File name: | photo_2019-04-24_15-33-56.jpg |
Full analysis: | https://app.any.run/tasks/94dd90e2-3492-4441-bd40-fd5da033e198 |
Verdict: | Malicious activity |
Analysis date: | April 25, 2019, 16:18:20 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | image/jpeg |
File info: | JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 728x1079, frames 3 |
MD5: | FF2A824DBAD350EDCEE0658B419CC834 |
SHA1: | DD2FDC003AA21E75EA3A05CDD1E64706CAFB8CF9 |
SHA256: | D61FF4249FE2203B785AA4ACEA204F0F28CB1F027FEA90017D360E73B6797B20 |
SSDEEP: | 3072:OH07rhPcRd3pVVvGzZPBZaucAvvHluFdcmZxJTZcmwynvpxk0NI0uDkhUQqZpl:OU+6zJDa9Aocmjh5IWU/Zpl |
.jpg | | | JFIF JPEG bitmap (50) |
---|---|---|
.jpg | | | JPEG bitmap (37.4) |
.mp3 | | | MP3 audio (12.4) |
JFIFVersion: | 1.01 |
---|---|
ResolutionUnit: | inches |
XResolution: | 96 |
YResolution: | 96 |
ImageSize: | 728x1079 |
---|---|
Megapixels: | 0.786 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1208 | "C:\Windows\System32\rundll32.exe" "C:\Program Files\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen C:\Users\admin\Desktop\photo_2019-04-24_15-33-56.jpg | C:\Windows\System32\rundll32.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2628 | "C:\Windows\system32\cmd.exe" | C:\Windows\system32\cmd.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 3221225786 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
904 | cmd /c "echo off&erase /F/Q/S *.* >NUL" | C:\Windows\system32\cmd.exe | cmd.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
(PID) Process: | (1208) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
Operation: | write | Name: | Name |
Value: rundll32.exe |