| File name: | PixillionImageConverter.exe |
| Full analysis: | https://app.any.run/tasks/5fbe83dd-53e4-4dc1-9e3c-4097696e06cd |
| Verdict: | Malicious activity |
| Analysis date: | January 03, 2024, 05:46:08 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E560332E5967896E6DCAABA5C3125103 |
| SHA1: | 41371F428CCD106FECB7EB39619FE52854D0EF00 |
| SHA256: | 4208169D08123945F6259EA02E9AACB3F655070467CE820326ED04B1811987F6 |
| SSDEEP: | 98304:yb9aeGgiHMEXAMXzFUvJ7lQgmU6D3nu3NDkPav54I0UOGDw6arpsxnHygt2Ix75N:igu |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:09:21 07:45:58+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 2560 |
| InitializedDataSize: | 2085888 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1286 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (Australian) |
| CharacterSet: | Unicode |
| CompanyName: | NCH Software |
| FileDescription: | Pixillion Image Converter |
| FileVersion: | 11.70+ |
| ProductVersion: | 11.70+ |
| ProductName: | Pixillion |
| LegalCopyright: | NCH Software |
| InternalName: | Pixillion |
| OriginalFileName: | Pixillion.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" | C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe | — | explorer.exe | |||||||||||
User: admin Company: NCH Software Integrity Level: MEDIUM Description: Pixillion Image Converter Exit code: 3221226540 Version: 11.70+ Modules
| |||||||||||||||
| 492 | "C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe" -installer "C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" -instdata "C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat" | C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe | PixillionImageConverter.exe | ||||||||||||
User: admin Company: NCH Software Integrity Level: HIGH Description: Pixillion Image Converter Exit code: 0 Version: 11.70+ Modules
| |||||||||||||||
| 712 | "C:\Program Files\NCH Software\Pixillion\pixillion.exe" -installsched | C:\Program Files\NCH Software\Pixillion\pixillion.exe | — | nchsetup.exe | |||||||||||
User: admin Company: NCH Software Integrity Level: MEDIUM Description: Pixillion Image Converter Exit code: 0 Version: 11.70+ Modules
| |||||||||||||||
| 1040 | "C:\Program Files\NCH Software\Pixillion\freetype.exe" -LQUIET -instby fiPixillion -instsvar PIXILLIONRelatedprogramspaidoffLLIBInstquickon | C:\Program Files\NCH Software\Pixillion\freetype.exe | — | nchsetup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1124 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3560 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1768 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.nchsoftware.com/software/thanks.html?software=Pixillion&appname=Pixillion&version=11.70&appbits=32&base=imageconverter&domain=nchsoftware&buyoffer=pixillion&pclass=plus&rgst=0&antivirus=expired&instby=dl&iid=GQ7ed2yGqRI&help=0&ostype=48&osver=6.1&svar=PIXILLIONRelatedprogramspaidoffLLIBInstquickonPIXILLIONShowoutfilesize2offLANhLLIBControloffEYivPIXILLIONSplashv2offIc2fUTfsPIXILLIONRecentfilesonDRBjGxotPIXILLIONRemovedropdownoffF3ocCC9wGUwrPIXILLIONOilpaintfilteronHZDhR4hjDiphHo1bIb1cNxmtI03nZTUvDFWwIwlpPIXILLIONRemovebgtboffOqwkFHoeHtppPIXILLIONNewoutdirlabeloffPIXILLIONOutputfolderpdlonPIXILLIONSetoutfolderonEwdjPz6fOVJfOElvTNDtPIXILLIONCompressbtnv2offPIXILLIONOutputformattopoffPIXILLIONSucav2onBISfMBNqPIXILLIONAllfilesfilteroffGVjtPIXILLIONApplyefxchoiceoffUizv&usage=08D001&usagestats=fromjpg(1)&usechoice=llinad(1)&daysusedprogram=1&usedsubstpct=2&secsfr=29&active10s=2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | pixillion.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1804 | "C:\Program Files\NCH Software\Pixillion\pixillion.exe" | C:\Program Files\NCH Software\Pixillion\pixillion.exe | — | nchsetup.exe | |||||||||||
User: admin Company: NCH Software Integrity Level: MEDIUM Description: Pixillion Image Converter Exit code: 0 Version: 11.70+ Modules
| |||||||||||||||
| 2420 | "C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" | C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe | explorer.exe | ||||||||||||
User: admin Company: NCH Software Integrity Level: HIGH Description: Pixillion Image Converter Exit code: 0 Version: 11.70+ Modules
| |||||||||||||||
| 2528 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2296 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2548 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2264 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (2420) PixillionImageConverter.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2420) PixillionImageConverter.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2420) PixillionImageConverter.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2420) PixillionImageConverter.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software |
| Operation: | write | Name: | SVar |
Value: PIXILLIONShowoutfilesize2off | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software |
| Operation: | delete value | Name: | SVar |
Value: PIXILLIONShowoutfilesize2offLANt | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software |
| Operation: | write | Name: | SVar |
Value: PIXILLIONRelatedprogramspaidoff | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2420 | PixillionImageConverter.exe | C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.cab | compressed | |
MD5:280CDD7BCE8DD508FF7792DF729F1D59 | SHA256:5C0D541298D54A4D132A9739B377842FEA5CB48D9AE2B7067B681141AE6F2D6C | |||
| 2420 | PixillionImageConverter.exe | C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat | executable | |
MD5:08B32873C614293491CDCDEDD55FB469 | SHA256:D5026AB1668EE26FBB7E2D1AE9553AA1C23B2F654352656E12F9A1442BA1D7B6 | |||
| 492 | nchsetup.exe | C:\Program Files\NCH Software\Pixillion\pixillion.exe | executable | |
MD5:4021CF3FD0B2A09CF1EE1027F1078B13 | SHA256:83EADEAA03B35447A625AB4429647A597386524270993A26CDC83022B12CEFC5 | |||
| 2420 | PixillionImageConverter.exe | C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe | executable | |
MD5:4021CF3FD0B2A09CF1EE1027F1078B13 | SHA256:83EADEAA03B35447A625AB4429647A597386524270993A26CDC83022B12CEFC5 | |||
| 492 | nchsetup.exe | C:\Program Files\NCH Software\Pixillion\shellmenua.msix | compressed | |
MD5:B7CE79B0BDF6573B7BE6B582E4EFD108 | SHA256:4ADB84DDFF4A21B5ED4B598EFA4D97BFF61C95AB597BBF941D9DEC42BD3ECD2B | |||
| 492 | nchsetup.exe | C:\Program Files\NCH Software\Pixillion\shellmenub.msix | compressed | |
MD5:5BC23026E012ABB939D71C11E5E8BB22 | SHA256:B2AF6A2F35945D0527820252A868DAD30488AC59AE2C7926C339008A932B6342 | |||
| 492 | nchsetup.exe | C:\Program Files\NCH Software\Pixillion\superresolution.nn | binary | |
MD5:44C554286E70AD597BA03CAE562DF365 | SHA256:B80576E3A39238DA26FBCA141F6D15211AA5AE82558B92DC0CA96A434A8C1C05 | |||
| 492 | nchsetup.exe | C:\Program Files\NCH Software\Pixillion\freetype.exe | executable | |
MD5:9D922FF98AB5EF728BF482A46C565647 | SHA256:946EC5E46E155101DA5A5E8B03AAAFB4F0359EFA437A99AE38D395763E73BCCF | |||
| 1040 | freetype.exe | C:\Users\admin\AppData\Local\Temp\freetype_.cab | compressed | |
MD5:B543F65A5CFC0342E857053BFB901DA6 | SHA256:EF5429418FF01885E4F3BEB0E02AF64471A87997D1D34D3B94D250B25002CB2D | |||
| 1040 | freetype.exe | C:\Program Files\NCH Software\Components\freetype\freetype.dll | executable | |
MD5:7D66FC033100AC6BF20416A28D688B23 | SHA256:C3043A6221E4A89FA3D731A1E25A3C1D2CB1D6E5F0006B33B025C7B8EC0A837D | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
492 | nchsetup.exe | 173.247.253.164:443 | secure.nch.com.au | INMOTION | US | unknown |
2804 | msedge.exe | 54.149.5.211:443 | www.nchsoftware.com | AMAZON-02 | US | unknown |
1768 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2804 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2804 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2804 | msedge.exe | 142.250.181.238:443 | apis.google.com | GOOGLE | US | whitelisted |
2804 | msedge.exe | 157.240.0.35:443 | www.facebook.com | FACEBOOK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
secure.nch.com.au |
| unknown |
www.nchsoftware.com |
| malicious |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
apis.google.com |
| whitelisted |
www.facebook.com |
| whitelisted |
www.bing.com |
| whitelisted |
www.youtube.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
accounts.google.com |
| shared |