File name:

PixillionImageConverter.exe

Full analysis: https://app.any.run/tasks/5fbe83dd-53e4-4dc1-9e3c-4097696e06cd
Verdict: Malicious activity
Analysis date: January 03, 2024, 05:46:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E560332E5967896E6DCAABA5C3125103

SHA1:

41371F428CCD106FECB7EB39619FE52854D0EF00

SHA256:

4208169D08123945F6259EA02E9AACB3F655070467CE820326ED04B1811987F6

SSDEEP:

98304:yb9aeGgiHMEXAMXzFUvJ7lQgmU6D3nu3NDkPav54I0UOGDw6arpsxnHygt2Ix75N:igu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • PixillionImageConverter.exe (PID: 2420)
      • nchsetup.exe (PID: 492)
      • pixillion.exe (PID: 1804)
    • Searches for installed software

      • nchsetup.exe (PID: 492)
  • INFO

    • Checks supported languages

      • PixillionImageConverter.exe (PID: 2420)
      • nchsetup.exe (PID: 492)
      • freetype.exe (PID: 1040)
      • pixillion.exe (PID: 1804)
      • pixillion.exe (PID: 712)
    • Drops the executable file immediately after the start

      • PixillionImageConverter.exe (PID: 2420)
      • nchsetup.exe (PID: 492)
      • freetype.exe (PID: 1040)
    • Reads the computer name

      • PixillionImageConverter.exe (PID: 2420)
      • nchsetup.exe (PID: 492)
      • pixillion.exe (PID: 712)
      • pixillion.exe (PID: 1804)
    • Create files in a temporary directory

      • PixillionImageConverter.exe (PID: 2420)
      • freetype.exe (PID: 1040)
      • pixillion.exe (PID: 1804)
    • Creates files in the program directory

      • nchsetup.exe (PID: 492)
      • freetype.exe (PID: 1040)
    • Starts itself from another location

      • nchsetup.exe (PID: 492)
    • Reads the machine GUID from the registry

      • pixillion.exe (PID: 1804)
    • Application launched itself

      • msedge.exe (PID: 1768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:09:21 07:45:58+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 2560
InitializedDataSize: 2085888
UninitializedDataSize: -
EntryPoint: 0x1286
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (Australian)
CharacterSet: Unicode
CompanyName: NCH Software
FileDescription: Pixillion Image Converter
FileVersion: 11.70+
ProductVersion: 11.70+
ProductName: Pixillion
LegalCopyright: NCH Software
InternalName: Pixillion
OriginalFileName: Pixillion.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
29
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pixillionimageconverter.exe nchsetup.exe freetype.exe no specs pixillion.exe no specs pixillion.exe no specs PhotoViewer.dll no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs pixillionimageconverter.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exeexplorer.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
Pixillion Image Converter
Exit code:
3221226540
Version:
11.70+
Modules
Images
c:\users\admin\appdata\local\temp\pixillionimageconverter.exe
c:\windows\system32\ntdll.dll
492"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe" -installer "C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" -instdata "C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe
PixillionImageConverter.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
Pixillion Image Converter
Exit code:
0
Version:
11.70+
Modules
Images
c:\users\admin\appdata\local\temp\n1s\nchsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
712"C:\Program Files\NCH Software\Pixillion\pixillion.exe" -installschedC:\Program Files\NCH Software\Pixillion\pixillion.exenchsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
Pixillion Image Converter
Exit code:
0
Version:
11.70+
Modules
Images
c:\program files\nch software\pixillion\pixillion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1040"C:\Program Files\NCH Software\Pixillion\freetype.exe" -LQUIET -instby fiPixillion -instsvar PIXILLIONRelatedprogramspaidoffLLIBInstquickonC:\Program Files\NCH Software\Pixillion\freetype.exenchsetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\nch software\pixillion\freetype.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1124"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3560 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1768"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.nchsoftware.com/software/thanks.html?software=Pixillion&appname=Pixillion&version=11.70&appbits=32&base=imageconverter&domain=nchsoftware&buyoffer=pixillion&pclass=plus&rgst=0&antivirus=expired&instby=dl&iid=GQ7ed2yGqRI&help=0&ostype=48&osver=6.1&svar=PIXILLIONRelatedprogramspaidoffLLIBInstquickonPIXILLIONShowoutfilesize2offLANhLLIBControloffEYivPIXILLIONSplashv2offIc2fUTfsPIXILLIONRecentfilesonDRBjGxotPIXILLIONRemovedropdownoffF3ocCC9wGUwrPIXILLIONOilpaintfilteronHZDhR4hjDiphHo1bIb1cNxmtI03nZTUvDFWwIwlpPIXILLIONRemovebgtboffOqwkFHoeHtppPIXILLIONNewoutdirlabeloffPIXILLIONOutputfolderpdlonPIXILLIONSetoutfolderonEwdjPz6fOVJfOElvTNDtPIXILLIONCompressbtnv2offPIXILLIONOutputformattopoffPIXILLIONSucav2onBISfMBNqPIXILLIONAllfilesfilteroffGVjtPIXILLIONApplyefxchoiceoffUizv&usage=08D001&usagestats=fromjpg(1)&usechoice=llinad(1)&daysusedprogram=1&usedsubstpct=2&secsfr=29&active10s=2C:\Program Files\Microsoft\Edge\Application\msedge.exe
pixillion.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1804"C:\Program Files\NCH Software\Pixillion\pixillion.exe"C:\Program Files\NCH Software\Pixillion\pixillion.exenchsetup.exe
User:
admin
Company:
NCH Software
Integrity Level:
MEDIUM
Description:
Pixillion Image Converter
Exit code:
0
Version:
11.70+
Modules
Images
c:\program files\nch software\pixillion\pixillion.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2420"C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe
explorer.exe
User:
admin
Company:
NCH Software
Integrity Level:
HIGH
Description:
Pixillion Image Converter
Exit code:
0
Version:
11.70+
Modules
Images
c:\users\admin\appdata\local\temp\pixillionimageconverter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2528"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2296 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2548"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2264 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
7 456
Read events
6 833
Write events
620
Delete events
3

Modification events

(PID) Process:(2420) PixillionImageConverter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2420) PixillionImageConverter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2420) PixillionImageConverter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2420) PixillionImageConverter.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software
Operation:writeName:SVar
Value:
PIXILLIONShowoutfilesize2off
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software
Operation:delete valueName:SVar
Value:
PIXILLIONShowoutfilesize2offLANt
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software
Operation:writeName:SVar
Value:
PIXILLIONRelatedprogramspaidoff
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(492) nchsetup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
10
Suspicious files
92
Text files
38
Unknown types
0

Dropped files

PID
Process
Filename
Type
2420PixillionImageConverter.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.cabcompressed
MD5:280CDD7BCE8DD508FF7792DF729F1D59
SHA256:5C0D541298D54A4D132A9739B377842FEA5CB48D9AE2B7067B681141AE6F2D6C
2420PixillionImageConverter.exeC:\Users\admin\AppData\Local\Temp\n1s\nchdata.datexecutable
MD5:08B32873C614293491CDCDEDD55FB469
SHA256:D5026AB1668EE26FBB7E2D1AE9553AA1C23B2F654352656E12F9A1442BA1D7B6
492nchsetup.exeC:\Program Files\NCH Software\Pixillion\pixillion.exeexecutable
MD5:4021CF3FD0B2A09CF1EE1027F1078B13
SHA256:83EADEAA03B35447A625AB4429647A597386524270993A26CDC83022B12CEFC5
2420PixillionImageConverter.exeC:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exeexecutable
MD5:4021CF3FD0B2A09CF1EE1027F1078B13
SHA256:83EADEAA03B35447A625AB4429647A597386524270993A26CDC83022B12CEFC5
492nchsetup.exeC:\Program Files\NCH Software\Pixillion\shellmenua.msixcompressed
MD5:B7CE79B0BDF6573B7BE6B582E4EFD108
SHA256:4ADB84DDFF4A21B5ED4B598EFA4D97BFF61C95AB597BBF941D9DEC42BD3ECD2B
492nchsetup.exeC:\Program Files\NCH Software\Pixillion\shellmenub.msixcompressed
MD5:5BC23026E012ABB939D71C11E5E8BB22
SHA256:B2AF6A2F35945D0527820252A868DAD30488AC59AE2C7926C339008A932B6342
492nchsetup.exeC:\Program Files\NCH Software\Pixillion\superresolution.nnbinary
MD5:44C554286E70AD597BA03CAE562DF365
SHA256:B80576E3A39238DA26FBCA141F6D15211AA5AE82558B92DC0CA96A434A8C1C05
492nchsetup.exeC:\Program Files\NCH Software\Pixillion\freetype.exeexecutable
MD5:9D922FF98AB5EF728BF482A46C565647
SHA256:946EC5E46E155101DA5A5E8B03AAAFB4F0359EFA437A99AE38D395763E73BCCF
1040freetype.exeC:\Users\admin\AppData\Local\Temp\freetype_.cabcompressed
MD5:B543F65A5CFC0342E857053BFB901DA6
SHA256:EF5429418FF01885E4F3BEB0E02AF64471A87997D1D34D3B94D250B25002CB2D
1040freetype.exeC:\Program Files\NCH Software\Components\freetype\freetype.dllexecutable
MD5:7D66FC033100AC6BF20416A28D688B23
SHA256:C3043A6221E4A89FA3D731A1E25A3C1D2CB1D6E5F0006B33B025C7B8EC0A837D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
57
DNS requests
62
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
492
nchsetup.exe
173.247.253.164:443
secure.nch.com.au
INMOTION
US
unknown
2804
msedge.exe
54.149.5.211:443
www.nchsoftware.com
AMAZON-02
US
unknown
1768
msedge.exe
239.255.255.250:1900
whitelisted
2804
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2804
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2804
msedge.exe
142.250.181.238:443
apis.google.com
GOOGLE
US
whitelisted
2804
msedge.exe
157.240.0.35:443
www.facebook.com
FACEBOOK
US
unknown

DNS requests

Domain
IP
Reputation
secure.nch.com.au
  • 173.247.253.164
unknown
www.nchsoftware.com
  • 54.149.5.211
  • 66.39.83.155
  • 198.84.119.122
malicious
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
apis.google.com
  • 142.250.181.238
whitelisted
www.facebook.com
  • 157.240.0.35
whitelisted
www.bing.com
  • 92.123.104.60
  • 92.123.104.32
  • 92.123.104.59
  • 92.123.104.34
  • 92.123.104.31
  • 92.123.104.28
  • 92.123.104.33
whitelisted
www.youtube.com
  • 142.250.181.238
  • 142.250.184.206
  • 142.250.184.238
  • 142.250.186.142
  • 142.250.186.46
  • 172.217.18.14
  • 172.217.16.206
  • 142.250.186.174
  • 216.58.206.46
  • 216.58.212.174
  • 216.58.212.142
  • 142.250.185.78
  • 142.250.185.110
  • 142.250.185.142
  • 142.250.185.174
  • 142.250.185.206
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.103.180.120
whitelisted
accounts.google.com
  • 108.177.15.84
shared

Threats

No threats detected
No debug info