| File name: | tabaaaaaaaaa.MP3 |
| Full analysis: | https://app.any.run/tasks/35a2d468-3fa2-4d79-b9d6-dfd913445326 |
| Verdict: | Malicious activity |
| Analysis date: | February 18, 2024, 01:09:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | audio/mpeg |
| File info: | Audio file with ID3 version 2.3.0, contains: MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, JntStereo |
| MD5: | 05D94FFDAACABAE6A7001C7234EFA221 |
| SHA1: | D4CC2FAAD4BF89F034A1BDEA3C07F64D399AE146 |
| SHA256: | 01F6C086C8E47C0B8BF63817CDAD7CDF4AC28DBCA63E1217A3A062182D8E0E10 |
| SSDEEP: | 3072:45lVHif9FhWYKnUpe/b4COO0K2g3U8d8ViG:+nCf9qNUs8E0K2g3U8dtG |
| .mp3 | | | LAME encoded MP3 audio (ID3 v2.x tag) (62.5) |
|---|---|---|
| .mp3 | | | MP3 audio (ID3 v2.x tag) (37.5) |
| MPEGAudioVersion: | 1 |
|---|---|
| AudioLayer: | 3 |
| AudioBitrate: | 128 kbps |
| SampleRate: | 44100 |
| ChannelMode: | Joint Stereo |
| MSStereo: | On |
| IntensityStereo: | Off |
| CopyrightFlag: | - |
| OriginalMedia: | |
| Emphasis: | None |
| EncoderSettings: | LAME3.101 (beta 2) |
|---|
| Duration: | 5.04 s (approx) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4052 | "C:\Windows\System32\cmd.exe" /c rd /s /q c:\ | C:\Windows\System32\cmd.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |























































































































