| File name: | dism.bat |
| Full analysis: | https://app.any.run/tasks/1943c252-0a03-4e4b-962e-632514b5efab |
| Verdict: | Malicious activity |
| Analysis date: | March 21, 2024, 18:17:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with no line terminators |
| MD5: | B3EEA402371D4279E4CBEC81FA65EBE8 |
| SHA1: | 5C0F90A1F2A7ED2F8D63B6BEAE00CA6E8C1C9993 |
| SHA256: | 94ADCC5EAD3779D3B4E231B2848906B85D1B93C906615BDB1C8BC2FC91D66DE8 |
| SSDEEP: | 3:dWawtECPz2A3fN:fwlPh |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 696 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1368 | "C:\Windows\system32\osk.exe" | C:\Windows\System32\osk.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Accessibility On-Screen Keyboard Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2036 | dism.exe /Online /Cleanup-image /Restorehealth | C:\Windows\System32\Dism.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Dism Image Servicing Utility Exit code: 87 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2548 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2648 | DISM.exe /Online /Cleanup-image /Restorehealth | C:\Windows\System32\Dism.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Dism Image Servicing Utility Exit code: 740 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3256 | dism.exe /online /cleanup-image /restorehealth | C:\Windows\System32\Dism.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Dism Image Servicing Utility Exit code: 740 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3308 | "C:\Windows\system32\osk.exe" | C:\Windows\System32\osk.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Accessibility On-Screen Keyboard Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3936 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\dism.bat" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 740 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 4004 | "C:\Windows\system32\cmd.exe" | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 4052 | C:\Users\admin\AppData\Local\Temp\56416BCE-8D17-4377-B6FD-397A6573A644\dismhost.exe {936EB9B2-9D83-4B3E-8C88-13A2F9169DF6} | C:\Users\admin\AppData\Local\Temp\56416BCE-8D17-4377-B6FD-397A6573A644\DismHost.exe | Dism.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Dism Host Servicing Process Exit code: 0 Version: 6.1.7601.24499 (win7sp1_ldr.190612-0600) Modules
| |||||||||||||||
| (PID) Process: | (1368) osk.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AccessibilityTemp |
| Operation: | write | Name: | osk |
Value: 3 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2036 | Dism.exe | C:\Users\admin\AppData\Local\Temp\56416BCE-8D17-4377-B6FD-397A6573A644\DismCorePS.dll | executable | |
MD5:9733B1D4E0EFCC3E11A133238B55F10F | SHA256:E07766D4908BAA9790D0C843E7A6E5CEE45DD17A84860B2CF0477D276392C97B | |||
| 2036 | Dism.exe | C:\Users\admin\AppData\Local\Temp\56416BCE-8D17-4377-B6FD-397A6573A644\DmiProvider.dll | executable | |
MD5:6128693331EA9946A186F2608330D5FB | SHA256:EFDA6FCDB7A9E94CA467DB23C00B04C42ADE536EE7D5B12D589EC913FB1B3536 | |||
| 2036 | Dism.exe | C:\Users\admin\AppData\Local\Temp\56416BCE-8D17-4377-B6FD-397A6573A644\en-US\CbsProvider.dll.mui | executable | |
MD5:3D3835F95630A5F46DEA1F7FD823E6A5 | SHA256:D32B28B184439673E3AC94070453FAF69434DF29A064558015D2A3FCE2956CA4 | |||
| 2036 | Dism.exe | C:\Users\admin\AppData\Local\Temp\56416BCE-8D17-4377-B6FD-397A6573A644\DismHost.exe | executable | |
MD5:5E2E337F6F942B63428DB19355D6742B | SHA256:F60406C5D01B22F95C7F7298498475F0930550CBBF6BB31EB01E1E565FA175AE | |||
| 2036 | Dism.exe | C:\Users\admin\AppData\Local\Temp\56416BCE-8D17-4377-B6FD-397A6573A644\en-US\DismProv.dll.mui | executable | |
MD5:7B570BC665C907256E5C97F10521381C | SHA256:C5D1876E93346DB7457F1C05CB1AB17C372D9440F92093315D3321C2D6A26194 | |||
| 2036 | Dism.exe | C:\Users\admin\AppData\Local\Temp\56416BCE-8D17-4377-B6FD-397A6573A644\en-US\LogProvider.dll.mui | executable | |
MD5:181620FDBDBC4DB69FB5D54AEB54EDDC | SHA256:A0B6C90317A7313D7C04C8ACFEE4DD2A7530130F18110570DF200C3B88699BB4 | |||
| 2036 | Dism.exe | C:\Users\admin\AppData\Local\Temp\56416BCE-8D17-4377-B6FD-397A6573A644\en-US\IntlProvider.dll.mui | executable | |
MD5:187359D54BE36B9A20B14EA0A54CDDB8 | SHA256:B283A7CFA81342638FCC5EDE1E96499E70E90A72ECDC22110CC11BE593F9BAAD | |||
| 2036 | Dism.exe | C:\Users\admin\AppData\Local\Temp\56416BCE-8D17-4377-B6FD-397A6573A644\en-US\MsiProvider.dll.mui | executable | |
MD5:98893D8D67951A2BD76AC23D0588CBF2 | SHA256:F9D4B2A4AEF6A7F4614E09D9BA3F7EBAA3783E28A988A0F188CDFA3A2A21B74E | |||
| 2036 | Dism.exe | C:\Users\admin\AppData\Local\Temp\56416BCE-8D17-4377-B6FD-397A6573A644\en-US\DismCore.dll.mui | executable | |
MD5:B065EAB0E07C62C698BD28AABC68411F | SHA256:9A2FC296980090295E214B25F37572820521C24439FED475F68C9E278DAAA3C9 | |||
| 2036 | Dism.exe | C:\Windows\Logs\DISM\dism.log | text | |
MD5:246179A68EC874568FF456692B484285 | SHA256:82FBEFFBCB1A3EAB22F45CA9A20377CBC7115C764A9CAFD6C4EB69E5B61AE927 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Process | Message |
|---|---|
Dism.exe | PID=2036 The requested provider was not found in the Provider Store. - CDISMProviderStore::Internal_GetProvider(hr:0x80004005) |
Dism.exe | PID=2036 Getting Provider OSServices - CDISMProviderStore::GetProvider |
Dism.exe | PID=2036 Attempting to initialize the logger from the Image Session. - CDISMProviderStore::Final_OnConnect |
Dism.exe | PID=2036 Failed to get an OSServices provider. Must be running in local store. Falling back to checking alongside the log provider for wdscore.dll. - CDISMLogger::FindWdsCore(hr:0x80004005) |
Dism.exe | PID=2036 Loading Provider from location C:\Windows\System32\Dism\LogProvider.dll - CDISMProviderStore::Internal_GetProvider |
Dism.exe | PID=2036 Connecting to the provider located at C:\Windows\System32\Dism\LogProvider.dll. - CDISMProviderStore::Internal_LoadProvider |
Dism.exe | PID=2036 Instantiating the Provider Store. - CDISMImageSession::get_ProviderStore |
Dism.exe | PID=2036 Initializing a provider store for the LOCAL session type. - CDISMProviderStore::Final_OnConnect |
Dism.exe | PID=2036 Provider has not previously been encountered. Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider |
DismHost.exe | PID=4052 Encountered a loaded provider DISMLogger. - CDISMProviderStore::Internal_DisconnectProvider |