| File name: | fuck.bat |
| Full analysis: | https://app.any.run/tasks/af66047d-e6b0-4420-8dee-ad081abf93f7 |
| Verdict: | Malicious activity |
| Analysis date: | March 14, 2019, 19:09:35 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/x-msdos-batch |
| File info: | DOS batch file, ASCII text, with CRLF line terminators |
| MD5: | B9060F65CE7E420CBC32CD5DA422C3DB |
| SHA1: | C2ED3039F27B891A1173C2F3C7CFB5996B3DF077 |
| SHA256: | 46BA8455E4B73F7F48B1E099824FEE52945D5F7F17428BA4368CF7D885D41538 |
| SSDEEP: | 3:mKDD5PfVn:hv |
PID | CMD | Path | Indicators | Parent process | |||||
|---|---|---|---|---|---|---|---|---|---|
| 284 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||
| 904 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||
| 908 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||
| 1164 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | |||||||||
| 2060 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||
| 2140 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||
| 2160 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||
| 2200 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||
| 2212 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||
| 2236 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||