File name:

0061eecc_abc.exe

Full analysis: https://app.any.run/tasks/7f900a1b-78f9-4d03-95af-e2277d1f7876
Verdict: Malicious activity
Analysis date: October 03, 2025, 17:17:31
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
anti-evasion
logmeinrescue
rmm-tool
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

142C4426738BD84D17CB483B8605FE56

SHA1:

9CA15F170271A7CF3021ECF2AE354DB2E126132A

SHA256:

AB0F6022844C74C73CD8A8EB046FB95A1940E41DAB33F2F37ACCA15EEC176FE5

SSDEEP:

196608:D1LumI69j3X2RKIF2HnwHPtnnU3TUJE7Eza:1Tj4XF2HwVnaTUJ0Eza

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 332)
    • Executable content was dropped or overwritten

      • 0061eecc_abc.exe (PID: 3040)
      • GoToResolveTools64.exe (PID: 7588)
      • GoToResolveUnattended.exe (PID: 7552)
    • Starts CMD.EXE for commands execution

      • 0061eecc_abc.exe (PID: 3040)
    • Reads security settings of Internet Explorer

      • GoToResolveUnattended.exe (PID: 5460)
      • GoToResolveProcessChecker.exe (PID: 8144)
      • GoToResolveUnattendedUi.exe (PID: 6512)
    • Executes as Windows Service

      • GoToResolveProcessChecker.exe (PID: 8068)
    • Executing commands from ".cmd" file

      • 0061eecc_abc.exe (PID: 3040)
    • The process checks if it is being run in the virtual environment

      • GoToResolveQuickView.exe (PID: 7560)
    • Reads the BIOS version

      • GoToResolveQuickView.exe (PID: 7560)
    • Creates/Modifies COM task schedule object

      • GoToResolveUnattended.exe (PID: 7552)
    • There is functionality for taking screenshot (YARA)

      • GoToResolveUnattended.exe (PID: 7552)
      • GoToResolveProcessChecker.exe (PID: 8068)
      • GoToResolveLoggerProcess.exe (PID: 6128)
      • GoToResolveFileManager.exe (PID: 5096)
      • GoToResolveExternalModuleHandler.exe (PID: 1536)
    • There is functionality for communication over UDP network (YARA)

      • GoToResolveUnattended.exe (PID: 7552)
      • GoToResolveProcessChecker.exe (PID: 8068)
      • GoToResolveLoggerProcess.exe (PID: 6128)
      • GoToResolveFileManager.exe (PID: 5096)
      • GoToResolveExternalModuleHandler.exe (PID: 1536)
    • LOGMEINRESCUE mutex has been found

      • GoToResolveUnattended.exe (PID: 7552)
  • INFO

    • Creates files or folders in the user directory

      • 0061eecc_abc.exe (PID: 3040)
      • GoToResolveUnattended.exe (PID: 5460)
      • BackgroundTransferHost.exe (PID: 9736)
    • Checks supported languages

      • 0061eecc_abc.exe (PID: 3040)
      • GoToResolveUnattended.exe (PID: 5460)
      • GoToResolveCrashHandler.exe (PID: 7744)
      • GoToResolveTools64.exe (PID: 7588)
      • drvinst.exe (PID: 7360)
      • GoToResolveProcessChecker.exe (PID: 8144)
      • GoToResolveCrashHandler.exe (PID: 2364)
      • GoToResolveProcessChecker.exe (PID: 8068)
      • GoToResolveCrashHandler.exe (PID: 2332)
      • GoToResolveLoggerProcess.exe (PID: 6128)
      • GoToResolveExternalModuleHandler.exe (PID: 1536)
      • GoToResolveUnattended.exe (PID: 7552)
      • GoToResolveFileManager.exe (PID: 5096)
      • GoToResolveServiceManager.exe (PID: 8004)
      • GoToResolveTerminal.exe (PID: 2176)
      • GoToResolveUnattendedUi.exe (PID: 6512)
      • GoToResolveRemoteControl.exe (PID: 2836)
      • GoToResolveQuickView.exe (PID: 7560)
      • GoToResolveRegistryEditor.exe (PID: 5836)
      • GoToResolveNetworkChecker.exe (PID: 5792)
      • GoToResolveCrashHandler.exe (PID: 2648)
      • GoToResolveCrashHandler.exe (PID: 2368)
      • GoToResolveCrashHandler.exe (PID: 8216)
      • GoToResolveCrashHandler.exe (PID: 8328)
      • GoToResolveCrashHandler.exe (PID: 8372)
      • GoToResolveCrashHandler.exe (PID: 8484)
      • GoToResolveCrashHandler.exe (PID: 8436)
      • GoToResolveCrashHandler.exe (PID: 8504)
      • GoToResolveCrashHandler.exe (PID: 8568)
      • GoToResolveCrashHandler.exe (PID: 8628)
    • Creates files in the program directory

      • 0061eecc_abc.exe (PID: 3040)
      • GoToResolveTools64.exe (PID: 7588)
      • GoToResolveCrashHandler.exe (PID: 7744)
      • GoToResolveUnattended.exe (PID: 5460)
      • GoToResolveProcessChecker.exe (PID: 8144)
      • GoToResolveCrashHandler.exe (PID: 2364)
      • GoToResolveProcessChecker.exe (PID: 8068)
      • GoToResolveUnattended.exe (PID: 7552)
      • GoToResolveCrashHandler.exe (PID: 2332)
      • GoToResolveLoggerProcess.exe (PID: 6128)
      • GoToResolveCrashHandler.exe (PID: 2648)
      • GoToResolveExternalModuleHandler.exe (PID: 1536)
      • GoToResolveCrashHandler.exe (PID: 2368)
      • GoToResolveQuickView.exe (PID: 7560)
      • GoToResolveCrashHandler.exe (PID: 8216)
      • GoToResolveFileManager.exe (PID: 5096)
      • GoToResolveCrashHandler.exe (PID: 8328)
      • GoToResolveTerminal.exe (PID: 2176)
      • GoToResolveCrashHandler.exe (PID: 8372)
      • GoToResolveUnattendedUi.exe (PID: 6512)
      • GoToResolveRemoteControl.exe (PID: 2836)
      • GoToResolveNetworkChecker.exe (PID: 5792)
      • GoToResolveCrashHandler.exe (PID: 8436)
      • GoToResolveCrashHandler.exe (PID: 8484)
      • GoToResolveCrashHandler.exe (PID: 8628)
      • GoToResolveCrashHandler.exe (PID: 8504)
      • GoToResolveCrashHandler.exe (PID: 8568)
      • GoToResolveRegistryEditor.exe (PID: 5836)
      • GoToResolveServiceManager.exe (PID: 8004)
    • Reads Environment values

      • GoToResolveTools64.exe (PID: 7588)
      • GoToResolveUnattended.exe (PID: 5460)
      • GoToResolveUnattended.exe (PID: 7552)
      • GoToResolveExternalModuleHandler.exe (PID: 1536)
      • GoToResolveRemoteControl.exe (PID: 2836)
      • GoToResolveQuickView.exe (PID: 7560)
    • The sample compiled with english language support

      • 0061eecc_abc.exe (PID: 3040)
      • GoToResolveTools64.exe (PID: 7588)
      • drvinst.exe (PID: 7360)
    • Reads the computer name

      • 0061eecc_abc.exe (PID: 3040)
      • GoToResolveTools64.exe (PID: 7588)
      • GoToResolveUnattended.exe (PID: 5460)
      • drvinst.exe (PID: 7360)
      • GoToResolveProcessChecker.exe (PID: 8068)
      • GoToResolveProcessChecker.exe (PID: 8144)
      • GoToResolveUnattended.exe (PID: 7552)
      • GoToResolveLoggerProcess.exe (PID: 6128)
      • GoToResolveExternalModuleHandler.exe (PID: 1536)
      • GoToResolveFileManager.exe (PID: 5096)
      • GoToResolveQuickView.exe (PID: 7560)
      • GoToResolveTerminal.exe (PID: 2176)
      • GoToResolveRegistryEditor.exe (PID: 5836)
      • GoToResolveServiceManager.exe (PID: 8004)
      • GoToResolveRemoteControl.exe (PID: 2836)
      • GoToResolveNetworkChecker.exe (PID: 5792)
      • GoToResolveUnattendedUi.exe (PID: 6512)
    • Reads the machine GUID from the registry

      • GoToResolveUnattended.exe (PID: 5460)
      • drvinst.exe (PID: 7360)
      • GoToResolveProcessChecker.exe (PID: 8144)
      • GoToResolveProcessChecker.exe (PID: 8068)
      • GoToResolveUnattended.exe (PID: 7552)
      • GoToResolveLoggerProcess.exe (PID: 6128)
      • GoToResolveExternalModuleHandler.exe (PID: 1536)
      • GoToResolveQuickView.exe (PID: 7560)
      • GoToResolveFileManager.exe (PID: 5096)
      • GoToResolveNetworkChecker.exe (PID: 5792)
      • GoToResolveTerminal.exe (PID: 2176)
      • GoToResolveRegistryEditor.exe (PID: 5836)
      • GoToResolveUnattendedUi.exe (PID: 6512)
      • GoToResolveServiceManager.exe (PID: 8004)
      • GoToResolveRemoteControl.exe (PID: 2836)
    • Reads the software policy settings

      • GoToResolveUnattended.exe (PID: 5460)
      • drvinst.exe (PID: 7360)
      • GoToResolveProcessChecker.exe (PID: 8144)
      • GoToResolveProcessChecker.exe (PID: 8068)
      • GoToResolveUnattended.exe (PID: 7552)
      • GoToResolveLoggerProcess.exe (PID: 6128)
      • GoToResolveExternalModuleHandler.exe (PID: 1536)
      • GoToResolveQuickView.exe (PID: 7560)
      • GoToResolveTerminal.exe (PID: 2176)
      • GoToResolveFileManager.exe (PID: 5096)
      • GoToResolveRegistryEditor.exe (PID: 5836)
      • GoToResolveRemoteControl.exe (PID: 2836)
      • GoToResolveServiceManager.exe (PID: 8004)
      • GoToResolveNetworkChecker.exe (PID: 5792)
      • GoToResolveUnattendedUi.exe (PID: 6512)
      • BackgroundTransferHost.exe (PID: 9736)
      • slui.exe (PID: 9624)
    • Reads CPU info

      • GoToResolveTools64.exe (PID: 7588)
      • GoToResolveUnattended.exe (PID: 5460)
      • GoToResolveUnattended.exe (PID: 7552)
      • GoToResolveRemoteControl.exe (PID: 2836)
      • GoToResolveQuickView.exe (PID: 7560)
    • Create files in a temporary directory

      • GoToResolveTools64.exe (PID: 7588)
    • Checks proxy server information

      • GoToResolveUnattended.exe (PID: 5460)
      • BackgroundTransferHost.exe (PID: 9736)
      • slui.exe (PID: 9624)
    • Process checks computer location settings

      • GoToResolveUnattended.exe (PID: 5460)
    • Creates a software uninstall entry

      • GoToResolveProcessChecker.exe (PID: 8144)
      • GoToResolveProcessChecker.exe (PID: 8068)
      • 0061eecc_abc.exe (PID: 3040)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 9536)
      • BackgroundTransferHost.exe (PID: 9736)
      • BackgroundTransferHost.exe (PID: 9912)
      • BackgroundTransferHost.exe (PID: 10128)
      • BackgroundTransferHost.exe (PID: 9068)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:09:02 09:05:13+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.34
CodeSize: 1144320
InitializedDataSize: 23277568
UninitializedDataSize: -
EntryPoint: 0xdca30
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.27.1.2836
ProductVersionNumber: 1.27.1.2836
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (0009)
CharacterSet: Unicode
CompanyName: GoTo, Inc.
FileDescription: LogMeIn Resolve
FileVersion: 1.27.1.2836
InternalName: GoToResolveUnattendedUpdater.exe
LegalCopyright: Copyright © 2016-2025 GoTo, Inc. US patents pending.
OriginalFileName: GoToResolveUnattendedUpdater.exe
ProductName: GoTo Resolve
ProductVersion: 1.27.1.2836
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
209
Monitored processes
41
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
332cmd.exe /S /C ""C:\Users\admin\Desktop\0061eecc_abc.exe.cmd" "C:\Users\admin\Desktop\0061eecc_abc.exe""C:\Windows\SysWOW64\cmd.exe0061eecc_abc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1536"C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveExternalModuleHandler.exe" -InstallationId 8hnB1hW42B -CompanyId 2829436394331576853 -publickey ad6f62556f498789e1e5df37ee22b5995ee0a024029f5b59bc56eb9566f48138 -LogLevel 2 -Environment ProductionC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveExternalModuleHandler.exe
GoToResolveUnattended.exe
User:
SYSTEM
Company:
GoTo, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Resolve
Version:
1.27.1.2836
Modules
Images
c:\program files (x86)\goto resolve unattended\2829436394331576853\gotoresolveexternalmodulehandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\msvcp_win.dll
2176GoToResolveTerminal.exe -CompanyId 2829436394331576853 -Environment Production -InstallationId 8hnB1hW42B -LogLevel 2C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveTerminal.exe
GoToResolveUnattended.exe
User:
SYSTEM
Company:
GoTo, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Resolve
Version:
1.27.1.2836
Modules
Images
c:\program files (x86)\goto resolve unattended\2829436394331576853\gotoresolveterminal.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\msvcp_win.dll
2332"C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveCrashHandler.exe" "--attachment=attachment_GoToResolveUnattended.log=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\appdata\GoToResolveUnattended.log" "--attachment=attachment_unattended.json=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\unattended.json" "--database=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\appdata\UnattendedCrashReportDB" "--metrics-dir=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\appdata\UnattendedCrashReportDB" --url=https://dumpster.console.gotoresolve.com/api/dump --annotation=format=minidump --annotation=hostname=DESKTOP-JGLLJLD --annotation=installationid=8hnB1hW42B --annotation=version=1.27.1.2836 --initial-client-data=0x7dc,0x7e0,0x7e4,0x584,0x7e8,0x70e26fac,0x70e26fbc,0x70e26fccC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveCrashHandler.exeGoToResolveUnattended.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\goto resolve unattended\2829436394331576853\gotoresolvecrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
2364"C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveCrashHandler.exe" "--database=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\appdata\ProcessCheckerCrashReportDB" "--metrics-dir=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\appdata\ProcessCheckerCrashReportDB" --url=https://dumpster.console.gotoresolve.com/api/dump --annotation=format=minidump --annotation=hostname=DESKTOP-JGLLJLD --annotation=installationid=8hnB1hW42B --annotation=version=1.27.1.2836 --initial-client-data=0x890,0x894,0x898,0x804,0x89c,0x70e26fac,0x70e26fbc,0x70e26fccC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveCrashHandler.exeGoToResolveProcessChecker.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\goto resolve unattended\2829436394331576853\gotoresolvecrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
2368"C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveCrashHandler.exe" "--database=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\appdata\ExternalModuleHandlerCrashReportDB" "--metrics-dir=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\appdata\ExternalModuleHandlerCrashReportDB" --url=https://dumpster.console.gotoresolve.com/api/dump --annotation=format=minidump --annotation=hostname=DESKTOP-JGLLJLD --annotation=installationid=8hnB1hW42B --annotation=version=1.27.1.2836 --initial-client-data=0x5f4,0x5e0,0x538,0x554,0x5d4,0x70e26fac,0x70e26fbc,0x70e26fccC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveCrashHandler.exeGoToResolveExternalModuleHandler.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\goto resolve unattended\2829436394331576853\gotoresolvecrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2648"C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveCrashHandler.exe" "--attachment=attachment_GoToResolveLoggerProcess.log=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\appdata\GoToResolveLoggerProcess.log" "--attachment=attachment_logger.json=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\logger.json" "--database=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\appdata\LoggerProcessCrashReportDB" "--metrics-dir=C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\appdata\LoggerProcessCrashReportDB" --url=https://dumpster.console.gotoresolve.com/api/dump --annotation=format=minidump --annotation=hostname=DESKTOP-JGLLJLD --annotation=installationid=8hnB1hW42B --annotation=version=1.27.1.2836 --initial-client-data=0x6dc,0x6d4,0x6e8,0x6e0,0x70c,0x70e26fac,0x70e26fbc,0x70e26fccC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveCrashHandler.exeGoToResolveLoggerProcess.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\goto resolve unattended\2829436394331576853\gotoresolvecrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
2836GoToResolveRemoteControl.exe -CompanyId 2829436394331576853 -InstallationId 8hnB1hW42B -WorkFolder "C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853" -Environment Production -ApplicationType 4 -LogLevel 2 -Service 1C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveRemoteControl.exe
GoToResolveUnattended.exe
User:
SYSTEM
Company:
GoTo, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Resolve
Version:
1.27.1.2836
Modules
Images
c:\program files (x86)\goto resolve unattended\2829436394331576853\gotoresolveremotecontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\msvcp_win.dll
3040"C:\Users\admin\Desktop\0061eecc_abc.exe" C:\Users\admin\Desktop\0061eecc_abc.exe
explorer.exe
User:
admin
Company:
GoTo, Inc.
Integrity Level:
HIGH
Description:
LogMeIn Resolve
Exit code:
0
Version:
1.27.1.2836
Modules
Images
c:\users\admin\desktop\0061eecc_abc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4108"C:\Users\admin\Desktop\0061eecc_abc.exe" C:\Users\admin\Desktop\0061eecc_abc.exeexplorer.exe
User:
admin
Company:
GoTo, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Resolve
Exit code:
3221226540
Version:
1.27.1.2836
Modules
Images
c:\users\admin\desktop\0061eecc_abc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
77 629
Read events
77 583
Write events
34
Delete events
12

Modification events

(PID) Process:(3040) 0061eecc_abc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoTo Resolve Unattended 2829436394331576853
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveUnattended.exe
(PID) Process:(3040) 0061eecc_abc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoTo Resolve Unattended 2829436394331576853
Operation:writeName:DisplayName
Value:
LogMeIn Resolve Unattended 2829436394331576853
(PID) Process:(3040) 0061eecc_abc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoTo Resolve Unattended 2829436394331576853
Operation:writeName:DisplayVersion
Value:
1.27.1.2836
(PID) Process:(3040) 0061eecc_abc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoTo Resolve Unattended 2829436394331576853
Operation:writeName:InstallLocation
Value:
C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853
(PID) Process:(3040) 0061eecc_abc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoTo Resolve Unattended 2829436394331576853
Operation:writeName:UninstallString
Value:
C:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveUnattendedRemover.exe
(PID) Process:(3040) 0061eecc_abc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GoTo Resolve Unattended\2829436394331576853
Operation:writeName:PublicKey
Value:
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000E800C405C6C8C543BF57BC0B73BBB6AC04000000020000000000106600000001000020000000AD88F8F8C1CCABE822E5ED6929637842B7A08084AE5F98926F77C14A3F85E3D8000000000E8000000002000020000000D0A540824027FB8F08BAA652A0F164690286FBC159A384A411FCC6E925710C9630000000CAF65FA1289AA84BA38DDE7561A08591D775761FB87B8A1265B5A0E55A8F7504910F22C57141C0A2F5F2F64B6515915E4000000078036163A0DB8C9EC6077E6105999F01A388F8096F8509F1705D952803577EEC9B7C4331D59F96088AC56EE6E3E3D6B3C90DBBDA24B05AB95101B494B88D0A4C
(PID) Process:(5460) GoToResolveUnattended.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GoTo Resolve Unattended\2829436394331576853
Operation:delete valueName:InstallationId
Value:
(PID) Process:(5460) GoToResolveUnattended.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GoTo Resolve Unattended\2829436394331576853
Operation:writeName:HostId
Value:
8a94e572ec8e00c85e215054b454f91b
(PID) Process:(5460) GoToResolveUnattended.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\GoTo Resolve Unattended\2829436394331576853
Operation:delete valueName:regsvc
Value:
(PID) Process:(8144) GoToResolveProcessChecker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoTo Resolve Unattended 2829436394331576853
Operation:writeName:DisplayName
Value:
LogMeIn Resolve Unattended 2829436394331576853
Executable files
46
Suspicious files
167
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
30400061eecc_abc.exeC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveUnattendedRemover.exeexecutable
MD5:11DFA6B306F1305A101E828077A315F4
SHA256:7BD9410677CDC3CEA3EDC06A96CB1AEB7C7BF72BA222D070E8EBA86BDECC73A8
30400061eecc_abc.exeC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveProcessChecker.exeexecutable
MD5:A4ACE4F2E6401EB63AF52A4F94696249
SHA256:BB1DF8D1764BDB506A6A4F73AAA6F068228CC0357AAF0778F61C18D125DA930F
30400061eecc_abc.exeC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\unattended.jsonbinary
MD5:D4AECB18082B32E5EA6AA56E7B003E38
SHA256:259F48D4AC57D4025DB91F33498B59F9ABE48586B2307A128B7D2C18C610DAFD
30400061eecc_abc.exeC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveRemoteControl.exeexecutable
MD5:D48E2D379BF2200C8E52A9D5132C742A
SHA256:06779604172C844E860120E96B0DDD3B24136C87543EA99F6F4B5FF57599ED2D
30400061eecc_abc.exeC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveUi.exeexecutable
MD5:D1C108B023B231B779488F6CD610080B
SHA256:1BFA081822B5610A6E68C0FBBFDDA796020A843BC37C7620DA71795A04FABFA2
30400061eecc_abc.exeC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveUnattended.exeexecutable
MD5:5F379149386225522203D074F951BA80
SHA256:5B3EC6BF2FEDA602949814762751E155EB18B6F6EB92C8B015B3D1951619D5BD
30400061eecc_abc.exeC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveLoggerProcess.exeexecutable
MD5:271636F6BBC066B4373ACAB2A4C4AAA6
SHA256:E9BE506B7E750150BBF9EA1E669F703458F62418AA1F0AFDB4F9F2E6A7152BB4
30400061eecc_abc.exeC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveUnattendedUi.exeexecutable
MD5:DB0F7391C4D8F13F1E48C980F805D8E8
SHA256:A948104AA578CAC631AF04053E900AF3238DF16F1FC89039D81B57888C67EDF9
30400061eecc_abc.exeC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\LibGoToResolve.dllexecutable
MD5:BAC348BEF5E3CBE38FB5CAEF9F8AF5E8
SHA256:EC73983805E0AF93291D585829242D0AE90E15CDD5177217D1E15DD853869574
30400061eecc_abc.exeC:\Program Files (x86)\GoTo Resolve Unattended\2829436394331576853\GoToResolveNetworkChecker.exeexecutable
MD5:E2B65DCBA9FA174D6AE90D5F00DD5991
SHA256:FB6C33E722C55FC5AC286E35724051DD2FE1705D8552284214C865D80C4993D7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
175
TCP/UDP connections
70
DNS requests
25
Threats
290

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5460
GoToResolveUnattended.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA4Mh2e7LU%2FvwtYX3xHOG4k%3D
DE
binary
727 b
whitelisted
5460
GoToResolveUnattended.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRbuhDibVrw1t5r3WYz1C9Jl6I%2FtwQU729TSunkBnx6yuKQVvYv1Ensy04CEAqA7xhLjfEFgtHEdqeVdGg%3D
DE
binary
727 b
whitelisted
8068
GoToResolveProcessChecker.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA4Mh2e7LU%2FvwtYX3xHOG4k%3D
DE
binary
727 b
whitelisted
POST
202
18.185.192.238:443
https://dumpster.console.gotoresolve.com/api/sendEventsV2
DE
unknown
8068
GoToResolveProcessChecker.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRbuhDibVrw1t5r3WYz1C9Jl6I%2FtwQU729TSunkBnx6yuKQVvYv1Ensy04CEAqA7xhLjfEFgtHEdqeVdGg%3D
DE
binary
727 b
whitelisted
POST
202
18.185.192.238:443
https://dumpster.console.gotoresolve.com/api/sendEventsV2
DE
unknown
POST
202
18.185.192.238:443
https://dumpster.console.gotoresolve.com/api/sendEventsV2
DE
unknown
POST
202
18.185.192.238:443
https://dumpster.console.gotoresolve.com/api/sendEventsV2
DE
unknown
POST
202
18.195.103.52:443
https://dumpster.console.gotoresolve.com/api/sendEventsV2
DE
unknown
GET
200
3.224.84.152:443
https://devices.console.gotoresolve.com/properties
US
binary
5.17 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5460
GoToResolveUnattended.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
8068
GoToResolveProcessChecker.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6128
GoToResolveLoggerProcess.exe
18.195.103.52:443
dumpster.console.gotoresolve.com
AMAZON-02
DE
unknown
7552
GoToResolveUnattended.exe
44.213.43.156:443
devices.console.gotoresolve.com
AMAZON-AES
US
unknown
5792
GoToResolveNetworkChecker.exe
3.33.179.166:80
ip.zscaler.com
AMAZON-02
US
unknown
5792
GoToResolveNetworkChecker.exe
18.195.103.52:443
dumpster.console.gotoresolve.com
AMAZON-02
DE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.78
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
dumpster.console.gotoresolve.com
  • 18.195.103.52
  • 18.185.192.238
unknown
devices.console.gotoresolve.com
  • 44.213.43.156
  • 54.167.193.144
  • 52.73.190.26
  • 52.4.19.161
  • 35.168.86.96
  • 18.209.169.249
  • 54.161.241.224
  • 44.193.59.142
unknown
ip.zscaler.com
  • 3.33.179.166
  • 52.223.22.206
unknown
zerotrust.services.gotoresolve.com
  • 13.107.253.45
  • 13.107.226.45
unknown
devices-iot.console.gotoresolve.com
  • 52.23.144.209
  • 13.223.144.35
  • 3.225.164.183
  • 34.194.96.151
  • 3.219.147.131
  • 107.20.50.19
  • 3.218.7.239
  • 52.5.161.186
  • 34.224.209.92
  • 3.210.14.99
  • 3.90.238.165
  • 54.173.45.125
  • 3.222.186.92
  • 13.219.170.234
  • 3.208.232.29
  • 3.209.44.207
unknown
sessions.console.gotoresolve.com
  • 3.67.158.139
  • 35.158.0.109
unknown
www.bing.com
  • 2.16.241.218
  • 2.16.241.201
  • 2.16.241.205
  • 2.16.241.207
whitelisted

Threats

PID
Process
Class
Message
2428
svchost.exe
Misc activity
ET INFO Observed DNS Query to RMM Domain (gotoresolve .com)
6128
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
6128
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
6128
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
6128
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
6128
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
6128
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
Process
Message
GoToResolveUnattended.exe
DllMain: DLL_PROCESS_ATTACH: lpReserved=0
GoToResolveUnattended.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveUnattended.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveUnattended.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveUnattended.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveUnattended.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveUnattended.exe
DllMain: DLL_THREAD_DETACH
GoToResolveProcessChecker.exe
DllMain: DLL_PROCESS_ATTACH: lpReserved=0
GoToResolveProcessChecker.exe
DllMain: DLL_PROCESS_ATTACH: lpReserved=0
GoToResolveProcessChecker.exe
DllMain: DLL_THREAD_ATTACH