File name:

Support-LogMeInRescue.zip

Full analysis: https://app.any.run/tasks/a5e99d27-a527-4baf-8386-78b074a59995
Verdict: Malicious activity
Analysis date: March 13, 2024, 19:00:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

3240AD7E5B30F3D0A2846192274E225A

SHA1:

E7E9F297123164E2A449167E8E3B8F5D23994913

SHA256:

B91B1F71C8A0836AFF1597CA291DD70DDE5E8C317E476D1C01E940F6A51E4DBE

SSDEEP:

98304:YUGftbkzURLEz2ebNIFAHH54zmpcnsCLiUDRATL4B1jGJKgqi663XsH/4Bz4ZHPg:jbJXNVmuD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3672)
      • Support-LogMeInRescue.exe (PID: 3972)
      • LMI_Rescue_srv.exe (PID: 3092)
      • Support-LogMeInRescue.exe (PID: 1740)
      • LMI_Rescue_srv.exe (PID: 492)
    • Changes the autorun value in the registry

      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Deletes the SafeBoot registry key

      • LMI_Rescue_srv.exe (PID: 2692)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3672)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Executable content was dropped or overwritten

      • Support-LogMeInRescue.exe (PID: 3972)
      • LMI_Rescue_srv.exe (PID: 3092)
      • Support-LogMeInRescue.exe (PID: 1740)
      • LMI_Rescue_srv.exe (PID: 492)
    • Reads the Internet Settings

      • LMI_Rescue.exe (PID: 3952)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue.exe (PID: 3684)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Reads the Windows owner or organization settings

      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Executes as Windows Service

      • LMI_Rescue_srv.exe (PID: 2692)
      • LMI_Rescue_srv.exe (PID: 1848)
    • Application launched itself

      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3672)
    • Creates files or folders in the user directory

      • Support-LogMeInRescue.exe (PID: 3972)
      • LMI_Rescue.exe (PID: 3952)
      • Support-LogMeInRescue.exe (PID: 1740)
      • LMI_Rescue.exe (PID: 3684)
    • Checks proxy server information

      • LMI_Rescue.exe (PID: 3952)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue.exe (PID: 3684)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Checks supported languages

      • Support-LogMeInRescue.exe (PID: 3972)
      • LMI_Rescue.exe (PID: 3952)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 3092)
      • LMI_Rescue_srv.exe (PID: 2692)
      • Support-LogMeInRescue.exe (PID: 1740)
      • LMI_Rescue_srv.exe (PID: 2432)
      • LMI_Rescue.exe (PID: 3684)
      • LMI_Rescue_srv.exe (PID: 1848)
      • LMI_Rescue_srv.exe (PID: 492)
    • Reads the computer name

      • LMI_Rescue.exe (PID: 3952)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 3092)
      • LMI_Rescue_srv.exe (PID: 2692)
      • LMI_Rescue_srv.exe (PID: 2432)
      • LMI_Rescue.exe (PID: 3684)
      • LMI_Rescue_srv.exe (PID: 492)
      • LMI_Rescue_srv.exe (PID: 1848)
    • Reads the machine GUID from the registry

      • LMI_Rescue.exe (PID: 3952)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 3092)
      • LMI_Rescue_srv.exe (PID: 2692)
      • LMI_Rescue.exe (PID: 3684)
      • LMI_Rescue_srv.exe (PID: 2432)
      • LMI_Rescue_srv.exe (PID: 492)
      • LMI_Rescue_srv.exe (PID: 1848)
    • Reads Windows Product ID

      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Process checks whether UAC notifications are on

      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Creates files in the program directory

      • LMI_Rescue_srv.exe (PID: 3092)
      • LMI_Rescue_srv.exe (PID: 492)
    • Reads the software policy settings

      • LMI_Rescue_srv.exe (PID: 2692)
      • LMI_Rescue_srv.exe (PID: 1848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:03:11 11:26:50
ZipCRC: 0x959c820a
ZipCompressedSize: 2484780
ZipUncompressedSize: 2590056
ZipFileName: Support-LogMeInRescue.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
12
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe support-logmeinrescue.exe lmi_rescue.exe no specs lmi_rescue_srv.exe lmi_rescue_srv.exe lmi_rescue_srv.exe support-logmeinrescue.exe lmi_rescue.exe no specs bcdedit.exe no specs lmi_rescue_srv.exe lmi_rescue_srv.exe lmi_rescue_srv.exe

Process information

PID
CMD
Path
Indicators
Parent process
492"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue_srv.exe" -regrunsvc -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp" -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue_srv.exe
LMI_Rescue_srv.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
HIGH
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10ba8001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
1740"C:\Users\admin\AppData\Local\Temp\Rar$EXa3672.291\Support-LogMeInRescue.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3672.291\Support-LogMeInRescue.exe
WinRAR.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3672.291\support-logmeinrescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1848"C:\Program Files\LogMeIn Rescue Applet\LMIR10BAF001.tmp\LMI_Rescue_srv.exe" -service -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1 -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp"C:\Program Files\LogMeIn Rescue Applet\LMIR10BAF001.tmp\LMI_Rescue_srv.exe
services.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\program files\logmein rescue applet\lmir10baf001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
2000C:\Windows\system32\bcdedit.exe /deletevalue safebootC:\Windows\System32\bcdedit.exeLMI_Rescue_srv.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Boot Configuration Data Editor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\bcdedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2432"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue_srv.exe" -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue_srv.exe
LMI_Rescue.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10ba8001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
2692"C:\Program Files\LogMeIn Rescue Applet\LMIR10B6D001.tmp\LMI_Rescue_srv.exe" -service -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1 -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp"C:\Program Files\LogMeIn Rescue Applet\LMIR10B6D001.tmp\LMI_Rescue_srv.exe
services.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\program files\logmein rescue applet\lmir10b6d001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
3092"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\LMI_Rescue_srv.exe" -regrunsvc -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp" -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\LMI_Rescue_srv.exe
LMI_Rescue_srv.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
HIGH
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10b67001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
3672"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\Support-LogMeInRescue.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3684"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue.exe"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue.exeSupport-LogMeInRescue.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10ba8001.tmp\lmi_rescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3784"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\LMI_Rescue_srv.exe" -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\LMI_Rescue_srv.exe
LMI_Rescue.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10b67001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
Total events
21 735
Read events
21 653
Write events
74
Delete events
8

Modification events

(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\Support-LogMeInRescue.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
30
Suspicious files
16
Text files
6
Unknown types
7

Dropped files

PID
Process
Filename
Type
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\logo.bmpbinary
MD5:CDB31BAAACCACC9273484427F39AA5CB
SHA256:003AA4DEB3D5184FB7B618DF99B680611CBCFA3D764D5A2A210FF4CAE5EC96B8
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3672.43765\Support-LogMeInRescue.exeexecutable
MD5:A76AE1176B3B7A3CE44A1117E066FB2F
SHA256:1BAC0E16322CCB250BF3C00E1C4923F7A0F7775A042937C6DCE56A2933A12876
3952LMI_Rescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\rescue.logbinary
MD5:A78847774A9E171B1E109962C12A0EBA
SHA256:C70C51067D3288AE20BC7A219A66BACA44D17929A09B545489F116967E4FB425
3952LMI_Rescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\rescue.infobinary
MD5:DE09082AD2F3231D831BDB94F63FC713
SHA256:5E80FBBB6ADA255B5F8E0F871E88AC0AF47037DC2FA1A1E1A0B2CC4804ED9DF2
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\rahook.dllexecutable
MD5:8E00263FD552CEA4D39E3EB010754F91
SHA256:2D21B16FB780926A61AA0D9A652EEE08978A2BAA4045202223CF98DA0892ED99
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\params.txttext
MD5:9F422A3DA4288604CBA347750CA5E5A6
SHA256:512BBD5888EA04BC9AF11BB3F3827E49F4BC3339DCB89760686747F6A4E39E4E
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\nvdaControllerClient32.dllexecutable
MD5:C84F1A24C88AC9E44409E15CF90DD0F2
SHA256:3E5CE67536F1267F38B347675A9E4BC1368AD20981474838A1016E4588F740C6
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\RescueWinRTLib.dllexecutable
MD5:1E2B834F5EA12D0572DD34273BEE2E18
SHA256:4ABCE232974AE5A241847101BF63FE31FB5FD5595BC9D765C7E3EBDEC0A5D4D9
3092LMI_Rescue_srv.exeC:\Program Files\LogMeIn Rescue Applet\LMIR10B6D001.tmp\rahook.dllexecutable
MD5:8E00263FD552CEA4D39E3EB010754F91
SHA256:2D21B16FB780926A61AA0D9A652EEE08978A2BAA4045202223CF98DA0892ED99
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\rescue.icoimage
MD5:8AD28E79941CE3E002804DFE1722EA87
SHA256:63424E176B75642EBAC9E5452ECCC8C6956266DACC0AE4388D636D5BEE5E7933
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2692
LMI_Rescue_srv.exe
158.120.16.94:443
control.rsc-app24-02.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
1848
LMI_Rescue_srv.exe
158.120.16.91:443
control.rsc-app24-03.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown

DNS requests

Domain
IP
Reputation
rescue-data-center.logmein-gateway.com
  • 216.219.114.24
unknown
rescue-list.24.logmein-gateway.com
unknown
control.rsc-app24-02.logmeinrescue.com
  • 158.120.16.94
unknown
control.rsc-app24-03.logmeinrescue.com
  • 158.120.16.91
unknown

Threats

No threats detected
No debug info