File name:

getscreen-682866376-x86.exe

Full analysis: https://app.any.run/tasks/1bacaf22-c5bf-418a-9a4b-39f3f48a279c
Verdict: Malicious activity
Analysis date: March 05, 2024, 05:52:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
remote
getmescreen
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

CDA32DC88CE1406042EFDA7848D365E6

SHA1:

E32582D85147FA3C0580416C467B661A81DF2141

SHA256:

DDB7E021E2614C38A487379B06C2D369B1394D82E1B869A0A4416EB003C06684

SSDEEP:

98304:fqrJNNcxEpbA8Xv763d5M5ggRVA33Azr1gL/4k2u8iR/mrZZfjDv/wmM+pFo/LIt:ha+WDX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • getscreen-682866376-x86.exe (PID: 1432)
      • getscreen-682866376-x86.exe (PID: 1876)
      • Advanced_IP_Scanner_2.5.4594.1 (3).exe (PID: 3316)
      • Advanced_IP_Scanner_2.5.4594.1 (3).tmp (PID: 908)
    • GETMESCREEN has been detected (SURICATA)

      • getscreen-682866376-x86.exe (PID: 1876)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • getscreen-682866376-x86.exe (PID: 1432)
      • advanced_ip_scanner.exe (PID: 1812)
    • Application launched itself

      • getscreen-682866376-x86.exe (PID: 1432)
      • getscreen-682866376-x86.exe (PID: 1876)
    • Reads the Internet Settings

      • getscreen-682866376-x86.exe (PID: 1432)
      • getscreen-682866376-x86.exe (PID: 1876)
      • advanced_ip_scanner.exe (PID: 1812)
    • Executable content was dropped or overwritten

      • getscreen-682866376-x86.exe (PID: 1876)
      • Advanced_IP_Scanner_2.5.4594.1 (3).exe (PID: 3316)
      • Advanced_IP_Scanner_2.5.4594.1 (3).tmp (PID: 908)
    • Changes Internet Explorer settings (feature browser emulation)

      • getscreen-682866376-x86.exe (PID: 2332)
    • Executes as Windows Service

      • depyhpojtxkgvhrsifwrhhawserdilf-elevate.exe (PID: 3428)
      • VSSVC.exe (PID: 920)
    • Connects to unusual port

      • getscreen-682866376-x86.exe (PID: 1876)
      • advanced_ip_scanner.exe (PID: 1812)
    • Reads the Windows owner or organization settings

      • Advanced_IP_Scanner_2.5.4594.1 (3).tmp (PID: 908)
    • Connects to FTP

      • advanced_ip_scanner.exe (PID: 1812)
    • Process drops legitimate windows executable

      • Advanced_IP_Scanner_2.5.4594.1 (3).tmp (PID: 908)
    • The process drops C-runtime libraries

      • Advanced_IP_Scanner_2.5.4594.1 (3).tmp (PID: 908)
    • Reads settings of System Certificates

      • advanced_ip_scanner.exe (PID: 1812)
    • Uses pipe srvsvc via SMB (transferring data)

      • advanced_ip_scanner.exe (PID: 1812)
    • Reads the history of recent RDP connections

      • mstsc.exe (PID: 3068)
  • INFO

    • Checks supported languages

      • getscreen-682866376-x86.exe (PID: 1432)
      • getscreen-682866376-x86.exe (PID: 1876)
      • getscreen-682866376-x86.exe (PID: 2332)
      • depyhpojtxkgvhrsifwrhhawserdilf-elevate.exe (PID: 3428)
      • getscreen-682866376-x86.exe (PID: 3540)
      • getscreen-682866376-x86.exe (PID: 2756)
      • getscreen-682866376-x86.exe (PID: 1404)
      • getscreen-682866376-x86.exe (PID: 2348)
      • Advanced_IP_Scanner_2.5.4594.1 (3).exe (PID: 3316)
      • advanced_ip_scanner.exe (PID: 1812)
      • Advanced_IP_Scanner_2.5.4594.1 (3).tmp (PID: 908)
    • Reads the computer name

      • getscreen-682866376-x86.exe (PID: 1432)
      • getscreen-682866376-x86.exe (PID: 1876)
      • getscreen-682866376-x86.exe (PID: 2332)
      • depyhpojtxkgvhrsifwrhhawserdilf-elevate.exe (PID: 3428)
      • getscreen-682866376-x86.exe (PID: 2756)
      • getscreen-682866376-x86.exe (PID: 3540)
      • getscreen-682866376-x86.exe (PID: 1404)
      • getscreen-682866376-x86.exe (PID: 2348)
      • Advanced_IP_Scanner_2.5.4594.1 (3).tmp (PID: 908)
      • advanced_ip_scanner.exe (PID: 1812)
    • Creates files in the program directory

      • getscreen-682866376-x86.exe (PID: 1432)
      • getscreen-682866376-x86.exe (PID: 1876)
    • Creates files or folders in the user directory

      • getscreen-682866376-x86.exe (PID: 1876)
      • advanced_ip_scanner.exe (PID: 1812)
    • Reads the machine GUID from the registry

      • getscreen-682866376-x86.exe (PID: 1876)
      • getscreen-682866376-x86.exe (PID: 2348)
      • Advanced_IP_Scanner_2.5.4594.1 (3).tmp (PID: 908)
      • advanced_ip_scanner.exe (PID: 1812)
    • Reads mouse settings

      • getscreen-682866376-x86.exe (PID: 1404)
    • Manual execution by a user

      • Advanced_IP_Scanner_2.5.4594.1 (3).exe (PID: 3316)
    • Create files in a temporary directory

      • Advanced_IP_Scanner_2.5.4594.1 (3).exe (PID: 3316)
      • Advanced_IP_Scanner_2.5.4594.1 (3).tmp (PID: 908)
    • Application launched itself

      • msedge.exe (PID: 1844)
      • msedge.exe (PID: 4080)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 3172)
    • Reads the software policy settings

      • msiexec.exe (PID: 3172)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 3172)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 3172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:01 08:03:49+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.36
CodeSize: 3620864
InitializedDataSize: 20480
UninitializedDataSize: 20402176
EntryPoint: 0x16e9100
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.18.1.0
ProductVersionNumber: 2.18.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (0009)
CharacterSet: Unicode
CompanyName: Getscreen.me
InternalName: Getscreen.me
OriginalFileName: getscreen.exe
ProductName: Getscreen.me
FileVersion: 2.18.1
LegalCopyright: Copyright (C) 2023
ProductVersion: 2.18.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
81
Monitored processes
32
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start getscreen-682866376-x86.exe no specs #GETMESCREEN getscreen-682866376-x86.exe getscreen-682866376-x86.exe no specs depyhpojtxkgvhrsifwrhhawserdilf-elevate.exe no specs getscreen-682866376-x86.exe getscreen-682866376-x86.exe no specs getscreen-682866376-x86.exe getscreen-682866376-x86.exe no specs advanced_ip_scanner_2.5.4594.1 (3).exe advanced_ip_scanner_2.5.4594.1 (3).tmp advanced_ip_scanner.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe vssvc.exe no specs mstsc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
896"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3532 --field-trial-handle=1324,i,6466765729917583022,1897426186185235790,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
908"C:\Users\admin\AppData\Local\Temp\is-U4JNR.tmp\Advanced_IP_Scanner_2.5.4594.1 (3).tmp" /SL5="$1E014C,20439558,139776,C:\Users\admin\Desktop\Advanced_IP_Scanner_2.5.4594.1 (3).exe" C:\Users\admin\AppData\Local\Temp\is-U4JNR.tmp\Advanced_IP_Scanner_2.5.4594.1 (3).tmp
Advanced_IP_Scanner_2.5.4594.1 (3).exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-u4jnr.tmp\advanced_ip_scanner_2.5.4594.1 (3).tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
908"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2212 --field-trial-handle=1336,i,13494372728412551683,9027148353173643715,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
920C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
924"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2160 --field-trial-handle=1324,i,6466765729917583022,1897426186185235790,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1028"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1032 --field-trial-handle=1336,i,13494372728412551683,9027148353173643715,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1404"C:\Users\admin\AppData\Local\Temp\getscreen-682866376-x86.exe" -cpipe \\.\pipe\PCommand96dloslxbscxjnxxp -childC:\Users\admin\AppData\Local\Temp\getscreen-682866376-x86.exe
getscreen-682866376-x86.exe
User:
SYSTEM
Company:
Getscreen.me
Integrity Level:
SYSTEM
Exit code:
0
Version:
2.18.1
Modules
Images
c:\users\admin\appdata\local\temp\getscreen-682866376-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1428"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6ba8f598,0x6ba8f5a8,0x6ba8f5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1432"C:\Users\admin\AppData\Local\Temp\getscreen-682866376-x86.exe" C:\Users\admin\AppData\Local\Temp\getscreen-682866376-x86.exeexplorer.exe
User:
admin
Company:
Getscreen.me
Integrity Level:
MEDIUM
Exit code:
0
Version:
2.18.1
Modules
Images
c:\users\admin\appdata\local\temp\getscreen-682866376-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1504"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1500 --field-trial-handle=1324,i,6466765729917583022,1897426186185235790,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
31 999
Read events
31 671
Write events
313
Delete events
15

Modification events

(PID) Process:(1432) getscreen-682866376-x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1432) getscreen-682866376-x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1432) getscreen-682866376-x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1432) getscreen-682866376-x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2332) getscreen-682866376-x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:getscreen-682866376-x86.exe
Value:
11001
(PID) Process:(2332) getscreen-682866376-x86.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:getscreen-682866376-x86.exe
Value:
11001
(PID) Process:(2332) getscreen-682866376-x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\getscreen.me
Operation:writeName:http
Value:
2
(PID) Process:(2332) getscreen-682866376-x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\getscreen.me
Operation:writeName:https
Value:
2
(PID) Process:(2332) getscreen-682866376-x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\getscreen.me
Operation:writeName:http
Value:
2
(PID) Process:(2332) getscreen-682866376-x86.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\getscreen.me
Operation:writeName:https
Value:
2
Executable files
107
Suspicious files
68
Text files
129
Unknown types
16

Dropped files

PID
Process
Filename
Type
2756getscreen-682866376-x86.exeC:\ProgramData\Getscreen.me\memory\0000pipe0PCommand96dloslxbscxjnxxp0
MD5:
SHA256:
1876getscreen-682866376-x86.exeC:\ProgramData\Getscreen.me\memory\972FC1B7BD6EDA0180AFD96CC16EDA0154070000FFFFFFFF
MD5:
SHA256:
908Advanced_IP_Scanner_2.5.4594.1 (3).tmpC:\Users\admin\AppData\Local\Temp\is-3A0F7.tmp\is-BAEHV.tmp
MD5:
SHA256:
908Advanced_IP_Scanner_2.5.4594.1 (3).tmpC:\Users\admin\AppData\Local\Temp\is-3A0F7.tmp\ip_scan_en_us_Release_2.5.4594.1.msi
MD5:
SHA256:
908Advanced_IP_Scanner_2.5.4594.1 (3).tmpC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner 2\media1.cab
MD5:
SHA256:
1432getscreen-682866376-x86.exeC:\ProgramData\Getscreen.me\logs\20240305.logtext
MD5:995A131E9CAAB74A47D93428466A2DE1
SHA256:3A2BB6C0863FAA6A17A1783A8D6CCE91F0588C14CA523491D341210CDA86485B
1876getscreen-682866376-x86.exeC:\ProgramData\Getscreen.me\depyhpojtxkgvhrsifwrhhawserdilf-elevate.exeexecutable
MD5:CDA32DC88CE1406042EFDA7848D365E6
SHA256:DDB7E021E2614C38A487379B06C2D369B1394D82E1B869A0A4416EB003C06684
908Advanced_IP_Scanner_2.5.4594.1 (3).tmpC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner 2\advanced_ip_scanner_bg_bg.qmbinary
MD5:1D2AAC0633801D7DEF387CF78A968BFF
SHA256:8FDF83BEB8D7E9D3CD0B77DDC636A77A1E4FF591ED10851229ED49BDC78644DF
908Advanced_IP_Scanner_2.5.4594.1 (3).tmpC:\Users\admin\AppData\Local\Temp\is-3A0F7.tmp\aips_is_install_dll.dllexecutable
MD5:57E73855FAD786A59893D6581E9FB5B9
SHA256:3A7A8AA906C65124C4EE82AACB81D723CE69864CCAF041F631B8131DE59E4A88
908Advanced_IP_Scanner_2.5.4594.1 (3).tmpC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner 2\advanced_ip_scanner_da_dk.qmbinary
MD5:AE4754AC60C32B9D44B47CAA489E5337
SHA256:D09D333B00D073C09837F669D7A8DDD77D50B2D94A177E58CE556AF83700371A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
186
DNS requests
38
Threats
1 010

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1812
advanced_ip_scanner.exe
GET
200
188.40.30.100:80
http://www.advanced-ip-scanner.com/checkupdate.php?lng=en&ver=2-5-4594-1&beta=n&type=upd&rmode=r&product=aips
unknown
text
28 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1876
getscreen-682866376-x86.exe
5.75.168.191:443
getscreen.me
Hetzner Online GmbH
DE
unknown
1876
getscreen-682866376-x86.exe
5.9.146.41:443
image.getscreen.me
Hetzner Online GmbH
DE
unknown
1876
getscreen-682866376-x86.exe
45.65.9.108:3478
px-us1.getscreen.me
unknown
1876
getscreen-682866376-x86.exe
95.85.71.16:3478
px-in1.getscreen.me
unknown
1876
getscreen-682866376-x86.exe
103.43.75.192:3478
px-au1.getscreen.me
unknown
1876
getscreen-682866376-x86.exe
162.55.165.163:3478
px-eu1.getscreen.me
unknown
1876
getscreen-682866376-x86.exe
5.161.108.215:3478
px-us2.getscreen.me
Hetzner Online GmbH
US
unknown

DNS requests

Domain
IP
Reputation
getscreen.me
  • 5.75.168.191
  • 78.47.165.25
unknown
image.getscreen.me
  • 5.9.146.41
unknown
px-in1.getscreen.me
  • 95.85.71.16
unknown
px-us1.getscreen.me
  • 45.65.9.108
unknown
px-eu1.getscreen.me
  • 162.55.165.163
unknown
px-il1.getscreen.me
  • 146.185.219.90
unknown
px-au1.getscreen.me
  • 103.43.75.192
unknown
px-br1.getscreen.me
  • 5.188.225.23
unknown
px-us2.getscreen.me
  • 5.161.108.215
unknown
www.advanced-ip-scanner.com
  • 188.40.30.100
shared

Threats

PID
Process
Class
Message
1876
getscreen-682866376-x86.exe
Misc activity
REMOTE [ANY.RUN] GetMeScreen Remote Desctop Software (TURN)
1876
getscreen-682866376-x86.exe
Misc activity
REMOTE [ANY.RUN] GetMeScreen Remote Desctop Software (TURN)
1876
getscreen-682866376-x86.exe
Misc activity
REMOTE [ANY.RUN] GetMeScreen Remote Desctop Software (TURN)
1876
getscreen-682866376-x86.exe
Misc activity
REMOTE [ANY.RUN] GetMeScreen Remote Desctop Software (TURN)
1876
getscreen-682866376-x86.exe
Misc activity
REMOTE [ANY.RUN] GetMeScreen Remote Desctop Software (TURN)
1876
getscreen-682866376-x86.exe
Misc activity
REMOTE [ANY.RUN] GetMeScreen Remote Desctop Software (TURN)
1876
getscreen-682866376-x86.exe
Misc activity
REMOTE [ANY.RUN] GetMeScreen Remote Desctop Software (TURN)
1876
getscreen-682866376-x86.exe
Misc activity
ET INFO Session Traversal Utilities for NAT (STUN Binding Request)
1876
getscreen-682866376-x86.exe
Misc activity
ET INFO Session Traversal Utilities for NAT (STUN Binding Request)
1876
getscreen-682866376-x86.exe
Misc activity
ET INFO Session Traversal Utilities for NAT (STUN Binding Request)
1 ETPRO signatures available at the full report
No debug info