mspaint.exe
- File Path:
C:\Windows\system32\mspaint.exe - Description: Paint
Screenshot

Hashes
| Type | Hash |
|---|---|
| MD5 | A5F69864C0CA8FDC157F3E7EF48F2F10 |
| SHA1 | 52802248F949C442D7EF40734B23AF109F2F23D2 |
| SHA256 | 5E832C11FBA0B0F2BCAB3B105FF7D63AC7A1A766D11282D50ECEE9BB038771F5 |
| SHA384 | 63349C7DED65E7E98FA904DAE0937A548328D1A61C6930F0416BB8CC24DC864A2C2FEDE4B6BD69697FB962E8E3FA9B7A |
| SHA512 | 023C7D3AABEB6719BD5B0D5B038890A899B4FA1549563C27DDBBC263F6AACFDE641B81B246C7CE08EAFAAFFC7C2E039D0C7030D449F74A216A2B10E0FE5EE215 |
| SSDEEP | 98304:TJD2u7InCEE+wysPM4mlaw0LI60GBGrGrGWAuU7jPLQ:TJD6nTE+wBMHlaw0/U7jPL |
Signature
- Status: Signature verified.
- Serial:
3300000266BD1580EFA75CD6D3000000000266 - Thumbprint:
A4341B9FD50FB9964283220A36A1EF6F6FAA7840 - Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: MSPAINT.EXE.MUI
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.14393.0 (rs1_release.160715-1616)
- Product Version: 10.0.14393.0
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
File Similarity (ssdeep match)
| File | Score |
|---|---|
| C:\windows\system32\mspaint.exe | 93 |
| C:\Windows\system32\mspaint.exe | 71 |
| C:\windows\SysWOW64\mspaint.exe | 90 |
| C:\Windows\SysWOW64\mspaint.exe | 69 |
| C:\Windows\SysWOW64\mspaint.exe | 91 |
Possible Misuse
The following table contains possible examples of mspaint.exe being misused. While mspaint.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
| Source | Source File | Example | License |
|---|---|---|---|
| sigma | sysmon_suspicious_remote_thread.yml | - '\mspaint.exe' |
DRL 1.0 |
| malware-ioc | nukesped_lazarus | .mspaint.exe (a 2009 file)``{:.highlight .language-cmhg} |
© ESET 2014-2018 |
| malware-ioc | nukesped_lazarus | .mspaint.exe``{:.highlight .language-cmhg} |
© ESET 2014-2018 |
| signature-base | apt_codoso.yar | $s4 = “mspaint.exe” fullword ascii | CC BY-NC 4.0 |
MIT License. Copyright (c) 2020-2021 Strontic.