File name:

PixillionImageConverter.exe

Full analysis: https://app.any.run/tasks/5fbe83dd-53e4-4dc1-9e3c-4097696e06cd
Verdict: Malicious activity
Analysis date: January 03, 2024, 05:46:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E560332E5967896E6DCAABA5C3125103

SHA1:

41371F428CCD106FECB7EB39619FE52854D0EF00

SHA256:

4208169D08123945F6259EA02E9AACB3F655070467CE820326ED04B1811987F6

SSDEEP:

98304:yb9aeGgiHMEXAMXzFUvJ7lQgmU6D3nu3NDkPav54I0UOGDw6arpsxnHygt2Ix75N:igu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • PixillionImageConverter.exe (PID: 2420)
      • nchsetup.exe (PID: 492)
      • pixillion.exe (PID: 1804)
    • Searches for installed software

      • nchsetup.exe (PID: 492)
  • INFO

    • Reads the computer name

      • PixillionImageConverter.exe (PID: 2420)
      • nchsetup.exe (PID: 492)
      • pixillion.exe (PID: 1804)
      • pixillion.exe (PID: 712)
    • Drops the executable file immediately after the start

      • PixillionImageConverter.exe (PID: 2420)
      • nchsetup.exe (PID: 492)
      • freetype.exe (PID: 1040)
    • Checks supported languages

      • nchsetup.exe (PID: 492)
      • freetype.exe (PID: 1040)
      • pixillion.exe (PID: 1804)
      • pixillion.exe (PID: 712)
      • PixillionImageConverter.exe (PID: 2420)
    • Creates files in the program directory

      • nchsetup.exe (PID: 492)
      • freetype.exe (PID: 1040)
    • Create files in a temporary directory

      • PixillionImageConverter.exe (PID: 2420)
      • freetype.exe (PID: 1040)
      • pixillion.exe (PID: 1804)
    • Starts itself from another location

      • nchsetup.exe (PID: 492)
    • Reads the machine GUID from the registry

      • pixillion.exe (PID: 1804)
    • Application launched itself

      • msedge.exe (PID: 1768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:09:21 07:45:58+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 2560
InitializedDataSize: 2085888
UninitializedDataSize: -
EntryPoint: 0x1286
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (Australian)
CharacterSet: Unicode
CompanyName: NCH Software
FileDescription: Pixillion Image Converter
FileVersion: 11.70+
ProductVersion: 11.70+
ProductName: Pixillion
LegalCopyright: NCH Software
InternalName: Pixillion
OriginalFileName: Pixillion.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
29
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pixillionimageconverter.exe nchsetup.exe freetype.exe no specs pixillion.exe no specs pixillion.exe no specs PhotoViewer.dll no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs pixillionimageconverter.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exeexplorer.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
Pixillion Image Converter
Exit code:
3221226540
Version:
11.70+
Modules
Images
c:\users\admin\appdata\local\temp\pixillionimageconverter.exe
c:\windows\system32\ntdll.dll
492"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe" -installer "C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" -instdata "C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe
PixillionImageConverter.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
Pixillion Image Converter
Exit code:
0
Version:
11.70+
Modules
Images
c:\users\admin\appdata\local\temp\n1s\nchsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
712"C:\Program Files\NCH Software\Pixillion\pixillion.exe" -installschedC:\Program Files\NCH Software\Pixillion\pixillion.exenchsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
Pixillion Image Converter
Exit code:
0
Version:
11.70+
Modules
Images
c:\program files\nch software\pixillion\pixillion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1040"C:\Program Files\NCH Software\Pixillion\freetype.exe" -LQUIET -instby fiPixillion -instsvar PIXILLIONRelatedprogramspaidoffLLIBInstquickonC:\Program Files\NCH Software\Pixillion\freetype.exenchsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\nch software\pixillion\freetype.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1124"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3560 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1768"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.nchsoftware.com/software/thanks.html?software=Pixillion&appname=Pixillion&version=11.70&appbits=32&base=imageconverter&domain=nchsoftware&buyoffer=pixillion&pclass=plus&rgst=0&antivirus=expired&instby=dl&iid=GQ7ed2yGqRI&help=0&ostype=48&osver=6.1&svar=PIXILLIONRelatedprogramspaidoffLLIBInstquickonPIXILLIONShowoutfilesize2offLANhLLIBControloffEYivPIXILLIONSplashv2offIc2fUTfsPIXILLIONRecentfilesonDRBjGxotPIXILLIONRemovedropdownoffF3ocCC9wGUwrPIXILLIONOilpaintfilteronHZDhR4hjDiphHo1bIb1cNxmtI03nZTUvDFWwIwlpPIXILLIONRemovebgtboffOqwkFHoeHtppPIXILLIONNewoutdirlabeloffPIXILLIONOutputfolderpdlonPIXILLIONSetoutfolderonEwdjPz6fOVJfOElvTNDtPIXILLIONCompressbtnv2offPIXILLIONOutputformattopoffPIXILLIONSucav2onBISfMBNqPIXILLIONAllfilesfilteroffGVjtPIXILLIONApplyefxchoiceoffUizv&usage=08D001&usagestats=fromjpg(1)&usechoice=llinad(1)&daysusedprogram=1&usedsubstpct=2&secsfr=29&active10s=2C:\Program Files\Microsoft\Edge\Application\msedge.exe
pixillion.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1804"C:\Program Files\NCH Software\Pixillion\pixillion.exe"C:\Program Files\NCH Software\Pixillion\pixillion.exenchsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
Pixillion Image Converter
Exit code:
0
Version:
11.70+
Modules
Images
c:\program files\nch software\pixillion\pixillion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2420"C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe
explorer.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
Pixillion Image Converter
Exit code:
0
Version:
11.70+
Modules
Images
c:\users\admin\appdata\local\temp\pixillionimageconverter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2528"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2296 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2548"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2264 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
7 456
Read events
6 833
Write events
620
Delete events
3

Modification events

(PID) Process:(2420) PixillionImageConverter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2420) PixillionImageConverter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2420) PixillionImageConverter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2420) PixillionImageConverter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software
Operation:writeName:SVar
Value:
PIXILLIONShowoutfilesize2off
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software
Operation:delete valueName:SVar
Value:
PIXILLIONShowoutfilesize2offLANt
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software
Operation:writeName:SVar
Value:
PIXILLIONRelatedprogramspaidoff
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
10
Suspicious files
92
Text files
38
Unknown types
0

Dropped files

PID
Process
Filename
Type
2420PixillionImageConverter.exeC:\Users\admin\AppData\Local\Temp\n1s\nchdata.datexecutable
MD5:08B32873C614293491CDCDEDD55FB469
SHA256:D5026AB1668EE26FBB7E2D1AE9553AA1C23B2F654352656E12F9A1442BA1D7B6
492nchsetup.exeC:\Program Files\NCH Software\Pixillion\shellmenu.dllexecutable
MD5:6AFB36C052EE41F2E8B3A1B8E273CA7F
SHA256:957115AA98D0576EB41C9BC5E8A4D420D37E2C39338708392EC4FE0C72D8CFAB
2420PixillionImageConverter.exeC:\Users\admin\AppData\Local\Temp\n1s\nchdata.cabcompressed
MD5:0AE25343FF4E6BCA1E07AEEE68E797A5
SHA256:7993BBD255B5B1A81D0464DE1915C988D9641866954B4C18B6D11C9047AC91C8
2420PixillionImageConverter.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exeexecutable
MD5:4021CF3FD0B2A09CF1EE1027F1078B13
SHA256:83EADEAA03B35447A625AB4429647A597386524270993A26CDC83022B12CEFC5
2420PixillionImageConverter.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.cabcompressed
MD5:280CDD7BCE8DD508FF7792DF729F1D59
SHA256:5C0D541298D54A4D132A9739B377842FEA5CB48D9AE2B7067B681141AE6F2D6C
492nchsetup.exeC:\Users\Public\Desktop\NCH Suite.lnkbinary
MD5:316C20DF31B9E37DABF51A63B013906B
SHA256:9F9A082AE73506AC38F46A9D584DEBBE1C30C753283E840A7FC17A16C6232193
492nchsetup.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pixillion Image Converter.lnkbinary
MD5:D3ABE62AD5B4CF4A764A7702334BA17E
SHA256:F0F6096D0F759344FB1D44A3F1DD8D0943B1E5D3294A91DBA03ACCC4000686AA
492nchsetup.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Audio Editing Software.lnkbinary
MD5:A44E39CA8AB2F2010938A750302DA8F4
SHA256:86455FC657E2E65D8C1FC0BB474EB1875F3DE8D2C2D4109CA293F4B43B14D682
1040freetype.exeC:\Users\admin\AppData\Local\Temp\freetype_.cabcompressed
MD5:B543F65A5CFC0342E857053BFB901DA6
SHA256:EF5429418FF01885E4F3BEB0E02AF64471A87997D1D34D3B94D250B25002CB2D
492nchsetup.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Video Editing Software.lnkbinary
MD5:F48E55EB6DDACAE0A79BB4E594CAAD6D
SHA256:984C61D1CF6906154ACDD6F8A94AC7613CB8D7C630B56A5D0B07CEA83203CA8A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
57
DNS requests
62
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
492
nchsetup.exe
173.247.253.164:443
secure.nch.com.au
INMOTION
US
unknown
2804
msedge.exe
54.149.5.211:443
www.nchsoftware.com
AMAZON-02
US
unknown
1768
msedge.exe
239.255.255.250:1900
whitelisted
2804
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2804
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2804
msedge.exe
142.250.181.238:443
apis.google.com
GOOGLE
US
whitelisted
2804
msedge.exe
157.240.0.35:443
www.facebook.com
FACEBOOK
US
unknown

DNS requests

Domain
IP
Reputation
secure.nch.com.au
  • 173.247.253.164
unknown
www.nchsoftware.com
  • 54.149.5.211
  • 66.39.83.155
  • 198.84.119.122
malicious
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
apis.google.com
  • 142.250.181.238
whitelisted
www.facebook.com
  • 157.240.0.35
whitelisted
www.bing.com
  • 92.123.104.60
  • 92.123.104.32
  • 92.123.104.59
  • 92.123.104.34
  • 92.123.104.31
  • 92.123.104.28
  • 92.123.104.33
whitelisted
www.youtube.com
  • 142.250.181.238
  • 142.250.184.206
  • 142.250.184.238
  • 142.250.186.142
  • 142.250.186.46
  • 172.217.18.14
  • 172.217.16.206
  • 142.250.186.174
  • 216.58.206.46
  • 216.58.212.174
  • 216.58.212.142
  • 142.250.185.78
  • 142.250.185.110
  • 142.250.185.142
  • 142.250.185.174
  • 142.250.185.206
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
accounts.google.com
  • 108.177.15.84
shared

Threats

No threats detected
No debug info