Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
proxy[1].png

Overview

General Information

Sample name:proxy[1].png
Analysis ID:1446063
MD5:0fbedb10ed339d1b065b66200c5ce802
SHA1:7b930d85e38fbcf4742565fc4896d8757b43a318
SHA256:44dc36f4fbd4d55b95dcf49843a2660662213f9e0da23322a57399c8937df033
Infos:

Detection

Score:2
Range:0 - 100
Whitelisted:false
Confidence:40%

Signatures

Abnormal high CPU Usage
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
May sleep (evasive loops) to hinder dynamic analysis
Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device

Classification

  • System is w10x64_ra
  • rundll32.exe (PID: 1940 cmdline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding MD5: EF3179D498793BF4234F708D3BE28633)
  • PaintStudio.View.exe (PID: 2752 cmdline: "C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe" MD5: 7E11B5F9F7A7FE66809577EC83971972)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: PaintStudio.View.exe, 00000016.00000002.2545476210.0000028A20157000.00000004.00000020.00020000.00000000.sdmp, PaintStudio.View.exe, 00000016.00000002.2549513252.0000028A201B6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://json-schema.org/draft-04/schema
Source: PaintStudio.View.exe, 00000016.00000002.2511694929.0000028A18F7C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ns.adobe.ho
Source: PaintStudio.View.exe, 00000016.00000002.2831965481.0000028A23969000.00000004.00000020.00020000.00000000.sdmp, PaintStudio.View.exe, 00000016.00000002.2543331343.0000028A20124000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/paint3dhelp
Source: PaintStudio.View.exe, 00000016.00000002.2851402839.0000028A23B71000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.remix3d.com/v3/creations
Source: PaintStudio.View.exe, 00000016.00000002.2836533698.0000028A239CC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.remix3d.com/v3/creations/
Source: PaintStudio.View.exe, 00000016.00000002.2831965481.0000028A23969000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://evoke-windowsservices-tas.msedge.net/
Source: PaintStudio.View.exe, 00000016.00000002.2530431480.0000028A2001D000.00000004.00000020.00020000.00000000.sdmp, PaintStudio.View.exe, 00000016.00000002.2831965481.0000028A23969000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://evoke-windowsservices-tas.msedge.net/ab
Source: PaintStudio.View.exe, 00000016.00000002.2831965481.0000028A23969000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://evoke-windowsservices-tas.msedge.net/abC
Source: PaintStudio.View.exe, 00000016.00000003.2166289033.0000028A224E2000.00000004.00000020.00020000.00000000.sdmp, PaintStudio.View.exe, 00000016.00000002.2629112342.0000028A20F4B000.00000004.00000020.00020000.00000000.sdmp, PaintStudio.View.exe, 00000016.00000002.2704854111.0000028A224E2000.00000004.00000020.00020000.00000000.sdmp, PaintStudio.View.exe, 00000016.00000003.2002442810.0000028A224DC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hubble.officeapps.live.com/mediasvc/api/media/
Source: PaintStudio.View.exe, 00000016.00000002.2629112342.0000028A20F4B000.00000004.00000020.00020000.00000000.sdmp, PaintStudio.View.exe, 00000016.00000003.2002442810.0000028A224DC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/
Source: PaintStudio.View.exe, 00000016.00000002.2635389939.0000028A20FD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://hubblecontent.osi.office.net/contentsvc/api/;Media=https://hubble.officeapps.live.com/medias
Source: PaintStudio.View.exe, 00000016.00000002.2550570449.0000028A201CD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com
Source: PaintStudio.View.exe, 00000016.00000002.2552751428.0000028A20224000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.local
Source: PaintStudio.View.exe, 00000016.00000002.2851402839.0000028A23B71000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.remix3d.com/details/
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess Stats: CPU usage > 24%
Source: classification engineClassification label: clean2.winPNG@2/11@0/0
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\TexturesJump to behavior
Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknownProcess created: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe "C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe"
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: telemetryuwp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: vccorlib140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: sharedmemoryuwp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: vcruntime140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: msvcp140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: execmodelclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: propsys.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: execmodelproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.ui.xaml.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.system.profile.retailinfo.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.applicationmodel.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: d2d1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.storage.applicationdata.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: rometadata.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.globalization.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: vcruntime140_1_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: rmclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: uiamanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.web.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: concrt140_app.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.applicationmodel.datatransfer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.networking.connectivity.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.accountscontrol.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.devices.enumeration.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: devdispitemprovider.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.energy.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.graphics.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: twinapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: userenv.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: profext.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.web.http.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: wininet.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: firewallapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: fwbase.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: mfplat.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: rtworkq.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.system.profile.platformdiagnosticsandusagedatasettings.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: schannel.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: threadpoolwinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: msxml6.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: wpnapps.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: msftedit.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: globinputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.ui.xaml.phone.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: ninput.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: efswrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: mpr.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: certenroll.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: certca.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: dsparse.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: mlang.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.system.profile.systemid.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: clipc.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: cryptowinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: windows.system.userprofile.diagnosticssettings.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeSection loaded: edputil.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1A66AEDC-93C3-4ACC-BA96-08F5716429F7}\InProcServer32Jump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeFile opened: C:\Windows\SYSTEM32\msftedit.dllJump to behavior
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeWindow / User API: threadDelayed 429Jump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe TID: 4248Thread sleep count: 46 > 30Jump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe TID: 4248Thread sleep count: 429 > 30Jump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: PaintStudio.View.exe, 00000016.00000002.2797046498.0000028A235D3000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ToolsVMToolsVM0
Source: PaintStudio.View.exe, 00000016.00000002.2741565591.0000028A22CAE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ToolsVMTools
Source: PaintStudio.View.exe, 00000016.00000002.2738009366.0000028A22C4B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ToolsVMToolsVM
Source: PaintStudio.View.exe, 00000016.00000002.2717526231.0000028A225EF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\Textures VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\Assets\Fonts\PaintA.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\Assets\Fonts\PaintA.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\Assets\Fonts\PaintA.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\Assets\Fonts\PaintA.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\Assets\Fonts\PaintA.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\Assets\Fonts\BhaiMDL2.2.52.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\Assets\Fonts\BhaiMDL2.2.52.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\Assets\Fonts\BhaiMDL2.2.52.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\Assets\Fonts\BhaiMDL2.2.52.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\Assets\Fonts\BhaiMDL2.2.52.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\cloudCommunitySettings.json VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\Projects VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\Projects\WorkingFolder\EngineConfigId.bin VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\Projects\WorkingFolder\SceneData.bin VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\Projects\WorkingFolder\Canvas_0.bin VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\Projects\WorkingFolder\Canvas_2.bin VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\Projects\WorkingFolder\Canvas_3.bin VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\Projects\WorkingFolder\Canvas_4.bin VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\Projects\Projects.json VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Rundll32
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Process Injection
NTDS11
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1446063 Sample: proxy[1].png Startdate: 22/05/2024 Architecture: WINDOWS Score: 2 4 PaintStudio.View.exe 73 33 2->4         started        6 rundll32.exe 2->6         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
proxy[1].png0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://login.windows.local0%URL Reputationsafe
https://api.remix3d.com/v3/creations/0%Avira URL Cloudsafe
http://ns.adobe.ho0%Avira URL Cloudsafe
https://aka.ms/paint3dhelp0%Avira URL Cloudsafe
http://json-schema.org/draft-04/schema0%Avira URL Cloudsafe
https://api.remix3d.com/v3/creations0%Avira URL Cloudsafe
https://www.remix3d.com/details/0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://login.windows.localPaintStudio.View.exe, 00000016.00000002.2552751428.0000028A20224000.00000004.00000020.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
https://aka.ms/paint3dhelpPaintStudio.View.exe, 00000016.00000002.2831965481.0000028A23969000.00000004.00000020.00020000.00000000.sdmp, PaintStudio.View.exe, 00000016.00000002.2543331343.0000028A20124000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://api.remix3d.com/v3/creationsPaintStudio.View.exe, 00000016.00000002.2851402839.0000028A23B71000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://ns.adobe.hoPaintStudio.View.exe, 00000016.00000002.2511694929.0000028A18F7C000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://json-schema.org/draft-04/schemaPaintStudio.View.exe, 00000016.00000002.2545476210.0000028A20157000.00000004.00000020.00020000.00000000.sdmp, PaintStudio.View.exe, 00000016.00000002.2549513252.0000028A201B6000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://api.remix3d.com/v3/creations/PaintStudio.View.exe, 00000016.00000002.2836533698.0000028A239CC000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
https://www.remix3d.com/details/PaintStudio.View.exe, 00000016.00000002.2851402839.0000028A23B71000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1446063
Start date and time:2024-05-22 21:31:59 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 14s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultwindowsinteractivecookbook.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:25
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Sample name:proxy[1].png
Detection:CLEAN
Classification:clean2.winPNG@2/11@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, RuntimeBroker.exe, Microsoft.Photos.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 51.104.136.2, 13.107.5.88
  • Excluded domains from analysis (whitelisted): t1.ssl.ak.tiles.virtualearth.net, evoke-windowsservices-tas-msedge-net.e-0009.e-msedge.net, fs.microsoft.com, slscr.update.microsoft.com, settings-prod-neu-2.northeurope.cloudapp.azure.com, settings-win.data.microsoft.com, e-0009.e-msedge.net, fe3cr.delivery.mp.microsoft.com, t3.ssl.ak.tiles.virtualearth.net, atm-settingsfe-prod-geo2.trafficmanager.net, evoke-windowsservices-tas.msedge.net, t0.ssl.ak.dynamic.tiles.virtualearth.net, t2.ssl.ak.tiles.virtualearth.net, t0.ssl.ak.tiles.virtualearth.net, ecn.dev.virtualearth.net
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
  • Report size getting too big, too many NtEnumerateKey calls found.
  • Report size getting too big, too many NtOpenKey calls found.
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtProtectVirtualMemory calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • VT rate limit hit for: proxy[1].png
No simulations
No context
No context
No context
No context
No context
Process:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
File Type:JSON data
Category:dropped
Size (bytes):242
Entropy (8bit):5.189865564667958
Encrypted:false
SSDEEP:6:rpahDh2KN4+l1gsj4y80RwupEJj1cydLjAHa:rSDZN4+lRRJpgj1fdLs6
MD5:A94D10C05E2ABBF0E6B5C5F5B19EA3B2
SHA1:D00BB251C50661AF46CD6621D2FBF7262411C3CA
SHA-256:12186A6E2A521350B71537866989BA04DFEA3F5828E243D23B7DA0DE423805B7
SHA-512:D3A005E54CC78A132A60F57E73438C6BFE311583C6AE80949512A4691AF73C2ECF241C8E31C011B5D6111405FAD6EF86A2173010F24D259680D1A14679463E66
Malicious:false
Reputation:low
Preview:[{"Id":"{a5fcbcd1-fda7-4c50-8188-cd8ea4fe002f}","SourceId":"","Name":"proxy[1].png","URI":"","DateTime":1.3360887049901898E+17,"Path":"Projects\\WorkingFolder","SourceFilePath":"","Version":0.21,"IsRecovered":false,"IsPreviouslySaved":false}]
Process:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
File Type:JSON data
Category:dropped
Size (bytes):242
Entropy (8bit):5.189865564667958
Encrypted:false
SSDEEP:6:rpahDh2KN4+l1gsj4y80RwupEJj1cydLjAHa:rSDZN4+lRRJpgj1fdLs6
MD5:A94D10C05E2ABBF0E6B5C5F5B19EA3B2
SHA1:D00BB251C50661AF46CD6621D2FBF7262411C3CA
SHA-256:12186A6E2A521350B71537866989BA04DFEA3F5828E243D23B7DA0DE423805B7
SHA-512:D3A005E54CC78A132A60F57E73438C6BFE311583C6AE80949512A4691AF73C2ECF241C8E31C011B5D6111405FAD6EF86A2173010F24D259680D1A14679463E66
Malicious:false
Reputation:low
Preview:[{"Id":"{a5fcbcd1-fda7-4c50-8188-cd8ea4fe002f}","SourceId":"","Name":"proxy[1].png","URI":"","DateTime":1.3360887049901898E+17,"Path":"Projects\\WorkingFolder","SourceFilePath":"","Version":0.21,"IsRecovered":false,"IsPreviouslySaved":false}]
Process:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
File Type:Matlab v4 mat-file (little endian) v\033, text, rows 11, columns 1230, imaginary
Category:dropped
Size (bytes):7054
Entropy (8bit):7.903038674226112
Encrypted:false
SSDEEP:192:/vWFEQeCKCg61VcKaGz+S9eNmVqWI9LNqu:/z8gkOHGvaSu
MD5:AA7789D13C424F82A52B3B3C57E0E1A3
SHA1:7FB3C4BE67D762002E7EF86170F34F1E01A2B9C9
SHA-256:7FDA032FE43662CC612E79CDAFBC448B57185BEDE7DFF775787275771619E856
SHA-512:09A5F219E20C586393CC7F443C89EAAC52CF51C2D917C7EAB8F3C2AA399B62F2464A57E1EF7872D75B6D4D029202D1E547DB754F851F835FFF152D59B1C3FCD4
Malicious:false
Reputation:low
Preview:....................v....PNG........IHDR....................sRGB.........gAMA......a.... IDATx^...5UY.....bihx.3.E$L.I..*T......D-O..`` ..d(b...`.JH.X.h...T...<.)e.)=..=.....{..Zs.....\{...~.o.;k..}..z.^{.v.i...Oc..q.0f.8..3a....0N.Vs}...[J..n!...S."..PZ.j....KW..5..>7...dL.8... .5.n...K?$u..K.X.H.B2&+S..7..'.G.G..44...?....1I.J...tW.!......`E.....K2........%....}S.O...%V..H..f.....H.H........WH.....)..%./KO....z..Q......1..{..a...3$2...c.H.K.....k..^z.t..I{...8C:Y.2?0f..........n..L.....'J^...g,..=.A._.)$.r......J...Q..;I.*.svgR@.2.sfwf..9[...o*........wK.;..2......K?;.39......J....t.Z..).E.cgw.K>&Q5..1.-....p~..a..B..%..f..a......s%.....$../.I.)....?....JT7~Z2..;..KC.fwfH.Q.P.....L:S"...;%N*JS...;J.%}G2..3........3Lx..%..(...x..Mb.G.".%.....J.!......)........~W......r|D.$....J..e.!.....iG.{n.........Ho.~|v.......|.....\_..$.e.lK.MpZ.}.iI.+..}T.=ivg...s...../..H.w.....x.o,....a..A..%.'..]..X......pTx.."oC..6m.5....~..A...........iI......0l..
Process:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
File Type:Matlab v4 mat-file (little endian) \202\002, text, rows 11, columns 1230, imaginary
Category:dropped
Size (bytes):666
Entropy (8bit):2.851816467757008
Encrypted:false
SSDEEP:3:vlll3lS82onv//thPktlVR3ujVLts7CX9/xWxbxYHZeklhAIK9Rp:vtTvv/lhPktPkjVR/CJxslhAIKnp
MD5:3A4D99A1600049410A5036D24E858962
SHA1:3022619CDB4D01ABE98268768DE735384812C1FC
SHA-256:9A0AF1C22E233A8A37FEC6A52DEB58862AF735B716C074B27E586A74F6ACEC2A
SHA-512:CCCB616AECD23EC565AF874EACBF825B90D2BD7415FDD7E4982A4317ADE4801E43FC77CD7C5D10E8E8E5F5A9ED878681FCB9527B109426D0067333FF71964082
Malicious:false
Reputation:low
Preview:.........................PNG........IHDR....................sRGB.........gAMA......a....,IDATx^..1.. ........E...zvw..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................d.<...]/.l.....IEND.B`.
Process:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
File Type:Matlab v4 mat-file (little endian) \202\002, text, rows 11, columns 1230, imaginary
Category:dropped
Size (bytes):666
Entropy (8bit):2.851816467757008
Encrypted:false
SSDEEP:3:vlll3lS82onv//thPktlVR3ujVLts7CX9/xWxbxYHZeklhAIK9Rp:vtTvv/lhPktPkjVR/CJxslhAIKnp
MD5:3A4D99A1600049410A5036D24E858962
SHA1:3022619CDB4D01ABE98268768DE735384812C1FC
SHA-256:9A0AF1C22E233A8A37FEC6A52DEB58862AF735B716C074B27E586A74F6ACEC2A
SHA-512:CCCB616AECD23EC565AF874EACBF825B90D2BD7415FDD7E4982A4317ADE4801E43FC77CD7C5D10E8E8E5F5A9ED878681FCB9527B109426D0067333FF71964082
Malicious:false
Reputation:low
Preview:.........................PNG........IHDR....................sRGB.........gAMA......a....,IDATx^..1.. ........E...zvw..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................d.<...]/.l.....IEND.B`.
Process:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
File Type:Matlab v4 mat-file (little endian) \202\002, text, rows 11, columns 1230, imaginary
Category:dropped
Size (bytes):666
Entropy (8bit):2.851816467757008
Encrypted:false
SSDEEP:3:vlll3lS82onv//thPktlVR3ujVLts7CX9/xWxbxYHZeklhAIK9Rp:vtTvv/lhPktPkjVR/CJxslhAIKnp
MD5:3A4D99A1600049410A5036D24E858962
SHA1:3022619CDB4D01ABE98268768DE735384812C1FC
SHA-256:9A0AF1C22E233A8A37FEC6A52DEB58862AF735B716C074B27E586A74F6ACEC2A
SHA-512:CCCB616AECD23EC565AF874EACBF825B90D2BD7415FDD7E4982A4317ADE4801E43FC77CD7C5D10E8E8E5F5A9ED878681FCB9527B109426D0067333FF71964082
Malicious:false
Reputation:low
Preview:.........................PNG........IHDR....................sRGB.........gAMA......a....,IDATx^..1.. ........E...zvw..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................d.<...]/.l.....IEND.B`.
Process:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
File Type:Matlab v4 mat-file (little endian) C\002, text, rows 11, columns 1230, imaginary
Category:dropped
Size (bytes):603
Entropy (8bit):5.160194055413447
Encrypted:false
SSDEEP:12:vtfSv/7I9/XqQNAw+w+w+w+w+w+w+w+w+w+w+w+w+w+w+w+w+w+w+w+w+e3Ghz:vtfY+3e
MD5:BE621CEE0FB8AE6035DD226E57F5D52D
SHA1:9061BED5C2C4D952D52040B854BA310E5C651DDF
SHA-256:D756807968C6507332F8DE3DF40990CDE7B0994F5CC4DA446E41870FCF7195BF
SHA-512:1CF585F6BC1E80B027278E1D9BE5C097FAB258920B692870EBD878C9A89C39C3E82E8676E08DDFBE820EA14FFA1E06B10072E770E9804A1972D24ABE3060813F
Malicious:false
Reputation:low
Preview:....................C....PNG........IHDR.............G7Qu....sRGB.........gAMA......a.....IDATx^..1............z'O.....n...q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8.....@`.....q 0....8............]........IEND.B`.
Process:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
File Type:data
Category:dropped
Size (bytes):88
Entropy (8bit):2.9160161239667026
Encrypted:false
SSDEEP:3:vlllhelqbSiFqhzIGCSOdTh6:vtIlViFXG/OdTh6
MD5:2CB0D4339341E6189CD737B364CDCD82
SHA1:52CB91F3D2F92C50D60630507182BB442F4AD6BD
SHA-256:54332C4C577158182D35F4C8DCF1ACA73FF880B053F03B8E6E85E2BAB8C40938
SHA-512:282D0047DB4C0B8A4BFF0935F8308CBDBC83DBE4AAF5CF77D193A697D77E4AD8EBE7D157FF89CFA65F6BCF445CE421E29D245082B2783E5DF8CA9000C2E97002
Malicious:false
Reputation:low
Preview:........&...{.A.9.2.A.5.9.C.6.-.7.2.7.8.-.4.6.D.D.-.9.9.F.2.-.1.C.7.B.F.7.1.E.1.1.5.B.}.
Process:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
File Type:data
Category:dropped
Size (bytes):22
Entropy (8bit):1.6729330318733675
Encrypted:false
SSDEEP:3:vlllZhldG:vtZhlM
MD5:DCF8BE4FA8C3A466400AD0DCD428C9D0
SHA1:3C28C788831A74D78AF450409B77085A83293E65
SHA-256:372232B0C6A3FA3A2332CB94DDE7ED9DA846A64942D006E93F0D531E2A70B1BE
SHA-512:DEC50D7999E81822074A3E42F7B8626BDF7084EF6361F8BDA1FD1A7C9FCC43511DE3B6A612446A5F47D55AD0C5CC3624A9D34CF8DCACD249C7B90B58D218D7F1
Malicious:false
Reputation:low
Preview:......................
Process:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
File Type:JSON data
Category:dropped
Size (bytes):2559
Entropy (8bit):5.440474440107185
Encrypted:false
SSDEEP:48:Y2O2M1MKtr7vQD1sN+J2sG91OMJMRUgFgQkXMJMK2+R/9VUXc4m6YAZnL:H27vQ266OGooGt9M
MD5:F4E4A03EBD0AB3A953C56A300D61D223
SHA1:97A9ACF22C3BDD6989D7C120C21077C4D5A9A80E
SHA-256:52BFB22AA2D7B0CE083D312FB8FA8DCDA3063207186F99FC259AEBD9064CBEDC
SHA-512:12AA71EEA45720A4D7D057DA0B662635671E4CD165AD2E0D30A3D2A43950B47DD60C26C1BBBE049418F815850E571B8D93E4C8B8CBBD686ABC3CF7926BA719C2
Malicious:false
Reputation:low
Preview:{"APP.COMMUNITY.CLIENTTYPE":"Microsoft.Paint3D","APP.COMMUNITY.GLTF.EXPORT.ENABLED":"True","APP.COMMUNITY.GLTF.IMPORT.ENABLED":"True","APP.FILEOPERATIONS.FORMAT.FBX.EXPORT.ENABLED":"True","APP.FILEOPERATIONS.FORMAT.FBX.IMPORT.ENABLED":"True","TOOLS.EDITINFREEVIEW.ENABLED":"True","APP.COMMUNITY.HUBBLE.ENVIRONMENT":"PROD","APP.COMMUNITY.HUBBLE.REQUEST1PHOST":"True","APP.COMMUNITY.HUBBLE.USEWEBVIEW":"False","APP.COMMUNITY.ENABLEDFORLOCALE":"True","APP.FILEOPERATIONS.IMPORT.SEPARATEOBJECTS.ENABLED":"True","APP.TEXTURES.CANVAS3D.DUALLAYER.ENABLED":"True","APP.CMS.CONFIGENDPOINT":"http://go.microsoft.com/fwlink/?LinkId=828137","APP.CMS.KILLSWITCHTURNEDON":"False","APP.CMS.MINIMUMAPPVERSION":"3.1710.30028.0","APP.COMMUNITY.ANONYMOUSBROWSE.ENABLED":"True","APP.COMMUNITY.ENABLEDFORLANGUAGE":"True","APP.COMMUNITY.ENDPOINTCONFIGJSON":"{\"EnvironmentOverrides\": { \"PREVIEW\": { \"TokenScope\": \"service::remix3d.com::MBI_SSL\", \"BrowseUri\": \"https://www.preview.remix3d.com/\", \"ProfileUri\":
Process:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
File Type:JSON data
Category:dropped
Size (bytes):2559
Entropy (8bit):5.440474440107185
Encrypted:false
SSDEEP:48:Y2O2M1MKtr7vQD1sN+J2sG91OMJMRUgFgQkXMJMK2+R/9VUXc4m6YAZnL:H27vQ266OGooGt9M
MD5:F4E4A03EBD0AB3A953C56A300D61D223
SHA1:97A9ACF22C3BDD6989D7C120C21077C4D5A9A80E
SHA-256:52BFB22AA2D7B0CE083D312FB8FA8DCDA3063207186F99FC259AEBD9064CBEDC
SHA-512:12AA71EEA45720A4D7D057DA0B662635671E4CD165AD2E0D30A3D2A43950B47DD60C26C1BBBE049418F815850E571B8D93E4C8B8CBBD686ABC3CF7926BA719C2
Malicious:false
Preview:{"APP.COMMUNITY.CLIENTTYPE":"Microsoft.Paint3D","APP.COMMUNITY.GLTF.EXPORT.ENABLED":"True","APP.COMMUNITY.GLTF.IMPORT.ENABLED":"True","APP.FILEOPERATIONS.FORMAT.FBX.EXPORT.ENABLED":"True","APP.FILEOPERATIONS.FORMAT.FBX.IMPORT.ENABLED":"True","TOOLS.EDITINFREEVIEW.ENABLED":"True","APP.COMMUNITY.HUBBLE.ENVIRONMENT":"PROD","APP.COMMUNITY.HUBBLE.REQUEST1PHOST":"True","APP.COMMUNITY.HUBBLE.USEWEBVIEW":"False","APP.COMMUNITY.ENABLEDFORLOCALE":"True","APP.FILEOPERATIONS.IMPORT.SEPARATEOBJECTS.ENABLED":"True","APP.TEXTURES.CANVAS3D.DUALLAYER.ENABLED":"True","APP.CMS.CONFIGENDPOINT":"http://go.microsoft.com/fwlink/?LinkId=828137","APP.CMS.KILLSWITCHTURNEDON":"False","APP.CMS.MINIMUMAPPVERSION":"3.1710.30028.0","APP.COMMUNITY.ANONYMOUSBROWSE.ENABLED":"True","APP.COMMUNITY.ENABLEDFORLANGUAGE":"True","APP.COMMUNITY.ENDPOINTCONFIGJSON":"{\"EnvironmentOverrides\": { \"PREVIEW\": { \"TokenScope\": \"service::remix3d.com::MBI_SSL\", \"BrowseUri\": \"https://www.preview.remix3d.com/\", \"ProfileUri\":
File type:PNG image data, 1230 x 176, 8-bit/color RGBA, non-interlaced
Entropy (8bit):7.655059424186753
TrID:
  • Portable Network Graphics (16016/1) 100.00%
File name:proxy[1].png
File size:8'809 bytes
MD5:0fbedb10ed339d1b065b66200c5ce802
SHA1:7b930d85e38fbcf4742565fc4896d8757b43a318
SHA256:44dc36f4fbd4d55b95dcf49843a2660662213f9e0da23322a57399c8937df033
SHA512:f04ea7f3ffa5b583babe717ea46507a6f60e48f40bfc28e87613e94bd87fe300d6a9462c4694748d2257766d9c9f3acb8057162753e27e27fe9650196312ed18
SSDEEP:192:D5aTKIaW2bfiTH7RnjOFpmaXl0aq3M8k5Tkdm+JyHgM2mKDdzuWT:9aTKIa1ziTNnjOnmaXlBq3MP5TToyAM2
TLSH:DB02AFC2EA4149E0C7362B7A8CE78A5F9D9140E1E1E02E7349D5D527CEF7250E04D7D2
File Content Preview:.PNG........IHDR...............".....tEXtSoftware.Adobe ImageReadyq.e<..."iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27
Icon Hash:74f0f0e4c6d6e0e4
No network behavior found

Click to jump to process

Click to jump to process

Click to jump to process

Target ID:16
Start time:15:33:09
Start date:22/05/2024
Path:C:\Windows\System32\rundll32.exe
Wow64 process (32bit):false
Commandline:C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Imagebase:0x7ff6418e0000
File size:71'680 bytes
MD5 hash:EF3179D498793BF4234F708D3BE28633
Has elevated privileges:false
Has administrator privileges:false
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

Target ID:22
Start time:15:33:42
Start date:22/05/2024
Path:C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\WindowsApps\Microsoft.MSPaint_6.1907.29027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe"
Imagebase:0x7ff703880000
File size:3'378'176 bytes
MD5 hash:7E11B5F9F7A7FE66809577EC83971972
Has elevated privileges:false
Has administrator privileges:false
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

No disassembly