File name:

GoToAssist.exe

Full analysis: https://app.any.run/tasks/bfbc8d9e-300b-4d46-97a3-5eb76b232567
Verdict: Malicious activity
Analysis date: September 01, 2021, 15:18:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B8D3798945D3181C689A452D7F81A8C1

SHA1:

79484B554045D3693667AD9E2DF45F928F511FD2

SHA256:

F1DF9236CD93A9D00563D0C511B03895F3BF58C1B6835D7328BCECD041A1BF2A

SSDEEP:

196608:5JO4CoYOsmI/w0Ifh+sD07wzOCq4BnT0be5FvmxBLk9eOlBnQ8mMTPwPJCKxNPAk:5Jxn0AhSwzOzU0a9mqPnQ8msPw8KLbx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GoToAssistService.exe (PID: 744)
      • GoToAssistProcessChecker.exe (PID: 2844)
      • GoToAssistProcessChecker.exe (PID: 3076)
      • GoToAssistCrashHandler.exe (PID: 832)
      • GoToAssistCrashHandler.exe (PID: 952)
      • GoToAssistLoggerProcess.exe (PID: 1760)
      • GoToAssistCrashHandler.exe (PID: 568)
      • GoToAssistService.exe (PID: 704)
      • GoToAssistProcessChecker.exe (PID: 900)
    • Loads dropped or rewritten executable

      • GoToAssistService.exe (PID: 744)
      • GoToAssistProcessChecker.exe (PID: 2844)
      • GoToAssistProcessChecker.exe (PID: 3076)
      • GoToAssistService.exe (PID: 704)
      • GoToAssistLoggerProcess.exe (PID: 1760)
      • GoToAssistProcessChecker.exe (PID: 900)
    • Deletes the SafeBoot registry key

      • GoToAssistProcessChecker.exe (PID: 900)
    • Changes the autorun value in the registry

      • GoToAssistService.exe (PID: 704)
  • SUSPICIOUS

    • Drops a file with a compile date too recent

      • GoToAssist.exe (PID: 2488)
    • Drops a file that was compiled in debug mode

      • GoToAssist.exe (PID: 2488)
    • Executable content was dropped or overwritten

      • GoToAssist.exe (PID: 2488)
    • Checks supported languages

      • GoToAssist.exe (PID: 2488)
      • GoToAssistService.exe (PID: 744)
      • cmd.exe (PID: 760)
      • GoToAssistProcessChecker.exe (PID: 2844)
      • GoToAssistProcessChecker.exe (PID: 3076)
      • GoToAssistCrashHandler.exe (PID: 832)
      • GoToAssistService.exe (PID: 704)
      • GoToAssistCrashHandler.exe (PID: 952)
      • GoToAssistLoggerProcess.exe (PID: 1760)
      • GoToAssistProcessChecker.exe (PID: 900)
      • GoToAssistCrashHandler.exe (PID: 568)
    • Starts CMD.EXE for commands execution

      • GoToAssist.exe (PID: 2488)
    • Reads the computer name

      • GoToAssistService.exe (PID: 744)
      • GoToAssistProcessChecker.exe (PID: 2844)
      • GoToAssistProcessChecker.exe (PID: 3076)
      • GoToAssistService.exe (PID: 704)
      • GoToAssistLoggerProcess.exe (PID: 1760)
      • GoToAssistProcessChecker.exe (PID: 900)
    • Reads CPU info

      • GoToAssistService.exe (PID: 744)
      • GoToAssistService.exe (PID: 704)
    • Executed as Windows Service

      • GoToAssistProcessChecker.exe (PID: 3076)
  • INFO

    • Reads settings of System Certificates

      • GoToAssistService.exe (PID: 744)
      • GoToAssistService.exe (PID: 704)
      • GoToAssistLoggerProcess.exe (PID: 1760)
    • Checks supported languages

      • bcdedit.exe (PID: 1828)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

ProductVersion: 5.6.0.1373
ProductName: GoToAssist
OriginalFileName: GoToAssistService.exe
LegalCopyright: Copyright © 2016-2021 LogMeIn, Inc. US patents pending.
InternalName: GoToAssistService.exe
FileVersion: 5.6.0.1373
FileDescription: GoToAssist Remote Support
CompanyName: LogMeIn, Inc.
CharacterSet: Unicode
LanguageCode: Unknown (0009)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 5.6.0.1373
FileVersionNumber: 5.6.0.1373
Subsystem: Windows GUI
SubsystemVersion: 6
ImageVersion: -
OSVersion: 6
EntryPoint: 0x9409
UninitializedDataSize: -
InitializedDataSize: 13115904
CodeSize: 265728
LinkerVersion: 14.28
PEType: PE32
TimeStamp: 2021:08:16 17:12:25+02:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 16-Aug-2021 15:12:25
Detected languages:
  • English - United States
Debug artifacts:
  • C:\build.tc\agent\work\464efc35df4c0270\bin\product\x86_G2ARelease\LogMeInBold360.pdb
CompanyName: LogMeIn, Inc.
FileDescription: GoToAssist Remote Support
FileVersion: 5.6.0.1373
InternalName: GoToAssistService.exe
LegalCopyright: Copyright © 2016-2021 LogMeIn, Inc. US patents pending.
OriginalFilename: GoToAssistService.exe
ProductName: GoToAssist
ProductVersion: 5.6.0.1373

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000110

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 16-Aug-2021 15:12:25
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00040C8E
0x00040E00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.63718
.rdata
0x00042000
0x0001173E
0x00011800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.32191
.data
0x00054000
0x0000267C
0x00001800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.90544
.rsrc
0x00057000
0x00C6BF40
0x00C6C000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.98865
.reloc
0x00CC3000
0x00003074
0x00003200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.5122

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.91161
381
Latin 1 / Western European
English - United States
RT_MANIFEST
2
5.31778
1384
Latin 1 / Western European
English - United States
RT_ICON
3
3.03072
744
Latin 1 / Western European
English - United States
RT_ICON
4
5.76011
2216
Latin 1 / Western European
English - United States
RT_ICON
5
2.7042
1640
Latin 1 / Western European
English - United States
RT_ICON
6
5.65748
3752
Latin 1 / Western European
English - United States
RT_ICON
7
5.03195
1128
Latin 1 / Western European
English - United States
RT_ICON
8
5.75016
4264
Latin 1 / Western European
English - United States
RT_ICON
9
5.8361
9640
Latin 1 / Western European
English - United States
RT_ICON
10
4.58285
270376
Latin 1 / Western European
English - United States
RT_ICON

Imports

ADVAPI32.dll
KERNEL32.dll
SHLWAPI.dll
USER32.dll
WTSAPI32.dll
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
12
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start gotoassist.exe gotoassistservice.exe no specs cmd.exe no specs gotoassistprocesschecker.exe gotoassistprocesschecker.exe gotoassistcrashhandler.exe no specs gotoassistservice.exe gotoassistloggerprocess.exe gotoassistcrashhandler.exe no specs gotoassistcrashhandler.exe no specs bcdedit.exe no specs gotoassistprocesschecker.exe

Process information

PID
CMD
Path
Indicators
Parent process
568"C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exe" "--attachment=attachment_params.json=C:/Users/admin/AppData/Local/GoToAssist Remote Support Applet/LMI0001.tmpparams.json" "--attachment=attachment_GoToAssistProcessChecker.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.log" "--attachment=attachment_GoToAssistProcessChecker.srv.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.srv.log" "--attachment=attachment_GoToAssistService.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistService.log" "--attachment=attachment_GoToAssistService.srv.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistService.srv.log" "--database=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\LoggerProcessCrashReportDB" "--metrics-dir=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\LoggerProcessCrashReportDB" --url=https://dumpster.console.gotoassist.com/api/dump?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE2MzA1OTQ4ODIsImlhdCI6MTYzMDUwODQ4Mn0.zqz7E1psaUfzPev_mx2Gs8rKy6Qa8A4heSelNaEl7Ug --annotation=format=minidump --annotation=hostname=User-PC --annotation=installationid=BXuVGx74O1 --annotation=sessionid=8a24dd27-3744-444a-a3d1-b63b51ea8ee9 --annotation=version=5.6.0.1373 --initial-client-data=0x2ac,0x2b0,0x2b4,0x2a4,0x2b8,0x6b74bd00,0x6b74bd10,0x6b74bd20C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exeGoToAssistLoggerProcess.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\gotoassist remote support applet\lmi0001.tmp\gotoassistcrashhandler.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
704"C:/Users/admin/AppData/Local/GoToAssist Remote Support Applet/LMI0001.tmp/GoToAssistService.exe" "-RegisteredProcess" "1" "-ParentProcessId" "3076" "-WtsStartingUsername" "USER-PC\admin" "-ServiceName" "G2ARemoteSupport_attended" "-Service"C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistService.exe
GoToAssistProcessChecker.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
GoToAssist Remote Support
Exit code:
0
Version:
5.6.0.1373
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gotoassist remote support applet\lmi0001.tmp\gotoassistservice.exe
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\gotoassist remote support applet\lmi0001.tmp\libgotoassist.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
744"C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistService.exe" C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistService.exeGoToAssist.exe
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
GoToAssist Remote Support
Exit code:
0
Version:
5.6.0.1373
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gotoassist remote support applet\lmi0001.tmp\gotoassistservice.exe
c:\users\admin\appdata\local\gotoassist remote support applet\lmi0001.tmp\libgotoassist.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
760cmd.exe /S /C ""C:\Users\admin\AppData\Local\Temp\GoToAssist.exe.cmd" "C:\Users\admin\AppData\Local\Temp\GoToAssist.exe""C:\Windows\system32\cmd.exeGoToAssist.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
832"C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exe" "--attachment=attachment_GoToAssistProcessChecker.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.log" "--attachment=attachment_GoToAssistProcessChecker.srv.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.srv.log" "--attachment=attachment_GoToAssistService.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistService.log" "--database=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\ProcessCheckerCrashReportDB" "--metrics-dir=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\ProcessCheckerCrashReportDB" --url=https://dumpster.console.gotoassist.com/api/dump?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE2MzA1OTQ4ODIsImlhdCI6MTYzMDUwODQ4Mn0.zqz7E1psaUfzPev_mx2Gs8rKy6Qa8A4heSelNaEl7Ug --annotation=format=minidump --annotation=hostname=User-PC --annotation=installationid=BXuVGx74O1 --annotation=sessionid=8a24dd27-3744-444a-a3d1-b63b51ea8ee9 --annotation=version=5.6.0.1373 --initial-client-data=0x324,0x328,0x32c,0x320,0x330,0x6b74bd00,0x6b74bd10,0x6b74bd20C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exeGoToAssistProcessChecker.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\gotoassist remote support applet\lmi0001.tmp\gotoassistcrashhandler.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\version.dll
900"C:/Users/admin/AppData/Local/GoToAssist Remote Support Applet/LMI0001.tmp/GoToAssistProcessChecker.exe" "-delsvc" "-ApplicationType" "1"C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistProcessChecker.exe
GoToAssistService.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
GoToAssist Remote Support
Exit code:
0
Version:
5.6.0.1373
Modules
Images
c:\users\admin\appdata\local\gotoassist remote support applet\lmi0001.tmp\gotoassistprocesschecker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gotoassist remote support applet\lmi0001.tmp\libgotoassist.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\rpcrt4.dll
952"C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exe" "--attachment=attachment_params.json=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\params.json" "--attachment=attachment_GoToAssistProcessChecker.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.log" "--attachment=attachment_GoToAssistProcessChecker.srv.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistProcessChecker.srv.log" "--attachment=attachment_GoToAssistService.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistService.log" "--attachment=attachment_GoToAssistService.srv.log=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\GoToAssistService.srv.log" "--database=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\ServiceCrashReportDB" "--metrics-dir=C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\appdata\ServiceCrashReportDB" --url=https://dumpster.console.gotoassist.com/api/dump?token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJleHAiOjE2MzA1OTQ4ODIsImlhdCI6MTYzMDUwODQ4Mn0.zqz7E1psaUfzPev_mx2Gs8rKy6Qa8A4heSelNaEl7Ug --annotation=format=minidump --annotation=hostname=User-PC --annotation=installationid=BXuVGx74O1 --annotation=sessionid=8a24dd27-3744-444a-a3d1-b63b51ea8ee9 --annotation=version=5.6.0.1373 --initial-client-data=0x370,0x3c4,0x3c8,0x3c0,0x3cc,0x6b74bd00,0x6b74bd10,0x6b74bd20C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistCrashHandler.exeGoToAssistService.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\gotoassist remote support applet\lmi0001.tmp\gotoassistcrashhandler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1760GoToAssistLoggerProcess.exe -HostId 52abd0f3251d22b05ca02f33073216ba -SessionType Attended -InstallationId BXuVGx74O1 -DeviceId "" -LogLevel 2C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistLoggerProcess.exe
GoToAssistService.exe
User:
SYSTEM
Company:
LogMeIn, Inc.
Integrity Level:
SYSTEM
Description:
GoToAssist Remote Support
Exit code:
0
Version:
5.6.0.1373
Modules
Images
c:\users\admin\appdata\local\gotoassist remote support applet\lmi0001.tmp\gotoassistloggerprocess.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\gotoassist remote support applet\lmi0001.tmp\libgotoassist.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
1828C:\Windows\system32\bcdedit.exe /deletevalue safebootC:\Windows\system32\bcdedit.exeGoToAssistService.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Boot Configuration Data Editor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\bcdedit.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2488"C:\Users\admin\AppData\Local\Temp\GoToAssist.exe" C:\Users\admin\AppData\Local\Temp\GoToAssist.exe
Explorer.EXE
User:
admin
Company:
LogMeIn, Inc.
Integrity Level:
MEDIUM
Description:
GoToAssist Remote Support
Exit code:
0
Version:
5.6.0.1373
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\gotoassist.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\advapi32.dll
Total events
7 853
Read events
7 818
Write events
34
Delete events
1

Modification events

(PID) Process:(744) GoToAssistService.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(744) GoToAssistService.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(744) GoToAssistService.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(744) GoToAssistService.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2844) GoToAssistProcessChecker.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\G2ARemoteSupport_attended
Operation:writeName:(default)
Value:
Service
(PID) Process:(3076) GoToAssistProcessChecker.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(704) GoToAssistService.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(704) GoToAssistService.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:GoToAssist_Cleanup_BXuVGx74O1
Value:
C:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\cleanup.bat
(PID) Process:(900) GoToAssistProcessChecker.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\G2ARemoteSupport_attended
Operation:delete keyName:(default)
Value:
Executable files
24
Suspicious files
5
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
2488GoToAssist.exeC:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMIInputHook32.dllexecutable
MD5:49F523055F29CCECD29833FB28EF8BAE
SHA256:214F5CAE813A8465CB842D53203FAF481EC6C1622359946A6E6DEFDB086A0CA6
2488GoToAssist.exeC:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\GoToAssistService.exeexecutable
MD5:3BDF02A9831922F1CD4B97AA2BC335B0
SHA256:DB33B245F9B2B985D342034B71B1E99199BEEE9683BAA1ED975E8F291331F07E
2488GoToAssist.exeC:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMISupport7x32.dllexecutable
MD5:57ABBC0C5B94B51D1846232E1E9F844E
SHA256:1994D94087BA56140B56C2C8D4A2C43BA5CB4C32FB658704C9B8F2D27EA7FBF0
2488GoToAssist.exeC:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMIInputHook64.dllexecutable
MD5:796AE55073AD592FFBA533A196F694F6
SHA256:1DCFEB644B439E2919AEFB18DBD8ACC5151877ADCA83B1D2C9BA5ECE6A131C0D
2488GoToAssist.exeC:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMIFilterHook32.dllexecutable
MD5:D440203A37B3BCBFDF272B8D36AD5CB9
SHA256:C078C6426132C343FA85D7FDA57A9997A5E8BD421C63FC8EBE89B48AC708606D
2488GoToAssist.exeC:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\lmiscrhook32.dllexecutable
MD5:00D1AFE4A647D2FEA8E6CC93ECC6F056
SHA256:D4A3985B3618E7E46A33DA12755CC20E969715F3F5FA5010545B32A8B89EA7A7
2488GoToAssist.exeC:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMISupportM32.exeexecutable
MD5:C7AF8173F79286374D466242D7DE4A6C
SHA256:17055AE50F49B00B202C779C7A65AEE1D7AF092D760E38489B56803FCE9DC2DE
2488GoToAssist.exeC:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\LMISupportM64.exeexecutable
MD5:4AF214B1869AFDAB3D7EB4EF593A34D5
SHA256:D1017231304A9EB1927CC2714D421675132D78643DC5C66378CC3E1A190119D7
2488GoToAssist.exeC:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\lmiscrhook64.dllexecutable
MD5:7BAFA136DC339F37AEFF9B435F90E599
SHA256:FA2348FABBA639E4B6F3A27D4C2426C7141323FC7802E3DA77F37324EBB33E6E
2488GoToAssist.exeC:\Users\admin\AppData\Local\GoToAssist Remote Support Applet\LMI0001.tmp\PasswordPrivacyDll.dllexecutable
MD5:4FFEFA8A92321594BAB2BE0B28871D63
SHA256:9511494466E83176D839B16EB4B60D162DC8975DE66995C47C7F48B6BA8FA530
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1760
GoToAssistLoggerProcess.exe
52.57.43.61:443
dumpster.console.gotoassist.com
Amazon.com, Inc.
DE
unknown
704
GoToAssistService.exe
3.92.208.61:443
prd-ava-be06.console.gotoassist.com
US
unknown

DNS requests

Domain
IP
Reputation
prd-ava-be06.console.gotoassist.com
  • 3.92.208.61
unknown
dumpster.console.gotoassist.com
  • 52.57.43.61
  • 35.157.42.108
unknown

Threats

No threats detected
Process
Message
GoToAssistProcessChecker.exe
MainThread: created
GoToAssistProcessChecker.exe
MainThread: created
GoToAssistService.exe
MainThread: created
GoToAssistProcessChecker.exe
MainThread: created