File name:

92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe

Full analysis: https://app.any.run/tasks/316d9910-1edd-4786-9216-c258fd55f479
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: February 02, 2024, 08:38:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
rat
rurat
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

075D6C122274CB9226521D3CD298F2F2

SHA1:

6F54D70F39FA28596EF90BFCB0C14278B016DB1B

SHA256:

92192AF947017C20AD861FAF4459FB705E63F7083B34C77C1727891B88091573

SSDEEP:

196608:+GNqIkHtux5ghkb4MK9vY0DxgbUZPs7YHdmkftsEW7T4/b:+Qrwkx5EA4d9vH9dGYHZK7T4j

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Rurat mutex has been detected

      • rutserv.exe (PID: 2824)
      • rfusclient.exe (PID: 2984)
      • rfusclient.exe (PID: 2372)
      • rutserv.exe (PID: 308)
      • rfusclient.exe (PID: 2500)
  • SUSPICIOUS

    • Reads the Internet Settings

      • 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe (PID: 2464)
    • Executes as Windows Service

      • rutserv.exe (PID: 2824)
    • Application launched itself

      • rutserv.exe (PID: 2824)
      • rfusclient.exe (PID: 2372)
    • Connects to unusual port

      • rutserv.exe (PID: 2824)
  • INFO

    • Create files in a temporary directory

      • 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe (PID: 2464)
    • Checks supported languages

      • 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe (PID: 2464)
      • rutserv.exe (PID: 2824)
      • rfusclient.exe (PID: 2984)
      • rfusclient.exe (PID: 2372)
      • rutserv.exe (PID: 308)
      • rfusclient.exe (PID: 2500)
    • Reads the computer name

      • 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe (PID: 2464)
      • rutserv.exe (PID: 2824)
      • rfusclient.exe (PID: 2984)
      • rfusclient.exe (PID: 2372)
      • rfusclient.exe (PID: 2500)
      • rutserv.exe (PID: 308)
    • Process checks computer location settings

      • rutserv.exe (PID: 2824)
      • rfusclient.exe (PID: 2372)
      • rfusclient.exe (PID: 2984)
      • rfusclient.exe (PID: 2500)
      • rutserv.exe (PID: 308)
    • Reads the machine GUID from the registry

      • rutserv.exe (PID: 2824)
      • rfusclient.exe (PID: 2984)
      • rfusclient.exe (PID: 2372)
      • rfusclient.exe (PID: 2500)
      • rutserv.exe (PID: 308)
    • Reads product name

      • rutserv.exe (PID: 2824)
      • rfusclient.exe (PID: 2984)
      • rfusclient.exe (PID: 2500)
      • rutserv.exe (PID: 308)
      • rfusclient.exe (PID: 2372)
    • Reads Windows Product ID

      • rutserv.exe (PID: 2824)
      • rfusclient.exe (PID: 2984)
      • rfusclient.exe (PID: 2372)
      • rfusclient.exe (PID: 2500)
      • rutserv.exe (PID: 308)
    • Reads Environment values

      • rutserv.exe (PID: 2824)
      • rfusclient.exe (PID: 2984)
      • rfusclient.exe (PID: 2372)
      • rfusclient.exe (PID: 2500)
      • rutserv.exe (PID: 308)
    • Creates files in the program directory

      • rutserv.exe (PID: 2824)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:12:13 15:03:01+01:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.33
CodeSize: 288768
InitializedDataSize: 223744
UninitializedDataSize: -
EntryPoint: 0x32dc0
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe msiexec.exe no specs rutserv.exe rfusclient.exe no specs rfusclient.exe no specs rfusclient.exe no specs rutserv.exe no specs 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
308"C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" -firewallC:\Program Files (x86)\Remote Utilities - Host\rutserv.exerutserv.exe
User:
SYSTEM
Company:
Remote Utilities Pty (Cy) Ltd.
Integrity Level:
SYSTEM
Description:
Remote Utilities - Host
Exit code:
0
Version:
7.2.2.0
Modules
Images
c:\program files (x86)\remote utilities - host\rutserv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1688"C:\Users\admin\AppData\Local\Temp\92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe" C:\Users\admin\AppData\Local\Temp\92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe
c:\windows\system32\ntdll.dll
2372"C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe"C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exerutserv.exe
User:
SYSTEM
Company:
Remote Utilities Pty (Cy) Ltd.
Integrity Level:
SYSTEM
Description:
Remote Utilities - Host
Exit code:
0
Version:
7.2.2.0
Modules
Images
c:\program files (x86)\remote utilities - host\rfusclient.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2464"C:\Users\admin\AppData\Local\Temp\92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe" C:\Users\admin\AppData\Local\Temp\92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2500"C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe" /trayC:\Program Files (x86)\Remote Utilities - Host\rfusclient.exerfusclient.exe
User:
admin
Company:
Remote Utilities Pty (Cy) Ltd.
Integrity Level:
MEDIUM
Description:
Remote Utilities - Host
Exit code:
0
Version:
7.2.2.0
Modules
Images
c:\program files (x86)\remote utilities - host\rfusclient.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2812"C:\Windows\System32\msiexec.exe" /i Exel.msi /qnC:\Windows\System32\msiexec.exe92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2824"C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" -serviceC:\Program Files (x86)\Remote Utilities - Host\rutserv.exe
services.exe
User:
SYSTEM
Company:
Remote Utilities Pty (Cy) Ltd.
Integrity Level:
SYSTEM
Description:
Remote Utilities - Host
Exit code:
0
Version:
7.2.2.0
Modules
Images
c:\program files (x86)\remote utilities - host\rutserv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2984"C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe" /trayC:\Program Files (x86)\Remote Utilities - Host\rfusclient.exerutserv.exe
User:
admin
Company:
Remote Utilities Pty (Cy) Ltd.
Integrity Level:
MEDIUM
Description:
Remote Utilities - Host
Exit code:
0
Version:
7.2.2.0
Modules
Images
c:\program files (x86)\remote utilities - host\rfusclient.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
1 928
Read events
1 892
Write events
34
Delete events
2

Modification events

(PID) Process:(2464) 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2464) 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2464) 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2464) 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2824) rutserv.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\Remote Utilities Host Installer
Operation:delete keyName:(default)
Value:
(PID) Process:(2824) rutserv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters
Operation:writeName:General
Value:
EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0D0A3C67656E6572616C5F73657474696E67732076657273696F6E3D223730323230223E3C706F72743E353635303C2F706F72743E3C686964655F747261795F69636F6E5F706F7075705F6D656E753E747275653C2F686964655F747261795F69636F6E5F706F7075705F6D656E753E3C747261795F6D656E755F686964655F73746F703E747275653C2F747261795F6D656E755F686964655F73746F703E3C6C616E67756167653E4B6F7265616E3C2F6C616E67756167653E3C63616C6C6261636B5F6175746F5F636F6E6E6563743E747275653C2F63616C6C6261636B5F6175746F5F636F6E6E6563743E3C63616C6C6261636B5F636F6E6E6563745F696E74657276616C3E36303C2F63616C6C6261636B5F636F6E6E6563745F696E74657276616C3E3C70617373776F72645F646174613E37656936756A7778394B413D3C2F70617373776F72645F646174613E3C70726F746563745F63616C6C6261636B5F73657474696E67733E747275653C2F70726F746563745F63616C6C6261636B5F73657474696E67733E3C70726F746563745F696E65745F69645F73657474696E67733E747275653C2F70726F746563745F696E65745F69645F73657474696E67733E3C7573655F6C65676163795F636170747572653E66616C73653C2F7573655F6C65676163795F636170747572653E3C646F5F6E6F745F636170747572655F7264703E66616C73653C2F646F5F6E6F745F636170747572655F7264703E3C7573655F69705F765F363E747275653C2F7573655F69705F765F363E3C6C6F675F7573653E66616C73653C2F6C6F675F7573653E3C6C6F675F7573655F77696E646F77733E66616C73653C2F6C6F675F7573655F77696E646F77733E3C636861745F636C69656E745F73657474696E67733E3C2F636861745F636C69656E745F73657474696E67733E3C617574685F6B65795F737472696E673E3C2F617574685F6B65795F737472696E673E3C7369645F69643E3C2F7369645F69643E3C6E6F746966795F73686F775F70616E656C3E66616C73653C2F6E6F746966795F73686F775F70616E656C3E3C6E6F746966795F6368616E67655F747261795F69636F6E3E747275653C2F6E6F746966795F6368616E67655F747261795F69636F6E3E3C6E6F746966795F62616C6C6F6E5F68696E743E66616C73653C2F6E6F746966795F62616C6C6F6E5F68696E743E3C6E6F746966795F706C61795F736F756E643E66616C73653C2F6E6F746966795F706C61795F736F756E643E3C6E6F746966795F70616E656C5F783E2D313C2F6E6F746966795F70616E656C5F783E3C6E6F746966795F70616E656C5F793E2D313C2F6E6F746966795F70616E656C5F793E3C70726F78795F73657474696E67733E3737752F5044393462577767646D567963326C76626A30694D5334774969426C626D4E765A476C755A7A3069565652474C546769507A344E436A7877636D39346556397A5A5852306157356E637942325A584A7A61573975505349334D4449794D43492B5048567A5A563977636D39346554356D5957787A5A54777664584E6C5833427962336835506A7877636D3934655639306558426C506A41384C33427962336835583352356347552B504768766333512B5043396F62334E30506A787762334A30506A67774F4441384C334276636E512B5047356C5A575266595856306144356D5957787A5A547776626D566C5A4639686458526F506A787564473173583246316447672B5A6D4673633255384C32353062577866595856306144343864584E6C636D35686257552B5043393163325679626D46745A5434386347467A63336476636D512B5043397759584E7A643239795A4434385A47397459576C75506A77765A47397459576C75506A777663484A7665486C666332563064476C755A334D2B44516F3D3C2F70726F78795F73657474696E67733E3C6164646974696F6E616C3E376432376A7767787761545A335936505044483070413D3D3C2F6164646974696F6E616C3E3C64697361626C655F696E7465726E65745F69643E66616C73653C2F64697361626C655F696E7465726E65745F69643E3C736166655F6D6F64655F7365743E66616C73653C2F736166655F6D6F64655F7365743E3C73686F775F69645F6E6F74696669636174696F6E3E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E3E3C73686F775F69645F6E6F74696669636174696F6E5F726571756573743E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E5F726571756573743E3C73686F775F69645F6E6F74696669636174696F6E5F776974685F74696D656F75743E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E5F776974685F74696D656F75743E3C696E746567726174655F6669726577616C6C5F61745F737461727475703E747275653C2F696E746567726174655F6669726577616C6C5F61745F737461727475703E3C636C6970626F6172645F7472616E736665725F6D6F64653E303C2F636C6970626F6172645F7472616E736665725F6D6F64653E3C636C6F73655F73657373696F6E5F69646C653E66616C73653C2F636C6F73655F73657373696F6E5F69646C653E3C636C6F73655F73657373696F6E5F69646C655F696E74657276616C3E36303C2F636C6F73655F73657373696F6E5F69646C655F696E74657276616C3E3C73686F775F636F6E6E656374696F6E5F616C6572745F666F725F616C6C3E66616C73653C2F73686F775F636F6E6E656374696F6E5F616C6572745F666F725F616C6C3E3C2F67656E6572616C5F73657474696E67733E0D0A
(PID) Process:(2824) rutserv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters
Operation:writeName:Security
Value:
EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0D0A3C73656375726974795F73657474696E67732076657273696F6E3D223730323230223E3C77696E646F77735F73656375726974793E3C2F77696E646F77735F73656375726974793E3C73696E676C655F70617373776F72645F686173683E37453443434233393036324638464435324544304135303438393437364633314135423331313637423035394637314542363937383641314641394430333145464633304245313231354646343438373336364641363344364233434239343637433538423241464531364432384433463534334639464337413538323737443C2F73696E676C655F70617373776F72645F686173683E3C6D795F757365725F6163636573735F6C6973743E3C757365725F6163636573735F6C6973742F3E3C2F6D795F757365725F6163636573735F6C6973743E3C69705F66696C7465725F747970653E323C2F69705F66696C7465725F747970653E3C69705F626C61636B5F6C6973743E3C2F69705F626C61636B5F6C6973743E3C69705F77686974655F6C6973743E3C2F69705F77686974655F6C6973743E3C617574685F6B696E643E313C2F617574685F6B696E643E3C6F74705F656E61626C653E66616C73653C2F6F74705F656E61626C653E3C6F74705F707269766174655F6B65793E3C2F6F74705F707269766174655F6B65793E3C6F74705F71725F7365637265743E3C2F6F74705F71725F7365637265743E3C757365725F7065726D697373696F6E735F61736B3E66616C73653C2F757365725F7065726D697373696F6E735F61736B3E3C757365725F7065726D697373696F6E735F696E74657276616C3E31303030303C2F757365725F7065726D697373696F6E735F696E74657276616C3E3C757365725F7065726D697373696F6E735F616C6C6F775F64656661756C743E66616C73653C2F757365725F7065726D697373696F6E735F616C6C6F775F64656661756C743E3C757365725F7065726D697373696F6E735F6F6E6C795F69665F757365725F6C6F676765645F6F6E3E66616C73653C2F757365725F7065726D697373696F6E735F6F6E6C795F69665F757365725F6C6F676765645F6F6E3E3C64697361626C655F72656D6F74655F636F6E74726F6C3E66616C73653C2F64697361626C655F72656D6F74655F636F6E74726F6C3E3C64697361626C655F72656D6F74655F73637265656E3E66616C73653C2F64697361626C655F72656D6F74655F73637265656E3E3C64697361626C655F66696C655F7472616E736665723E66616C73653C2F64697361626C655F66696C655F7472616E736665723E3C64697361626C655F72656469726563743E66616C73653C2F64697361626C655F72656469726563743E3C64697361626C655F74656C6E65743E66616C73653C2F64697361626C655F74656C6E65743E3C64697361626C655F72656D6F74655F657865637574653E66616C73653C2F64697361626C655F72656D6F74655F657865637574653E3C64697361626C655F7461736B5F6D616E616765723E66616C73653C2F64697361626C655F7461736B5F6D616E616765723E3C64697361626C655F73687574646F776E3E66616C73653C2F64697361626C655F73687574646F776E3E3C64697361626C655F72656D6F74655F757067726164653E66616C73653C2F64697361626C655F72656D6F74655F757067726164653E3C64697361626C655F707265766965775F636170747572653E66616C73653C2F64697361626C655F707265766965775F636170747572653E3C64697361626C655F6465766963655F6D616E616765723E66616C73653C2F64697361626C655F6465766963655F6D616E616765723E3C64697361626C655F636861743E747275653C2F64697361626C655F636861743E3C64697361626C655F73637265656E5F7265636F72643E66616C73653C2F64697361626C655F73637265656E5F7265636F72643E3C64697361626C655F61765F636170747572653E66616C73653C2F64697361626C655F61765F636170747572653E3C64697361626C655F73656E645F6D6573736167653E747275653C2F64697361626C655F73656E645F6D6573736167653E3C64697361626C655F72656769737472793E66616C73653C2F64697361626C655F72656769737472793E3C64697361626C655F61765F636861743E747275653C2F64697361626C655F61765F636861743E3C64697361626C655F72656D6F74655F73657474696E67733E66616C73653C2F64697361626C655F72656D6F74655F73657474696E67733E3C64697361626C655F72656D6F74655F7072696E74696E673E747275653C2F64697361626C655F72656D6F74655F7072696E74696E673E3C64697361626C655F7264703E66616C73653C2F64697361626C655F7264703E3C637573746F6D5F7365727665725F6C6973743E3737752F5044393462577767646D567963326C76626A30694D5334774969426C626D4E765A476C755A7A3069565652474C546769507A344E436A787A5A584A325A584A6659323975626D566A6446396A623235305A58683049485A6C636E4E7062323439496A63774D6A4977496A3438636D317A58334E6C636E5A6C636E4D76506A777663325679646D567958324E76626D356C5933526659323975644756346444344E43673D3D3C2F637573746F6D5F7365727665725F6C6973743E3C73656C65637465645F637573746F6D5F7365727665725F69643E3C2F73656C65637465645F637573746F6D5F7365727665725F69643E3C637573746F6D5F7365727665725F6163636573733E3737752F5044393462577767646D567963326C76626A30694D5334774969426C626D4E765A476C755A7A3069565652474C546769507A344E436A787962584E6659574E7349485A6C636E4E7062323439496A63774D6A4977496A3438636D317A5832466A5A584D76506A786C626D4669624756666157356F5A584A7064443530636E566C5043396C626D4669624756666157356F5A584A70644434384C334A74633139685932772B44516F3D3C2F637573746F6D5F7365727665725F6163636573733E3C2F73656375726974795F73657474696E67733E0D0A
(PID) Process:(2824) rutserv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters
Operation:writeName:General
Value:
EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0D0A3C67656E6572616C5F73657474696E67732076657273696F6E3D223730323230223E3C706F72743E353635303C2F706F72743E3C686964655F747261795F69636F6E5F706F7075705F6D656E753E747275653C2F686964655F747261795F69636F6E5F706F7075705F6D656E753E3C747261795F6D656E755F686964655F73746F703E747275653C2F747261795F6D656E755F686964655F73746F703E3C6C616E67756167653E4B6F7265616E3C2F6C616E67756167653E3C63616C6C6261636B5F6175746F5F636F6E6E6563743E747275653C2F63616C6C6261636B5F6175746F5F636F6E6E6563743E3C63616C6C6261636B5F636F6E6E6563745F696E74657276616C3E36303C2F63616C6C6261636B5F636F6E6E6563745F696E74657276616C3E3C70617373776F72645F646174613E37656936756A7778394B413D3C2F70617373776F72645F646174613E3C70726F746563745F63616C6C6261636B5F73657474696E67733E747275653C2F70726F746563745F63616C6C6261636B5F73657474696E67733E3C70726F746563745F696E65745F69645F73657474696E67733E747275653C2F70726F746563745F696E65745F69645F73657474696E67733E3C7573655F6C65676163795F636170747572653E66616C73653C2F7573655F6C65676163795F636170747572653E3C646F5F6E6F745F636170747572655F7264703E66616C73653C2F646F5F6E6F745F636170747572655F7264703E3C7573655F69705F765F363E747275653C2F7573655F69705F765F363E3C6C6F675F7573653E66616C73653C2F6C6F675F7573653E3C6C6F675F7573655F77696E646F77733E66616C73653C2F6C6F675F7573655F77696E646F77733E3C636861745F636C69656E745F73657474696E67733E3C2F636861745F636C69656E745F73657474696E67733E3C617574685F6B65795F737472696E673E3C2F617574685F6B65795F737472696E673E3C7369645F69643E34353332342E333630333735353738373C2F7369645F69643E3C6E6F746966795F73686F775F70616E656C3E66616C73653C2F6E6F746966795F73686F775F70616E656C3E3C6E6F746966795F6368616E67655F747261795F69636F6E3E747275653C2F6E6F746966795F6368616E67655F747261795F69636F6E3E3C6E6F746966795F62616C6C6F6E5F68696E743E66616C73653C2F6E6F746966795F62616C6C6F6E5F68696E743E3C6E6F746966795F706C61795F736F756E643E66616C73653C2F6E6F746966795F706C61795F736F756E643E3C6E6F746966795F70616E656C5F783E2D313C2F6E6F746966795F70616E656C5F783E3C6E6F746966795F70616E656C5F793E2D313C2F6E6F746966795F70616E656C5F793E3C70726F78795F73657474696E67733E3737752F5044393462577767646D567963326C76626A30694D5334774969426C626D4E765A476C755A7A3069565652474C546769507A344E436A7877636D39346556397A5A5852306157356E637942325A584A7A61573975505349334D4449794D43492B5048567A5A563977636D39346554356D5957787A5A54777664584E6C5833427962336835506A7877636D3934655639306558426C506A41384C33427962336835583352356347552B504768766333512B5043396F62334E30506A787762334A30506A67774F4441384C334276636E512B5047356C5A575266595856306144356D5957787A5A547776626D566C5A4639686458526F506A787564473173583246316447672B5A6D4673633255384C32353062577866595856306144343864584E6C636D35686257552B5043393163325679626D46745A5434386347467A63336476636D512B5043397759584E7A643239795A4434385A47397459576C75506A77765A47397459576C75506A777663484A7665486C666332563064476C755A334D2B44516F3D3C2F70726F78795F73657474696E67733E3C6164646974696F6E616C3E376432376A7767787761545A335936505044483070413D3D3C2F6164646974696F6E616C3E3C64697361626C655F696E7465726E65745F69643E66616C73653C2F64697361626C655F696E7465726E65745F69643E3C736166655F6D6F64655F7365743E66616C73653C2F736166655F6D6F64655F7365743E3C73686F775F69645F6E6F74696669636174696F6E3E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E3E3C73686F775F69645F6E6F74696669636174696F6E5F726571756573743E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E5F726571756573743E3C73686F775F69645F6E6F74696669636174696F6E5F776974685F74696D656F75743E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E5F776974685F74696D656F75743E3C696E746567726174655F6669726577616C6C5F61745F737461727475703E747275653C2F696E746567726174655F6669726577616C6C5F61745F737461727475703E3C636C6970626F6172645F7472616E736665725F6D6F64653E303C2F636C6970626F6172645F7472616E736665725F6D6F64653E3C636C6F73655F73657373696F6E5F69646C653E66616C73653C2F636C6F73655F73657373696F6E5F69646C653E3C636C6F73655F73657373696F6E5F69646C655F696E74657276616C3E36303C2F636C6F73655F73657373696F6E5F69646C655F696E74657276616C3E3C73686F775F636F6E6E656374696F6E5F616C6572745F666F725F616C6C3E66616C73653C2F73686F775F636F6E6E656374696F6E5F616C6572745F666F725F616C6C3E3C2F67656E6572616C5F73657474696E67733E0D0A
(PID) Process:(2824) rutserv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters
Operation:writeName:InternetId
Value:
EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0D0A3C726D735F696E7465726E65745F69645F73657474696E67732076657273696F6E3D223730323230223E3C696E7465726E65745F69643E3C2F696E7465726E65745F69643E3C7573655F696E65745F636F6E6E656374696F6E3E66616C73653C2F7573655F696E65745F636F6E6E656374696F6E3E3C696E65745F7365727665723E3C2F696E65745F7365727665723E3C7573655F637573746F6D5F696E65745F7365727665723E66616C73653C2F7573655F637573746F6D5F696E65745F7365727665723E3C696E65745F69645F706F72743E353635353C2F696E65745F69645F706F72743E3C7573655F696E65745F69645F697076363E66616C73653C2F7573655F696E65745F69645F697076363E3C696E65745F69645F7573655F70696E3E66616C73653C2F696E65745F69645F7573655F70696E3E3C696E65745F69645F70696E3E3C2F696E65745F69645F70696E3E3C2F726D735F696E7465726E65745F69645F73657474696E67733E0D0A
(PID) Process:(2824) rutserv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters
Operation:writeName:Certificates
Value:
EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0D0A3C636572746966696374655F73657474696E67732076657273696F6E3D223730323230223E3C63657274696669636174653E3C2F63657274696669636174653E3C707269766174655F6B65793E3C2F707269766174655F6B65793E3C2F636572746966696374655F73657474696E67733E0D0A
Executable files
0
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
246492192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exeC:\Users\admin\AppData\Local\Temp\Exel.msi
MD5:
SHA256:
2824rutserv.exeC:\ProgramData\Remote Utilities\Logs\rut_log_2024-02.htmlhtml
MD5:303A5D51CB543D9F2084CE5598A2B9D8
SHA256:9CE7FD59F448F196B00512C6430089A569C998F7BCAC0F4B8CFE7B51B7C9589B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
352
svchost.exe
224.0.0.252:5355
unknown
2824
rutserv.exe
64.20.61.146:5655
id72.remoteutilities.com
IS-AS-1
US
unknown
2824
rutserv.exe
77.105.132.70:5651
Plus Telecom LLC
RU
malicious
2824
rutserv.exe
77.105.132.70:80
Plus Telecom LLC
RU
malicious
2824
rutserv.exe
101.99.94.54:80
Verdina Ltd.
MY
unknown
2824
rutserv.exe
185.70.104.90:5651
Hostkey B.v.
RU
malicious
2824
rutserv.exe
101.99.94.54:5651
Verdina Ltd.
MY
unknown
2824
rutserv.exe
101.99.94.54:465
Verdina Ltd.
MY
unknown

DNS requests

Domain
IP
Reputation
id72.remoteutilities.com
  • 64.20.61.146
unknown

Threats

No threats detected
Process
Message
rutserv.exe
TMainService.Start
rutserv.exe
MSG_KEEP_ALIVE
rutserv.exe
02-02-2024_08:39:32:091#T:MSG_KEEP_ALIVE
rutserv.exe
MSG_KEEP_ALIVE
rutserv.exe
02-02-2024_08:40:00:435#T:MSG_KEEP_ALIVE
rutserv.exe
MSG_KEEP_ALIVE
rutserv.exe
02-02-2024_08:40:30:841#T:MSG_KEEP_ALIVE