| File name: | FAX_20190705_1562295482_464.tif |
| Full analysis: | https://app.any.run/tasks/27e1ecba-63d9-408d-b3a6-db5d8c74c6a1 |
| Verdict: | No threats detected |
| Analysis date: | July 05, 2019, 16:27:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | image/tiff |
| File info: | TIFF image data, little-endian, direntries=21, height=2202, bps=1, compression=bi-level group 3, PhotometricIntepretation=WhiteIsZero, name=/usr/local/fax/spool/media_server/localstore/pdx_did10-1562295437-14012234937-464.tif, orientation=upper-left, width=1728 |
| MD5: | 3D71C20D409B68B79193A35BF4494B51 |
| SHA1: | 33B3799753899A9CDDF6248F7BBB7F6DCFA3FA8E |
| SHA256: | F6DE74D01331D8A844D45F7EFEB64501653BEA95EAF778D31B95C5976D1B6D29 |
| SSDEEP: | 768:IqO6FTwPN1j9BTsHlM7FTg/bIPZPPd3/yavSGJrIfjqJ4FGLhPOURYR1:IqO6aPN10HoPZPPd3/yaXIShPOea1 |
| .tif/tiff | | | Tagged Image File Format Bitmap (little endian) (100) |
|---|
| ImageWidth: | 1728 |
|---|---|
| ImageHeight: | 2202 |
| BitsPerSample: | 1 |
| Compression: | T4/Group 3 Fax |
| PhotometricInterpretation: | WhiteIsZero |
| FillOrder: | Reversed |
| DocumentName: | /usr/local/fax/spool/media_server/localstore/pdx_did10-1562295437-14012234937-464.tif |
| StripOffsets: | 8 |
| Orientation: | Horizontal (normal) |
| SamplesPerPixel: | 1 |
| RowsPerStrip: | 2202 |
| StripByteCounts: | 58915 |
| XResolution: | 204 |
| YResolution: | 196 |
| PlanarConfiguration: | Chunky |
| T4Options: | Fill bits added |
| ResolutionUnit: | inches |
| PageNumber: | 0 1 |
| Software: | Spandsp 20120902 163333 |
| ModifyDate: | 2019/07/05 02:57:55 |
| HostComputer: | did10.pdx.j2noc.com |
| ImageSize: | 1728x2202 |
|---|---|
| Megapixels: | 3.8 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2992 | "C:\Windows\System32\rundll32.exe" "C:\Program Files\Windows Photo Viewer\PhotoViewer.dll", ImageView_Fullscreen C:\Users\admin\AppData\Local\Temp\FAX_20190705_1562295482_464.tif | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2992) rundll32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: rundll32.exe | |||