| File name: | PixillionImageConverter.exe |
| Full analysis: | https://app.any.run/tasks/5fbe83dd-53e4-4dc1-9e3c-4097696e06cd |
| Verdict: | Malicious activity |
| Analysis date: | January 03, 2024, 05:46:08 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E560332E5967896E6DCAABA5C3125103 |
| SHA1: | 41371F428CCD106FECB7EB39619FE52854D0EF00 |
| SHA256: | 4208169D08123945F6259EA02E9AACB3F655070467CE820326ED04B1811987F6 |
| SSDEEP: | 98304:yb9aeGgiHMEXAMXzFUvJ7lQgmU6D3nu3NDkPav54I0UOGDw6arpsxnHygt2Ix75N:igu |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:09:21 07:45:58+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 2560 |
| InitializedDataSize: | 2085888 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1286 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (Australian) |
| CharacterSet: | Unicode |
| CompanyName: | NCH Software |
| FileDescription: | Pixillion Image Converter |
| FileVersion: | 11.70+ |
| ProductVersion: | 11.70+ |
| ProductName: | Pixillion |
| LegalCopyright: | NCH Software |
| InternalName: | Pixillion |
| OriginalFileName: | Pixillion.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" | C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe | — | explorer.exe | |||||||||||
User: admin Company: NCH Software Integrity Level: MEDIUM Description: Pixillion Image Converter Exit code: 3221226540 Version: 11.70+ Modules
| |||||||||||||||
| 492 | "C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe" -installer "C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" -instdata "C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat" | C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe | PixillionImageConverter.exe | ||||||||||||
User: admin Company: NCH Software Integrity Level: HIGH Description: Pixillion Image Converter Exit code: 0 Version: 11.70+ Modules
| |||||||||||||||
| 712 | "C:\Program Files\NCH Software\Pixillion\pixillion.exe" -installsched | C:\Program Files\NCH Software\Pixillion\pixillion.exe | — | nchsetup.exe | |||||||||||
User: admin Company: NCH Software Integrity Level: MEDIUM Description: Pixillion Image Converter Exit code: 0 Version: 11.70+ Modules
| |||||||||||||||
| 1040 | "C:\Program Files\NCH Software\Pixillion\freetype.exe" -LQUIET -instby fiPixillion -instsvar PIXILLIONRelatedprogramspaidoffLLIBInstquickon | C:\Program Files\NCH Software\Pixillion\freetype.exe | — | nchsetup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1124 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3560 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1768 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.nchsoftware.com/software/thanks.html?software=Pixillion&appname=Pixillion&version=11.70&appbits=32&base=imageconverter&domain=nchsoftware&buyoffer=pixillion&pclass=plus&rgst=0&antivirus=expired&instby=dl&iid=GQ7ed2yGqRI&help=0&ostype=48&osver=6.1&svar=PIXILLIONRelatedprogramspaidoffLLIBInstquickonPIXILLIONShowoutfilesize2offLANhLLIBControloffEYivPIXILLIONSplashv2offIc2fUTfsPIXILLIONRecentfilesonDRBjGxotPIXILLIONRemovedropdownoffF3ocCC9wGUwrPIXILLIONOilpaintfilteronHZDhR4hjDiphHo1bIb1cNxmtI03nZTUvDFWwIwlpPIXILLIONRemovebgtboffOqwkFHoeHtppPIXILLIONNewoutdirlabeloffPIXILLIONOutputfolderpdlonPIXILLIONSetoutfolderonEwdjPz6fOVJfOElvTNDtPIXILLIONCompressbtnv2offPIXILLIONOutputformattopoffPIXILLIONSucav2onBISfMBNqPIXILLIONAllfilesfilteroffGVjtPIXILLIONApplyefxchoiceoffUizv&usage=08D001&usagestats=fromjpg(1)&usechoice=llinad(1)&daysusedprogram=1&usedsubstpct=2&secsfr=29&active10s=2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | pixillion.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1804 | "C:\Program Files\NCH Software\Pixillion\pixillion.exe" | C:\Program Files\NCH Software\Pixillion\pixillion.exe | — | nchsetup.exe | |||||||||||
User: admin Company: NCH Software Integrity Level: MEDIUM Description: Pixillion Image Converter Exit code: 0 Version: 11.70+ Modules
| |||||||||||||||
| 2420 | "C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe" | C:\Users\admin\AppData\Local\Temp\PixillionImageConverter.exe | explorer.exe | ||||||||||||
User: admin Company: NCH Software Integrity Level: HIGH Description: Pixillion Image Converter Exit code: 0 Version: 11.70+ Modules
| |||||||||||||||
| 2528 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2296 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2548 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2264 --field-trial-handle=1308,i,18439962368443838845,597548095713535119,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (2420) PixillionImageConverter.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2420) PixillionImageConverter.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2420) PixillionImageConverter.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2420) PixillionImageConverter.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software |
| Operation: | write | Name: | SVar |
Value: PIXILLIONShowoutfilesize2off | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software |
| Operation: | delete value | Name: | SVar |
Value: PIXILLIONShowoutfilesize2offLANt | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\NCH Software\Pixillion\Software |
| Operation: | write | Name: | SVar |
Value: PIXILLIONRelatedprogramspaidoff | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (492) nchsetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2420 | PixillionImageConverter.exe | C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat | executable | |
MD5:08B32873C614293491CDCDEDD55FB469 | SHA256:D5026AB1668EE26FBB7E2D1AE9553AA1C23B2F654352656E12F9A1442BA1D7B6 | |||
| 492 | nchsetup.exe | C:\Program Files\NCH Software\Pixillion\shellmenu.dll | executable | |
MD5:6AFB36C052EE41F2E8B3A1B8E273CA7F | SHA256:957115AA98D0576EB41C9BC5E8A4D420D37E2C39338708392EC4FE0C72D8CFAB | |||
| 2420 | PixillionImageConverter.exe | C:\Users\admin\AppData\Local\Temp\n1s\nchdata.cab | compressed | |
MD5:0AE25343FF4E6BCA1E07AEEE68E797A5 | SHA256:7993BBD255B5B1A81D0464DE1915C988D9641866954B4C18B6D11C9047AC91C8 | |||
| 2420 | PixillionImageConverter.exe | C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe | executable | |
MD5:4021CF3FD0B2A09CF1EE1027F1078B13 | SHA256:83EADEAA03B35447A625AB4429647A597386524270993A26CDC83022B12CEFC5 | |||
| 2420 | PixillionImageConverter.exe | C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.cab | compressed | |
MD5:280CDD7BCE8DD508FF7792DF729F1D59 | SHA256:5C0D541298D54A4D132A9739B377842FEA5CB48D9AE2B7067B681141AE6F2D6C | |||
| 492 | nchsetup.exe | C:\Users\Public\Desktop\NCH Suite.lnk | binary | |
MD5:316C20DF31B9E37DABF51A63B013906B | SHA256:9F9A082AE73506AC38F46A9D584DEBBE1C30C753283E840A7FC17A16C6232193 | |||
| 492 | nchsetup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pixillion Image Converter.lnk | binary | |
MD5:D3ABE62AD5B4CF4A764A7702334BA17E | SHA256:F0F6096D0F759344FB1D44A3F1DD8D0943B1E5D3294A91DBA03ACCC4000686AA | |||
| 492 | nchsetup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Audio Editing Software.lnk | binary | |
MD5:A44E39CA8AB2F2010938A750302DA8F4 | SHA256:86455FC657E2E65D8C1FC0BB474EB1875F3DE8D2C2D4109CA293F4B43B14D682 | |||
| 1040 | freetype.exe | C:\Users\admin\AppData\Local\Temp\freetype_.cab | compressed | |
MD5:B543F65A5CFC0342E857053BFB901DA6 | SHA256:EF5429418FF01885E4F3BEB0E02AF64471A87997D1D34D3B94D250B25002CB2D | |||
| 492 | nchsetup.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite\Video Editing Software.lnk | binary | |
MD5:F48E55EB6DDACAE0A79BB4E594CAAD6D | SHA256:984C61D1CF6906154ACDD6F8A94AC7613CB8D7C630B56A5D0B07CEA83203CA8A | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
492 | nchsetup.exe | 173.247.253.164:443 | secure.nch.com.au | INMOTION | US | unknown |
2804 | msedge.exe | 54.149.5.211:443 | www.nchsoftware.com | AMAZON-02 | US | unknown |
1768 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2804 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2804 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2804 | msedge.exe | 142.250.181.238:443 | apis.google.com | GOOGLE | US | whitelisted |
2804 | msedge.exe | 157.240.0.35:443 | www.facebook.com | FACEBOOK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
secure.nch.com.au |
| unknown |
www.nchsoftware.com |
| malicious |
config.edge.skype.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
apis.google.com |
| whitelisted |
www.facebook.com |
| whitelisted |
www.bing.com |
| whitelisted |
www.youtube.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
accounts.google.com |
| shared |