File name:

Support-LogMeInRescue.zip

Full analysis: https://app.any.run/tasks/120f2702-7993-401a-b3d3-8a5f915328dd
Verdict: Malicious activity
Analysis date: March 13, 2024, 19:14:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

3240AD7E5B30F3D0A2846192274E225A

SHA1:

E7E9F297123164E2A449167E8E3B8F5D23994913

SHA256:

B91B1F71C8A0836AFF1597CA291DD70DDE5E8C317E476D1C01E940F6A51E4DBE

SSDEEP:

98304:YUGftbkzURLEz2ebNIFAHH54zmpcnsCLiUDRATL4B1jGJKgqi663XsH/4Bz4ZHPg:jbJXNVmuD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2472)
      • Support-LogMeInRescue.exe (PID: 3916)
      • LMI_Rescue_srv.exe (PID: 2648)
      • Support-LogMeInRescue.exe (PID: 2100)
      • Support-LogMeInRescue.exe (PID: 2372)
      • LMI_Rescue_srv.exe (PID: 3496)
    • Changes the autorun value in the registry

      • LMI_Rescue_srv.exe (PID: 3736)
      • LMI_Rescue_srv.exe (PID: 3276)
      • LMI_Rescue_srv.exe (PID: 2592)
    • Deletes the SafeBoot registry key

      • LMI_Rescue_srv.exe (PID: 3276)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2472)
      • LMI_Rescue_srv.exe (PID: 3736)
      • LMI_Rescue_srv.exe (PID: 3276)
      • LMI_Rescue_srv.exe (PID: 2592)
    • Reads the Internet Settings

      • LMI_Rescue.exe (PID: 3972)
      • LMI_Rescue_srv.exe (PID: 3736)
      • LMI_Rescue.exe (PID: 1976)
      • LMI_Rescue.exe (PID: 1368)
      • LMI_Rescue_srv.exe (PID: 2592)
    • Executable content was dropped or overwritten

      • Support-LogMeInRescue.exe (PID: 3916)
      • LMI_Rescue_srv.exe (PID: 2648)
      • Support-LogMeInRescue.exe (PID: 2372)
      • Support-LogMeInRescue.exe (PID: 2100)
      • LMI_Rescue_srv.exe (PID: 3496)
    • Reads the Windows owner or organization settings

      • LMI_Rescue_srv.exe (PID: 3736)
      • LMI_Rescue_srv.exe (PID: 2592)
    • Application launched itself

      • LMI_Rescue_srv.exe (PID: 3736)
      • LMI_Rescue_srv.exe (PID: 2592)
    • Executes as Windows Service

      • LMI_Rescue_srv.exe (PID: 3276)
      • LMI_Rescue_srv.exe (PID: 1540)
    • Starts CMD.EXE for commands execution

      • LMI_Rescue_srv.exe (PID: 3276)
    • Executing commands from a ".bat" file

      • LMI_Rescue_srv.exe (PID: 3276)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2472)
    • Reads the computer name

      • LMI_Rescue.exe (PID: 3972)
      • LMI_Rescue_srv.exe (PID: 3736)
      • LMI_Rescue_srv.exe (PID: 3276)
      • LMI_Rescue_srv.exe (PID: 2648)
      • LMI_Rescue.exe (PID: 1976)
      • LMI_Rescue.exe (PID: 1368)
      • LMI_Rescue_srv.exe (PID: 2592)
      • LMI_Rescue_srv.exe (PID: 1540)
      • LMI_Rescue_srv.exe (PID: 3496)
    • Checks supported languages

      • Support-LogMeInRescue.exe (PID: 3916)
      • LMI_Rescue.exe (PID: 3972)
      • LMI_Rescue_srv.exe (PID: 3736)
      • LMI_Rescue_srv.exe (PID: 2648)
      • LMI_Rescue_srv.exe (PID: 3276)
      • Support-LogMeInRescue.exe (PID: 2100)
      • Support-LogMeInRescue.exe (PID: 2372)
      • LMI_Rescue.exe (PID: 1976)
      • LMI_Rescue.exe (PID: 1368)
      • LMI_Rescue_srv.exe (PID: 2592)
      • LMI_Rescue_srv.exe (PID: 1540)
      • LMI_Rescue_srv.exe (PID: 3496)
    • Reads the machine GUID from the registry

      • LMI_Rescue.exe (PID: 3972)
      • LMI_Rescue_srv.exe (PID: 3736)
      • LMI_Rescue_srv.exe (PID: 2648)
      • LMI_Rescue_srv.exe (PID: 3276)
      • LMI_Rescue.exe (PID: 1976)
      • LMI_Rescue.exe (PID: 1368)
      • LMI_Rescue_srv.exe (PID: 2592)
      • LMI_Rescue_srv.exe (PID: 3496)
      • LMI_Rescue_srv.exe (PID: 1540)
    • Creates files or folders in the user directory

      • Support-LogMeInRescue.exe (PID: 3916)
      • LMI_Rescue.exe (PID: 3972)
      • LMI_Rescue.exe (PID: 1976)
      • Support-LogMeInRescue.exe (PID: 2100)
      • Support-LogMeInRescue.exe (PID: 2372)
      • LMI_Rescue.exe (PID: 1368)
    • Checks proxy server information

      • LMI_Rescue.exe (PID: 3972)
      • LMI_Rescue_srv.exe (PID: 3736)
      • LMI_Rescue.exe (PID: 1976)
      • LMI_Rescue.exe (PID: 1368)
      • LMI_Rescue_srv.exe (PID: 2592)
    • Reads Windows Product ID

      • LMI_Rescue_srv.exe (PID: 3736)
      • LMI_Rescue_srv.exe (PID: 2592)
    • Process checks whether UAC notifications are on

      • LMI_Rescue_srv.exe (PID: 3736)
      • LMI_Rescue_srv.exe (PID: 2592)
    • Reads the software policy settings

      • LMI_Rescue_srv.exe (PID: 3276)
      • LMI_Rescue_srv.exe (PID: 1540)
    • Creates files in the program directory

      • LMI_Rescue_srv.exe (PID: 2648)
      • LMI_Rescue_srv.exe (PID: 3276)
      • LMI_Rescue_srv.exe (PID: 3496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:03:11 11:26:50
ZipCRC: 0x959c820a
ZipCompressedSize: 2484780
ZipUncompressedSize: 2590056
ZipFileName: Support-LogMeInRescue.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
15
Malicious processes
11
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe support-logmeinrescue.exe lmi_rescue.exe no specs lmi_rescue_srv.exe lmi_rescue_srv.exe lmi_rescue_srv.exe support-logmeinrescue.exe lmi_rescue.exe no specs bcdedit.exe no specs cmd.exe no specs support-logmeinrescue.exe lmi_rescue.exe no specs lmi_rescue_srv.exe lmi_rescue_srv.exe lmi_rescue_srv.exe

Process information

PID
CMD
Path
Indicators
Parent process
1368"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10F38001.tmp\LMI_Rescue.exe"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10F38001.tmp\LMI_Rescue.exeSupport-LogMeInRescue.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10f38001.tmp\lmi_rescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1540"C:\Program Files\LogMeIn Rescue Applet\LMIR10F3C001.tmp\LMI_Rescue_srv.exe" -service -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1 -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10F38001.tmp"C:\Program Files\LogMeIn Rescue Applet\LMIR10F3C001.tmp\LMI_Rescue_srv.exe
services.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\program files\logmein rescue applet\lmir10f3c001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
1860C:\Windows\system32\bcdedit.exe /deletevalue safebootC:\Windows\System32\bcdedit.exeLMI_Rescue_srv.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Boot Configuration Data Editor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\bcdedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1976"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10F2C001.tmp\LMI_Rescue.exe"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10F2C001.tmp\LMI_Rescue.exeSupport-LogMeInRescue.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10f2c001.tmp\lmi_rescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2100"C:\Users\admin\AppData\Local\Temp\Rar$EXa2472.41437\Support-LogMeInRescue.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2472.41437\Support-LogMeInRescue.exe
WinRAR.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2472.41437\support-logmeinrescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2372"C:\Users\admin\AppData\Local\Temp\Rar$EXa2472.40304\Support-LogMeInRescue.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2472.40304\Support-LogMeInRescue.exe
WinRAR.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2472.40304\support-logmeinrescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2472"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\Support-LogMeInRescue.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2564"C:\Windows\system32\cmd.exe" /S/C "C:\Program Files\LMIR10EC5001.tmp.bat"C:\Windows\System32\cmd.exeLMI_Rescue_srv.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2592"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10F38001.tmp\LMI_Rescue_srv.exe" -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10F38001.tmp"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10F38001.tmp\LMI_Rescue_srv.exe
LMI_Rescue.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10f38001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
2648"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\LMI_Rescue_srv.exe" -regrunsvc -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp" -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\LMI_Rescue_srv.exe
LMI_Rescue_srv.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
HIGH
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10ec0001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
Total events
25 289
Read events
25 175
Write events
95
Delete events
19

Modification events

(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2472) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\Support-LogMeInRescue.zip
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
38
Suspicious files
12
Text files
12
Unknown types
11

Dropped files

PID
Process
Filename
Type
3916Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\Lmi_Rescue_srv.exeexecutable
MD5:AF694F4246062BAAA9FDACDF6C47F29D
SHA256:329B3A01C9071E263A575E23B88ADCCB6A4F8F5F3EBA2FDADB98C9BC0EB9B2C9
3972LMI_Rescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\rescue.infobinary
MD5:EA22AC8A65F9D8D5E04663212FC7C0FC
SHA256:0C4BF7116379F39C6D3600F7E9C0D2D3832F7DD4911F9883B7AA36958BE20B46
3916Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\RescueWinRTLib.dllexecutable
MD5:1E2B834F5EA12D0572DD34273BEE2E18
SHA256:4ABCE232974AE5A241847101BF63FE31FB5FD5595BC9D765C7E3EBDEC0A5D4D9
3916Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\nvdaControllerClient32.dllexecutable
MD5:C84F1A24C88AC9E44409E15CF90DD0F2
SHA256:3E5CE67536F1267F38B347675A9E4BC1368AD20981474838A1016E4588F740C6
3916Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\rahook.dllexecutable
MD5:8E00263FD552CEA4D39E3EB010754F91
SHA256:2D21B16FB780926A61AA0D9A652EEE08978A2BAA4045202223CF98DA0892ED99
3916Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\logo.bmpimage
MD5:CDB31BAAACCACC9273484427F39AA5CB
SHA256:003AA4DEB3D5184FB7B618DF99B680611CBCFA3D764D5A2A210FF4CAE5EC96B8
3916Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\rescue.icoimage
MD5:8AD28E79941CE3E002804DFE1722EA87
SHA256:63424E176B75642EBAC9E5452ECCC8C6956266DACC0AE4388D636D5BEE5E7933
3916Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\params.txttext
MD5:9F422A3DA4288604CBA347750CA5E5A6
SHA256:512BBD5888EA04BC9AF11BB3F3827E49F4BC3339DCB89760686747F6A4E39E4E
3916Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\LMI_RescueRC.exeexecutable
MD5:CF6EF3D01650867871D61FDA64288DFA
SHA256:7C3117E0930C13ACB3E826305B5A582DCD72EA20C8858F5315440A70B5AC3E4D
3972LMI_Rescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10EC0001.tmp\rescue.logbinary
MD5:615CB03A44A240C9EA7B1326F9122D24
SHA256:F7296C13B57D70024FBC1CFE1BEB4B8BBA50CD8874BBDC6B08015361AB94A8B0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
14
DNS requests
14
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3276
LMI_Rescue_srv.exe
158.120.16.91:443
control.rsc-app24-03.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
3276
LMI_Rescue_srv.exe
158.120.16.94:443
control.rsc-app24-02.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
3276
LMI_Rescue_srv.exe
158.120.16.114:443
control.rsc-app24-05.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
1540
LMI_Rescue_srv.exe
158.120.16.114:443
control.rsc-app24-05.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
1540
LMI_Rescue_srv.exe
158.120.16.94:443
control.rsc-app24-02.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
1540
LMI_Rescue_srv.exe
158.120.16.91:443
control.rsc-app24-03.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown

DNS requests

Domain
IP
Reputation
rescue-data-center.logmein-gateway.com
  • 216.219.114.24
unknown
rescue-list.24.logmein-gateway.com
unknown
control.rsc-app24-03.logmeinrescue.com
  • 158.120.16.91
unknown
control.rsc-app24-02.logmeinrescue.com
  • 158.120.16.94
unknown
control.rsc-app24-05.logmeinrescue.com
  • 158.120.16.114
unknown

Threats

No threats detected
No debug info