File name:

Support-LogMeInRescue.zip

Full analysis: https://app.any.run/tasks/39a5a911-f50d-4bcc-ab3a-c5e49085028b
Verdict: Malicious activity
Analysis date: March 13, 2024, 19:03:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

3240AD7E5B30F3D0A2846192274E225A

SHA1:

E7E9F297123164E2A449167E8E3B8F5D23994913

SHA256:

B91B1F71C8A0836AFF1597CA291DD70DDE5E8C317E476D1C01E940F6A51E4DBE

SSDEEP:

98304:YUGftbkzURLEz2ebNIFAHH54zmpcnsCLiUDRATL4B1jGJKgqi663XsH/4Bz4ZHPg:jbJXNVmuD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • LMI_Rescue_srv.exe (PID: 3708)
      • LMI_Rescue_srv.exe (PID: 3964)
      • LMI_Rescue_srv.exe (PID: 2804)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3864)
      • Support-LogMeInRescue.exe (PID: 3692)
      • Support-LogMeInRescue.exe (PID: 1888)
      • LMI_Rescue_srv.exe (PID: 2232)
      • Support-LogMeInRescue.exe (PID: 2388)
      • LMI_Rescue_srv.exe (PID: 3444)
    • Deletes the SafeBoot registry key

      • LMI_Rescue_srv.exe (PID: 3964)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3864)
      • LMI_Rescue_srv.exe (PID: 3708)
      • LMI_Rescue_srv.exe (PID: 3964)
      • LMI_Rescue_srv.exe (PID: 2804)
    • Executable content was dropped or overwritten

      • Support-LogMeInRescue.exe (PID: 3692)
      • Support-LogMeInRescue.exe (PID: 1888)
      • LMI_Rescue_srv.exe (PID: 2232)
      • Support-LogMeInRescue.exe (PID: 2388)
      • LMI_Rescue_srv.exe (PID: 3444)
    • Reads the Windows owner or organization settings

      • LMI_Rescue_srv.exe (PID: 3708)
      • LMI_Rescue_srv.exe (PID: 2804)
    • Reads the Internet Settings

      • LMI_Rescue.exe (PID: 2044)
      • LMI_Rescue_srv.exe (PID: 3708)
      • LMI_Rescue.exe (PID: 3508)
      • LMI_Rescue.exe (PID: 2484)
      • LMI_Rescue_srv.exe (PID: 2804)
    • Application launched itself

      • LMI_Rescue_srv.exe (PID: 3708)
      • LMI_Rescue_srv.exe (PID: 2804)
    • Executes as Windows Service

      • LMI_Rescue_srv.exe (PID: 3964)
      • LMI_Rescue_srv.exe (PID: 296)
    • Executing commands from a ".bat" file

      • LMI_Rescue_srv.exe (PID: 3964)
    • Starts CMD.EXE for commands execution

      • LMI_Rescue_srv.exe (PID: 3964)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 3436)
  • INFO

    • Checks supported languages

      • Support-LogMeInRescue.exe (PID: 3692)
      • LMI_Rescue.exe (PID: 2044)
      • LMI_Rescue_srv.exe (PID: 3708)
      • LMI_Rescue_srv.exe (PID: 2232)
      • Support-LogMeInRescue.exe (PID: 1888)
      • LMI_Rescue_srv.exe (PID: 3964)
      • Support-LogMeInRescue.exe (PID: 2388)
      • LMI_Rescue.exe (PID: 2484)
      • LMI_Rescue_srv.exe (PID: 2804)
      • LMI_Rescue_srv.exe (PID: 3444)
      • LMI_Rescue_srv.exe (PID: 296)
      • wmpnscfg.exe (PID: 664)
      • LMI_Rescue.exe (PID: 3508)
    • Reads the computer name

      • LMI_Rescue.exe (PID: 2044)
      • LMI_Rescue_srv.exe (PID: 3708)
      • LMI_Rescue_srv.exe (PID: 2232)
      • LMI_Rescue_srv.exe (PID: 3964)
      • LMI_Rescue.exe (PID: 2484)
      • LMI_Rescue_srv.exe (PID: 2804)
      • LMI_Rescue_srv.exe (PID: 3444)
      • LMI_Rescue_srv.exe (PID: 296)
      • wmpnscfg.exe (PID: 664)
      • LMI_Rescue.exe (PID: 3508)
    • Reads the machine GUID from the registry

      • LMI_Rescue.exe (PID: 2044)
      • LMI_Rescue_srv.exe (PID: 3708)
      • LMI_Rescue_srv.exe (PID: 2232)
      • LMI_Rescue_srv.exe (PID: 3964)
      • LMI_Rescue.exe (PID: 3508)
      • LMI_Rescue.exe (PID: 2484)
      • LMI_Rescue_srv.exe (PID: 2804)
      • LMI_Rescue_srv.exe (PID: 3444)
      • LMI_Rescue_srv.exe (PID: 296)
    • Creates files or folders in the user directory

      • LMI_Rescue.exe (PID: 2044)
      • Support-LogMeInRescue.exe (PID: 3692)
      • Support-LogMeInRescue.exe (PID: 1888)
      • LMI_Rescue.exe (PID: 3508)
      • Support-LogMeInRescue.exe (PID: 2388)
      • LMI_Rescue.exe (PID: 2484)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3864)
    • Checks proxy server information

      • LMI_Rescue.exe (PID: 2044)
      • LMI_Rescue_srv.exe (PID: 3708)
      • LMI_Rescue.exe (PID: 3508)
      • LMI_Rescue.exe (PID: 2484)
      • LMI_Rescue_srv.exe (PID: 2804)
    • Process checks whether UAC notifications are on

      • LMI_Rescue_srv.exe (PID: 3708)
      • LMI_Rescue_srv.exe (PID: 2804)
    • Reads Windows Product ID

      • LMI_Rescue_srv.exe (PID: 3708)
      • LMI_Rescue_srv.exe (PID: 2804)
    • Creates files in the program directory

      • LMI_Rescue_srv.exe (PID: 2232)
      • LMI_Rescue_srv.exe (PID: 3964)
      • LMI_Rescue_srv.exe (PID: 3444)
    • Reads the software policy settings

      • LMI_Rescue_srv.exe (PID: 3964)
      • LMI_Rescue_srv.exe (PID: 296)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 664)
      • cmd.exe (PID: 392)
      • explorer.exe (PID: 1020)
      • cmd.exe (PID: 3436)
      • cmd.exe (PID: 3756)
      • cmd.exe (PID: 3644)
      • notepad++.exe (PID: 3584)
      • notepad.exe (PID: 3368)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:03:11 11:26:50
ZipCRC: 0x959c820a
ZipCompressedSize: 2484780
ZipUncompressedSize: 2590056
ZipFileName: Support-LogMeInRescue.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
74
Monitored processes
26
Malicious processes
11
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe support-logmeinrescue.exe lmi_rescue.exe no specs lmi_rescue_srv.exe lmi_rescue_srv.exe lmi_rescue_srv.exe support-logmeinrescue.exe lmi_rescue.exe no specs bcdedit.exe no specs cmd.exe no specs support-logmeinrescue.exe lmi_rescue.exe no specs lmi_rescue_srv.exe lmi_rescue_srv.exe lmi_rescue_srv.exe wmpnscfg.exe no specs explorer.exe no specs cmd.exe no specs cmd.exe no specs timeout.exe no specs timeout.exe no specs timeout.exe no specs cmd.exe no specs cmd.exe no specs notepad++.exe notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
296"C:\Program Files\LogMeIn Rescue Applet\LMIR10CAA001.tmp\LMI_Rescue_srv.exe" -service -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1 -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10CA5001.tmp"C:\Program Files\LogMeIn Rescue Applet\LMIR10CAA001.tmp\LMI_Rescue_srv.exe
services.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\program files\logmein rescue applet\lmir10caa001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
392C:\Windows\system32\cmd.exe /c ""C:\Program Files\LMIR10C1A001.tmp_r.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
664"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1020"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1888"C:\Users\admin\AppData\Local\Temp\Rar$EXa3864.23906\Support-LogMeInRescue.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3864.23906\Support-LogMeInRescue.exe
WinRAR.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3864.23906\support-logmeinrescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2044"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp\LMI_Rescue.exe"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp\LMI_Rescue.exeSupport-LogMeInRescue.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10c15001.tmp\lmi_rescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2060"C:\Windows\system32\cmd.exe" /S/C "C:\Program Files\LMIR10C1A001.tmp.bat"C:\Windows\System32\cmd.exeLMI_Rescue_srv.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2232"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp\LMI_Rescue_srv.exe" -regrunsvc -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp" -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp\LMI_Rescue_srv.exe
LMI_Rescue_srv.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
HIGH
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10c15001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
2388"C:\Users\admin\AppData\Local\Temp\Rar$EXa3864.25574\Support-LogMeInRescue.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3864.25574\Support-LogMeInRescue.exe
WinRAR.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3864.25574\support-logmeinrescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2484"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10CA5001.tmp\LMI_Rescue.exe"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10CA5001.tmp\LMI_Rescue.exeSupport-LogMeInRescue.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10ca5001.tmp\lmi_rescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
25 929
Read events
25 812
Write events
98
Delete events
19

Modification events

(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3864) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\Support-LogMeInRescue.zip
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3864) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
38
Suspicious files
14
Text files
12
Unknown types
9

Dropped files

PID
Process
Filename
Type
3692Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp\logo.bmpbinary
MD5:CDB31BAAACCACC9273484427F39AA5CB
SHA256:003AA4DEB3D5184FB7B618DF99B680611CBCFA3D764D5A2A210FF4CAE5EC96B8
3692Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp\rahook.dllexecutable
MD5:8E00263FD552CEA4D39E3EB010754F91
SHA256:2D21B16FB780926A61AA0D9A652EEE08978A2BAA4045202223CF98DA0892ED99
3692Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp\rescue.icoimage
MD5:8AD28E79941CE3E002804DFE1722EA87
SHA256:63424E176B75642EBAC9E5452ECCC8C6956266DACC0AE4388D636D5BEE5E7933
3692Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp\params.txttext
MD5:9F422A3DA4288604CBA347750CA5E5A6
SHA256:512BBD5888EA04BC9AF11BB3F3827E49F4BC3339DCB89760686747F6A4E39E4E
2232LMI_Rescue_srv.exeC:\Program Files\LogMeIn Rescue Applet\LMIR10C1A001.tmp\LMI_Rescue.exeexecutable
MD5:CCEE5DFA73B23F57F457532BD444DD3C
SHA256:64243C03C081CA5A68124730638B64A95B4C6E3D417FCE62F1318DE94FBFD06A
3692Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp\ra64app.exeexecutable
MD5:ADB5481D6AD334B76B5B2BD48F5E3E03
SHA256:C94ADD9B456766EB610FA11C343CFA3EBB4CFB0A4DF29F15DDD0C707085E3B61
2044LMI_Rescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp\rescue.infobinary
MD5:D4F4A044DAEA045E6601E2C68CDC49AC
SHA256:2DE89894972AA2B605E1C52A3D6D60FA26442C15D21FD249C96C35C08595FF71
2044LMI_Rescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10C15001.tmp\rescue.logbinary
MD5:668705531395BD77996661D7663378F9
SHA256:A51D2DB313B90B98E492D1183B55BD334E8014AE757A8F6D76DFD11DEAB1DB42
2232LMI_Rescue_srv.exeC:\Program Files\LogMeIn Rescue Applet\LMIR10C1A001.tmp\rahook.dllexecutable
MD5:8E00263FD552CEA4D39E3EB010754F91
SHA256:2D21B16FB780926A61AA0D9A652EEE08978A2BAA4045202223CF98DA0892ED99
2044LMI_Rescue.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QB Support.lnkbinary
MD5:725294E39FB7ACB9EBA6598BD4A5B9BD
SHA256:9BA32A2748231B8E353F694B5F36149985831B878AB2C685933CEDCAE9A00451
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
14
DNS requests
15
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3964
LMI_Rescue_srv.exe
158.120.16.116:443
control.rsc-app24-01.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
3964
LMI_Rescue_srv.exe
158.120.16.94:443
control.rsc-app24-02.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
3964
LMI_Rescue_srv.exe
158.120.16.114:443
control.rsc-app24-05.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
296
LMI_Rescue_srv.exe
158.120.16.116:443
control.rsc-app24-01.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
296
LMI_Rescue_srv.exe
158.120.16.94:443
control.rsc-app24-02.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
296
LMI_Rescue_srv.exe
158.120.16.91:443
control.rsc-app24-03.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown

DNS requests

Domain
IP
Reputation
rescue-data-center.logmein-gateway.com
  • 216.219.114.24
unknown
rescue-list.24.logmein-gateway.com
unknown
control.rsc-app24-01.logmeinrescue.com
  • 158.120.16.116
unknown
control.rsc-app24-02.logmeinrescue.com
  • 158.120.16.94
unknown
control.rsc-app24-05.logmeinrescue.com
  • 158.120.16.114
unknown
control.rsc-app24-03.logmeinrescue.com
  • 158.120.16.91
unknown

Threats

No threats detected
Process
Message
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3