paint.net.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from d.baixakifiles2.com and multiple other hosts.
MD5:
2c2804e3830fc358464693c2f5f6ab81

SHA-1:
af3ffabcbd1dcb542867f435080ffb4f924c5819

SHA-256:
b2742a8ef2a4eaf458d1e6ed017b580ea5565a3b75b11475a5840b40bf2f474f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 2:15:46 AM UTC  (today)

File size:
6 MB (6,272,852 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\downloads\3676090eded622c6bec547ed78bdf6d1\698d51a19d8a121ce581499d7b701668\paint.net.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
98304:Yu/pc+cQWDtAVpWrWQaIiD4/hoYrGPTYsEVN/zBBl2mPTM4TH3eOaNwJ7fEFp:Yi3IqWrla9DfDPHEvBXfTMyOr6Ap

Entry point:
50, 4B, 03, 04, 14, 00, 00, 00, 08, 00, EA, 79, F6, 44, AD, DD, 4A, BE, 98, B6, 5F, 00, F0, 1E, 60, 00, 1B, 00, 00, 00, 70, 61, 69, 6E, 74, 2E, 6E, 65, 74, 2E, 34, 2E, 30, 2E, 33, 2E, 69, 6E, 73, 74, 61, 6C, 6C, 2E, 65, 78, 65, EC, 5C, 7D, 74, 14, 57, 15, 9F, FD, 4A, 36, C9, 2E, B3, 81, A4, 0D, 25, A1, 81, 04, C4, 06, 30, 74, 09, 25, DD, 04, 36, 34, 1B, B0, 6D, E8, A6, 4B, 76, A1, 4D, A0, DA, 12, 97, B1, B6, 01, 66, 28, 55, 16, 12, 37, D1, 6C, 86, 54, 54, AA, 55, AB, 36, 06, 15, B5, 1E, 50, 6B, 4D, 95, 86...
 
[+]

The file paint.net.exe has been seen being distributed by the following 4 URLs.

http://d.baixakifiles2.com/?ic_user_id=254&data=0XZilMgapU x3tDTqYDsE0n65z5jE3sMECSLjSpuVTKqH4rWskdwKwiQF0FwFJ7wzVdFTJnN0ExUMUdPcPCn02xC/EKmNLWVbL8uKj6s3YJGwoHq9Oz4A8cG4XDKDX G090ehFqgtC/ApwNYpL0Unz5fjWZ8ZnSE52CMHD1UP6nCKscrHsKNvDSyblVqu6E3jaLb4RySxsJkxQiDVrAiQ3TM4bWv72U4vplAapee6lDmJl8D5evewpLZFKrJ2KOeFX/2xv/Tj89TZhT3ckiSs7xj2GYhV9sotFY8gQMcHREAh2wnGOqNChPcGsHEVRCaaPdkclylffHamAlCsltqtmfc9tLb5ZzfrUmE5GSWaiYeynXrHzE7LJhdnmFk ZjKodDjPtSmfPOKNpZ8H/GOdJupK7fTxL1oJpeN4vICv0pXDw/xGL6vxhUEtPnZU5/BJ2MZ0 fNhTW0e9PAnu03a2lotmC5/LOR3Tx9xPyVHwbbwczPzvgG6QitIVnM4T69VlYsOUqvEpQyQ5NBSKfTA5l2qNleTQBROvdaVlg26NrTjPq2E4FEoNuSbUD9sx9wahElIIaTMnPHRRAHQdB3mD//Hn2IGrBGNd/.../Po1zLnX1Ww3yx8y9PsaF6D jx1beIiDRyc6Dcj BPrBbbLSuyOR

Scan paint.net.exe - Powered by Reason Core Security