| File name: | RSVP_INVITATION.msi |
| Full analysis: | https://app.any.run/tasks/d8bc462a-0a85-4bcc-9e16-6bc02926e284 |
| Verdict: | Malicious activity |
| Analysis date: | October 03, 2025, 17:55:05 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Number of Pages: 300, Template: Intel;0, Number of Words: 0, Security: 0, Name of Creating Application: Windows Installer, Author: LogMeIn, Inc., Title: LogMeIn Resolve Unattended, Comments: LogMeIn Resolve Unattended v1.27.1.2832, Revision Number: {E9764575-4FF0-4197-9947-9C301EA53E3E} |
| MD5: | 67EC8F02675FC5D022CFA158A2AAAD15 |
| SHA1: | 6E76FA01F4C7EB89F5B3EABD1B76383A6194EEF8 |
| SHA256: | ECBA32DDADBA05A0CB690A0C24A0587917BCD356B245E05631FB4FCE648393CD |
| SSDEEP: | 196608:cxNqcrtPBWO7O7xds5eRwLmx8xLfxWbhdBv9YbhF:2qcrNjYx4e8txWbzGhF |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Pages: | 300 |
| Template: | Intel;0 |
| Words: | - |
| Security: | None |
| Software: | Windows Installer |
| Author: | LogMeIn, Inc. |
| Title: | LogMeIn Resolve Unattended |
| Comments: | LogMeIn Resolve Unattended v1.27.1.2832 |
| RevisionNumber: | {E9764575-4FF0-4197-9947-9C301EA53E3E} |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 332 | "C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349\GoToResolveCrashHandler.exe" "--database=C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349\appdata\ProcessCheckerCrashReportDB" "--metrics-dir=C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349\appdata\ProcessCheckerCrashReportDB" --url=https://dumpster.console.gotoresolve.com/api/dump --annotation=format=minidump --annotation=hostname=DESKTOP-JGLLJLD --annotation=installationid=6W12LtimdA --annotation=version=1.27.1.2832 --initial-client-data=0x7b8,0x7bc,0x7c0,0x6f8,0x7c4,0x70b06fac,0x70b06fbc,0x70b06fcc | C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349\GoToResolveCrashHandler.exe | — | GoToResolveProcessChecker.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Modules
| |||||||||||||||
| 560 | "C:\Windows\System32\msiexec.exe" /i C:\Users\admin\Desktop\RSVP_INVITATION.msi | C:\Windows\System32\msiexec.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1400 | "C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349\GoToResolveTools64.exe" -InstallVDD | C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349\GoToResolveTools64.exe | unattended-updater.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 1532 | timeout /T 3 | C:\Windows\SysWOW64\timeout.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: timeout - pauses command processing Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1916 | GoToResolveQuickView.exe -InstallationId 6W12LtimdA -LogLevel 2 -Environment Production | C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349\GoToResolveQuickView.exe | GoToResolveUnattended.exe | ||||||||||||
User: SYSTEM Company: GoTo, Inc. Integrity Level: SYSTEM Description: LogMeIn Resolve Version: 1.27.1.2832 Modules
| |||||||||||||||
| 2260 | GoToResolveRegistryEditor.exe -CompanyId 8355338843416056349 -Environment Production -InstallationId 6W12LtimdA -LogLevel 2 | C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349\GoToResolveRegistryEditor.exe | GoToResolveUnattended.exe | ||||||||||||
User: SYSTEM Company: GoTo, Inc. Integrity Level: SYSTEM Description: LogMeIn Resolve Version: 1.27.1.2832 Modules
| |||||||||||||||
| 3240 | "C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349\GoToResolveProcessChecker.exe" -regsvc -expectadmin -starterpid 5648 -InstallationId 6W12LtimdA -WorkFolder "C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349" -ApplicationType 4 -Environment "Production" -ForceInstall 0 | C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349\GoToResolveProcessChecker.exe | GoToResolveUnattended.exe | ||||||||||||
User: SYSTEM Company: GoTo, Inc. Integrity Level: SYSTEM Description: LogMeIn Resolve Exit code: 0 Version: 1.27.1.2832 Modules
| |||||||||||||||
| 3984 | GoToResolveServiceManager.exe -CompanyId 8355338843416056349 -Environment Production -InstallationId 6W12LtimdA -LogLevel 2 | C:\Program Files (x86)\GoTo Resolve Unattended\8355338843416056349\GoToResolveServiceManager.exe | GoToResolveUnattended.exe | ||||||||||||
User: SYSTEM Company: GoTo, Inc. Integrity Level: SYSTEM Description: LogMeIn Resolve Version: 1.27.1.2832 Modules
| |||||||||||||||
| 4312 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4372 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | SrTasks.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (7828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 48000000000000006C147AE38E34DC01941E0000201C0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (7828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Enter) |
Value: 48000000000000006C147AE38E34DC01941E0000201C0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (7828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 14 | |||
| (PID) Process: | (7828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 48000000000000004F472FE48E34DC01941E00007C120000E8030000000000000000000000000000EF830524736A0941908C76D43D5D0F6800000000000000000000000000000000 | |||
| (PID) Process: | (7828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGetSnapshots (Leave) |
Value: 4800000000000000B2767CE38E34DC01941E0000201C0000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (7828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Enter) |
Value: 4800000000000000B2767CE38E34DC01941E0000201C0000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (7828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppEnumGroups (Leave) |
Value: 4800000000000000B2767CE38E34DC01941E0000201C0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (7828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 480000000000000002D97EE38E34DC01941E0000201C0000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (7828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4800000000000000329E83E38E34DC01941E0000201C0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (7828) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4800000000000000E70086E38E34DC01941E00007C120000E8030000010000000000000000000000EF830524736A0941908C76D43D5D0F6800000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7828 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 7828 | msiexec.exe | C:\Windows\Installer\174b80.msi | — | |
MD5:— | SHA256:— | |||
| 7828 | msiexec.exe | C:\Windows\Installer\174b82.msi | — | |
MD5:— | SHA256:— | |||
| 560 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB | binary | |
MD5:30EB90E86B2070872E575A61F8685C07 | SHA256:65DA52DBDD381DCF720138AFF4EF6271CE2DF580695DBCDF24D4CFC3010FEE34 | |||
| 560 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_1B47B234E9558C0145847E653CBECED5 | binary | |
MD5:2BE92F8BA477617F21E140D5A3FD0ABC | SHA256:B56F53F68721356EABC86AB3D6E8D08BDEA8BE0A9B298D7ACD4972B6E53A1A63 | |||
| 560 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_1B47B234E9558C0145847E653CBECED5 | binary | |
MD5:8718F80AF6A11CCA93A255EBC35724E9 | SHA256:34F45399FF000F30303F3DA54F89CA27693B0FAD3858EBB3748C8D82128BE4FA | |||
| 560 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141 | binary | |
MD5:B68240A799F7BA8B6146A79D3B1079F0 | SHA256:C19CF1AF7906A0F650C9B495C314B75AFD9FEBBDE90B5192EC235FD756978918 | |||
| 7828 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{240583ef-6a73-4109-908c-76d43d5d0f68}_OnDiskSnapshotProp | binary | |
MD5:82540FF5D8E175EA8D75CB78DF1906FF | SHA256:9B0129541A9309390D9C7300C799FDC6E91FEE7696CD611E83414F1CB803A0A4 | |||
| 7828 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:82540FF5D8E175EA8D75CB78DF1906FF | SHA256:9B0129541A9309390D9C7300C799FDC6E91FEE7696CD611E83414F1CB803A0A4 | |||
| 560 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141 | binary | |
MD5:26455DE7E08C6D1C821C117C5566F50B | SHA256:4D1420D530266ECC2880658C5EEFC699BC19D87153E17846D898E1115947BDEF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
560 | msiexec.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | US | binary | 727 b | whitelisted |
560 | msiexec.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | US | binary | 471 b | whitelisted |
— | — | POST | 202 | 18.185.192.238:443 | https://dumpster.console.gotoresolve.com/api/sendEventsV2 | DE | — | — | unknown |
— | — | POST | 202 | 18.185.192.238:443 | https://dumpster.console.gotoresolve.com/api/sendEventsV2 | DE | — | — | unknown |
— | — | POST | 202 | 18.195.103.52:443 | https://dumpster.console.gotoresolve.com/api/sendEventsV2 | DE | — | — | unknown |
— | — | GET | 200 | 52.206.176.59:443 | https://devices.console.gotoresolve.com/properties | US | binary | 5.17 Kb | unknown |
— | — | POST | 202 | 18.195.103.52:443 | https://dumpster.console.gotoresolve.com/api/sendEventsV2 | DE | — | — | unknown |
— | — | POST | 202 | 18.195.103.52:443 | https://dumpster.console.gotoresolve.com/api/sendEventsV2 | DE | — | — | unknown |
— | — | POST | 202 | 18.185.192.238:443 | https://dumpster.console.gotoresolve.com/api/sendEventsV2 | DE | — | — | unknown |
— | — | POST | 202 | 18.185.192.238:443 | https://dumpster.console.gotoresolve.com/api/sendEventsV2 | DE | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6016 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
560 | msiexec.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
5948 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5648 | GoToResolveUnattended.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
7784 | GoToResolveLoggerProcess.exe | 18.195.103.52:443 | dumpster.console.gotoresolve.com | AMAZON-02 | DE | unknown |
8272 | GoToResolveUnattendedUi.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
5024 | GoToResolveUnattended.exe | 52.206.176.59:443 | devices.console.gotoresolve.com | AMAZON-AES | US | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
dumpster.console.gotoresolve.com |
| unknown |
devices.console.gotoresolve.com |
| unknown |
ip.zscaler.com |
| unknown |
zerotrust.services.gotoresolve.com |
| unknown |
devices-iot.console.gotoresolve.com |
| unknown |
sessions.console.gotoresolve.com |
| unknown |
activation-v2.sls.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2428 | svchost.exe | Misc activity | ET INFO Observed DNS Query to RMM Domain (gotoresolve .com) |
7784 | GoToResolveLoggerProcess.exe | Misc activity | ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI) |
7784 | GoToResolveLoggerProcess.exe | Misc activity | ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI) |
7784 | GoToResolveLoggerProcess.exe | Misc activity | ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI) |
7784 | GoToResolveLoggerProcess.exe | Misc activity | ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI) |
7784 | GoToResolveLoggerProcess.exe | Misc activity | ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI) |
7784 | GoToResolveLoggerProcess.exe | Misc activity | ET INFO Observed RMM Domain (gotoresolve .com in TLS SNI) |
— | — | Misc activity | INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0) |
— | — | Misc activity | INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0) |
— | — | Misc activity | INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0) |
Process | Message |
|---|---|
GoToResolveUnattended.exe | DllMain: DLL_PROCESS_ATTACH: lpReserved=0
|
GoToResolveUnattended.exe | DllMain: DLL_THREAD_ATTACH
|
GoToResolveUnattended.exe | DllMain: DLL_THREAD_ATTACH
|
GoToResolveUnattended.exe | DllMain: DLL_THREAD_ATTACH
|
GoToResolveUnattended.exe | DllMain: DLL_THREAD_ATTACH
|
GoToResolveUnattended.exe | DllMain: DLL_THREAD_ATTACH
|
GoToResolveUnattended.exe | DllMain: DLL_THREAD_DETACH
|
GoToResolveProcessChecker.exe | DllMain: DLL_PROCESS_ATTACH: lpReserved=0
|
GoToResolveProcessChecker.exe | DllMain: DLL_PROCESS_ATTACH: lpReserved=0
|
GoToResolveProcessChecker.exe | DllMain: DLL_THREAD_ATTACH
|