File name:

pfmap.exe

Full analysis: https://app.any.run/tasks/0fdabd44-2de6-4a20-aeff-57057ffc40f2
Verdict: Malicious activity
Analysis date: April 15, 2024, 11:21:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7DC94D6115481027E574925D436BF3AE

SHA1:

4294B74BE12D7FAA04624C6EDAC2E868BA52F4D5

SHA256:

FE63BEC54A57A58641AA657816610542339AF321CA57D890D6B2B1F8B24D1F84

SSDEEP:

98304:ARzAyp1m9cKHp+KMlnyjl1Zgjb4f84acUtOxCVcKbS3AD8x5bhK6pIuP7xe0ln0O:lRyAN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • pfmap.exe (PID: 2892)
      • pfmap-setup.exe (PID: 2908)
      • pfminst.exe (PID: 1976)
      • ptsysexec.exe (PID: 2596)
    • Creates a writable file in the system directory

      • pfminst.exe (PID: 1976)
      • pfmap-setup.exe (PID: 2908)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • pfmap.exe (PID: 2892)
      • pfminst.exe (PID: 1976)
      • pfmap-setup.exe (PID: 2908)
      • ptsysexec.exe (PID: 2596)
    • Drops a system driver (possible attempt to evade defenses)

      • pfmap.exe (PID: 2892)
      • pfminst.exe (PID: 1976)
    • The process creates files with name similar to system file names

      • pfmap.exe (PID: 2892)
      • pfminst.exe (PID: 1976)
    • Reads Microsoft Outlook installation path

      • pfmap-setup.exe (PID: 2908)
    • Reads security settings of Internet Explorer

      • pfmap-setup.exe (PID: 2908)
    • Reads the Internet Settings

      • pfmap-setup.exe (PID: 2908)
    • Reads Internet Explorer settings

      • pfmap-setup.exe (PID: 2908)
    • Creates a software uninstall entry

      • pfmap-setup.exe (PID: 2908)
    • Creates files in the driver directory

      • pfminst.exe (PID: 1976)
    • Creates/Modifies COM task schedule object

      • ptdllrun1.exe (PID: 3324)
    • Executes as Windows Service

      • ptsysexec.exe (PID: 2240)
    • Creates or modifies Windows services

      • ptsysexec.exe (PID: 2596)
      • pfminst.exe (PID: 1976)
  • INFO

    • Checks supported languages

      • pfmap.exe (PID: 2892)
      • pfmap-setup.exe (PID: 2908)
      • ptdllrun1.exe (PID: 1560)
      • pfminst.exe (PID: 1976)
      • ptdllrun1.exe (PID: 2904)
      • ptdllrun1.exe (PID: 3324)
      • ptsysexec.exe (PID: 2596)
      • pfmcontrol.exe (PID: 2592)
      • ptsysexec.exe (PID: 2240)
      • pfmstart.exe (PID: 680)
    • Reads the computer name

      • pfmap.exe (PID: 2892)
      • pfmap-setup.exe (PID: 2908)
      • pfminst.exe (PID: 1976)
      • ptdllrun1.exe (PID: 1560)
      • ptdllrun1.exe (PID: 2904)
      • ptdllrun1.exe (PID: 3324)
      • ptsysexec.exe (PID: 2596)
      • pfmcontrol.exe (PID: 2592)
      • pfmstart.exe (PID: 680)
      • ptsysexec.exe (PID: 2240)
    • Create files in a temporary directory

      • pfmap-setup.exe (PID: 2908)
      • pfmap.exe (PID: 2892)
    • Checks proxy server information

      • pfmap-setup.exe (PID: 2908)
    • Reads the machine GUID from the registry

      • pfmap-setup.exe (PID: 2908)
    • Creates files in the program directory

      • pfmap-setup.exe (PID: 2908)
    • Manual execution by a user

      • pfmcontrol.exe (PID: 2592)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:05:05 06:38:39+00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 414208
InitializedDataSize: 103424
UninitializedDataSize: -
EntryPoint: 0x44c9d
OSVersion: 5.1
ImageVersion: 5.1
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.177
ProductVersionNumber: 1.0.0.177
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Pismo Technic Inc.
FileDescription: Setup - Pismo File Mount Audit Package
FileVersion: pfmap.1.0.0.177 2015.5.7
LegalCopyright: Pismo Technic Inc. Copyright 2006-2015 Joe Lowe
ProductName: Pismo File Mount Audit Package
ProductVersion: pfmap.1.0.0.177 2015.5.7
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
11
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pfmap.exe pfmap-setup.exe pfminst.exe ptdllrun1.exe no specs ptsysexec.exe ptdllrun1.exe no specs ptdllrun1.exe no specs pfmcontrol.exe no specs ptsysexec.exe no specs pfmstart.exe no specs pfmap.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680"C:\Windows\PismoFileMount\pfmstart.exe" sysstartC:\Windows\PismoFileMount\pfmstart.exeptsysexec.exe
User:
SYSTEM
Company:
Pismo Technic Inc.
Integrity Level:
SYSTEM
Description:
Driver/Daemon Loader - Pismo File Mount
Exit code:
0
Version:
pfm.1.0.0.177 2015.5.7
Modules
Images
c:\windows\pismofilemount\pfmstart.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1560"C:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\ptdllrun1.exe" -i C:\Windows\system32\pfmapi_177.dllC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\ptdllrun1.exepfminst.exe
User:
admin
Company:
Pismo Technic Inc.
Integrity Level:
HIGH
Description:
Pismo Technic DLL Host process
Exit code:
0
Version:
pismo.1.0.0.176 2015.5.5
Modules
Images
c:\users\admin\appdata\local\temp\pfmap-133576537226391250\ptdllrun1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1976"C:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfminst.exe" install uOqZLRTBSE/XBuJE0PNM5Ta3kxoKqUGm4GF8PceX2zQ=C:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfminst.exe
pfmap-setup.exe
User:
admin
Company:
Pismo Technic Inc.
Integrity Level:
HIGH
Description:
Setup - Pismo File Mount
Exit code:
0
Version:
pfm.1.0.0.177 2015.5.7
Modules
Images
c:\users\admin\appdata\local\temp\pfmap-133576537226391250\pfminst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2124"C:\Users\admin\AppData\Local\Temp\pfmap.exe" C:\Users\admin\AppData\Local\Temp\pfmap.exeexplorer.exe
User:
admin
Company:
Pismo Technic Inc.
Integrity Level:
MEDIUM
Description:
Setup - Pismo File Mount Audit Package
Exit code:
3221226540
Version:
pfmap.1.0.0.177 2015.5.7
Modules
Images
c:\users\admin\appdata\local\temp\pfmap.exe
c:\windows\system32\ntdll.dll
2240"C:\Windows\ptsysexec.exe" serviceC:\Windows\ptsysexec.exeservices.exe
User:
SYSTEM
Company:
Pismo Technic Inc.
Integrity Level:
SYSTEM
Description:
Pismo Technic Setup/Daemon Isolated Execution Service
Exit code:
0
Version:
pismo.1.0.0.176 2015.5.5
Modules
Images
c:\windows\ptsysexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2592"C:\Program Files\Pismo File Mount Audit Package\pfmcontrol.exe" C:\Program Files\Pismo File Mount Audit Package\pfmcontrol.exeexplorer.exe
User:
admin
Company:
Pismo Technic Inc.
Integrity Level:
MEDIUM
Description:
Mount Control - Pismo File Mount Audit Package
Version:
pfmap.1.0.0.177 2015.5.7
Modules
Images
c:\program files\pismo file mount audit package\pfmcontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2596"C:\Windows\PismoFileMount\ptsysexec.exe" approve C:\Windows\PismoFileMount\pfmstart.exeC:\Windows\PismoFileMount\ptsysexec.exe
pfminst.exe
User:
admin
Company:
Pismo Technic Inc.
Integrity Level:
HIGH
Description:
Pismo Technic Setup/Daemon Isolated Execution Service
Exit code:
0
Version:
pismo.1.0.0.176 2015.5.5
Modules
Images
c:\windows\pismofilemount\ptsysexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2892"C:\Users\admin\AppData\Local\Temp\pfmap.exe" C:\Users\admin\AppData\Local\Temp\pfmap.exe
explorer.exe
User:
admin
Company:
Pismo Technic Inc.
Integrity Level:
HIGH
Description:
Setup - Pismo File Mount Audit Package
Exit code:
0
Version:
pfmap.1.0.0.177 2015.5.7
Modules
Images
c:\users\admin\appdata\local\temp\pfmap.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2904"C:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\ptdllrun1.exe" -i C:\Windows\PismoFileMount\pfmpfolderfs.dllC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\ptdllrun1.exepfminst.exe
User:
admin
Company:
Pismo Technic Inc.
Integrity Level:
HIGH
Description:
Pismo Technic DLL Host process
Exit code:
0
Version:
pismo.1.0.0.176 2015.5.5
Modules
Images
c:\users\admin\appdata\local\temp\pfmap-133576537226391250\ptdllrun1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2908"C:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfmap-setup.exe"C:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfmap-setup.exe
pfmap.exe
User:
admin
Company:
Pismo Technic Inc.
Integrity Level:
HIGH
Description:
Setup - Pismo File Mount Audit Package
Exit code:
0
Version:
pfmap.1.0.0.177 2015.5.7
Modules
Images
c:\users\admin\appdata\local\temp\pfmap-133576537226391250\pfmap-setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
Total events
2 287
Read events
2 226
Write events
47
Delete events
14

Modification events

(PID) Process:(2908) pfmap-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2908) pfmap-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2908) pfmap-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2908) pfmap-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2908) pfmap-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2908) pfmap-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2908) pfmap-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2908) pfmap-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PismoFileMountAuditPackage
Operation:writeName:DisplayName
Value:
Pismo File Mount Audit Package
(PID) Process:(2908) pfmap-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PismoFileMountAuditPackage
Operation:writeName:UninstallString
Value:
"C:\Program Files\Pismo File Mount Audit Package\pfmuninstall.exe"
(PID) Process:(2908) pfmap-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PismoFileMountAuditPackage
Operation:writeName:DisplayIcon
Value:
"C:\Program Files\Pismo File Mount Audit Package\pfmuninstall.exe",0
Executable files
92
Suspicious files
9
Text files
27
Unknown types
0

Dropped files

PID
Process
Filename
Type
2892pfmap.exeC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfm-license-auditpackage.txttext
MD5:
SHA256:
2892pfmap.exeC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfm.exeexecutable
MD5:
SHA256:
2892pfmap.exeC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfmap-doc.htmlhtml
MD5:
SHA256:
2892pfmap.exeC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfmap-license.txttext
MD5:
SHA256:
2892pfmap.exeC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfmap-readme.txttext
MD5:
SHA256:
2892pfmap.exeC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfmap-setup.exeexecutable
MD5:
SHA256:
2892pfmap.exeC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfmapi_177.dllexecutable
MD5:
SHA256:
2892pfmap.exeC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfmcontrol.exeexecutable
MD5:
SHA256:
2892pfmap.exeC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfmfs_177.sysexecutable
MD5:
SHA256:
2892pfmap.exeC:\Users\admin\AppData\Local\Temp\pfmap-133576537226391250\pfmhost.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info