download: | /downloads/ice/pafmicesetup.exe |
Full analysis: | https://app.any.run/tasks/d2a762d5-e943-463a-83e8-d662760d0cb3 |
Verdict: | Malicious activity |
Analysis date: | February 16, 2024, 04:32:20 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 80F920260ED19EA076A8AF4BC1FF6B14 |
SHA1: | 59B06D9242000D00D25473A560618A448FA56230 |
SHA256: | 8F727B1191B73F4B0560EBBE11A38D15D542BC6A85B4E7F1D126CA325D773CFE |
SSDEEP: | 98304:2Sk/3GPGaNuAElhSD3gY4PCRgURws5zkA2asFs2mb3Tz9S:2liGaNk4Lw8OsDO2Hb33s |
.exe | | | Win32 Executable MS Visual C++ (generic) (38.7) |
---|---|---|
.exe | | | Win64 Executable (generic) (34.3) |
.scr | | | Windows screen saver (16.2) |
.exe | | | Win32 Executable (generic) (5.6) |
.exe | | | Generic Win/DOS Executable (2.4) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2008:09:11 05:55:59+00:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
PEType: | PE32 |
LinkerVersion: | 6 |
CodeSize: | 425984 |
InitializedDataSize: | 200704 |
UninitializedDataSize: | - |
EntryPoint: | 0x36327 |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
FileVersionNumber: | 15.0.0.591 |
ProductVersionNumber: | 15.0.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Dynamic link library |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Unicode |
CompanyName: | PJLM Software Inc. |
FileDescription: | Contact: Your local administrator |
FileVersion: | 1.35.0 |
InternalName: | Setup |
LegalCopyright: | Copyright 2007-2017 |
OriginalFileName: | Setup.exe |
ProductName: | Print Audit Facilities Manager ICE |
ProductVersion: | 1.35.0 |
InternalBuildNumber: | 82160 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1432 | MSIEXEC.EXE /i "C:\Users\admin\AppData\Local\Temp\{85CA6654-F18E-4AA5-9F75-9E67A5EF2198}\pafmice.msi" SETUPEXEDIR="C:\Users\admin\AppData\Local\Temp" SETUPEXENAME="pafmicesetup.exe" | C:\Windows\System32\msiexec.exe | — | pafmicesetup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2072 | "C:\Program Files\Print Audit Inc\Facilities Manager\pafmice.exe" | C:\Program Files\Print Audit Inc\Facilities Manager\pafmice.exe | — | services.exe | |||||||||||
User: SYSTEM Company: PJLM Software Inc. Integrity Level: SYSTEM Description: Retrieves meters reads from network capable MFP's Exit code: 0 Version: 1.35.0.0 Modules
| |||||||||||||||
2364 | "C:\Program Files\Print Audit Inc\Facilities Manager\pafmupd.exe" | C:\Program Files\Print Audit Inc\Facilities Manager\pafmupd.exe | — | services.exe | |||||||||||
User: SYSTEM Company: PJLM Software Inc. Integrity Level: SYSTEM Description: Automatically downloads updates for the Print Audit FM Information Collection Engine Exit code: 0 Version: 1.35.0.0 Modules
| |||||||||||||||
2900 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3668 | "C:\Users\admin\AppData\Local\Temp\pafmicesetup.exe" | C:\Users\admin\AppData\Local\Temp\pafmicesetup.exe | explorer.exe | ||||||||||||
User: admin Company: PJLM Software Inc. Integrity Level: MEDIUM Description: Contact: Your local administrator Exit code: 0 Version: 1.35.0 Modules
| |||||||||||||||
3732 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (1432) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3732) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000024A3A52E9160DA01940E0000BC0E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3732) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000024A3A52E9160DA01940E00006C0F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3732) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000007E05A82E9160DA01940E00006C0F0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3732) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000007E05A82E9160DA01940E0000D4050000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3732) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000007E05A82E9160DA01940E00006C0F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3732) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000D867AA2E9160DA01940E0000BC0E0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3732) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000D867AA2E9160DA01940E0000D4050000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3732) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000D867AA2E9160DA01940E00006C0F0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3732) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5} |
Operation: | write | Name: | PROVIDER_BEGINPREPARE (Enter) |
Value: 4000000000000000126850309160DA01940E00006C0F000001040000010000000000000000000000FE189973D5BAF549AFB91DD81D9ACDC70000000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3668 | pafmicesetup.exe | C:\Users\admin\AppData\Local\Temp\{85CA6654-F18E-4AA5-9F75-9E67A5EF2198}\0x0409.ini | text | |
MD5:758747727E96A23C7C5A5BBB011656E4 | SHA256:BAD3B2E854149DF9413F06E6C1C7B7C875545393877F59B59907F6B083CE5825 | |||
3668 | pafmicesetup.exe | C:\Users\admin\AppData\Local\Temp\{85CA6654-F18E-4AA5-9F75-9E67A5EF2198}\Setup.INI | ini | |
MD5:0C864C692AB369C3241E8859A6780D28 | SHA256:F58526BB725149A499D1A31442DADD6F0DB863D5A72E8721042D604B9913DC7D | |||
3668 | pafmicesetup.exe | C:\Users\admin\AppData\Local\Temp\_isF281.tmp | pz | |
MD5:6FB294095B6CF0D7318BEF4CCD5A2923 | SHA256:4725AB02F3437A3B58F5B20638E0A6ADDBBC3E2A972052B3B99D533D3AD79864 | |||
3668 | pafmicesetup.exe | C:\Users\admin\AppData\Local\Temp\_isF260.tmp | pz | |
MD5:AE10F061AF304517F6E3F3157795A5B7 | SHA256:C1C419BE1398ADDBD82F88BE6C3FF810ED04B8C970AB7349B07EC11B07368043 | |||
3668 | pafmicesetup.exe | C:\Users\admin\AppData\Local\Temp\{85CA6654-F18E-4AA5-9F75-9E67A5EF2198}\_ISMSIDEL.INI | text | |
MD5:C7EE18FE797A8C66ED063E44B8012DCD | SHA256:75B553599A6E4B87F3B1B22317A36E27489A8AFA5467A1CF0206504E421E1B1F | |||
3668 | pafmicesetup.exe | C:\Users\admin\AppData\Local\Temp\_isF2EF.tmp | binary | |
MD5:200E8710B960D1767D285A1A791CD760 | SHA256:F221F1B3BB2EC0ADBD7290B8F7A91ADAADF39A4A13331191B827A622652C6A50 | |||
3668 | pafmicesetup.exe | C:\Users\admin\AppData\Local\Temp\~F280.tmp | ini | |
MD5:0C864C692AB369C3241E8859A6780D28 | SHA256:F58526BB725149A499D1A31442DADD6F0DB863D5A72E8721042D604B9913DC7D | |||
3668 | pafmicesetup.exe | C:\Users\admin\AppData\Local\Temp\{85CA6654-F18E-4AA5-9F75-9E67A5EF2198}\pafmice.msi | executable | |
MD5:FB52B640A77E6668BD501610DC2840C4 | SHA256:77A8587F561CC59C525FFAB97FD509939565719BC38228B5B0D6834DD095B5E7 | |||
3668 | pafmicesetup.exe | C:\Users\admin\AppData\Local\Temp\_isF24F.tmp | pz | |
MD5:6FB294095B6CF0D7318BEF4CCD5A2923 | SHA256:4725AB02F3437A3B58F5B20638E0A6ADDBBC3E2A972052B3B99D533D3AD79864 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |