File name:

Waybill-Notes-Express.pdf.exe

Full analysis: https://app.any.run/tasks/080fa448-441b-40f7-8a26-55fb66b4edc9
Verdict: Malicious activity
Analysis date: April 29, 2025, 00:01:19
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
logmeinrescue
rmm-tool
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

BADCC0C1CC6783AAB03F9E7563453ACF

SHA1:

2D441F85E341B74DDC8ECCDAE8A5D58D84601DC3

SHA256:

7E259137F92089D33319747134130F4682744B86F07FE8D6322249BA5339CAEB

SSDEEP:

196608:N8QgE4bbO2kDe6lk4D6YXo7AaTwo20T1z/4SseB3dVUt:qtbbJGe67947TwM1zASsGet

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates a software uninstall entry

      • Waybill-Notes-Express.pdf.exe (PID: 6632)
      • GoToResolveProcessChecker.exe (PID: 4740)
      • GoToResolveProcessChecker.exe (PID: 7012)
    • Executable content was dropped or overwritten

      • Waybill-Notes-Express.pdf.exe (PID: 6632)
      • GoToResolveTools64.exe (PID: 2088)
      • drvinst.exe (PID: 5756)
      • GoToResolveUnattended.exe (PID: 840)
      • GoToResolveExternalModuleHandler.exe (PID: 6508)
    • Starts CMD.EXE for commands execution

      • Waybill-Notes-Express.pdf.exe (PID: 6632)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 5892)
    • Reads security settings of Internet Explorer

      • GoToResolveUnattended.exe (PID: 5772)
      • GoToResolveProcessChecker.exe (PID: 4740)
      • GoToResolveUnattendedUi.exe (PID: 7220)
      • GoToResolveUnattended.exe (PID: 840)
    • Creates files in the driver directory

      • drvinst.exe (PID: 5756)
    • Executes as Windows Service

      • GoToResolveProcessChecker.exe (PID: 7012)
    • Executing commands from ".cmd" file

      • Waybill-Notes-Express.pdf.exe (PID: 6632)
    • Reads the BIOS version

      • GoToResolveQuickView.exe (PID: 3332)
      • GoToResolveUnattended.exe (PID: 840)
    • Creates/Modifies COM task schedule object

      • GoToResolveUnattended.exe (PID: 840)
    • LOGMEINRESCUE mutex has been found

      • GoToResolveUnattended.exe (PID: 840)
    • Adds/modifies Windows certificates

      • GoToResolveUnattended.exe (PID: 840)
    • The process executes via Task Scheduler

      • PLUGScheduler.exe (PID: 4160)
    • The process checks if it is being run in the virtual environment

      • GoToResolveQuickView.exe (PID: 3332)
  • INFO

    • Checks supported languages

      • Waybill-Notes-Express.pdf.exe (PID: 6632)
      • GoToResolveUnattended.exe (PID: 5772)
      • GoToResolveTools64.exe (PID: 2088)
      • drvinst.exe (PID: 5756)
      • GoToResolveProcessChecker.exe (PID: 4740)
      • GoToResolveProcessChecker.exe (PID: 7012)
      • GoToResolveCrashHandler.exe (PID: 6560)
      • GoToResolveUnattended.exe (PID: 840)
      • GoToResolveCrashHandler.exe (PID: 660)
      • GoToResolveLoggerProcess.exe (PID: 4112)
      • GoToResolveExternalModuleHandler.exe (PID: 920)
      • GoToResolveFileManager.exe (PID: 6744)
      • GoToResolveTerminal.exe (PID: 2136)
      • GoToResolveQuickView.exe (PID: 3332)
      • GoToResolveServiceManager.exe (PID: 736)
      • GoToResolveRegistryEditor.exe (PID: 4228)
      • GoToResolveCrashHandler.exe (PID: 4976)
      • GoToResolveNetworkChecker.exe (PID: 4724)
      • GoToResolveUnattendedUi.exe (PID: 7220)
      • GoToResolveCrashHandler.exe (PID: 7232)
      • GoToResolveCrashHandler.exe (PID: 7376)
      • GoToResolveCrashHandler.exe (PID: 7468)
      • GoToResolveCrashHandler.exe (PID: 7552)
      • GoToResolveCrashHandler.exe (PID: 7508)
      • GoToResolveCrashHandler.exe (PID: 7636)
      • GoToResolveCrashHandler.exe (PID: 7760)
      • GoToResolveCrashHandler.exe (PID: 7732)
      • GoToResolveCrashHandler.exe (PID: 7668)
      • GoToResolveCrashHandler.exe (PID: 7820)
      • GoToResolveRemoteControl.exe (PID: 672)
    • Creates files or folders in the user directory

      • Waybill-Notes-Express.pdf.exe (PID: 6632)
      • GoToResolveUnattended.exe (PID: 5772)
    • Creates files in the program directory

      • Waybill-Notes-Express.pdf.exe (PID: 6632)
      • GoToResolveCrashHandler.exe (PID: 4976)
      • GoToResolveUnattended.exe (PID: 5772)
      • GoToResolveProcessChecker.exe (PID: 4740)
      • GoToResolveProcessChecker.exe (PID: 7012)
      • GoToResolveCrashHandler.exe (PID: 6560)
      • GoToResolveCrashHandler.exe (PID: 660)
      • GoToResolveUnattended.exe (PID: 840)
      • GoToResolveLoggerProcess.exe (PID: 4112)
      • GoToResolveCrashHandler.exe (PID: 7232)
      • GoToResolveTools64.exe (PID: 2088)
      • GoToResolveRegistryEditor.exe (PID: 4228)
      • GoToResolveExternalModuleHandler.exe (PID: 920)
      • GoToResolveCrashHandler.exe (PID: 7376)
      • GoToResolveQuickView.exe (PID: 3332)
      • GoToResolveFileManager.exe (PID: 6744)
      • GoToResolveTerminal.exe (PID: 2136)
      • GoToResolveCrashHandler.exe (PID: 7468)
      • GoToResolveCrashHandler.exe (PID: 7508)
      • GoToResolveCrashHandler.exe (PID: 7552)
      • GoToResolveRemoteControl.exe (PID: 672)
      • GoToResolveCrashHandler.exe (PID: 7668)
      • GoToResolveCrashHandler.exe (PID: 7636)
      • GoToResolveServiceManager.exe (PID: 736)
      • GoToResolveNetworkChecker.exe (PID: 4724)
      • GoToResolveCrashHandler.exe (PID: 7820)
      • GoToResolveCrashHandler.exe (PID: 7732)
      • GoToResolveCrashHandler.exe (PID: 7760)
      • GoToResolveUnattendedUi.exe (PID: 7220)
    • Reads the computer name

      • Waybill-Notes-Express.pdf.exe (PID: 6632)
      • GoToResolveTools64.exe (PID: 2088)
      • GoToResolveUnattended.exe (PID: 5772)
      • drvinst.exe (PID: 5756)
      • GoToResolveProcessChecker.exe (PID: 4740)
      • GoToResolveProcessChecker.exe (PID: 7012)
      • GoToResolveUnattended.exe (PID: 840)
      • GoToResolveLoggerProcess.exe (PID: 4112)
      • GoToResolveExternalModuleHandler.exe (PID: 920)
      • GoToResolveQuickView.exe (PID: 3332)
      • GoToResolveFileManager.exe (PID: 6744)
      • GoToResolveTerminal.exe (PID: 2136)
      • GoToResolveServiceManager.exe (PID: 736)
      • GoToResolveRegistryEditor.exe (PID: 4228)
      • GoToResolveRemoteControl.exe (PID: 672)
      • GoToResolveNetworkChecker.exe (PID: 4724)
      • GoToResolveUnattendedUi.exe (PID: 7220)
    • The sample compiled with english language support

      • Waybill-Notes-Express.pdf.exe (PID: 6632)
      • GoToResolveTools64.exe (PID: 2088)
      • drvinst.exe (PID: 5756)
    • Create files in a temporary directory

      • Waybill-Notes-Express.pdf.exe (PID: 6632)
      • GoToResolveTools64.exe (PID: 2088)
    • Reads CPU info

      • GoToResolveTools64.exe (PID: 2088)
      • GoToResolveUnattended.exe (PID: 5772)
      • GoToResolveUnattended.exe (PID: 840)
      • GoToResolveRemoteControl.exe (PID: 672)
      • GoToResolveQuickView.exe (PID: 3332)
    • Checks proxy server information

      • GoToResolveUnattended.exe (PID: 5772)
    • Reads the machine GUID from the registry

      • GoToResolveUnattended.exe (PID: 5772)
      • drvinst.exe (PID: 5756)
      • GoToResolveProcessChecker.exe (PID: 4740)
      • GoToResolveProcessChecker.exe (PID: 7012)
      • GoToResolveUnattended.exe (PID: 840)
      • GoToResolveLoggerProcess.exe (PID: 4112)
      • GoToResolveQuickView.exe (PID: 3332)
      • GoToResolveTerminal.exe (PID: 2136)
      • GoToResolveRemoteControl.exe (PID: 672)
      • GoToResolveFileManager.exe (PID: 6744)
      • GoToResolveExternalModuleHandler.exe (PID: 920)
      • GoToResolveServiceManager.exe (PID: 736)
      • GoToResolveRegistryEditor.exe (PID: 4228)
      • GoToResolveNetworkChecker.exe (PID: 4724)
      • GoToResolveUnattendedUi.exe (PID: 7220)
    • Reads the software policy settings

      • drvinst.exe (PID: 5756)
      • GoToResolveProcessChecker.exe (PID: 4740)
      • GoToResolveUnattended.exe (PID: 840)
      • GoToResolveProcessChecker.exe (PID: 7012)
      • GoToResolveLoggerProcess.exe (PID: 4112)
      • GoToResolveExternalModuleHandler.exe (PID: 920)
      • GoToResolveQuickView.exe (PID: 3332)
      • GoToResolveServiceManager.exe (PID: 736)
      • GoToResolveFileManager.exe (PID: 6744)
      • GoToResolveTerminal.exe (PID: 2136)
      • GoToResolveNetworkChecker.exe (PID: 4724)
      • GoToResolveRemoteControl.exe (PID: 672)
      • GoToResolveUnattendedUi.exe (PID: 7220)
      • GoToResolveUnattended.exe (PID: 5772)
      • GoToResolveRegistryEditor.exe (PID: 4228)
    • Reads Environment values

      • GoToResolveUnattended.exe (PID: 5772)
      • GoToResolveUnattended.exe (PID: 840)
      • GoToResolveTools64.exe (PID: 2088)
      • GoToResolveExternalModuleHandler.exe (PID: 920)
      • GoToResolveRemoteControl.exe (PID: 672)
      • GoToResolveQuickView.exe (PID: 3332)
    • Process checks computer location settings

      • GoToResolveUnattended.exe (PID: 5772)
      • GoToResolveUnattended.exe (PID: 840)
    • Reads the time zone

      • GoToResolveUnattended.exe (PID: 840)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:04:23 09:54:52+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.34
CodeSize: 1138688
InitializedDataSize: 23255040
UninitializedDataSize: -
EntryPoint: 0xdb460
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.25.0.856
ProductVersionNumber: 1.25.0.856
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (0009)
CharacterSet: Unicode
CompanyName: GoTo, Inc.
FileDescription: LogMeIn Resolve
FileVersion: 1.25.0.856
InternalName: GoToResolveUnattendedUpdater.exe
LegalCopyright: Copyright © 2016-2025 GoTo, Inc. US patents pending.
OriginalFileName: GoToResolveUnattendedUpdater.exe
ProductName: GoTo Resolve
ProductVersion: 1.25.0.856
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
313
Monitored processes
61
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start waybill-notes-express.pdf.exe gotoresolveunattended.exe gotoresolvetools64.exe cmd.exe no specs conhost.exe no specs gotoresolvecrashhandler.exe no specs timeout.exe no specs timeout.exe no specs drvinst.exe gotoresolveprocesschecker.exe no specs gotoresolveprocesschecker.exe gotoresolvecrashhandler.exe no specs gotoresolveunattended.exe gotoresolveloggerprocess.exe gotoresolvecrashhandler.exe no specs gotoresolveexternalmodulehandler.exe no specs gotoresolvefilemanager.exe no specs gotoresolvequickview.exe no specs gotoresolveterminal.exe no specs gotoresolveservicemanager.exe no specs gotoresolveremotecontrol.exe no specs gotoresolveregistryeditor.exe no specs gotoresolvenetworkchecker.exe gotoresolveunattendedui.exe no specs gotoresolvecrashhandler.exe no specs tiworker.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolveprocesschecker.exe no specs gotoresolvecrashhandler.exe no specs gotoresolveunattended.exe plugscheduler.exe no specs gotoresolveloggerprocess.exe gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolveexternalmodulehandler.exe gotoresolvefilemanager.exe no specs gotoresolvequickview.exe no specs gotoresolveterminal.exe no specs gotoresolveservicemanager.exe no specs gotoresolveremotecontrol.exe no specs gotoresolveregistryeditor.exe no specs gotoresolvenetworkchecker.exe gotoresolveunattendedui.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs waybill-notes-express.pdf.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
660"C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveCrashHandler.exe" "--attachment=attachment_GoToResolveUnattended.log=C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\appdata\GoToResolveUnattended.log" "--attachment=attachment_unattended.json=C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\unattended.json" "--database=C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\appdata\UnattendedCrashReportDB" "--metrics-dir=C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\appdata\UnattendedCrashReportDB" --url=https://dumpster.console.gotoresolve.com/api/dump --annotation=format=minidump --annotation=hostname=DESKTOP-JGLLJLD --annotation=installationid=zy5vHEtScW --annotation=version=1.25.0.856 --initial-client-data=0x79c,0x7a0,0x7a4,0x524,0x7a8,0x7057d72c,0x7057d73c,0x7057d74cC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveCrashHandler.exeGoToResolveUnattended.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files (x86)\goto resolve unattended\2462565644419079679\gotoresolvecrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
672GoToResolveRemoteControl.exe -CompanyId 2462565644419079679 -InstallationId zy5vHEtScW -WorkFolder "C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679" -Environment Production -ApplicationType 4 -LogLevel 2 -Service 1C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveRemoteControl.exeGoToResolveUnattended.exe
User:
SYSTEM
Company:
GoTo, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Resolve
Exit code:
0
Version:
1.25.0.856
Modules
Images
c:\program files (x86)\goto resolve unattended\2462565644419079679\gotoresolveremotecontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\msvcp_win.dll
736GoToResolveServiceManager.exe -CompanyId 2462565644419079679 -Environment Production -InstallationId zy5vHEtScW -LogLevel 2C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveServiceManager.exeGoToResolveUnattended.exe
User:
SYSTEM
Company:
GoTo, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Resolve
Exit code:
0
Version:
1.25.0.856
Modules
Images
c:\program files (x86)\goto resolve unattended\2462565644419079679\gotoresolveservicemanager.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\msvcp_win.dll
840"C:/Program Files (x86)/GoTo Resolve Unattended/2462565644419079679/GoToResolveUnattended.exe" "-RegisteredProcess" "1" "-ParentProcessId" "7012" "-InstallationId" "zy5vHEtScW" "-WtsStartingSessionId" "5" "-ServiceName" "GoToResolve_2462565644419079679" "-Service" "-LogLevel" "2"C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveUnattended.exe
GoToResolveProcessChecker.exe
User:
SYSTEM
Company:
GoTo, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Resolve
Exit code:
0
Version:
1.25.0.856
Modules
Images
c:\program files (x86)\goto resolve unattended\2462565644419079679\gotoresolveunattended.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\msvcp_win.dll
920"C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveExternalModuleHandler.exe" -InstallationId zy5vHEtScW -CompanyId 2462565644419079679 -publickey ec7ffae54c6bdbe299b358b00c78d179005d9d3ef839d747aafa942bed6d3ae4 -LogLevel 2 -Environment ProductionC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveExternalModuleHandler.exeGoToResolveUnattended.exe
User:
SYSTEM
Company:
GoTo, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Resolve
Exit code:
0
Version:
1.25.0.856
Modules
Images
c:\program files (x86)\goto resolve unattended\2462565644419079679\gotoresolveexternalmodulehandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\msvcp_win.dll
968"C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveCrashHandler.exe" "--attachment=attachment_GoToResolveUnattendedUi.log=C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\appdata\GoToResolveUnattendedUi.log" "--attachment=attachment_unattended.json=C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\unattended.json" "--database=C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\appdata\UnattendedUiCrashReportDB" "--metrics-dir=C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\appdata\UnattendedUiCrashReportDB" --url=https://dumpster.console.gotoresolve.com/api/dump --annotation=format=minidump --annotation=hostname=DESKTOP-JGLLJLD --annotation=installationid=zy5vHEtScW --annotation=version=1.25.0.856 --initial-client-data=0x714,0x718,0x71c,0x5e4,0x720,0x713fd72c,0x713fd73c,0x713fd74cC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveCrashHandler.exeGoToResolveUnattendedUi.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files (x86)\goto resolve unattended\2462565644419079679\gotoresolvecrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1020timeout /T 3 C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1108"C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveCrashHandler.exe" "--database=C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\appdata\FileManagerCrashReportDB" "--metrics-dir=C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\appdata\FileManagerCrashReportDB" --url=https://dumpster.console.gotoresolve.com/api/dump --annotation=format=minidump --annotation=hostname=DESKTOP-JGLLJLD --annotation=installationid=zy5vHEtScW --annotation=version=1.25.0.856 --initial-client-data=0x7f4,0x7f8,0x7fc,0x7d0,0x804,0x713fd72c,0x713fd73c,0x713fd74cC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveCrashHandler.exeGoToResolveFileManager.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\goto resolve unattended\2462565644419079679\gotoresolvecrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1328timeout /T 3 C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2088"C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveTools64.exe" -InstallVDDC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveTools64.exe
Waybill-Notes-Express.pdf.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\goto resolve unattended\2462565644419079679\gotoresolvetools64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
Total events
120 028
Read events
119 978
Write events
28
Delete events
22

Modification events

(PID) Process:(6632) Waybill-Notes-Express.pdf.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GoTo Resolve Unattended\2462565644419079679
Operation:writeName:PublicKey
Value:
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000D037601E5051A445BB6848B5CD56576204000000020000000000106600000001000020000000F6899794CEF6F9B77453F049DD726BE2824DA4103AE0E9FA758D4C705F966888000000000E80000000020000200000003117788B87E884138B453CD4F8CF7101AB7488362DE1C8DBAB1A28AC9027DE9E300000000D681A3EFD1B5DC8153FF00D6735137E301C307C7B42546FE6FD06E3C155BB8ADF19142B37F0771D7022E521A93C54B040000000B402B45CCBE02CBD7EDF556685477B0F20F3A484A3AD6793FA4BB34CD5BBC6E18CA0C5E0698D43C04DF5E439C5B02066BBA6A4A3D9C0720ACF40E906212FD2CF
(PID) Process:(6632) Waybill-Notes-Express.pdf.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoTo Resolve Unattended 2462565644419079679
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveUnattended.exe
(PID) Process:(6632) Waybill-Notes-Express.pdf.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoTo Resolve Unattended 2462565644419079679
Operation:writeName:DisplayName
Value:
LogMeIn Resolve Unattended 2462565644419079679
(PID) Process:(6632) Waybill-Notes-Express.pdf.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoTo Resolve Unattended 2462565644419079679
Operation:writeName:DisplayVersion
Value:
1.25.0.856
(PID) Process:(6632) Waybill-Notes-Express.pdf.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoTo Resolve Unattended 2462565644419079679
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679
(PID) Process:(6632) Waybill-Notes-Express.pdf.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoTo Resolve Unattended 2462565644419079679
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveUnattendedRemover.exe
(PID) Process:(2088) GoToResolveTools64.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
Operation:writeName:setupapi.dev.log
Value:
4096
(PID) Process:(5772) GoToResolveUnattended.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GoTo Resolve Unattended\2462565644419079679
Operation:delete valueName:regsvc
Value:
(PID) Process:(5772) GoToResolveUnattended.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GoTo Resolve Unattended\2462565644419079679
Operation:delete valueName:InstallationId
Value:
(PID) Process:(5772) GoToResolveUnattended.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GoTo Resolve Unattended\2462565644419079679
Operation:writeName:HostId
Value:
a7c1f8cfa0c32c63f2959fc75b536fbb
Executable files
50
Suspicious files
312
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
6632Waybill-Notes-Express.pdf.exeC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\unattended.jsonbinary
MD5:06693E7B6AD655C38D1363A5B52E98EC
SHA256:DB5DC438753EC2E0C3099636A77F85B88AE7918AF550B943E5F4CFDECDD03141
6632Waybill-Notes-Express.pdf.exeC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveProcessChecker.exeexecutable
MD5:4BBBC5AC11233599CD2FF2B4EE02DCBC
SHA256:6CEA363A153CFACF3BA8EFADCB2F1C89C96BF727C8BB8AB6E9940732F0842F23
6632Waybill-Notes-Express.pdf.exeC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveRemoteControl.exeexecutable
MD5:DB0E57306858B08D5AAAA9D82BE2C77A
SHA256:22D6617A697522432D75DDDA2E55F36510B14AEB08690017C5CBC19232007F6F
6632Waybill-Notes-Express.pdf.exeC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveUnattended.exeexecutable
MD5:2FAE5330384060C0C559E60BC83F26F7
SHA256:53EF8364CDDC557FA1AC1CD9DB312EF5D6AD0F4264D389D6BAF5144E5354C582
6632Waybill-Notes-Express.pdf.exeC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveUnattendedUi.exeexecutable
MD5:6CF5505F9DF485DB140800243E524E55
SHA256:1F6E2C3020ABC8E64BA77BF306E73C54893D9BF8F084D1A9716B3B7BE3485FEF
6632Waybill-Notes-Express.pdf.exeC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveFileManager.exeexecutable
MD5:D4C4280767E61D66EE194D066785C902
SHA256:FD3BC0270EF9FDAE74F769DEC272CE66B36F268C10DB6E9AC2B8A58E27D91B3E
6632Waybill-Notes-Express.pdf.exeC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveServiceManager.exeexecutable
MD5:6D65DC2BDCB35C06C5AB6E8574C2FFC1
SHA256:5E1D937F9BB4B469D2761C4B059893456E1E18698EE2EDA7A29D0E8CD3DEA977
6632Waybill-Notes-Express.pdf.exeC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveRegistryEditor.exeexecutable
MD5:D6EDB72EE700DBF6F34FEA42AAD89E8F
SHA256:664170E67058D0FC447A282FD3FB6DB24E447F4CCFF116E6D86EC9B781B50B46
6632Waybill-Notes-Express.pdf.exeC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveLoggerProcess.exeexecutable
MD5:AD59DDE2D71F02C2F19C10FDCF6FAB99
SHA256:60C857654DD319713AC42081329A5FA4377799EF4785A6198F0C5A4AB0279C7F
6632Waybill-Notes-Express.pdf.exeC:\Program Files (x86)\GoTo Resolve Unattended\2462565644419079679\GoToResolveUi.exeexecutable
MD5:3CFB224CC855D3714C5DBF1B01E35C8B
SHA256:424B01D92116D8F43E2565EAA8B292B5B54EBB248967DDC65CD96C767C1D19E4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
13
TCP/UDP connections
89
DNS requests
46
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5772
GoToResolveUnattended.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTjzY2p9Pa8oibmj%2BNSMWsz63kmWgQUuhbZbU2FL3MpdpovdYxqII%2BeyG8CEAuuZrxaun%2BVh8b56QTjMwQ%3D
unknown
whitelisted
GET
200
23.32.238.112:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7012
GoToResolveProcessChecker.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA4Mh2e7LU%2FvwtYX3xHOG4k%3D
unknown
whitelisted
4724
GoToResolveNetworkChecker.exe
GET
165.225.4.122:80
http://ip.zscaler.com/
unknown
unknown
7012
GoToResolveProcessChecker.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTjzY2p9Pa8oibmj%2BNSMWsz63kmWgQUuhbZbU2FL3MpdpovdYxqII%2BeyG8CEAuuZrxaun%2BVh8b56QTjMwQ%3D
unknown
whitelisted
7932
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7932
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6672
GoToResolveNetworkChecker.exe
GET
200
165.225.4.122:80
http://ip.zscaler.com/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4784
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.32.238.112:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6544
svchost.exe
20.190.160.5:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
2112
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5772
GoToResolveUnattended.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.78
whitelisted
crl.microsoft.com
  • 23.32.238.112
  • 23.32.238.107
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 20.190.160.5
  • 20.190.160.64
  • 20.190.160.131
  • 20.190.160.3
  • 40.126.32.68
  • 20.190.160.20
  • 20.190.160.22
  • 20.190.160.14
  • 20.190.160.128
  • 40.126.32.136
  • 40.126.32.76
  • 40.126.32.134
  • 40.126.32.138
  • 20.190.160.17
  • 20.190.160.130
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
dumpster.console.gotoresolve.com
  • 3.124.128.113
  • 3.66.243.215
unknown
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

PID
Process
Class
Message
4724
GoToResolveNetworkChecker.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
2252
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] An application monitoring request to sentry .io
6672
GoToResolveNetworkChecker.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
6672
GoToResolveNetworkChecker.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
Process
Message
GoToResolveProcessChecker.exe
DllMain: DLL_PROCESS_ATTACH: lpReserved=0
GoToResolveProcessChecker.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveProcessChecker.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveProcessChecker.exe
DllMain: DLL_THREAD_ATTACH