| File name: | 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe |
| Full analysis: | https://app.any.run/tasks/316d9910-1edd-4786-9216-c258fd55f479 |
| Verdict: | Malicious activity |
| Threats: | Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links. |
| Analysis date: | February 02, 2024, 08:38:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows |
| MD5: | 075D6C122274CB9226521D3CD298F2F2 |
| SHA1: | 6F54D70F39FA28596EF90BFCB0C14278B016DB1B |
| SHA256: | 92192AF947017C20AD861FAF4459FB705E63F7083B34C77C1727891B88091573 |
| SSDEEP: | 196608:+GNqIkHtux5ghkb4MK9vY0DxgbUZPs7YHdmkftsEW7T4/b:+Qrwkx5EA4d9vH9dGYHZK7T4j |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2023:12:13 15:03:01+01:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.33 |
| CodeSize: | 288768 |
| InitializedDataSize: | 223744 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x32dc0 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 308 | "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" -firewall | C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe | — | rutserv.exe | |||||||||||
User: SYSTEM Company: Remote Utilities Pty (Cy) Ltd. Integrity Level: SYSTEM Description: Remote Utilities - Host Exit code: 0 Version: 7.2.2.0 Modules
| |||||||||||||||
| 1688 | "C:\Users\admin\AppData\Local\Temp\92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe" | C:\Users\admin\AppData\Local\Temp\92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2372 | "C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe" | C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe | — | rutserv.exe | |||||||||||
User: SYSTEM Company: Remote Utilities Pty (Cy) Ltd. Integrity Level: SYSTEM Description: Remote Utilities - Host Exit code: 0 Version: 7.2.2.0 Modules
| |||||||||||||||
| 2464 | "C:\Users\admin\AppData\Local\Temp\92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe" | C:\Users\admin\AppData\Local\Temp\92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2500 | "C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe" /tray | C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe | — | rfusclient.exe | |||||||||||
User: admin Company: Remote Utilities Pty (Cy) Ltd. Integrity Level: MEDIUM Description: Remote Utilities - Host Exit code: 0 Version: 7.2.2.0 Modules
| |||||||||||||||
| 2812 | "C:\Windows\System32\msiexec.exe" /i Exel.msi /qn | C:\Windows\System32\msiexec.exe | — | 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2824 | "C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe" -service | C:\Program Files (x86)\Remote Utilities - Host\rutserv.exe | services.exe | ||||||||||||
User: SYSTEM Company: Remote Utilities Pty (Cy) Ltd. Integrity Level: SYSTEM Description: Remote Utilities - Host Exit code: 0 Version: 7.2.2.0 Modules
| |||||||||||||||
| 2984 | "C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe" /tray | C:\Program Files (x86)\Remote Utilities - Host\rfusclient.exe | — | rutserv.exe | |||||||||||
User: admin Company: Remote Utilities Pty (Cy) Ltd. Integrity Level: MEDIUM Description: Remote Utilities - Host Exit code: 0 Version: 7.2.2.0 Modules
| |||||||||||||||
| (PID) Process: | (2464) 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2464) 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2464) 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2464) 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2824) rutserv.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\Remote Utilities Host Installer |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2824) rutserv.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters |
| Operation: | write | Name: | General |
Value: EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0D0A3C67656E6572616C5F73657474696E67732076657273696F6E3D223730323230223E3C706F72743E353635303C2F706F72743E3C686964655F747261795F69636F6E5F706F7075705F6D656E753E747275653C2F686964655F747261795F69636F6E5F706F7075705F6D656E753E3C747261795F6D656E755F686964655F73746F703E747275653C2F747261795F6D656E755F686964655F73746F703E3C6C616E67756167653E4B6F7265616E3C2F6C616E67756167653E3C63616C6C6261636B5F6175746F5F636F6E6E6563743E747275653C2F63616C6C6261636B5F6175746F5F636F6E6E6563743E3C63616C6C6261636B5F636F6E6E6563745F696E74657276616C3E36303C2F63616C6C6261636B5F636F6E6E6563745F696E74657276616C3E3C70617373776F72645F646174613E37656936756A7778394B413D3C2F70617373776F72645F646174613E3C70726F746563745F63616C6C6261636B5F73657474696E67733E747275653C2F70726F746563745F63616C6C6261636B5F73657474696E67733E3C70726F746563745F696E65745F69645F73657474696E67733E747275653C2F70726F746563745F696E65745F69645F73657474696E67733E3C7573655F6C65676163795F636170747572653E66616C73653C2F7573655F6C65676163795F636170747572653E3C646F5F6E6F745F636170747572655F7264703E66616C73653C2F646F5F6E6F745F636170747572655F7264703E3C7573655F69705F765F363E747275653C2F7573655F69705F765F363E3C6C6F675F7573653E66616C73653C2F6C6F675F7573653E3C6C6F675F7573655F77696E646F77733E66616C73653C2F6C6F675F7573655F77696E646F77733E3C636861745F636C69656E745F73657474696E67733E3C2F636861745F636C69656E745F73657474696E67733E3C617574685F6B65795F737472696E673E3C2F617574685F6B65795F737472696E673E3C7369645F69643E3C2F7369645F69643E3C6E6F746966795F73686F775F70616E656C3E66616C73653C2F6E6F746966795F73686F775F70616E656C3E3C6E6F746966795F6368616E67655F747261795F69636F6E3E747275653C2F6E6F746966795F6368616E67655F747261795F69636F6E3E3C6E6F746966795F62616C6C6F6E5F68696E743E66616C73653C2F6E6F746966795F62616C6C6F6E5F68696E743E3C6E6F746966795F706C61795F736F756E643E66616C73653C2F6E6F746966795F706C61795F736F756E643E3C6E6F746966795F70616E656C5F783E2D313C2F6E6F746966795F70616E656C5F783E3C6E6F746966795F70616E656C5F793E2D313C2F6E6F746966795F70616E656C5F793E3C70726F78795F73657474696E67733E3737752F5044393462577767646D567963326C76626A30694D5334774969426C626D4E765A476C755A7A3069565652474C546769507A344E436A7877636D39346556397A5A5852306157356E637942325A584A7A61573975505349334D4449794D43492B5048567A5A563977636D39346554356D5957787A5A54777664584E6C5833427962336835506A7877636D3934655639306558426C506A41384C33427962336835583352356347552B504768766333512B5043396F62334E30506A787762334A30506A67774F4441384C334276636E512B5047356C5A575266595856306144356D5957787A5A547776626D566C5A4639686458526F506A787564473173583246316447672B5A6D4673633255384C32353062577866595856306144343864584E6C636D35686257552B5043393163325679626D46745A5434386347467A63336476636D512B5043397759584E7A643239795A4434385A47397459576C75506A77765A47397459576C75506A777663484A7665486C666332563064476C755A334D2B44516F3D3C2F70726F78795F73657474696E67733E3C6164646974696F6E616C3E376432376A7767787761545A335936505044483070413D3D3C2F6164646974696F6E616C3E3C64697361626C655F696E7465726E65745F69643E66616C73653C2F64697361626C655F696E7465726E65745F69643E3C736166655F6D6F64655F7365743E66616C73653C2F736166655F6D6F64655F7365743E3C73686F775F69645F6E6F74696669636174696F6E3E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E3E3C73686F775F69645F6E6F74696669636174696F6E5F726571756573743E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E5F726571756573743E3C73686F775F69645F6E6F74696669636174696F6E5F776974685F74696D656F75743E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E5F776974685F74696D656F75743E3C696E746567726174655F6669726577616C6C5F61745F737461727475703E747275653C2F696E746567726174655F6669726577616C6C5F61745F737461727475703E3C636C6970626F6172645F7472616E736665725F6D6F64653E303C2F636C6970626F6172645F7472616E736665725F6D6F64653E3C636C6F73655F73657373696F6E5F69646C653E66616C73653C2F636C6F73655F73657373696F6E5F69646C653E3C636C6F73655F73657373696F6E5F69646C655F696E74657276616C3E36303C2F636C6F73655F73657373696F6E5F69646C655F696E74657276616C3E3C73686F775F636F6E6E656374696F6E5F616C6572745F666F725F616C6C3E66616C73653C2F73686F775F636F6E6E656374696F6E5F616C6572745F666F725F616C6C3E3C2F67656E6572616C5F73657474696E67733E0D0A | |||
| (PID) Process: | (2824) rutserv.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters |
| Operation: | write | Name: | Security |
Value: EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0D0A3C73656375726974795F73657474696E67732076657273696F6E3D223730323230223E3C77696E646F77735F73656375726974793E3C2F77696E646F77735F73656375726974793E3C73696E676C655F70617373776F72645F686173683E37453443434233393036324638464435324544304135303438393437364633314135423331313637423035394637314542363937383641314641394430333145464633304245313231354646343438373336364641363344364233434239343637433538423241464531364432384433463534334639464337413538323737443C2F73696E676C655F70617373776F72645F686173683E3C6D795F757365725F6163636573735F6C6973743E3C757365725F6163636573735F6C6973742F3E3C2F6D795F757365725F6163636573735F6C6973743E3C69705F66696C7465725F747970653E323C2F69705F66696C7465725F747970653E3C69705F626C61636B5F6C6973743E3C2F69705F626C61636B5F6C6973743E3C69705F77686974655F6C6973743E3C2F69705F77686974655F6C6973743E3C617574685F6B696E643E313C2F617574685F6B696E643E3C6F74705F656E61626C653E66616C73653C2F6F74705F656E61626C653E3C6F74705F707269766174655F6B65793E3C2F6F74705F707269766174655F6B65793E3C6F74705F71725F7365637265743E3C2F6F74705F71725F7365637265743E3C757365725F7065726D697373696F6E735F61736B3E66616C73653C2F757365725F7065726D697373696F6E735F61736B3E3C757365725F7065726D697373696F6E735F696E74657276616C3E31303030303C2F757365725F7065726D697373696F6E735F696E74657276616C3E3C757365725F7065726D697373696F6E735F616C6C6F775F64656661756C743E66616C73653C2F757365725F7065726D697373696F6E735F616C6C6F775F64656661756C743E3C757365725F7065726D697373696F6E735F6F6E6C795F69665F757365725F6C6F676765645F6F6E3E66616C73653C2F757365725F7065726D697373696F6E735F6F6E6C795F69665F757365725F6C6F676765645F6F6E3E3C64697361626C655F72656D6F74655F636F6E74726F6C3E66616C73653C2F64697361626C655F72656D6F74655F636F6E74726F6C3E3C64697361626C655F72656D6F74655F73637265656E3E66616C73653C2F64697361626C655F72656D6F74655F73637265656E3E3C64697361626C655F66696C655F7472616E736665723E66616C73653C2F64697361626C655F66696C655F7472616E736665723E3C64697361626C655F72656469726563743E66616C73653C2F64697361626C655F72656469726563743E3C64697361626C655F74656C6E65743E66616C73653C2F64697361626C655F74656C6E65743E3C64697361626C655F72656D6F74655F657865637574653E66616C73653C2F64697361626C655F72656D6F74655F657865637574653E3C64697361626C655F7461736B5F6D616E616765723E66616C73653C2F64697361626C655F7461736B5F6D616E616765723E3C64697361626C655F73687574646F776E3E66616C73653C2F64697361626C655F73687574646F776E3E3C64697361626C655F72656D6F74655F757067726164653E66616C73653C2F64697361626C655F72656D6F74655F757067726164653E3C64697361626C655F707265766965775F636170747572653E66616C73653C2F64697361626C655F707265766965775F636170747572653E3C64697361626C655F6465766963655F6D616E616765723E66616C73653C2F64697361626C655F6465766963655F6D616E616765723E3C64697361626C655F636861743E747275653C2F64697361626C655F636861743E3C64697361626C655F73637265656E5F7265636F72643E66616C73653C2F64697361626C655F73637265656E5F7265636F72643E3C64697361626C655F61765F636170747572653E66616C73653C2F64697361626C655F61765F636170747572653E3C64697361626C655F73656E645F6D6573736167653E747275653C2F64697361626C655F73656E645F6D6573736167653E3C64697361626C655F72656769737472793E66616C73653C2F64697361626C655F72656769737472793E3C64697361626C655F61765F636861743E747275653C2F64697361626C655F61765F636861743E3C64697361626C655F72656D6F74655F73657474696E67733E66616C73653C2F64697361626C655F72656D6F74655F73657474696E67733E3C64697361626C655F72656D6F74655F7072696E74696E673E747275653C2F64697361626C655F72656D6F74655F7072696E74696E673E3C64697361626C655F7264703E66616C73653C2F64697361626C655F7264703E3C637573746F6D5F7365727665725F6C6973743E3737752F5044393462577767646D567963326C76626A30694D5334774969426C626D4E765A476C755A7A3069565652474C546769507A344E436A787A5A584A325A584A6659323975626D566A6446396A623235305A58683049485A6C636E4E7062323439496A63774D6A4977496A3438636D317A58334E6C636E5A6C636E4D76506A777663325679646D567958324E76626D356C5933526659323975644756346444344E43673D3D3C2F637573746F6D5F7365727665725F6C6973743E3C73656C65637465645F637573746F6D5F7365727665725F69643E3C2F73656C65637465645F637573746F6D5F7365727665725F69643E3C637573746F6D5F7365727665725F6163636573733E3737752F5044393462577767646D567963326C76626A30694D5334774969426C626D4E765A476C755A7A3069565652474C546769507A344E436A787962584E6659574E7349485A6C636E4E7062323439496A63774D6A4977496A3438636D317A5832466A5A584D76506A786C626D4669624756666157356F5A584A7064443530636E566C5043396C626D4669624756666157356F5A584A70644434384C334A74633139685932772B44516F3D3C2F637573746F6D5F7365727665725F6163636573733E3C2F73656375726974795F73657474696E67733E0D0A | |||
| (PID) Process: | (2824) rutserv.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters |
| Operation: | write | Name: | General |
Value: EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0D0A3C67656E6572616C5F73657474696E67732076657273696F6E3D223730323230223E3C706F72743E353635303C2F706F72743E3C686964655F747261795F69636F6E5F706F7075705F6D656E753E747275653C2F686964655F747261795F69636F6E5F706F7075705F6D656E753E3C747261795F6D656E755F686964655F73746F703E747275653C2F747261795F6D656E755F686964655F73746F703E3C6C616E67756167653E4B6F7265616E3C2F6C616E67756167653E3C63616C6C6261636B5F6175746F5F636F6E6E6563743E747275653C2F63616C6C6261636B5F6175746F5F636F6E6E6563743E3C63616C6C6261636B5F636F6E6E6563745F696E74657276616C3E36303C2F63616C6C6261636B5F636F6E6E6563745F696E74657276616C3E3C70617373776F72645F646174613E37656936756A7778394B413D3C2F70617373776F72645F646174613E3C70726F746563745F63616C6C6261636B5F73657474696E67733E747275653C2F70726F746563745F63616C6C6261636B5F73657474696E67733E3C70726F746563745F696E65745F69645F73657474696E67733E747275653C2F70726F746563745F696E65745F69645F73657474696E67733E3C7573655F6C65676163795F636170747572653E66616C73653C2F7573655F6C65676163795F636170747572653E3C646F5F6E6F745F636170747572655F7264703E66616C73653C2F646F5F6E6F745F636170747572655F7264703E3C7573655F69705F765F363E747275653C2F7573655F69705F765F363E3C6C6F675F7573653E66616C73653C2F6C6F675F7573653E3C6C6F675F7573655F77696E646F77733E66616C73653C2F6C6F675F7573655F77696E646F77733E3C636861745F636C69656E745F73657474696E67733E3C2F636861745F636C69656E745F73657474696E67733E3C617574685F6B65795F737472696E673E3C2F617574685F6B65795F737472696E673E3C7369645F69643E34353332342E333630333735353738373C2F7369645F69643E3C6E6F746966795F73686F775F70616E656C3E66616C73653C2F6E6F746966795F73686F775F70616E656C3E3C6E6F746966795F6368616E67655F747261795F69636F6E3E747275653C2F6E6F746966795F6368616E67655F747261795F69636F6E3E3C6E6F746966795F62616C6C6F6E5F68696E743E66616C73653C2F6E6F746966795F62616C6C6F6E5F68696E743E3C6E6F746966795F706C61795F736F756E643E66616C73653C2F6E6F746966795F706C61795F736F756E643E3C6E6F746966795F70616E656C5F783E2D313C2F6E6F746966795F70616E656C5F783E3C6E6F746966795F70616E656C5F793E2D313C2F6E6F746966795F70616E656C5F793E3C70726F78795F73657474696E67733E3737752F5044393462577767646D567963326C76626A30694D5334774969426C626D4E765A476C755A7A3069565652474C546769507A344E436A7877636D39346556397A5A5852306157356E637942325A584A7A61573975505349334D4449794D43492B5048567A5A563977636D39346554356D5957787A5A54777664584E6C5833427962336835506A7877636D3934655639306558426C506A41384C33427962336835583352356347552B504768766333512B5043396F62334E30506A787762334A30506A67774F4441384C334276636E512B5047356C5A575266595856306144356D5957787A5A547776626D566C5A4639686458526F506A787564473173583246316447672B5A6D4673633255384C32353062577866595856306144343864584E6C636D35686257552B5043393163325679626D46745A5434386347467A63336476636D512B5043397759584E7A643239795A4434385A47397459576C75506A77765A47397459576C75506A777663484A7665486C666332563064476C755A334D2B44516F3D3C2F70726F78795F73657474696E67733E3C6164646974696F6E616C3E376432376A7767787761545A335936505044483070413D3D3C2F6164646974696F6E616C3E3C64697361626C655F696E7465726E65745F69643E66616C73653C2F64697361626C655F696E7465726E65745F69643E3C736166655F6D6F64655F7365743E66616C73653C2F736166655F6D6F64655F7365743E3C73686F775F69645F6E6F74696669636174696F6E3E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E3E3C73686F775F69645F6E6F74696669636174696F6E5F726571756573743E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E5F726571756573743E3C73686F775F69645F6E6F74696669636174696F6E5F776974685F74696D656F75743E66616C73653C2F73686F775F69645F6E6F74696669636174696F6E5F776974685F74696D656F75743E3C696E746567726174655F6669726577616C6C5F61745F737461727475703E747275653C2F696E746567726174655F6669726577616C6C5F61745F737461727475703E3C636C6970626F6172645F7472616E736665725F6D6F64653E303C2F636C6970626F6172645F7472616E736665725F6D6F64653E3C636C6F73655F73657373696F6E5F69646C653E66616C73653C2F636C6F73655F73657373696F6E5F69646C653E3C636C6F73655F73657373696F6E5F69646C655F696E74657276616C3E36303C2F636C6F73655F73657373696F6E5F69646C655F696E74657276616C3E3C73686F775F636F6E6E656374696F6E5F616C6572745F666F725F616C6C3E66616C73653C2F73686F775F636F6E6E656374696F6E5F616C6572745F666F725F616C6C3E3C2F67656E6572616C5F73657474696E67733E0D0A | |||
| (PID) Process: | (2824) rutserv.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters |
| Operation: | write | Name: | InternetId |
Value: EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0D0A3C726D735F696E7465726E65745F69645F73657474696E67732076657273696F6E3D223730323230223E3C696E7465726E65745F69643E3C2F696E7465726E65745F69643E3C7573655F696E65745F636F6E6E656374696F6E3E66616C73653C2F7573655F696E65745F636F6E6E656374696F6E3E3C696E65745F7365727665723E3C2F696E65745F7365727665723E3C7573655F637573746F6D5F696E65745F7365727665723E66616C73653C2F7573655F637573746F6D5F696E65745F7365727665723E3C696E65745F69645F706F72743E353635353C2F696E65745F69645F706F72743E3C7573655F696E65745F69645F697076363E66616C73653C2F7573655F696E65745F69645F697076363E3C696E65745F69645F7573655F70696E3E66616C73653C2F696E65745F69645F7573655F70696E3E3C696E65745F69645F70696E3E3C2F696E65745F69645F70696E3E3C2F726D735F696E7465726E65745F69645F73657474696E67733E0D0A | |||
| (PID) Process: | (2824) rutserv.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Usoris\Remote Utilities Host\Host\Parameters |
| Operation: | write | Name: | Certificates |
Value: EFBBBF3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D38223F3E0D0A3C636572746966696374655F73657474696E67732076657273696F6E3D223730323230223E3C63657274696669636174653E3C2F63657274696669636174653E3C707269766174655F6B65793E3C2F707269766174655F6B65793E3C2F636572746966696374655F73657474696E67733E0D0A | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2464 | 92192af947017c20ad861faf4459fb705e63f7083b34c77c1727891b88091573.exe | C:\Users\admin\AppData\Local\Temp\Exel.msi | — | |
MD5:— | SHA256:— | |||
| 2824 | rutserv.exe | C:\ProgramData\Remote Utilities\Logs\rut_log_2024-02.html | html | |
MD5:303A5D51CB543D9F2084CE5598A2B9D8 | SHA256:9CE7FD59F448F196B00512C6430089A569C998F7BCAC0F4B8CFE7B51B7C9589B | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
352 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2824 | rutserv.exe | 64.20.61.146:5655 | id72.remoteutilities.com | IS-AS-1 | US | unknown |
2824 | rutserv.exe | 77.105.132.70:5651 | — | Plus Telecom LLC | RU | malicious |
2824 | rutserv.exe | 77.105.132.70:80 | — | Plus Telecom LLC | RU | malicious |
2824 | rutserv.exe | 101.99.94.54:80 | — | Verdina Ltd. | MY | unknown |
2824 | rutserv.exe | 185.70.104.90:5651 | — | Hostkey B.v. | RU | malicious |
2824 | rutserv.exe | 101.99.94.54:5651 | — | Verdina Ltd. | MY | unknown |
2824 | rutserv.exe | 101.99.94.54:465 | — | Verdina Ltd. | MY | unknown |
Domain | IP | Reputation |
|---|---|---|
id72.remoteutilities.com |
| unknown |
Process | Message |
|---|---|
rutserv.exe | TMainService.Start |
rutserv.exe | MSG_KEEP_ALIVE |
rutserv.exe | 02-02-2024_08:39:32:091#T:MSG_KEEP_ALIVE |
rutserv.exe | MSG_KEEP_ALIVE |
rutserv.exe | 02-02-2024_08:40:00:435#T:MSG_KEEP_ALIVE |
rutserv.exe | MSG_KEEP_ALIVE |
rutserv.exe | 02-02-2024_08:40:30:841#T:MSG_KEEP_ALIVE |