| File name: | Pcmflash.exe |
| Full analysis: | https://app.any.run/tasks/9656cbc5-01af-44b0-949e-5946a2c74b43 |
| Verdict: | Malicious activity |
| Analysis date: | March 05, 2024, 16:18:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 4E3BDB56E5591B122ADFA1754C19DE70 |
| SHA1: | 1A7D553F637A1B758FC524CCE4B1E4AC11C7FE40 |
| SHA256: | FCD910520385EC34D09E18DE246B18623A918672BF4FAC7A5EBD2CEF024092E7 |
| SSDEEP: | 98304:7r7ayGJ6kHOSN1SCS9dEETwh1pml953kg5vbLJFSjgbQtdV85hFi1RW8VZWr9R1G:PDm3kuORJEFfPgEsRZoqWbT |
| .exe | | | Win32 Executable Borland Delphi 7 (83.1) |
|---|---|---|
| .exe | | | Inno Setup installer (13.7) |
| .exe | | | Win32 Executable Delphi generic (1.7) |
| .exe | | | Win32 Executable (generic) (0.5) |
| .exe | | | Win16/32 Executable Delphi generic (0.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 629760 |
| InitializedDataSize: | 12195840 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9ab80 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.4 |
| ProductVersionNumber: | 1.0.0.4 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Turkish |
| CharacterSet: | Windows, Turkish |
| CompanyName: | Synaptics |
| FileDescription: | Synaptics Pointing Device Driver |
| FileVersion: | 1.0.0.4 |
| InternalName: | - |
| LegalCopyright: | - |
| LegalTrademarks: | - |
| OriginalFileName: | - |
| ProductName: | Synaptics Pointing Device Driver |
| ProductVersion: | 1.0.0.0 |
| Comments: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 696 | "C:\Program Files\PCMflash\pcmflash.exe" | C:\Program Files\PCMflash\pcmflash.exe | ._cache_Pcmflash.tmp | ||||||||||||
User: admin Company: quickie@yandex.ru Integrity Level: MEDIUM Description: PCMflash Exit code: 2000 Version: 1.2.0.0 Modules
| |||||||||||||||
| 1888 | C:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exe -CAPTION="pcmflash.exe" -TEXT="Guardant dongle not found: Make sure that Guardant dongle is connected to the computer and the latest Guardant driver is installed(49\50)"C:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exe -CAPTION="pcmflash.exe" -TEXT="Guardant dongle not found: Make sure that Guardant dongle is connected to the computer and the latest Guardant driver is installed(49\50)" MB_RETRYCANCEL | C:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exe | — | pcmflash.exe | |||||||||||
User: admin Company: Activ Co. Integrity Level: MEDIUM Description: Command-line utility protection Exit code: 2 Version: 7, 0, 1, 0 Modules
| |||||||||||||||
| 2072 | "C:\Program Files\PCMflash\pcmflash.exe" | C:\Program Files\PCMflash\pcmflash.exe | — | explorer.exe | |||||||||||
User: admin Company: quickie@yandex.ru Integrity Level: MEDIUM Description: PCMflash Exit code: 2000 Version: 1.2.0.0 Modules
| |||||||||||||||
| 2624 | "C:\ProgramData\Synaptics\Synaptics.exe" InjUpdate | C:\ProgramData\Synaptics\Synaptics.exe | Pcmflash.exe | ||||||||||||
User: admin Company: Synaptics Integrity Level: HIGH Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 3348 | "C:\Users\admin\AppData\Local\Temp\is-9FDVT.tmp\._cache_Pcmflash.tmp" /SL5="$16013E,11790810,54272,C:\Users\admin\AppData\Local\Temp\._cache_Pcmflash.exe" | C:\Users\admin\AppData\Local\Temp\is-9FDVT.tmp\._cache_Pcmflash.tmp | — | ._cache_Pcmflash.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 3536 | "C:\Users\admin\AppData\Local\Temp\._cache_Pcmflash.exe" | C:\Users\admin\AppData\Local\Temp\._cache_Pcmflash.exe | Pcmflash.exe | ||||||||||||
User: admin Company: PCMflash Integrity Level: MEDIUM Description: PCMflash Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 3544 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\System32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3700 | "C:\Users\admin\AppData\Local\Temp\Pcmflash.exe" | C:\Users\admin\AppData\Local\Temp\Pcmflash.exe | explorer.exe | ||||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 3776 | C:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exe -CAPTION="pcmflash.exe" -TEXT="Guardant dongle not found: Make sure that Guardant dongle is connected to the computer and the latest Guardant driver is installed(49\50)"C:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exe -CAPTION="pcmflash.exe" -TEXT="Guardant dongle not found: Make sure that Guardant dongle is connected to the computer and the latest Guardant driver is installed(49\50)" MB_RETRYCANCEL | C:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exe | — | pcmflash.exe | |||||||||||
User: admin Company: Activ Co. Integrity Level: MEDIUM Description: Command-line utility protection Exit code: 2 Version: 7, 0, 1, 0 Modules
| |||||||||||||||
| 3956 | "C:\Users\admin\AppData\Local\Temp\is-AH38A.tmp\._cache_Pcmflash.tmp" /SL5="$8020A,11790810,54272,C:\Users\admin\AppData\Local\Temp\._cache_Pcmflash.exe" /SPAWNWND=$120176 /NOTIFYWND=$16013E | C:\Users\admin\AppData\Local\Temp\is-AH38A.tmp\._cache_Pcmflash.tmp | ._cache_Pcmflash.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3700) Pcmflash.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3700) Pcmflash.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3700) Pcmflash.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3700) Pcmflash.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3700) Pcmflash.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | Synaptics Pointing Device Driver |
Value: C:\ProgramData\Synaptics\Synaptics.exe | |||
| (PID) Process: | (3700) Pcmflash.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3348) ._cache_Pcmflash.tmp | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3956) ._cache_Pcmflash.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 740F000036AC68DD186FDA01 | |||
| (PID) Process: | (3956) ._cache_Pcmflash.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 9A3EBB85D6923CF9599F74CF0A4E120709D2493F15A4FB05C32AE566B18C2978 | |||
| (PID) Process: | (3956) ._cache_Pcmflash.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3536 | ._cache_Pcmflash.exe | C:\Users\admin\AppData\Local\Temp\is-9FDVT.tmp\._cache_Pcmflash.tmp | executable | |
MD5:6B99893EE22CD8775D55979D3F537030 | SHA256:9E8C3247701E0E7DAC13B473B3A187B365C966085F891FD744A941DA4A08C5F2 | |||
| 3956 | ._cache_Pcmflash.tmp | C:\Program Files\PCMflash\is-7EM7T.tmp | executable | |
MD5:56A41D58C5495981B2FB5D885504D8B1 | SHA256:768C4830501CDC77F19FAF6BEBF4B1DBB2AC04C13B7635C434E937C9881D55CA | |||
| 3700 | Pcmflash.exe | C:\ProgramData\Synaptics\RCX4ED.tmp | executable | |
MD5:C725925C04C052EAAAAAE21B1040BC80 | SHA256:65C5B363B3FEC9A7E2FBFC10D4D0E4949A21B6673FD5D950C9D9566C755ADA10 | |||
| 3700 | Pcmflash.exe | C:\ProgramData\Synaptics\Synaptics.exe | executable | |
MD5:4E3BDB56E5591B122ADFA1754C19DE70 | SHA256:FCD910520385EC34D09E18DE246B18623A918672BF4FAC7A5EBD2CEF024092E7 | |||
| 3956 | ._cache_Pcmflash.tmp | C:\Program Files\PCMflash\unins000.exe | executable | |
MD5:F17DFB89F41AE7C3155D5871C0B13A3D | SHA256:2A9BB84BF61D74116EEA76B02D6D5ED26DD750FEB64DF9E01C33D659FB24FC56 | |||
| 3700 | Pcmflash.exe | C:\Users\admin\AppData\Local\Temp\._cache_Pcmflash.exe | executable | |
MD5:12324387789529A933FF92CEEFF2E66F | SHA256:2A598B4B2BE13129CB8B3642838E4D7623DA2D38FD6C93BDC0CB238835375795 | |||
| 4008 | ._cache_Pcmflash.exe | C:\Users\admin\AppData\Local\Temp\is-AH38A.tmp\._cache_Pcmflash.tmp | executable | |
MD5:6B99893EE22CD8775D55979D3F537030 | SHA256:9E8C3247701E0E7DAC13B473B3A187B365C966085F891FD744A941DA4A08C5F2 | |||
| 3956 | ._cache_Pcmflash.tmp | C:\Users\Public\Desktop\PCMflash.lnk | lnk | |
MD5:2BA3B07618F68C8164B02233EA218B96 | SHA256:F92756D08D817FE8608AB112F825631D383AF6C6E1B68386DCD5A832D4D658D4 | |||
| 3956 | ._cache_Pcmflash.tmp | C:\Program Files\PCMflash\is-UMNDM.tmp | executable | |
MD5:F17DFB89F41AE7C3155D5871C0B13A3D | SHA256:2A9BB84BF61D74116EEA76B02D6D5ED26DD750FEB64DF9E01C33D659FB24FC56 | |||
| 696 | pcmflash.exe | C:\Users\admin\AppData\Local\Temp\grddialog-x86.7.0.1.0.exe | executable | |
MD5:3A00867414E479B7FEC10B6D23230EB0 | SHA256:4A8A557CA6D5667B64017F5B7B8BD51556F321CE88F780DFC0A74CF372743449 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2624 | Synaptics.exe | GET | 304 | 2.16.100.179:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c1adc6ce095ff73c | DE | — | — | unknown |
2624 | Synaptics.exe | GET | 200 | 69.42.215.252:80 | http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978 | US | text | 31 b | unknown |
2624 | Synaptics.exe | GET | 200 | 142.250.184.227:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | US | binary | 1.41 Kb | unknown |
2624 | Synaptics.exe | GET | 200 | 142.250.184.227:80 | http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCECzpBwEAqmZNCdn%2B9lFcFjc%3D | US | binary | 471 b | unknown |
2624 | Synaptics.exe | GET | 200 | 142.250.184.227:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQCRd4hKrA6aBAnnS3UYBsso | US | binary | 472 b | unknown |
2624 | Synaptics.exe | GET | 200 | 142.250.184.227:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | US | binary | 724 b | unknown |
1080 | svchost.exe | GET | 200 | 88.221.110.120:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e90c163b6659448e | DE | compressed | 67.5 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2624 | Synaptics.exe | 49.13.77.253:1199 | xred.mooo.com | Hetzner Online GmbH | DE | unknown |
2624 | Synaptics.exe | 69.42.215.252:80 | freedns.afraid.org | AWKNET | US | unknown |
2624 | Synaptics.exe | 142.250.186.174:443 | docs.google.com | GOOGLE | US | whitelisted |
2624 | Synaptics.exe | 2.16.100.179:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | whitelisted |
2624 | Synaptics.exe | 142.250.184.227:80 | ocsp.pki.goog | GOOGLE | US | whitelisted |
2624 | Synaptics.exe | 142.250.184.193:443 | drive.usercontent.google.com | GOOGLE | US | whitelisted |
1080 | svchost.exe | 88.221.110.120:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
xred.mooo.com |
| unknown |
freedns.afraid.org |
| whitelisted |
docs.google.com |
| shared |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
drive.usercontent.google.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | ET INFO DYNAMIC_DNS Query to Abused Domain *.mooo.com |