File name: | Italiano.reg |
Full analysis: | https://app.any.run/tasks/b7d4cfe2-42f7-4174-aedd-bd19db388133 |
Verdict: | Suspicious activity |
Analysis date: | April 17, 2019, 11:32:09 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | UTF-8 Unicode text, with CRLF, LF line terminators |
MD5: | 12A90099EEA0FECCD2837083DD30F546 |
SHA1: | 057B0FD025DFE1957DAF8322E9299318F8837697 |
SHA256: | 97764898F88F10917CE1FF3B0A7090C21674F9CBDA73C1C39B3A220F652B50C8 |
SSDEEP: | 48:9JY0qHQoRER7W7cI4tkP7e0k9yEb7+G6QlQcqeEVe9hchoUo:PNqwoRER7W714tI7e0k9Tb7+QQcqemep |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2076 | "C:\Windows\regedit.exe" "C:\Users\admin\Desktop\Italiano.reg" | C:\Windows\regedit.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
488 | "C:\Windows\regedit.exe" "C:\Users\admin\Desktop\Italiano.reg" | C:\Windows\regedit.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
332 | "C:\Windows\System32\control.exe" "C:\Windows\system32\timedate.cpl", | C:\Windows\System32\control.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Control Panel Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2584 | "C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL "C:\Windows\system32\timedate.cpl", | C:\Windows\system32\rundll32.exe | — | control.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3904 | "regedit.exe" "C:\Users\admin\Desktop\Italiano.reg" | C:\Windows\regedit.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3376 | "regedit.exe" "C:\Users\admin\Desktop\Italiano.reg" | C:\Windows\regedit.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
856 | "C:\Windows\regedit.exe" | C:\Windows\regedit.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3916 | "C:\Windows\regedit.exe" | C:\Windows\regedit.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1412 | "C:\Windows\System32\control.exe" "C:\Windows\system32\timedate.cpl", | C:\Windows\System32\control.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Control Panel Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3152 | "C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL "C:\Windows\system32\timedate.cpl", | C:\Windows\system32\rundll32.exe | — | control.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |