URL:

https://aqlawfirm.com/bid/182invite_s_8DDFF00C56EFFFF12-3-0_c_w.exe

Full analysis: https://app.any.run/tasks/697895b8-bbb3-4b0f-a677-737981405586
Verdict: Malicious activity
Analysis date: October 03, 2025, 17:20:05
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
anti-evasion
logmeinrescue
rmm-tool
arch-exec
Indicators:
MD5:

C145FAD2826474E5A5D518304C9BF512

SHA1:

C8D22C18FC9FC07CCF59662AE516E9FEE1496F45

SHA256:

BFEA5955062A6699DFA811FEAF1844482E2788F33907660E3AB6D5AAD4B43809

SSDEEP:

3:N8iGZIKgjdh1sflt64N:2iPilI4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes settings of System certificates

      • GoToResolveUnattended.exe (PID: 8284)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 182invite_s_8DDFF00C56EFFFF12-3-0_c_w.exe (PID: 5264)
      • GoToResolveTools64.exe (PID: 4208)
      • GoToResolveUnattended.exe (PID: 8284)
      • GoToResolveExternalModuleHandler.exe (PID: 9032)
    • Starts CMD.EXE for commands execution

      • 182invite_s_8DDFF00C56EFFFF12-3-0_c_w.exe (PID: 5264)
      • GoToResolveUnattended.exe (PID: 8284)
    • Executing commands from ".cmd" file

      • 182invite_s_8DDFF00C56EFFFF12-3-0_c_w.exe (PID: 5264)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 9020)
    • Reads security settings of Internet Explorer

      • GoToResolveUnattended.exe (PID: 6404)
      • GoToResolveProcessChecker.exe (PID: 7140)
      • GoToResolveUnattendedUi.exe (PID: 5940)
      • GoToResolveUnattended.exe (PID: 8284)
    • Executes as Windows Service

      • GoToResolveProcessChecker.exe (PID: 7776)
      • WmiApSrv.exe (PID: 6752)
    • The process checks if it is being run in the virtual environment

      • GoToResolveQuickView.exe (PID: 2580)
      • GoTo.Resolve.Alerts.Monitor.App.exe (PID: 5296)
    • Reads the BIOS version

      • GoToResolveQuickView.exe (PID: 2580)
      • GoToResolveUnattended.exe (PID: 8284)
    • LOGMEINRESCUE mutex has been found

      • GoToResolveUnattended.exe (PID: 8284)
    • Creates/Modifies COM task schedule object

      • GoToResolveUnattended.exe (PID: 8284)
    • Adds/modifies Windows certificates

      • GoToResolveUnattended.exe (PID: 8284)
    • Process drops legitimate windows executable

      • GoToResolveExternalModuleHandler.exe (PID: 9032)
    • The process creates files with name similar to system file names

      • GoToResolveExternalModuleHandler.exe (PID: 9032)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 8456)
    • Executing commands from a ".bat" file

      • GoToResolveUnattended.exe (PID: 8284)
  • INFO

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 4532)
    • Creates files or folders in the user directory

      • 182invite_s_8DDFF00C56EFFFF12-3-0_c_w.exe (PID: 5264)
      • GoToResolveUnattended.exe (PID: 6404)
    • Checks supported languages

      • 182invite_s_8DDFF00C56EFFFF12-3-0_c_w.exe (PID: 5264)
      • GoToResolveUnattended.exe (PID: 6404)
      • GoToResolveTools64.exe (PID: 4208)
      • GoToResolveCrashHandler.exe (PID: 2416)
      • drvinst.exe (PID: 8396)
      • GoToResolveProcessChecker.exe (PID: 7140)
      • GoToResolveProcessChecker.exe (PID: 7776)
      • GoToResolveCrashHandler.exe (PID: 8572)
      • GoToResolveUnattended.exe (PID: 8284)
      • GoToResolveLoggerProcess.exe (PID: 7744)
      • GoToResolveCrashHandler.exe (PID: 8596)
      • GoToResolveExternalModuleHandler.exe (PID: 9032)
      • GoToResolveFileManager.exe (PID: 8792)
      • GoToResolveQuickView.exe (PID: 2580)
      • GoToResolveTerminal.exe (PID: 8364)
      • GoToResolveServiceManager.exe (PID: 8440)
      • GoToResolveRegistryEditor.exe (PID: 2528)
      • GoToResolveNetworkChecker.exe (PID: 8476)
      • GoToResolveRemoteControl.exe (PID: 8384)
      • GoToResolveCrashHandler.exe (PID: 6320)
      • GoToResolveUnattendedUi.exe (PID: 5940)
      • GoToResolveCrashHandler.exe (PID: 1824)
      • GoToResolveCrashHandler.exe (PID: 8516)
      • GoToResolveCrashHandler.exe (PID: 8220)
      • GoToResolveCrashHandler.exe (PID: 8664)
      • GoToResolveCrashHandler.exe (PID: 8260)
      • GoToResolveCrashHandler.exe (PID: 5552)
      • GoToResolveCrashHandler.exe (PID: 8952)
      • GoToResolveCrashHandler.exe (PID: 2648)
      • GoToResolveCrashHandler.exe (PID: 8268)
      • GoTo.Resolve.Bcdr.App.exe (PID: 7412)
      • GoTo.Resolve.Alerts.Monitor.App.exe (PID: 5296)
      • GoTo.Resolve.PatchManagement.Client.exe (PID: 4260)
      • RemoteExecution.Runner.exe (PID: 5632)
      • GoToResolveRegistryEditor.exe (PID: 6916)
    • Checks proxy server information

      • slui.exe (PID: 8888)
      • GoToResolveUnattended.exe (PID: 6404)
    • The sample compiled with english language support

      • 182invite_s_8DDFF00C56EFFFF12-3-0_c_w.exe (PID: 5264)
      • GoToResolveTools64.exe (PID: 4208)
      • drvinst.exe (PID: 8396)
      • GoToResolveExternalModuleHandler.exe (PID: 9032)
    • Launching a file from the Downloads directory

      • chrome.exe (PID: 4532)
    • Reads the computer name

      • 182invite_s_8DDFF00C56EFFFF12-3-0_c_w.exe (PID: 5264)
      • GoToResolveUnattended.exe (PID: 6404)
      • GoToResolveTools64.exe (PID: 4208)
      • drvinst.exe (PID: 8396)
      • GoToResolveProcessChecker.exe (PID: 7140)
      • GoToResolveProcessChecker.exe (PID: 7776)
      • GoToResolveUnattended.exe (PID: 8284)
      • GoToResolveFileManager.exe (PID: 8792)
      • GoToResolveExternalModuleHandler.exe (PID: 9032)
      • GoToResolveLoggerProcess.exe (PID: 7744)
      • GoToResolveTerminal.exe (PID: 8364)
      • GoToResolveServiceManager.exe (PID: 8440)
      • GoToResolveRemoteControl.exe (PID: 8384)
      • GoToResolveRegistryEditor.exe (PID: 2528)
      • GoToResolveNetworkChecker.exe (PID: 8476)
      • GoToResolveQuickView.exe (PID: 2580)
      • GoToResolveUnattendedUi.exe (PID: 5940)
      • RemoteExecution.Runner.exe (PID: 5632)
      • GoTo.Resolve.Bcdr.App.exe (PID: 7412)
      • GoTo.Resolve.Alerts.Monitor.App.exe (PID: 5296)
      • GoTo.Resolve.PatchManagement.Client.exe (PID: 4260)
      • GoToResolveRegistryEditor.exe (PID: 6916)
    • Creates a software uninstall entry

      • 182invite_s_8DDFF00C56EFFFF12-3-0_c_w.exe (PID: 5264)
      • GoToResolveProcessChecker.exe (PID: 7140)
      • GoToResolveProcessChecker.exe (PID: 7776)
    • Application launched itself

      • chrome.exe (PID: 4532)
    • Creates files in the program directory

      • 182invite_s_8DDFF00C56EFFFF12-3-0_c_w.exe (PID: 5264)
      • GoToResolveTools64.exe (PID: 4208)
      • GoToResolveCrashHandler.exe (PID: 2416)
      • GoToResolveProcessChecker.exe (PID: 7140)
      • GoToResolveProcessChecker.exe (PID: 7776)
      • GoToResolveCrashHandler.exe (PID: 8572)
      • GoToResolveUnattended.exe (PID: 6404)
      • GoToResolveCrashHandler.exe (PID: 8596)
      • GoToResolveUnattended.exe (PID: 8284)
      • GoToResolveLoggerProcess.exe (PID: 7744)
      • GoToResolveCrashHandler.exe (PID: 6320)
      • GoToResolveExternalModuleHandler.exe (PID: 9032)
      • GoToResolveCrashHandler.exe (PID: 1824)
      • GoToResolveFileManager.exe (PID: 8792)
      • GoToResolveTerminal.exe (PID: 8364)
      • GoToResolveCrashHandler.exe (PID: 8516)
      • GoToResolveQuickView.exe (PID: 2580)
      • GoToResolveCrashHandler.exe (PID: 8664)
      • GoToResolveCrashHandler.exe (PID: 8220)
      • GoToResolveRemoteControl.exe (PID: 8384)
      • GoToResolveCrashHandler.exe (PID: 8260)
      • GoToResolveServiceManager.exe (PID: 8440)
      • GoToResolveRegistryEditor.exe (PID: 2528)
      • GoToResolveNetworkChecker.exe (PID: 8476)
      • GoToResolveUnattendedUi.exe (PID: 5940)
      • GoToResolveCrashHandler.exe (PID: 5552)
      • GoToResolveCrashHandler.exe (PID: 2648)
      • GoToResolveCrashHandler.exe (PID: 8952)
      • GoToResolveCrashHandler.exe (PID: 8268)
      • GoTo.Resolve.Alerts.Monitor.App.exe (PID: 5296)
      • GoTo.Resolve.PatchManagement.Client.exe (PID: 4260)
      • GoTo.Resolve.Bcdr.App.exe (PID: 7412)
      • RemoteExecution.Runner.exe (PID: 5632)
    • Reads the software policy settings

      • slui.exe (PID: 8888)
      • GoToResolveUnattended.exe (PID: 6404)
      • drvinst.exe (PID: 8396)
      • GoToResolveProcessChecker.exe (PID: 7140)
      • GoToResolveProcessChecker.exe (PID: 7776)
      • GoToResolveUnattended.exe (PID: 8284)
      • GoToResolveLoggerProcess.exe (PID: 7744)
      • GoToResolveExternalModuleHandler.exe (PID: 9032)
      • GoToResolveFileManager.exe (PID: 8792)
      • GoToResolveQuickView.exe (PID: 2580)
      • GoToResolveTerminal.exe (PID: 8364)
      • GoToResolveNetworkChecker.exe (PID: 8476)
      • GoToResolveRegistryEditor.exe (PID: 2528)
      • GoToResolveServiceManager.exe (PID: 8440)
      • GoToResolveRemoteControl.exe (PID: 8384)
      • GoToResolveUnattendedUi.exe (PID: 5940)
      • GoTo.Resolve.PatchManagement.Client.exe (PID: 4260)
      • GoTo.Resolve.Alerts.Monitor.App.exe (PID: 5296)
      • RemoteExecution.Runner.exe (PID: 5632)
      • GoTo.Resolve.Bcdr.App.exe (PID: 7412)
      • GoToResolveRegistryEditor.exe (PID: 6916)
    • Reads Environment values

      • GoToResolveTools64.exe (PID: 4208)
      • GoToResolveUnattended.exe (PID: 6404)
      • GoToResolveUnattended.exe (PID: 8284)
      • GoToResolveExternalModuleHandler.exe (PID: 9032)
      • GoToResolveRemoteControl.exe (PID: 8384)
      • GoToResolveQuickView.exe (PID: 2580)
    • Reads CPU info

      • GoToResolveTools64.exe (PID: 4208)
      • GoToResolveUnattended.exe (PID: 6404)
      • GoToResolveUnattended.exe (PID: 8284)
      • GoToResolveRemoteControl.exe (PID: 8384)
      • GoToResolveQuickView.exe (PID: 2580)
      • GoTo.Resolve.Alerts.Monitor.App.exe (PID: 5296)
    • Reads the machine GUID from the registry

      • GoToResolveUnattended.exe (PID: 6404)
      • drvinst.exe (PID: 8396)
      • GoToResolveProcessChecker.exe (PID: 7140)
      • GoToResolveProcessChecker.exe (PID: 7776)
      • GoToResolveLoggerProcess.exe (PID: 7744)
      • GoToResolveUnattended.exe (PID: 8284)
      • GoToResolveExternalModuleHandler.exe (PID: 9032)
      • GoToResolveFileManager.exe (PID: 8792)
      • GoToResolveQuickView.exe (PID: 2580)
      • GoToResolveTerminal.exe (PID: 8364)
      • GoToResolveRegistryEditor.exe (PID: 2528)
      • GoToResolveNetworkChecker.exe (PID: 8476)
      • GoToResolveRemoteControl.exe (PID: 8384)
      • GoToResolveServiceManager.exe (PID: 8440)
      • GoToResolveUnattendedUi.exe (PID: 5940)
      • GoToResolveRegistryEditor.exe (PID: 6916)
    • Create files in a temporary directory

      • GoToResolveTools64.exe (PID: 4208)
    • Process checks computer location settings

      • GoToResolveUnattended.exe (PID: 6404)
      • GoToResolveUnattended.exe (PID: 8284)
      • GoTo.Resolve.Bcdr.App.exe (PID: 7412)
      • GoTo.Resolve.Alerts.Monitor.App.exe (PID: 5296)
      • GoTo.Resolve.PatchManagement.Client.exe (PID: 4260)
      • RemoteExecution.Runner.exe (PID: 5632)
    • Reads the time zone

      • GoToResolveUnattended.exe (PID: 8284)
      • GoTo.Resolve.Alerts.Monitor.App.exe (PID: 5296)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
248
Monitored processes
67
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs slui.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs 182invite_s_8ddff00c56effff12-3-0_c_w.exe no specs 182invite_s_8ddff00c56effff12-3-0_c_w.exe gotoresolveunattended.exe gotoresolvetools64.exe cmd.exe no specs conhost.exe no specs gotoresolvecrashhandler.exe no specs timeout.exe no specs drvinst.exe no specs gotoresolveprocesschecker.exe gotoresolveprocesschecker.exe timeout.exe no specs gotoresolvecrashhandler.exe no specs gotoresolveunattended.exe gotoresolveloggerprocess.exe gotoresolvecrashhandler.exe no specs gotoresolveexternalmodulehandler.exe gotoresolvefilemanager.exe gotoresolvequickview.exe tiworker.exe no specs gotoresolveterminal.exe gotoresolveservicemanager.exe gotoresolveremotecontrol.exe gotoresolveregistryeditor.exe gotoresolvenetworkchecker.exe gotoresolvecrashhandler.exe no specs gotoresolveunattendedui.exe gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs gotoresolvecrashhandler.exe no specs chrome.exe no specs chrome.exe no specs remoteexecution.runner.exe conhost.exe no specs goto.resolve.bcdr.app.exe conhost.exe no specs goto.resolve.patchmanagement.client.exe goto.resolve.alerts.monitor.app.exe conhost.exe no specs conhost.exe no specs where.exe no specs cmd.exe no specs conhost.exe no specs wmiapsrv.exe no specs ping.exe no specs gotoresolveregistryeditor.exe

Process information

PID
CMD
Path
Indicators
Parent process
588"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=2928,i,2951900705501237766,9930247634611002232,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=5916 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
600\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1536"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=133.0.6943.127 --initial-client-data=0x21c,0x220,0x224,0x1f8,0x228,0x7ffba225fff8,0x7ffba2260004,0x7ffba2260010C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1824"C:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\GoToResolveCrashHandler.exe" "--database=C:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\appdata\ExternalModuleHandlerCrashReportDB" "--metrics-dir=C:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\appdata\ExternalModuleHandlerCrashReportDB" --url=https://dumpster.console.gotoresolve.com/api/dump --annotation=format=minidump --annotation=hostname=DESKTOP-JGLLJLD --annotation=installationid=T8peDqrIVe --annotation=version=1.27.1.2836 --initial-client-data=0x7c0,0x7c4,0x7c8,0x63c,0x7cc,0x70e26fac,0x70e26fbc,0x70e26fccC:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\GoToResolveCrashHandler.exeGoToResolveExternalModuleHandler.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\program files (x86)\goto resolve unattended\782818644527742485\gotoresolvecrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1924"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgABAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=1964,i,2951900705501237766,9930247634611002232,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=1948 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2416"C:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\GoToResolveCrashHandler.exe" "--database=C:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\appdata\CrashReportDB" "--metrics-dir=C:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\appdata\CrashReportDB" --url=https://dumpster.console.gotoresolve.com/api/dump --annotation=format=minidump --annotation=hostname=DESKTOP-JGLLJLD --annotation=version=1.24.0.142 --initial-client-data=0x340,0x344,0x348,0x330,0x34c,0x7ff73e4abaf8,0x7ff73e4abb10,0x7ff73e4abb28C:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\GoToResolveCrashHandler.exeGoToResolveTools64.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\goto resolve unattended\782818644527742485\gotoresolvecrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2528GoToResolveRegistryEditor.exe -CompanyId 782818644527742485 -Environment Production -InstallationId T8peDqrIVe -LogLevel 2C:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\GoToResolveRegistryEditor.exe
GoToResolveUnattended.exe
User:
SYSTEM
Company:
GoTo, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Resolve
Exit code:
0
Version:
1.27.1.2836
Modules
Images
c:\program files (x86)\goto resolve unattended\782818644527742485\gotoresolveregistryeditor.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\msvcp_win.dll
2568"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=1928,i,2951900705501237766,9930247634611002232,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=1940 /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2580GoToResolveQuickView.exe -InstallationId T8peDqrIVe -LogLevel 2 -Environment ProductionC:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\GoToResolveQuickView.exe
GoToResolveUnattended.exe
User:
SYSTEM
Company:
GoTo, Inc.
Integrity Level:
SYSTEM
Description:
LogMeIn Resolve
Exit code:
0
Version:
1.27.1.2836
Modules
Images
c:\program files (x86)\goto resolve unattended\782818644527742485\gotoresolvequickview.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\msvcp_win.dll
2648"C:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\GoToResolveCrashHandler.exe" "--database=C:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\appdata\NetworkCheckerCrashReportDB" "--metrics-dir=C:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\appdata\NetworkCheckerCrashReportDB" --url=https://dumpster.console.gotoresolve.com/api/dump --annotation=format=minidump --annotation=hostname=DESKTOP-JGLLJLD --annotation=installationid=T8peDqrIVe --annotation=version=1.27.1.2836 --initial-client-data=0x76c,0x770,0x774,0x744,0x778,0x70e26fac,0x70e26fbc,0x70e26fccC:\Program Files (x86)\GoTo Resolve Unattended\782818644527742485\GoToResolveCrashHandler.exeGoToResolveNetworkChecker.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files (x86)\goto resolve unattended\782818644527742485\gotoresolvecrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
Total events
97 573
Read events
97 485
Write events
52
Delete events
36

Modification events

(PID) Process:(4532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(4532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(4532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(4532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(4532) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(4532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Common\Rlz\Events\C
Operation:writeName:C1I
Value:
1
(PID) Process:(4532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Common\Rlz\Events\C
Operation:writeName:C2I
Value:
1
(PID) Process:(4532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Common\Rlz\Events\C
Operation:writeName:C7I
Value:
1
(PID) Process:(4532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Common\Rlz\Events\C
Operation:writeName:C1S
Value:
1
(PID) Process:(4532) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Common\Rlz\Events\C
Operation:writeName:C7S
Value:
1
Executable files
518
Suspicious files
326
Text files
65
Unknown types
0

Dropped files

PID
Process
Filename
Type
4532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old~RF17124f.TMP
MD5:
SHA256:
4532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old
MD5:
SHA256:
4532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF17125f.TMP
MD5:
SHA256:
4532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF17125f.TMP
MD5:
SHA256:
4532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old
MD5:
SHA256:
4532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
4532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF17126e.TMP
MD5:
SHA256:
4532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old~RF17126e.TMP
MD5:
SHA256:
4532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
4532chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF17126e.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
82
DNS requests
52
Threats
41

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7776
GoToResolveProcessChecker.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEA4Mh2e7LU%2FvwtYX3xHOG4k%3D
DE
binary
727 b
whitelisted
2568
chrome.exe
GET
200
142.250.185.142:80
http://clients2.google.com/time/1/current?cup2key=8:jZeTBuFSgJrfhfrGAxo8mbScgYJYwrgR-oaMmo0ECjQ&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
106 b
whitelisted
8592
backgroundTaskHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
whitelisted
8556
backgroundTaskHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
binary
313 b
whitelisted
8076
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acpeapixpwuzscfa5h5j5m7c4xaa_2025.6.16.0/niikhdgajlphfehepabhhblakbdgeefj_2025.06.16.00_all_acgsomx5qtwgffxcrxwhoksfom7q.crx3
US
whitelisted
8076
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acpeapixpwuzscfa5h5j5m7c4xaa_2025.6.16.0/niikhdgajlphfehepabhhblakbdgeefj_2025.06.16.00_all_acgsomx5qtwgffxcrxwhoksfom7q.crx3
US
binary
1.09 Kb
whitelisted
8648
backgroundTaskHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
whitelisted
8076
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acpeapixpwuzscfa5h5j5m7c4xaa_2025.6.16.0/niikhdgajlphfehepabhhblakbdgeefj_2025.06.16.00_all_acgsomx5qtwgffxcrxwhoksfom7q.crx3
US
binary
132 b
whitelisted
8076
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acpeapixpwuzscfa5h5j5m7c4xaa_2025.6.16.0/niikhdgajlphfehepabhhblakbdgeefj_2025.06.16.00_all_acgsomx5qtwgffxcrxwhoksfom7q.crx3
US
binary
924 b
whitelisted
8076
svchost.exe
GET
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/V3P1l2hLvLw_7/7_all_sslErrorAssistant.crx3
US
binary
5.28 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5904
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2568
chrome.exe
172.217.18.10:443
safebrowsingohttpgateway.googleapis.com
GOOGLE
US
whitelisted
4
System
192.168.100.255:138
whitelisted
2568
chrome.exe
142.250.185.142:80
clients2.google.com
GOOGLE
US
whitelisted
2568
chrome.exe
108.177.15.84:443
accounts.google.com
GOOGLE
US
whitelisted
2568
chrome.exe
208.79.238.8:443
aqlawfirm.com
LIQUIDWEB
US
unknown
4532
chrome.exe
224.0.0.251:5353
whitelisted
2568
chrome.exe
142.250.185.196:443
www.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
clients2.google.com
  • 142.250.185.142
whitelisted
safebrowsingohttpgateway.googleapis.com
  • 172.217.18.10
  • 142.250.185.106
  • 172.217.16.138
  • 142.250.186.74
  • 142.250.184.202
  • 142.250.186.138
  • 142.250.185.138
  • 142.250.185.170
  • 142.250.185.74
  • 172.217.18.106
  • 216.58.212.138
  • 142.250.186.106
  • 142.250.186.170
  • 142.250.186.42
  • 142.250.185.202
  • 142.250.184.234
whitelisted
aqlawfirm.com
  • 208.79.238.8
unknown
accounts.google.com
  • 108.177.15.84
whitelisted
www.google.com
  • 142.250.185.196
whitelisted
www.bing.com
  • 2.16.241.201
  • 2.16.241.205
  • 2.16.241.218
  • 2.16.241.207
whitelisted
login.live.com
  • 40.126.31.71
  • 40.126.31.131
  • 40.126.31.0
  • 20.190.159.75
  • 20.190.159.73
  • 40.126.31.129
  • 20.190.159.129
  • 40.126.31.128
whitelisted
ocsp.digicert.com
  • 162.159.142.9
  • 172.66.2.5
  • 2.17.190.73
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2428
svchost.exe
Misc activity
ET INFO Observed DNS Query to RMM Domain (gotoresolve .com)
7744
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
7744
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
7744
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
7744
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
7744
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
7744
GoToResolveLoggerProcess.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
2428
svchost.exe
Misc activity
ET INFO Observed DNS Query to RMM Domain (gotoresolve .com)
8284
GoToResolveUnattended.exe
Misc activity
ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI)
Process
Message
GoToResolveUnattended.exe
DllMain: DLL_PROCESS_ATTACH: lpReserved=0
GoToResolveUnattended.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveUnattended.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveUnattended.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveUnattended.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveUnattended.exe
DllMain: DLL_THREAD_ATTACH
GoToResolveUnattended.exe
DllMain: DLL_THREAD_DETACH
GoToResolveProcessChecker.exe
DllMain: DLL_PROCESS_ATTACH: lpReserved=0
GoToResolveProcessChecker.exe
DllMain: DLL_PROCESS_ATTACH: lpReserved=0
GoToResolveProcessChecker.exe
DllMain: DLL_THREAD_ATTACH