pamfax.exe

PamFax

PamConsult GmbH.

This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘pamfax’. The file has been seen being downloaded from pamfax.softonic.com and multiple other hosts.
Publisher:
PamConsult GmbH.

Product:
PamFax

Version:
4.1.3

MD5:
ef9c1d8b124cd5532d5d261b77718986

SHA-1:
136b9d4d78fa4c462e657d2b6011d90a58fb9426

SHA-256:
009ce260fa5a3f897dd3ba62e357b0d6e6f0c0d7d38efba94f38924db34c665b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 4:52:43 AM UTC  (today)

File size:
84.1 MB (88,206,848 bytes)

Product version:
4.1.3

Copyright:
2006-2015 PamConsult GmbH.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\squirrelmachineinstalls\pamfax.exe

File PE Metadata
Compilation timestamp:
9/9/2015 12:39:49 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
1572864:nNP9izMB5uK+cO2atAqFW5ExAz8MefFlZn42f9m:NP9iQBkAOhtBFWmxO8DfFlZ9

Entry address:
0xAD5E

Entry point:
E8, 48, 66, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, 44, 99, 42, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA, 25, 04, 84, 42, 00, 01, 0F, 82, 7F, 67, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83...
 
[+]

Entropy:
7.9992  (probably packed)

Code size:
109.5 KB (112,128 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
pamfax

Command:
C:\ProgramData\squirrelmachineinstalls\pamfax.exe --checkinstall


The file pamfax.exe has been seen being distributed by the following 3 URLs.

http://pamfax.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/trmsvRChbxdrflJq3ZIylWtAJKug4ApNfQLscYPFtCg 8 01mUIxRaDavqmSwSp0IGAZ4N28fGlyPzVw2oWb2j3yfjFqAe/Qxso4lNwh1yqZSFkZUtHkc1VN9/ed43l4A7eyF23K0/.../scKnuMg=

Scan pamfax.exe - Powered by Reason Core Security