7133a9496d9c54668bcb3fc1bddeda9cc68b1e965d01873894d
SHA3 3910a2d8a70279ac9aa06afa99d64c73942aaa30d73f2fcb5b0d86c6ac49c509
VirtualSize 0xd5d36
VirtualAddress 0x1000
SizeOfRawData 0xd5e00
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.47945

.rdata

MD5 b23aaa1f13343c6c5a8d638224fc01d1
SHA1 708d3f2d644e7bbc28866af7ea61f33e2a5cd05d
SHA256 e0e07076f51c409f46f6328ed194070b6c2a8cc187840fc66134e200baa5c34b
SHA3 3db4b981e9c07b0ffce92cb2c2515a95e707709ee2483b41d97273b8a98cd259
VirtualSize 0x2db1c
VirtualAddress 0xd7000
SizeOfRawData 0x2dc00
PointerToRawData 0xd6200
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.90529

.buildid

MD5 e78a70044e069c08d2cdeea692c80e7d
SHA1 8ef1f8371e37af1a95285e780be0e37af47f3eed
SHA256 2f792d48a0ef7b25d00a55d8b43c7780fe4a41cb6e952a7891d7bf49c771eadd
SHA3 10e16cab7db3689a7c656edb77bd293ec7ccd8b00d8284e627a7617ac27966e8
VirtualSize 0x35
VirtualAddress 0x105000
SizeOfRawData 0x200
PointerToRawData 0x103e00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 0.637277

.data

MD5 b725dbfe4f6700118035bde136f8195f
SHA1 e77a6b8e5dbd8992db7e591196ea102986e81bb7
SHA256 e5834dbed9f6c157ba61fa2e29a1c7794a3538f8e825193c675848b87474fecd
SHA3 e32a25fac96a18e6c449bfb75d42e9f25059c9e33e179b611e257f51ae9fcc0a
VirtualSize 0xbcc0
VirtualAddress 0x106000
SizeOfRawData 0x4800
PointerToRawData 0x104000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0.674696

.pdata

MD5 2849e5a38f1addd381f926fb407831fc
SHA1 436494c15f28785821643ce7c4e47ff68826036b
SHA256 d5d3e63d4252702fc052cb8a87b5f94e2ca956604eee62659c3240c4e0945ade
SHA3 600e618d67825f2ccf00b1efcf135745a48bd80aca9a16b8ded183d5a26f8c6b
VirtualSize 0x2e38
VirtualAddress 0x112000
SizeOfRawData 0x3000
PointerToRawData 0x108800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.7358

.tls

MD5 bf619eac0cdf3f68d496ea9344137e8b
SHA1 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5
SHA256 076a27c79e5ace2a3d47f9dd2e83e4ff6ea8872b3c2218f66c92b89b55f36560
SHA3 622de1e1568ddef36c4b89b706b05201c13481c3575d0fc804ff8224787fcb59
VirtualSize 0x10
VirtualAddress 0x115000
SizeOfRawData 0x200
PointerToRawData 0x10b800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 0

.rsrc

MD5 34b208bea1d86ee9da74cbad77bfa582
SHA1 b58a0f190cf133f2d3c9d1b4a9833184eb479ef4
SHA256 60df85379777b215e05a1a2ad5619962e9e97ab61c511a30400f83671347093d
SHA3 d421b3e38e8c9693a96f1bda4ea725f099dd06896bb15b3c3493929fde24b324
VirtualSize 0xb50
VirtualAddress 0x116000
SizeOfRawData 0xc00
PointerToRawData 0x10ba00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.09058

.reloc

MD5 463df4917919d8c46bfe533db92fc046
SHA1 ef6f5940a48b107286ee40edd6eff625c980235c
SHA256 285f925e8221849774fb208fb319a28612c368c0c23d326a10a1e72dd54a2061
SHA3 ea3f432dc045ad1f99a7002ec78334de14db63fe3216b6aab8d55ddfec04afcb
VirtualSize 0x480
VirtualAddress 0x117000
SizeOfRawData 0x600
PointerToRawData 0x10c600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.43963

/4

MD5 eaf9633977766c6276f9861de636a94d
SHA1 4e47c64c8b783943a03ff1927b822892e0f7808c
SHA256 20a989b1612052a2f6d056ff2e9394fe47a5b75f707e112696df5e88060a0dae
SHA3 68335307af2c9a88f013171900e4aed14819e19a6ad4e4d57ca2723e476facd1
VirtualSize 0x1f8d
VirtualAddress 0x118000
SizeOfRawData 0x2000
PointerToRawData 0x10cc00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 4.63341

/18

MD5 27805dff50aceb01e18e7ebbbca8e621
SHA1 44480ed54f88d4e81b358a8104f869a8a2ca4634
SHA256 699861d7771bc4179928cb0e62eec0a21cf5364899c44f8968a91effab0edbc6
SHA3 083b18a78619470b9b372d391d486fac58b5cda63cb100ebf8e4974694ffd602
VirtualSize 0x30
VirtualAddress 0x11a000
SizeOfRawData 0x200
PointerToRawData 0x10ec00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 0.220113

/58

MD5 2e736e28a2855fb2625ecfb568931c94
SHA1 c6ee59f13ea025dd11031e7db1556ad8b74bc69b
SHA256 f4c0923ac5683e162c6c7525adfd50e52e5cb2f306869f9abbb04841c862f015
SHA3 a97ccca7f077fdae82ae2fdaf92c8b7f3c8ca4f6fbd3ae38fcf80c3337ebe655
VirtualSize 0x5b89
VirtualAddress 0x11b000
SizeOfRawData 0x5c00
PointerToRawData 0x10ee00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.16051

/70

MD5 2e05580b0429bb2736649b58a308d1b3
SHA1 3c119c77b1fa906feee89b8fc60a00621e67d266
SHA256 a7e996bc57d4f0412df9e721534d967b0c3b7631c70a8cd085fcb82cd5de56d7
SHA3 11280bab0308515f076caa64977d765b127c8f8bd7f005572ad37fe658fe0c3b
VirtualSize 0x3130
VirtualAddress 0x121000
SizeOfRawData 0x3200
PointerToRawData 0x114a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.61339

/82

MD5 f184d2b772dd1279fc5f0a111a9b1e48
SHA1 b80bfb4a0293704bf093c5cf106bb4f6130e31a4
SHA256 aab6bbd16cd40b6cb823442ae8d1d4523202563c963d42bfb45e930983e45033
SHA3 28acaca8c63f2d3c01dc89371bc5dd573ec7bc059758029efa2d00bf21225fdc
VirtualSize 0x275a
VirtualAddress 0x125000
SizeOfRawData 0x2800
PointerToRawData 0x117c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.94132

/33

MD5 50e5e39849973cce340ccafe0abf0b2a
SHA1 5175f5392f6f1703cdb970352841b6ca07db6a10
SHA256 c99ceacacaf8ea061026c58ef045cb38d4579acf68c965ef7c66305dd8d86636
SHA3 d843a8766ad632ab26a495f90b38a438666b964c56a78e9c0c379c84b590e82f
VirtualSize 0x1b0
VirtualAddress 0x128000
SizeOfRawData 0x200
PointerToRawData 0x11a400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 1.14813

/47

MD5 f3a9d054b0bdbaea6ae8acdbb909b9a3
SHA1 0591eb83ee8b4ada46f35a03728b000029f46048
SHA256 c88eb425d37aa8795949cd461baa39091aab013139889ec520607324f92aeb30
SHA3 619a5e1f1116269958d5e17bf21df58b64ef791f79c4bc26586e900c5d89499a
VirtualSize 0x52e4
VirtualAddress 0x129000
SizeOfRawData 0x5400
PointerToRawData 0x11a600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.37536

Imports

d3d11.dll D3D11CreateDeviceAndSwapChain
D3DCOMPILER_47.dll D3DCompile
dwmapi.dll DwmEnableBlurBehindWindow
DwmGetColorizationColor
DwmIsCompositionEnabled
DwmSetWindowAttribute
KERNEL32.dll CloseHandle
CreateFileW
CreateProcessW
CreateToolhelp32Snapshot
DeleteCriticalSection
EnterCriticalSection
FileTimeToLocalFileTime
FileTimeToSystemTime
FreeLibrary
GetCurrentProcess
GetFileAttributesA
GetFileTime
GetLastError
GetLocaleInfoA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetProcAddress
GetStartupInfoW
GetTempPathW
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
LocalFileTimeToFileTime
Module32NextW
MultiByteToWideChar
OpenThread
QueryPerformanceCounter
QueryPerformanceFrequency
ResumeThread
SetFileTime
SetUnhandledExceptionFilter
Sleep
SuspendThread
SystemTimeToFileTime
Thread32First
Thread32Next
TlsGetValue
VerSetConditionMask
VirtualProtect
VirtualQuery
WideCharToMultiByte
WriteFile
USER32.dll ClientToScreen
CloseClipboard
CreateWindowExW
DefWindowProcW
DestroyWindow
DispatchMessageW
EmptyClipboard
GetCapture
GetClientRect
GetClipboardData
GetCursorPos
GetDC
GetForegroundWindow
GetKeyState
GetKeyboardLayout
GetMessageExtraInfo
IsWindowUnicode
LoadCursorA
MessageBoxW
MonitorFromWindow
OpenClipboard
PeekMessageW
PostQuitMessage
RegisterClassExW
ReleaseCapture
ReleaseDC
ScreenToClient
SendMessageW
SetCapture
SetClipboardData
SetCursor
SetCursorPos
SetFocus
SetForegroundWindow
SetProcessDPIAware
SetWindowRgn
ShowWindow
TrackMouseEvent
TranslateMessage
UnregisterClassW
UpdateWindow
GDI32.dll CreateRectRgn
CreateRoundRectRgn
DeleteObject
GetDeviceCaps
SHELL32.dll DragAcceptFiles
DragFinish
DragQueryFileW
ShellExecuteA
comdlg32.dll GetOpenFileNameW
ADVAPI32.dll AdjustTokenPrivileges
CloseServiceHandle
LookupPrivilegeValueW
OpenProcessToken
OpenSCManagerW
OpenServiceW
QueryServiceStatusEx
RegCloseKey
RegDeleteValueW
RegEnumValueW
RegOpenKeyExW
libc++.dll _ZNSt11logic_errorC2EPKc
_ZNSt12length_errorD1Ev
_ZNSt12out_of_rangeD1Ev
_ZNSt20bad_array_new_lengthC1Ev
_ZNSt20bad_array_new_lengthD1Ev
_ZNSt3__112basic_stringIcNS_11char_traitsIcEENS_9allocatorIcEEE6appendEPKc
_ZNSt3__112basic_stringIwNS_11char_traitsIwEENS_9allocatorIwEEE6appendEPKw
_ZNSt3__112basic_stringIwNS_11char_traitsIwEENS_9allocatorIwEEE6insertEyPKw
_ZNSt3__112basic_stringIwNS_11char_traitsIwEENS_9allocatorIwEEEaSERKS5_
_ZSt9terminatev
_ZTVN10__cxxabiv117__class_type_infoE
_ZTVN10__cxxabiv120__si_class_type_infoE
_ZTVSt12length_error
_ZTVSt12out_of_range
_ZdlPv
_Znwy
__cxa_allocate_exception
__cxa_begin_catch
__cxa_free_exception
__cxa_guard_abort
__cxa_guard_acquire
__cxa_guard_release
__cxa_throw
__gxx_personality_seh0
libunwind.dll _Unwind_Resume
api-ms-win-crt-stdio-l1-1-0.dll __acrt_iob_func
__p__commode
__p__fmode
__stdio_common_vfprintf
__stdio_common_vsprintf
__stdio_common_vsscanf
fclose
fflush
fopen
fread
fseek
ftell
fwrite
setvbuf
api-ms-win-crt-string-l1-1-0.dll _wcsicmp
memset
strcmp
strlen
strncmp
strncpy
toupper
towlower
towupper
wcslen
api-ms-win-crt-runtime-l1-1-0.dll __p___argc
__p___wargv
__p__wcmdln
_cexit
_configure_wide_argv
_crt_atexit
_exit
_initialize_wide_environment
_initterm
_initterm_e
_seh_filter_exe
_set_app_type
_set_invalid_parameter_handler
abort
exit
api-ms-win-crt-locale-l1-1-0.dll _configthreadlocale
api-ms-win-crt-math-l1-1-0.dll __setusermatherr
acosf
atan2f
ceilf
cosf
floorf
fmodf
log
logf
pow
powf
sinf
sqrtf
api-ms-win-crt-convert-l1-1-0.dll atof
atoi
api-ms-win-crt-heap-l1-1-0.dll _set_new_mode
calloc
free
malloc
api-ms-win-crt-private-l1-1-0.dll memchr
memcmp
memcpy
memmove
strchr
strstr
api-ms-win-crt-utility-l1-1-0.dll qsort
api-ms-win-crt-environment-l1-1-0.dll __p__wenviron

Delayed Imports

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.15853
MD5 f42ac84f05da933dadf8b21c9def47c5
SHA1 9248196e2004688f8f9d1b52eb8568fe902667b8
SHA256 538a693f9419d10f94d7c1760bd1ab29b1d52c63976f83a51764b72ed2d4d0da
SHA3 2eca2319a9735ae44668482fa5e2c8352d4b4407b746400f10645f9e2763030b

1 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x14
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.16096
Detected Filetype Icon file
MD5 42cf62b780813706e75fb9f2b2e8c258
SHA1 a022d5c1cfdd8aace0089f3e72f2eedd41bda464
SHA256 a0c9d012e2bf6b2fe05c2d97cb5594d97cf2f539e97935c12abd7a3562f4d9bf
SHA3 0aafc8e3d8b6bde595537da4ffe0efc5fe53f01dafe336a2a5828b6a71283d3c

1 (#3)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x35c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.442
MD5 b4e1588b76d517611bf941393cf0094d
SHA1 8d0880bf2784b38de2bc422ea3f75a1fe316c2c9
SHA256 d2f113a9b5fad4d4807c261318960fa1d75038c8648a7544242bb50872e07504
SHA3 60dc8d76c5c1d99a16ae9db7d2f2f77f573aa5a00bab1326c9234111922258ca

1 (#4)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x3bd
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.74471
MD5 bc549dd687a242ab5d73f9424d6a935a
SHA1 ccd02d2b7889cb1f2150edc469e91c6db9c99ea5
SHA256 570b7dce3299c5c25436a463168f0c105d993fe0aec5dccc21cea58f6f5b425e
SHA3 505c73e3987ff24f5df7b8ffc7ea8dc1ef8327643a7067d1edc1df0243211742

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 23.246.1126.2
ProductVersion 23.246.1126.2
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription Microsoft OneDrive
FileVersion (#2) 23.246.1126.0002
InternalName OneDrive
LegalCopyright Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFilename OneDrive.exe
ProductName Microsoft OneDrive
ProductVersion (#2) 23.246.1126.0002
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 2026-Aug-02 23:02:39
Version 0.0
SizeofData 25
AddressOfRawData 0x10501c
PointerToRawData 0x103e1c

TLS Callbacks

StartAddressOfRawData 0x140115000
EndAddressOfRawData 0x140115008
AddressOfIndex 0x140111c20
AddressOfCallbacks 0x1400fb7b8
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_8BYTES
Callbacks 0x00000001400D4E10
0x00000001400D4E90

Load Configuration

Size 0x138
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0

RICH Header

Errors

[*] Warning: Tried to read outside the COFF string table to get the name of section /4! [*] Warning: Tried to read outside the COFF string table to get the name of section /18! [*] Warning: Tried to read outside the COFF string table to get the name of section /58! [*] Warning: Tried to read outside the COFF string table to get the name of section /70! [*] Warning: Tried to read outside the COFF string table to get the name of section /82! [*] Warning: Tried to read outside the COFF string table to get the name of section /33! [*] Warning: Tried to read outside the COFF string table to get the name of section /47! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections! [*] Warning: COFF symbol's section number is bigger than the number of sections!
Leave a comment

No comments yet.