File name:

Support-LogMeInRescue.zip

Full analysis: https://app.any.run/tasks/a5e99d27-a527-4baf-8386-78b074a59995
Verdict: Malicious activity
Analysis date: March 13, 2024, 19:00:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

3240AD7E5B30F3D0A2846192274E225A

SHA1:

E7E9F297123164E2A449167E8E3B8F5D23994913

SHA256:

B91B1F71C8A0836AFF1597CA291DD70DDE5E8C317E476D1C01E940F6A51E4DBE

SSDEEP:

98304:YUGftbkzURLEz2ebNIFAHH54zmpcnsCLiUDRATL4B1jGJKgqi663XsH/4Bz4ZHPg:jbJXNVmuD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3672)
      • Support-LogMeInRescue.exe (PID: 3972)
      • LMI_Rescue_srv.exe (PID: 3092)
      • Support-LogMeInRescue.exe (PID: 1740)
      • LMI_Rescue_srv.exe (PID: 492)
    • Changes the autorun value in the registry

      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Deletes the SafeBoot registry key

      • LMI_Rescue_srv.exe (PID: 2692)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 3672)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Executable content was dropped or overwritten

      • Support-LogMeInRescue.exe (PID: 3972)
      • LMI_Rescue_srv.exe (PID: 3092)
      • Support-LogMeInRescue.exe (PID: 1740)
      • LMI_Rescue_srv.exe (PID: 492)
    • Reads the Internet Settings

      • LMI_Rescue.exe (PID: 3952)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue.exe (PID: 3684)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Reads the Windows owner or organization settings

      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Application launched itself

      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Executes as Windows Service

      • LMI_Rescue_srv.exe (PID: 2692)
      • LMI_Rescue_srv.exe (PID: 1848)
  • INFO

    • Checks supported languages

      • Support-LogMeInRescue.exe (PID: 3972)
      • LMI_Rescue.exe (PID: 3952)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 3092)
      • LMI_Rescue_srv.exe (PID: 2692)
      • Support-LogMeInRescue.exe (PID: 1740)
      • LMI_Rescue.exe (PID: 3684)
      • LMI_Rescue_srv.exe (PID: 2432)
      • LMI_Rescue_srv.exe (PID: 492)
      • LMI_Rescue_srv.exe (PID: 1848)
    • Creates files or folders in the user directory

      • Support-LogMeInRescue.exe (PID: 3972)
      • LMI_Rescue.exe (PID: 3952)
      • Support-LogMeInRescue.exe (PID: 1740)
      • LMI_Rescue.exe (PID: 3684)
    • Reads the computer name

      • LMI_Rescue.exe (PID: 3952)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 3092)
      • LMI_Rescue_srv.exe (PID: 2692)
      • LMI_Rescue.exe (PID: 3684)
      • LMI_Rescue_srv.exe (PID: 2432)
      • LMI_Rescue_srv.exe (PID: 492)
      • LMI_Rescue_srv.exe (PID: 1848)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3672)
    • Reads the machine GUID from the registry

      • LMI_Rescue.exe (PID: 3952)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 3092)
      • LMI_Rescue_srv.exe (PID: 2692)
      • LMI_Rescue.exe (PID: 3684)
      • LMI_Rescue_srv.exe (PID: 2432)
      • LMI_Rescue_srv.exe (PID: 492)
      • LMI_Rescue_srv.exe (PID: 1848)
    • Checks proxy server information

      • LMI_Rescue.exe (PID: 3952)
      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue.exe (PID: 3684)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Reads Windows Product ID

      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Process checks whether UAC notifications are on

      • LMI_Rescue_srv.exe (PID: 3784)
      • LMI_Rescue_srv.exe (PID: 2432)
    • Creates files in the program directory

      • LMI_Rescue_srv.exe (PID: 3092)
      • LMI_Rescue_srv.exe (PID: 492)
    • Reads the software policy settings

      • LMI_Rescue_srv.exe (PID: 2692)
      • LMI_Rescue_srv.exe (PID: 1848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:03:11 11:26:50
ZipCRC: 0x959c820a
ZipCompressedSize: 2484780
ZipUncompressedSize: 2590056
ZipFileName: Support-LogMeInRescue.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
12
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe support-logmeinrescue.exe lmi_rescue.exe no specs lmi_rescue_srv.exe lmi_rescue_srv.exe lmi_rescue_srv.exe support-logmeinrescue.exe lmi_rescue.exe no specs bcdedit.exe no specs lmi_rescue_srv.exe lmi_rescue_srv.exe lmi_rescue_srv.exe

Process information

PID
CMD
Path
Indicators
Parent process
492"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue_srv.exe" -regrunsvc -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp" -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue_srv.exe
LMI_Rescue_srv.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
HIGH
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10ba8001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
1740"C:\Users\admin\AppData\Local\Temp\Rar$EXa3672.291\Support-LogMeInRescue.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa3672.291\Support-LogMeInRescue.exe
WinRAR.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa3672.291\support-logmeinrescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1848"C:\Program Files\LogMeIn Rescue Applet\LMIR10BAF001.tmp\LMI_Rescue_srv.exe" -service -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1 -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp"C:\Program Files\LogMeIn Rescue Applet\LMIR10BAF001.tmp\LMI_Rescue_srv.exe
services.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\program files\logmein rescue applet\lmir10baf001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
2000C:\Windows\system32\bcdedit.exe /deletevalue safebootC:\Windows\System32\bcdedit.exeLMI_Rescue_srv.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Boot Configuration Data Editor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\bcdedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2432"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue_srv.exe" -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue_srv.exe
LMI_Rescue.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10ba8001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
2692"C:\Program Files\LogMeIn Rescue Applet\LMIR10B6D001.tmp\LMI_Rescue_srv.exe" -service -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1 -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp"C:\Program Files\LogMeIn Rescue Applet\LMIR10B6D001.tmp\LMI_Rescue_srv.exe
services.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\program files\logmein rescue applet\lmir10b6d001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
3092"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\LMI_Rescue_srv.exe" -regrunsvc -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp" -sid f06d961a-b255-ec83-c37a-a567e6e0d8e1C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\LMI_Rescue_srv.exe
LMI_Rescue_srv.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
HIGH
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10b67001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
3672"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Downloads\Support-LogMeInRescue.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3684"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue.exe"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10BA8001.tmp\LMI_Rescue.exeSupport-LogMeInRescue.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10ba8001.tmp\lmi_rescue.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3784"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\LMI_Rescue_srv.exe" -wd "C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp"C:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\LMI_Rescue_srv.exe
LMI_Rescue.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
LogMeIn Rescue
Exit code:
0
Version:
7.51.442
Modules
Images
c:\users\admin\appdata\local\logmein rescue applet\lmir10b67001.tmp\lmi_rescue_srv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
Total events
21 735
Read events
21 653
Write events
74
Delete events
8

Modification events

(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3672) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\Support-LogMeInRescue.zip
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3672) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
30
Suspicious files
16
Text files
6
Unknown types
7

Dropped files

PID
Process
Filename
Type
3952LMI_Rescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\session.logtext
MD5:81051BCC2CF1BEDF378224B0A93E2877
SHA256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\Lmi_Rescue_srv.exeexecutable
MD5:AF694F4246062BAAA9FDACDF6C47F29D
SHA256:329B3A01C9071E263A575E23B88ADCCB6A4F8F5F3EBA2FDADB98C9BC0EB9B2C9
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\RescueWinRTLib.dllexecutable
MD5:1E2B834F5EA12D0572DD34273BEE2E18
SHA256:4ABCE232974AE5A241847101BF63FE31FB5FD5595BC9D765C7E3EBDEC0A5D4D9
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\ra64app.exeexecutable
MD5:ADB5481D6AD334B76B5B2BD48F5E3E03
SHA256:C94ADD9B456766EB610FA11C343CFA3EBB4CFB0A4DF29F15DDD0C707085E3B61
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\rahook.dllexecutable
MD5:8E00263FD552CEA4D39E3EB010754F91
SHA256:2D21B16FB780926A61AA0D9A652EEE08978A2BAA4045202223CF98DA0892ED99
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\LMI_RescueRC.exeexecutable
MD5:CF6EF3D01650867871D61FDA64288DFA
SHA256:7C3117E0930C13ACB3E826305B5A582DCD72EA20C8858F5315440A70B5AC3E4D
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\LMI_Rescue.exeexecutable
MD5:CCEE5DFA73B23F57F457532BD444DD3C
SHA256:64243C03C081CA5A68124730638B64A95B4C6E3D417FCE62F1318DE94FBFD06A
3672WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa3672.43765\Support-LogMeInRescue.exeexecutable
MD5:A76AE1176B3B7A3CE44A1117E066FB2F
SHA256:1BAC0E16322CCB250BF3C00E1C4923F7A0F7775A042937C6DCE56A2933A12876
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\nvdaControllerClient32.dllexecutable
MD5:C84F1A24C88AC9E44409E15CF90DD0F2
SHA256:3E5CE67536F1267F38B347675A9E4BC1368AD20981474838A1016E4588F740C6
3972Support-LogMeInRescue.exeC:\Users\admin\AppData\Local\LogMeIn Rescue Applet\LMIR10B67001.tmp\rescue.icoimage
MD5:8AD28E79941CE3E002804DFE1722EA87
SHA256:63424E176B75642EBAC9E5452ECCC8C6956266DACC0AE4388D636D5BEE5E7933
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2692
LMI_Rescue_srv.exe
158.120.16.94:443
control.rsc-app24-02.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown
1848
LMI_Rescue_srv.exe
158.120.16.91:443
control.rsc-app24-03.logmeinrescue.com
ORACLE-BMC-31898
DE
unknown

DNS requests

Domain
IP
Reputation
rescue-data-center.logmein-gateway.com
  • 216.219.114.24
unknown
rescue-list.24.logmein-gateway.com
unknown
control.rsc-app24-02.logmeinrescue.com
  • 158.120.16.94
unknown
control.rsc-app24-03.logmeinrescue.com
  • 158.120.16.91
unknown

Threats

No threats detected
No debug info