File name:

noname.bin

Full analysis: https://app.any.run/tasks/d63d4e2d-0e9f-48ff-ac15-09426b7d98c9
Verdict: Malicious activity
Analysis date: August 04, 2023, 09:41:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: image/jpeg
File info: JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=4], baseline, precision 8, 190x70, components 3
MD5:

797CA77CADEB6F6571EF0E9C59CDE2D4

SHA1:

1B8992DAEC866F0DDC80652B1CD87C754B69983A

SHA256:

578E79F3D03E0B492AF8813D4D9A5E88AF94F82AE7E14B834A50D7CCD86E1B87

SSDEEP:

96:ipkmTk0MsFUzSEoan8nGzfyeTA+ayftCn5B:4k4kdO6SmzfzAD75B

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • rundll32.exe (PID: 2804)
  • INFO

    • The process checks LSA protection

      • dllhost.exe (PID: 2176)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jpg | JFIF-EXIF JPEG Bitmap (38.4)
.jpg | JFIF JPEG bitmap (30.7)
.jpg | JPEG bitmap (23)
.mp3 | MP3 audio (7.6)

EXIF

Composite

SubSecDateTimeOriginal: 2018:12:21 23:02:58.26
SubSecCreateDate: 2018:12:21 23:02:58.26
Megapixels: 0.013
ImageSize: 190x70

XMP

Creator: Jusayan, Mary Joyce
CreateDate: 2018:12:21 23:02:58.258
About: uuid:faf5bdd5-ba3d-11da-ad31-d33d75182f1b

EXIF

Padding: (Binary data 2060 bytes, use -b option to extract)
XPAuthor: Jusayan, Mary Joyce
SubSecTimeDigitized: 26
SubSecTimeOriginal: 26
CreateDate: 2018:12:21 23:02:58
DateTimeOriginal: 2018:12:21 23:02:58
Artist: Jusayan, Mary Joyce

JFIF

YResolution: 96
XResolution: 96
ResolutionUnit: inches
JFIFVersion: 1.01
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rundll32.exe no specs PhotoViewer.dll no specs

Process information

PID
CMD
Path
Indicators
Parent process
2176C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
2804"C:\Windows\System32\rundll32.exe" "C:\Program Files\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen "C:\Users\admin\Desktop\noname.bin.jpg"C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
163
Read events
161
Write events
2
Delete events
0

Modification events

(PID) Process:(2804) rundll32.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(2176) dllhost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
2640
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info