File name: | 1.bat |
Full analysis: | https://app.any.run/tasks/0501698c-4faa-4946-b2b4-749afa208de3 |
Verdict: | Malicious activity |
Analysis date: | December 14, 2018, 11:20:14 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with no line terminators |
MD5: | 3808D82ED52876C3DDA66FBF4CB142C8 |
SHA1: | 224DCBC79590E1D4ABFDA3D17B083B333FA00980 |
SHA256: | 11EA65B2709BB714F059CF53767F7EE5AE6DEFE5B5D548E32375E65571B66015 |
SSDEEP: | 3:wZw:wq |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3620 | cmd /c ""C:\Users\admin\AppData\Local\Temp\1.bat" " | C:\Windows\system32\cmd.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2384 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2448 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3064 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3124 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3168 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3272 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2396 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2560 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2620 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) |