| File name: | 1.bat |
| Full analysis: | https://app.any.run/tasks/0501698c-4faa-4946-b2b4-749afa208de3 |
| Verdict: | Malicious activity |
| Analysis date: | December 14, 2018, 11:20:14 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with no line terminators |
| MD5: | 3808D82ED52876C3DDA66FBF4CB142C8 |
| SHA1: | 224DCBC79590E1D4ABFDA3D17B083B333FA00980 |
| SHA256: | 11EA65B2709BB714F059CF53767F7EE5AE6DEFE5B5D548E32375E65571B66015 |
| SSDEEP: | 3:wZw:wq |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 936 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 956 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1236 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1432 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1488 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1596 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1732 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1748 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1964 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2000 | C:\Windows\system32\cmd.exe /S /D /c" "C:\Users\admin\AppData\Local\Temp\1.bat"" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||