File name: | GoToAssist.exe |
Full analysis: | https://app.any.run/tasks/bfbc8d9e-300b-4d46-97a3-5eb76b232567 |
Verdict: | Malicious activity |
Analysis date: | September 01, 2021, 15:18:26 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | B8D3798945D3181C689A452D7F81A8C1 |
SHA1: | 79484B554045D3693667AD9E2DF45F928F511FD2 |
SHA256: | F1DF9236CD93A9D00563D0C511B03895F3BF58C1B6835D7328BCECD041A1BF2A |
SSDEEP: | 196608:5JO4CoYOsmI/w0Ifh+sD07wzOCq4BnT0be5FvmxBLk9eOlBnQ8mMTPwPJCKxNPAk:5Jxn0AhSwzOzU0a9mqPnQ8msPw8KLbx |
.exe | | | Win64 Executable (generic) (64.6) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (15.4) |
.exe | | | Win32 Executable (generic) (10.5) |
.exe | | | Generic Win/DOS Executable (4.6) |
.exe | | | DOS Executable Generic (4.6) |
ProductVersion: | 5.6.0.1373 |
---|---|
ProductName: | GoToAssist |
OriginalFileName: | GoToAssistService.exe |
LegalCopyright: | Copyright © 2016-2021 LogMeIn, Inc. US patents pending. |
InternalName: | GoToAssistService.exe |
FileVersion: | 5.6.0.1373 |
FileDescription: | GoToAssist Remote Support |
CompanyName: | LogMeIn, Inc. |
CharacterSet: | Unicode |
LanguageCode: | Unknown (0009) |
FileSubtype: | - |
ObjectFileType: | Executable application |
FileOS: | Windows NT 32-bit |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 5.6.0.1373 |
FileVersionNumber: | 5.6.0.1373 |
Subsystem: | Windows GUI |
SubsystemVersion: | 6 |
ImageVersion: | - |
OSVersion: | 6 |
EntryPoint: | 0x9409 |
UninitializedDataSize: | - |
InitializedDataSize: | 13115904 |
CodeSize: | 265728 |
LinkerVersion: | 14.28 |
PEType: | PE32 |
TimeStamp: | 2021:08:16 17:12:25+02:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 16-Aug-2021 15:12:25 |
Detected languages: |
|
Debug artifacts: |
|
CompanyName: | LogMeIn, Inc. |
FileDescription: | GoToAssist Remote Support |
FileVersion: | 5.6.0.1373 |
InternalName: | GoToAssistService.exe |
LegalCopyright: | Copyright © 2016-2021 LogMeIn, Inc. US patents pending. |
OriginalFilename: | GoToAssistService.exe |
ProductName: | GoToAssist |
ProductVersion: | 5.6.0.1373 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000110 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 5 |
Time date stamp: | 16-Aug-2021 15:12:25 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00040C8E | 0x00040E00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.63718 |
.rdata | 0x00042000 | 0x0001173E | 0x00011800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.32191 |
.data | 0x00054000 | 0x0000267C | 0x00001800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.90544 |
.rsrc | 0x00057000 | 0x00C6BF40 | 0x00C6C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.98865 |
.reloc | 0x00CC3000 | 0x00003074 | 0x00003200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.5122 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 4.91161 | 381 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 5.31778 | 1384 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 3.03072 | 744 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 5.76011 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 2.7042 | 1640 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 5.65748 | 3752 | Latin 1 / Western European | English - United States | RT_ICON |
7 | 5.03195 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
8 | 5.75016 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
9 | 5.8361 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
10 | 4.58285 | 270376 | Latin 1 / Western European | English - United States | RT_ICON |
ADVAPI32.dll |
KERNEL32.dll |
SHLWAPI.dll |
USER32.dll |
WTSAPI32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
568 | "C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exe" "--attachment=attachment_params.json=C:/Users/admin/AppData/Local/GoToAssist Remote Support Applet/LMI0001.tmpparams.json" "--attachment=attachment_GoToAssistProcessChecker.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.log" "--attachment=attachment_GoToAssistProcessChecker.srv.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.srv.log" "--attachment=attachment_GoToAssistService.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistService.log" "--attachment=attachment_GoToAssistService.srv.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistService.srv.log" "--database=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\LoggerProcessCrashReportDB" "--metrics-dir=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\LoggerProcessCrashReportDB" --url=https://dumpster.console.gotoassist.com/api/dump?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE2MzA1OTQ4ODIsImlhdCI6MTYzMDUwODQ4Mn0.zqz7E1psaUfzPev_mx2Gs8rKy6Qa8A4heSelNaEl7Ug --annotation=format=minidump --annotation=hostname=User-PC --annotation=installationid=BXuVGx74O1 --annotation=sessionid=8a24dd27-3744-444a-a3d1-b63b51ea8ee9 --annotation=version=5.6.0.1373 --initial-client-data=0x2ac,0x2b0,0x2b4,0x2a4,0x2b8,0x6b74bd00,0x6b74bd10,0x6b74bd20 | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exe | — | GoToAssistLoggerProcess.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
704 | "C:/Users/admin/AppData/Local/GoToAssist Remote Support Applet/LMI0001.tmp/GoToAssistService.exe" "-RegisteredProcess" "1" "-ParentProcessId" "3076" "-WtsStartingUsername" "USER-PC\admin" "-ServiceName" "G2ARemoteSupport_attended" "-Service" | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistService.exe | GoToAssistProcessChecker.exe | ||||||||||||
User: SYSTEM Company: LogMeIn, Inc. Integrity Level: SYSTEM Description: GoToAssist Remote Support Exit code: 0 Version: 5.6.0.1373 Modules
| |||||||||||||||
744 | "C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistService.exe" | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistService.exe | — | GoToAssist.exe | |||||||||||
User: admin Company: LogMeIn, Inc. Integrity Level: MEDIUM Description: GoToAssist Remote Support Exit code: 0 Version: 5.6.0.1373 Modules
| |||||||||||||||
760 | cmd.exe /S /C ""C:\Users\admin\AppData\Local\Temp\GoToAssist.exe.cmd" "C:\Users\admin\AppData\Local\Temp\GoToAssist.exe"" | C:\Windows\system32\cmd.exe | — | GoToAssist.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
832 | "C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exe" "--attachment=attachment_GoToAssistProcessChecker.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.log" "--attachment=attachment_GoToAssistProcessChecker.srv.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.srv.log" "--attachment=attachment_GoToAssistService.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistService.log" "--database=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\ProcessCheckerCrashReportDB" "--metrics-dir=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\ProcessCheckerCrashReportDB" --url=https://dumpster.console.gotoassist.com/api/dump?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE2MzA1OTQ4ODIsImlhdCI6MTYzMDUwODQ4Mn0.zqz7E1psaUfzPev_mx2Gs8rKy6Qa8A4heSelNaEl7Ug --annotation=format=minidump --annotation=hostname=User-PC --annotation=installationid=BXuVGx74O1 --annotation=sessionid=8a24dd27-3744-444a-a3d1-b63b51ea8ee9 --annotation=version=5.6.0.1373 --initial-client-data=0x324,0x328,0x32c,0x320,0x330,0x6b74bd00,0x6b74bd10,0x6b74bd20 | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exe | — | GoToAssistProcessChecker.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
900 | "C:/Users/admin/AppData/Local/GoToAssist Remote Support Applet/LMI0001.tmp/GoToAssistProcessChecker.exe" "-delsvc" "-ApplicationType" "1" | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistProcessChecker.exe | GoToAssistService.exe | ||||||||||||
User: SYSTEM Company: LogMeIn, Inc. Integrity Level: SYSTEM Description: GoToAssist Remote Support Exit code: 0 Version: 5.6.0.1373 Modules
| |||||||||||||||
952 | "C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exe" "--attachment=attachment_params.json=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\params.json" "--attachment=attachment_GoToAssistProcessChecker.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.log" "--attachment=attachment_GoToAssistProcessChecker.srv.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.srv.log" "--attachment=attachment_GoToAssistService.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistService.log" "--attachment=attachment_GoToAssistService.srv.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistService.srv.log" "--database=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\ServiceCrashReportDB" "--metrics-dir=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\ServiceCrashReportDB" --url=https://dumpster.console.gotoassist.com/api/dump?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE2MzA1OTQ4ODIsImlhdCI6MTYzMDUwODQ4Mn0.zqz7E1psaUfzPev_mx2Gs8rKy6Qa8A4heSelNaEl7Ug --annotation=format=minidump --annotation=hostname=User-PC --annotation=installationid=BXuVGx74O1 --annotation=sessionid=8a24dd27-3744-444a-a3d1-b63b51ea8ee9 --annotation=version=5.6.0.1373 --initial-client-data=0x370,0x3c4,0x3c8,0x3c0,0x3cc,0x6b74bd00,0x6b74bd10,0x6b74bd20 | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exe | — | GoToAssistService.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
1760 | GoToAssistLoggerProcess.exe -HostId 52abd0f3251d22b05ca02f33073216ba -SessionType Attended -InstallationId BXuVGx74O1 -DeviceId "" -LogLevel 2 | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistLoggerProcess.exe | GoToAssistService.exe | ||||||||||||
User: SYSTEM Company: LogMeIn, Inc. Integrity Level: SYSTEM Description: GoToAssist Remote Support Exit code: 0 Version: 5.6.0.1373 Modules
| |||||||||||||||
1828 | C:\Windows\system32\bcdedit.exe /deletevalue safeboot | C:\Windows\system32\bcdedit.exe | — | GoToAssistService.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Boot Configuration Data Editor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2488 | "C:\Users\admin\AppData\Local\Temp\GoToAssist.exe" | C:\Users\admin\AppData\Local\Temp\GoToAssist.exe | Explorer.EXE | ||||||||||||
User: admin Company: LogMeIn, Inc. Integrity Level: MEDIUM Description: GoToAssist Remote Support Exit code: 0 Version: 5.6.0.1373 Modules
|
(PID) Process: | (744) GoToAssistService.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (744) GoToAssistService.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (744) GoToAssistService.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (744) GoToAssistService.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (2844) GoToAssistProcessChecker.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\G2ARemoteSupport_attended |
Operation: | write | Name: | (default) |
Value: Service | |||
(PID) Process: | (3076) GoToAssistProcessChecker.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\171\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (704) GoToAssistService.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\171\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (704) GoToAssistService.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
Operation: | write | Name: | GoToAssist_Cleanup_BXuVGx74O1 |
Value: C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\cleanup.bat | |||
(PID) Process: | (900) GoToAssistProcessChecker.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\G2ARemoteSupport_attended |
Operation: | delete key | Name: | (default) |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
2488 | GoToAssist.exe | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMIInputHook32.dll | executable | |
MD5:49F523055F29CCECD29833FB28EF8BAE | SHA256:214F5CAE813A8465CB842D53203FAF481EC6C1622359946A6E6DEFDB086A0CA6 | |||
2488 | GoToAssist.exe | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistService.exe | executable | |
MD5:3BDF02A9831922F1CD4B97AA2BC335B0 | SHA256:DB33B245F9B2B985D342034B71B1E99199BEEE9683BAA1ED975E8F291331F07E | |||
2488 | GoToAssist.exe | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMISupport7x32.dll | executable | |
MD5:57ABBC0C5B94B51D1846232E1E9F844E | SHA256:1994D94087BA56140B56C2C8D4A2C43BA5CB4C32FB658704C9B8F2D27EA7FBF0 | |||
2488 | GoToAssist.exe | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMIInputHook64.dll | executable | |
MD5:796AE55073AD592FFBA533A196F694F6 | SHA256:1DCFEB644B439E2919AEFB18DBD8ACC5151877ADCA83B1D2C9BA5ECE6A131C0D | |||
2488 | GoToAssist.exe | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMIFilterHook32.dll | executable | |
MD5:D440203A37B3BCBFDF272B8D36AD5CB9 | SHA256:C078C6426132C343FA85D7FDA57A9997A5E8BD421C63FC8EBE89B48AC708606D | |||
2488 | GoToAssist.exe | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\lmiscrhook32.dll | executable | |
MD5:00D1AFE4A647D2FEA8E6CC93ECC6F056 | SHA256:D4A3985B3618E7E46A33DA12755CC20E969715F3F5FA5010545B32A8B89EA7A7 | |||
2488 | GoToAssist.exe | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMISupportM32.exe | executable | |
MD5:C7AF8173F79286374D466242D7DE4A6C | SHA256:17055AE50F49B00B202C779C7A65AEE1D7AF092D760E38489B56803FCE9DC2DE | |||
2488 | GoToAssist.exe | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMISupportM64.exe | executable | |
MD5:4AF214B1869AFDAB3D7EB4EF593A34D5 | SHA256:D1017231304A9EB1927CC2714D421675132D78643DC5C66378CC3E1A190119D7 | |||
2488 | GoToAssist.exe | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\lmiscrhook64.dll | executable | |
MD5:7BAFA136DC339F37AEFF9B435F90E599 | SHA256:FA2348FABBA639E4B6F3A27D4C2426C7141323FC7802E3DA77F37324EBB33E6E | |||
2488 | GoToAssist.exe | C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\PasswordPrivacyDll.dll | executable | |
MD5:4FFEFA8A92321594BAB2BE0B28871D63 | SHA256:9511494466E83176D839B16EB4B60D162DC8975DE66995C47C7F48B6BA8FA530 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1760 | GoToAssistLoggerProcess.exe | 52.57.43.61:443 | dumpster.console.gotoassist.com | Amazon.com, Inc. | DE | unknown |
704 | GoToAssistService.exe | 3.92.208.61:443 | prd-ava-be06.console.gotoassist.com | — | US | unknown |
Domain | IP | Reputation |
---|---|---|
prd-ava-be06.console.gotoassist.com |
| unknown |
dumpster.console.gotoassist.com |
| unknown |
Process | Message |
---|---|
GoToAssistProcessChecker.exe | MainThread: created
|
GoToAssistProcessChecker.exe | MainThread: created
|
GoToAssistService.exe | MainThread: created
|
GoToAssistProcessChecker.exe | MainThread: created
|