| File name: | 90656 (1).jpeg |
| Full analysis: | https://app.any.run/tasks/dfd9063f-1086-42a7-858a-551e382dc0ed |
| Verdict: | Malicious activity |
| Analysis date: | June 25, 2023, 14:35:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | image/jpeg |
| File info: | JPEG image data, baseline, precision 8, 756x1008, components 3 |
| MD5: | 9CE3B5B11C8EAE74081A686AA9352AC1 |
| SHA1: | ABBB206C7C43BB63FC5D774FAA96F7398B04AF4E |
| SHA256: | 1F4628ABA6A800E70D4E0F7C091FE41EB5BC62EBB4337EF0BCC6F94B8963DE9C |
| SSDEEP: | 1536:bFk9iMicTWgE2tDMybJd5ckylC0gBn/GVyy9CJhU6WvK+oJ:K98cTrfwybZcLUjGshH88 |
| .jpg | | | JFIF JPEG bitmap (50) |
|---|---|---|
| .jpg | | | JPEG bitmap (37.4) |
| .mp3 | | | MP3 audio (12.4) |
| Megapixels: | 0.762 |
|---|---|
| ImageSize: | 756x1008 |
| ThumbnailImage: | (Binary data 4262 bytes, use -b option to extract) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3140 | "C:\Windows\System32\rundll32.exe" "C:\Program Files\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen "C:\Users\admin\Desktop\90656 (1).jpeg.jpg" | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3700 | "C:\Windows\system32\mspaint.exe" "C:\Users\admin\Desktop\90656 (1).jpeg.jpg" | C:\Windows\System32\mspaint.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Paint Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3140) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: Explorer.EXE | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1076 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2748 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |








