| File name: | xpaj.exe |
| Full analysis: | https://app.any.run/tasks/52cbe7c8-0895-4650-a64a-4a25ab43e748 |
| Verdict: | Malicious activity |
| Analysis date: | January 13, 2026, 18:02:53 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed, 3 sections |
| MD5: | D5C12FCFEEBBE63F74026601CD7F39B2 |
| SHA1: | 50281DE9ABB1BEC1B6A1F13CCD3CE3493DEE8850 |
| SHA256: | 9DB7EF2D1495DBA921F3084B05D95E418A16F4C5E8DE93738ABEF2479AD5B0DA |
| SSDEEP: | 6144:Gqmg/v4y/MqGs38KHF1SubUriPOKAJnP8:jmgXxXGNKHCm |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 0000:00:00 00:00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 73728 |
| InitializedDataSize: | - |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1000 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1948 | C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -Embedding | C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Modules Installer Worker Version: 10.0.19041.3989 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4972 | C:\WINDOWS\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1467 Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6000 | C:\WINDOWS\System32\mobsync.exe -Embedding | C:\Windows\System32\mobsync.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Sync Center Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7192 | "C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mca | C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Search application Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7468 | "C:\Users\admin\AppData\Local\Temp\xpaj.exe" | C:\Users\admin\AppData\Local\Temp\xpaj.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 7656 | C:\WINDOWS\system32\WerFault.exe -u -p 4972 -s 8652 | C:\Windows\System32\WerFault.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 8096 | "C:\WINDOWS\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe" -ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca | C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 8128 | "C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca | C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Version: 123.26505.0.0 Modules
| |||||||||||||||
| (PID) Process: | (4972) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
| Operation: | write | Name: | CheckSetting |
Value: 23004100430042006C006F00620000000000000000000000010000004400000044000000 | |||
| (PID) Process: | (8096) StartMenuExperienceHost.exe | Key: | \REGISTRY\A\{414776db-b8f3-c5f0-1744-3f7529614190}\LocalState\DataCorruptionRecovery |
| Operation: | write | Name: | InitializationAttemptCount |
Value: 0100000006FBDDDCB684DC01 | |||
| (PID) Process: | (8096) StartMenuExperienceHost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TileDataModel\Migration\StartNonLayoutProperties |
| Operation: | write | Name: | Completed |
Value: 1 | |||
| (PID) Process: | (8096) StartMenuExperienceHost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TileDataModel\Migration\StartNonLayoutProperties_AppUsageData |
| Operation: | write | Name: | Completed |
Value: 1 | |||
| (PID) Process: | (8096) StartMenuExperienceHost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TileDataModel\Migration\StartNonLayoutProperties_TargetedContentTiles |
| Operation: | write | Name: | Completed |
Value: 1 | |||
| (PID) Process: | (7192) SearchApp.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\SearchSettings |
| Operation: | write | Name: | SafeSearchMode |
Value: 1 | |||
| (PID) Process: | (7192) SearchApp.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search |
| Operation: | write | Name: | CortanaStateLastRun |
Value: D888666900000000 | |||
| (PID) Process: | (7192) SearchApp.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Flighting |
| Operation: | write | Name: | CachedFeatureString |
Value: | |||
| (PID) Process: | (7192) SearchApp.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.search_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7192) SearchApp.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.search_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7656 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Explorer.EXE_6b2f479e7b52cac91f9e556e35e19ef59932ab_a6883b46_72927fa9-8382-46b9-b8dd-f57864954214\Report.wer | — | |
MD5:— | SHA256:— | |||
| 7656 | WerFault.exe | C:\Users\admin\AppData\Local\CrashDumps\explorer.exe.4972.dmp | — | |
MD5:— | SHA256:— | |||
| 1948 | TiWorker.exe | C:\Windows\Logs\CBS\CBS.log | — | |
MD5:— | SHA256:— | |||
| 7468 | xpaj.exe | C:\Users\admin\AppData\Local\Temp\D7D8.tmp | executable | |
MD5:D5C12FCFEEBBE63F74026601CD7F39B2 | SHA256:9DB7EF2D1495DBA921F3084B05D95E418A16F4C5E8DE93738ABEF2479AD5B0DA | |||
| 7468 | xpaj.exe | C:\Users\admin\AppData\Local\Temp\D7FA.tmp | executable | |
MD5:D5C12FCFEEBBE63F74026601CD7F39B2 | SHA256:9DB7EF2D1495DBA921F3084B05D95E418A16F4C5E8DE93738ABEF2479AD5B0DA | |||
| 7192 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10D | binary | |
MD5:E567ABEAB49ABF761DBEC0259CD186C7 | SHA256:CF67A90C17B54B9295357F76364728C38644AB9ECCC91F29BEE2733AB1F485DC | |||
| 7192 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\Q84V0JUH\ANzUnPnVY0oL0XWxs0RLJxjJLUo.br[1].js | text | |
MD5:9E527B91C2D8B31B0017B76049B5E4E3 | SHA256:38EDF0F961C1CCB287880B88F12F370775FC65B2E28227EEE215E849CDBE9BBC | |||
| 7192 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5Y734AMR\88\_cqOeJKtsnBu9LrnbJX1CjU2yBg[1].js | text | |
MD5:1938D24823A70193AAE12D6F5CA837D0 | SHA256:DFBEC009777C2508FE3BDDF75DE3C472239DD02737C3533FAD7CBE7E69089080 | |||
| 7192 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5Y734AMR\88\FgBbpIj0thGWZOh_xFnM9i4O7ek[1].css | text | |
MD5:A889E641E8C039E7DECE507C66252CFB | SHA256:2B7361D1E68D55F6B798BDB253C816F52F948407A57C693E0790208682B8F542 | |||
| 7656 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERE102.tmp.xml | xml | |
MD5:1F1F0E7A3080B4FC3EC810387E348FC1 | SHA256:6A5B85696899F163751A4BE5C51A306324E503A8FFDF086684124B4F418AFE18 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3176 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
3176 | svchost.exe | POST | 200 | 40.126.32.133:443 | https://login.live.com/RST2.srf | US | xml | 11.1 Kb | whitelisted |
7192 | SearchApp.exe | GET | 200 | 2.16.241.212:443 | https://www.bing.com/rp/ANzUnPnVY0oL0XWxs0RLJxjJLUo.br.js | NL | text | 20.3 Kb | whitelisted |
7192 | SearchApp.exe | POST | 204 | 2.16.241.212:443 | https://www.bing.com/threshold/xls.aspx | NL | — | — | whitelisted |
7192 | SearchApp.exe | POST | 204 | 2.16.241.212:443 | https://www.bing.com/threshold/xls.aspx | NL | — | — | whitelisted |
3176 | svchost.exe | POST | 200 | 40.126.32.133:443 | https://login.live.com/RST2.srf | US | xml | 11.1 Kb | whitelisted |
7192 | SearchApp.exe | GET | 304 | 2.16.241.212:443 | https://www.bing.com/rp/h2m6AVCpDtS8Ff3ZxuDGx1A2-O8.br.js | NL | — | — | whitelisted |
3176 | svchost.exe | POST | 200 | 40.126.32.133:443 | https://login.live.com/RST2.srf | US | xml | 5.53 Kb | whitelisted |
7192 | SearchApp.exe | GET | 304 | 2.16.241.212:443 | https://www.bing.com/rp/ikpPfkLjP14eKCzM16ksiFVp92Y.br.js | NL | — | — | whitelisted |
7192 | SearchApp.exe | GET | 200 | 2.16.241.212:443 | https://www.bing.com/manifest/threshold.appcache | NL | text | 2.55 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2308 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
6768 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6236 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
3412 | svchost.exe | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3176 | svchost.exe | 40.126.32.133:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3176 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
7192 | SearchApp.exe | 2.16.241.212:443 | www.bing.com | AKAMAI-ASN1 | NL | whitelisted |
7192 | SearchApp.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
nortiniolosto.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.bing.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |