Bomgar2.exe is usually located in the 'c:\downloads\' folder.
Some of the anti-virus scanners at VirusTotal detected Bomgar2.exe.
If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.
Bomgar2.exe is not signed.
16 of the 69 anti-virus programs at VirusTotal detected the Bomgar2.exe file. That's a 23% detection rate.
| Scanner | Detection Name |
|---|---|
| Acronis | suspicious |
| AegisLab | Trojan.Win32.Generic.4!c |
| Avast | Win32:Malware-gen |
| AVG | Win32:Malware-gen |
| ClamAV | Win.Malware.Generic-6917225-0 |
| CrowdStrike | win/malicious_confidence_60% (W) |
| Cylance | Unsafe |
| Cyren | W32/Trojan.VLJF-9020 |
| Endgame | malicious (high confidence) |
| FireEye | Generic.mg.84b7c343eca0b085 |
| Invincea | heuristic |
| McAfee | Artemis!84B7C343ECA0 |
| McAfee-GW-Edition | BehavesLike.Win32.Backdoor.wc |
| Microsoft | Trojan:Win32/Zpevdo.A |
| Trapmine | malicious.high.ml.score |
| Yandex | Trojan.PowerShell! |
The following information was gathered by executing the file inside Cuckoo Sandbox.
Successfully executed process in sandbox.
{
"file_created": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarC5FE.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab68F1.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabC5FD.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabEE88.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab6903.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab68D0.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarEE89.tmp",
"C:\\Bomgar\\__tmp_rar_sfx_access_check_31297046",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarC620.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar7DC8.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab6924.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar68D1.tmp",
"C:\\Bomgar\\bomgar-scc-win32.msi",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabC61F.tmp",
"C:\\Bomgar\\BomgarInstall2.vbs",
"C:\\Bomgar\\bom.bat",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab7DC7.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar6904.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar68F2.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar6925.tmp"
],
"file_recreated": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarC5FE.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab68F1.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabC5FD.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabEE88.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab6903.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab68D0.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarEE89.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\TarC620.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar7DC8.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab6924.tmp",
"\\Device\\KsecDD",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar68D1.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\CabC61F.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab7DC7.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar6904.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar68F2.tmp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar6925.tmp"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
"HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\HRZR_PGYFRFFVBA",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\\Blob",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet"
],
"dll_loaded": [
"C:\\Windows\\system32\\sfc.dll",
"API-MS-Win-Security-LSALookup-L1-1-0.dll",
"DNSAPI.dll",
"UxTheme.dll",
"C:\\Windows\\system32\\ole32.dll",
"dwmapi.dll",
"C:\\Windows\\SysWOW64\\SHLWAPI.DLL",
"cryptsp.dll",
"C:\\Windows\\system32\\uxtheme.dll",
"ncrypt.dll",
"API-MS-WIN-Service-Management-L2-1-0.dll",
"PROPSYS.dll",
"crypt32.dll",
"C:\\Windows\\SysWOW64\\bcryptprimitives.dll",
"SspiCli.dll",
"advapi32.dll",
"COMCTL32",
"ole32.dll",
"SHLWAPI.dll",
"USER32.dll",
"C:\\Windows\\SysWOW64\\wshext.dll",
"C:\\Windows\\syswow64\\CRYPT32.dll",
"WINTRUST.dll",
"WindowsCodecs.dll",
"C:\\Windows\\system32\\version.dll",
"SHELL32.dll",
"C:\\Windows\\System32\\wship6.dll",
"C:\\Windows\\system32\\shell32.dll",
"CFGMGR32.dll",
"C:\\Windows\\SysWOW64\\KERNEL32.DLL",
"C:\\Windows\\System32\\wshtcpip.dll",
"C:\\Windows\\system32\\riched20.dll",
"urlmon.dll",
"api-ms-win-appmodel-runtime-l1-1-1",
"apphelp.dll",
"kernel32.dll",
"SensApi.dll",
"ntdll.dll",
"Dropped
[
{
"yara": [],
"sha1": "c864b62490653c2f87f2f984471f1ba9e83d2563",
"name": "917cd20faf84ad86_bom.bat",
"filepath": "C:\\Bomgar\\bom.bat",
"type": "DOS batch file, ASCII text, with CRLF line terminators",
"sha256": "917cd20faf84ad86510a04aba1c78fd3b3c9b30e0071346c4d58566d464e542c",
"urls": [],
"crc32": "911D6812",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/917cd20faf84ad86_bom.bat",
"ssdeep": null,
"size": 130,
"sha512": "fc6478682002afe02ab1d0108905812cf251d437e718de092fc80e58b662fb235ac9cba258492f283acf73175a76850ac63b745cb8b4c94839475ce82f0ecbb6",
"pids": [
2732
],
"md5": "8be863f69f003cf025ab8226d206e734"
},
{
"yara": [],
"sha1": "da39a3ee5e6b4b0d3255bfef95601890afd80709",
"name": "e3b0c44298fc1c14___tmp_rar_sfx_access_check_31297046",
"type": "empty",
"sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
"urls": [],
"crc32": "00000000",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/e3b0c44298fc1c14___tmp_rar_sfx_access_check_31297046",
"ssdeep": null,
"size": 0,
"sha512": "cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e",
"md5": "d41d8cd98f00b204e9800998ecf8427e"
},
{
"yara": [],
"sha1": "d0b15e096f355cd16c357992c806c7b3e0be1992",
"name": "52a830db287b96d2_bomgar-scc-win32.msi",
"filepath": "C:\\Bomgar\\bomgar-scc-win32.msi",
"type": "Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: The Bomgar Jump Client, Author: Bomgar, Keywords: Installer, Comments: The Bomgar Jump Client, Template: Intel;1033, Revision Number: {227DB9E5-EE48-45C1-B4EB-13B3B89F4A3D}, Create Time\/Date: Mon Jan 22 16:34:08 2018, Last Saved Time\/Date: Mon Jan 22 16:34:08 2018, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML (3.7.1224.0), Security: 2",
"sha256": "52a830db287b96d2cec056d885cef9c941591ea700c61f9c78fdbc0a349b296a",
"urls": [
"http:\/\/s.symcb.com\/universal-root.crl0",
"http:\/\/s2.symcb.com0",
"https:\/\/d.symcb.com\/cps0%",
"http:\/\/sv.symcb.com\/sv.crt0",
"http:\/\/ts-ocsp.ws.symantec.com0",
"http:\/\/sv.symcb.com\/sv.crl0a",
"http:\/\/www.bomgar.com\/0",
"http:\/\/ts-aia.ws.symantec.com\/sha256-tss-ca.cer0(",
"http:\/\/sv.symcd.com0",
"http:\/\/www.symauth.com\/rpa00",
"http:\/\/s1.symcb.com\/pca3-g5.crl0",
"http:\/\/www.symauth.com\/cps0(",
"https:\/\/d.symcb.com\/rpa0.",
"https:\/\/d.symcb.com\/rpa0",
"http:\/\/s.symcd.com06",
"http:\/\/ts-crl.ws.symantec.com\/sha256-tss-ca.crl0"
],
"crc32": "3DC91A74",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/52a830db287b96d2_bomgar-scc-win32.msi",
"ssdeep": null,
"size": 2965504,
"sha512": "e943df5219d6115e20d7867a407630cc6a878fb382403f4d2f54c52e55bef1cfa90cd18b65d0edd85f9667a741ed40281374f9dce85a0be435718f2d07f5dd0e",
"pids": [
2732
],
"md5": "f37cb76805ceb99a16f195127e3cc22c"
},
{
"yara": [],
"sha1": "cf925fc512b936fe7d44ceb6e999e4a020ed6ff0",
"name": "4c9c4d831d61c8c3_Cab68D0.tmp",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab68D0.tmp",
"type": "Microsoft Cabinet archive data, 56952 bytes, 1 file",
"sha256": "4c9c4d831d61c8c38b2513f9b431ef4f4cf6af9fb18a2317cd2178d6e0997822",
"urls": [],
"crc32": "5168F337",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/4c9c4d831d61c8c3_Cab68D0.tmp",
"ssdeep": null,
"size": 56952,
"sha512": "65dc435f6d3e1afd347ba1617a3eee59c6660f221faa36456a09e307d434d7276e8095e8aa34d59933e685a9f84564ec783e59ae9658791f7ebdbbc2eda32f7a",
"pids": [
2360
],
"md5": "04d79a0dc77a8f449cbff6252862d398"
},
{
"yara": [],
"sha1": "5a7bbbc2e08d176a580d10e6a5fe3efd304889c8",
"name": "1a8ec0b866d68159_bomgarinstall2.vbs",
"filepath": "C:\\Bomgar\\BomgarInstall2.vbs",
"type": "ASCII text, with CRLF line terminators",
"sha256": "1a8ec0b866d68159a5ad2b77adc531e7d118b86891f6bbeba1b83af1b4325d12",
"urls": [],
"crc32": "B93FA7A0",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/1a8ec0b866d68159_bomgarinstall2.vbs",
"ssdeep": null,
"size": 3942,
"sha512": "9adec16d77b219a46296edafc86934cd978ec4247c2ff0a6470f0506368f6f3571045d2024bd63da9a722f8e5adfec2d9959160bba95bd39d68a761f5b9bee0d",
"pids": [
2732
],
"md5": "066b7633db20d9d9da85bae3ba340559"
},
{
"yara": [],
"sha1": "c64ad224b877cd5bbdcdb1799b71f3682602d231",
"name": "b0a39e28d93f7822_Tar68D1.tmp",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar68D1.tmp",
"type": "data",
"sha256": "b0a39e28d93f7822fe6cac1e082c7adc581dcd2b61eb9f536e74bd14a75b27bc",
"urls": [
"http:\/\/www.microsoft.com\/pkiops\/certs\/Microsoft%20Certificate%20Trust%20List%20PCA(3).crt0",
"http:\/\/www.microsoft.com\/pki\/certs\/MicRooCerAut_2010-06-23.crt07",
"http:\/\/www.microsoft.com\/pki\/certs\/MicCerLisCA2011_2011-03-29.crt0",
"http:\/\/www.microsoft.com\/pki\/certs\/MicrosoftRootCert.crt0",
"http:\/\/www.microsoft.com\/pkiops\/crl\/Microsoft%20Certificate%20Trust%20List%20PCA(3).crl0u"
],
"crc32": "B495BE07",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/b0a39e28d93f7822_Tar68D1.tmp",
"ssdeep": null,
"size": 138525,
"sha512": "0663fb22bcefd0ac5f090104322a8c0dc1ceb77a168b589d7dbb9a74d109daf38beac97dab715220abab08c355496f5719159e17995248caa19eff45bc2a5d46",
"pids": [
2360
],
"md5": "0e34ebf89b843b303f0fb5f194be9d28"
}
]Generic
[
{
"process_path": "C:\\Windows\\SysWOW64\\taskkill.exe",
"process_name": "taskkill.exe",
"pid": 1508,
"summary": {
"dll_loaded": [
"C:\\Windows\\system32\\Winsta.dll",
"OLEAUT32.dll"
],
"file_opened": [
"C:\\Windows\\System32\\wbem\\en-US\\wmiutils.dll.mui",
"C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32",
"HKEY_CURRENT_USER\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}",
"HKEY_CURRENT_USER\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\WBEM\\CIMOM",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32"
],
"wmi_query": [
"SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process"
],
"guid": [
"{4590f812-1d3a-11d0-891f-00aa004b2e24}",
"{00000003-0000-0000-c000-000000000046}",
"{eb87e1bd-3233-11d2-aec9-00c04fb68820}",
"{4590f811-1d3a-11d0-891f-00aa004b2e24}",
"{44aca674-e8fc-11d0-a07c-00c04fb68820}",
"{eb87e1bc-3233-11d2-aec9-00c04fb68820}",
"{674b6698-ee92-11d0-ad71-00c04fd8fdff}",
"{8bc3f05e-d86b-11d0-a075-00c04fb68820}",
"{7c857801-7381-11cf-884d-00aa004b2e24}",
"{d5f569d0-593b-101a-b569-08002b2dbf7a}",
"{f309ad18-d86a-11d0-a075-00c04fb68820}",
"{dc12a687-737f-11cf-884d-00aa004b2e24}"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\WBEM\\CIMOM\\EnableObjectValidation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32\\(Default)",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\WBEM\\CIMOM\\Logging",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32\\(Default)"
]
},
"first_seen": 1577346889.4685,
"ppid": 1516
},
{
"process_path": "C:\\Windows\\explorer.exe",
"process_name": "explorer.exe",
"pid": 1788,
"summary": {
"regkey_written": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\HRZR_PGYFRFFVBA",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr"
],
"file_opened": [
"C:\\Windows\\SysWOW64\\",
"C:\\Windows\\",
"C:\\"
],
"file_exists": [
"C:\\cuckoo_1508.ini",
"C:\\Config.Msi",
"C:\\cuckoo_1788.ini",
"C:\\Windows\\SysWOW64\\taskkill.exe",
"C:\\ProgramData"
],
"file_failed": [
"C:\\cuckoo_1508.ini",
"C:\\Config.Msi",
"C:\\cuckoo_1788.ini"
],
"guid": [
"{76765b11-3f95-4af2-ac9d-ea55d8994f1a}",
"{00000000-0000-0000-c000-000000000046}",
"{660b90c8-73a9-4b58-8cae-355b7f55341b}",
"{46a6eeff-908e-4dc6-92a6-64be9177b41c}"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.msi\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msi.Package\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.msi\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msi.Package\\DocObject",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msi.Package\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msi.Package\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msi.Package\\IsShortcut"
]
},
"first_seen": 1577346858.984125,
"ppid": 1740
},
{
"process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\c62d73f85370422f102f45dd139a8fab5aa65f2bcc6483d4632c73107ee3b71a.bin",
"process_name": "c62d73f85370422f102f45dd139a8fab5aa65f2bcc6483d4632c73107ee3b71a.bin",
"pid": 2732,
"summary": {
"file_created": [
"C:\\Bomgar\\bom.bat",
"C:\\Bomgar\\bomgar-scc-win32.msi",
"C:\\Bomgar\\BomgarInstall2.vbs",
"C:\\Bomgar\\__tmp_rar_sfx_access_check_31297046"
],
"directory_created": [
"C:\\Bomgar",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches"
],
"dll_loaded": [
"C:\\Windows\\system32\\sfc.dll",
"C:\\Windows\\system32\\riched20.dll",
"kernel32",
"kernel32.dll",
"UxTheme.dll",
"C:\\Windows\\system32\\rsaenh.dll",
"C:\\Windows\\system32\\ole32.dll",
"C:\\Windows\\system32\\sfc_os.dll",
"dwmapi.dll",
"C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\\gdiplus.dll",
"C:\\Windows\\system32\\DXGIDebug.dll",
"ntmarta.dll",
"Signatures
[
{
"markcount": 8,
"families": [],
"description": "Queries for the computername",
"severity": 1,
"marks": [
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetComputerNameW",
"return_value": 1,
"arguments": {
"computer_name": "CUCKPC"
},
"time": 1577346788.56225,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 781
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetComputerNameW",
"return_value": 1,
"arguments": {
"computer_name": "CUCKPC"
},
"time": 1577346889.04625,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 1861
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetComputerNameA",
"return_value": 1,
"arguments": {
"computer_name": "CUCKPC"
},
"time": 1577346889.12425,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 1978
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetComputerNameW",
"return_value": 1,
"arguments": {
"computer_name": "CUCKPC"
},
"time": 1577346889.12425,
"tid": 3016,
"flags": {}
},
"pid": 1516,
"type": "call",
"cid": 1979
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetComputerNameW",
"return_value": 1,
"arguments": {
"computer_name": "CUCKPC"
},
"time": 1577346825.42175,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 6226
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetComputerNameA",
"return_value": 1,
"arguments": {
"computer_name": "CUCKPC"
},
"time": 1577346858.96875,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 6921
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetComputerNameW",
"return_value": 1,
"arguments": {
"computer_name": "CUCKPC"
},
"time": 1577346858.96875,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 6922
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetComputerNameW",
"return_value": 1,
"arguments": {
"computer_name": "CUCKPC"
},
"time": 1577346889.5625,
"tid": 304,
"flags": {}
},
"pid": 1508,
"type": "call",
"cid": 68
}
],
"references": [],
"name": "antivm_queries_computername"
},
{
"markcount": 1,
"families": [],
"description": "Checks if process is being debugged by a debugger",
"severity": 1,
"marks": [
{
"call": {
"category": "system",
"status": 0,
"stacktrace": [],
"last_error": 0,
"nt_status": -1073741789,
"api": "IsDebuggerPresent",
"return_value": 0,
"arguments": {},
"time": 1577346789.10875,
"tid": 2772,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 164
}
],
"references": [],
"name": "checks_debugger"
},
{
"markcount": 2,
"families": [],
"description": "Command line console output was observed",
"severity": 1,
"marks": [
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "ERROR: The process with PID 1508 (child process of PID 1516) could not be terminated.\nReason: The process cannot terminate itself.\n",
"console_handle": "0x0000000b"
},
"time": 1577346889.6085,
"tid": 304,
"flags": {}
},
"pid": 1508,
"type": "call",
"cid": 427
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "WriteConsoleW",
"return_value": 1,
"arguments": {
"buffer": "SUCCESS: The process with PID 1516 (child process of PID 2732) has been terminated.\n",
"console_handle": "0x00000007"
},
"time": 1577346889.6085,
"tid": 304,
"flags": {}
},
"pid": 1508,
"type": "call",
"cid": 437
}
],
"references": [],
"name": "console_output"
},
{
"markcount": 1,
"families": [],
"description": "This executable has a PDB path",
"severity": 1,
"marks": [
{
"category": "pdb_path",
"ioc": "D:\\Projects\\WinRAR\\sfx\\build\\sfxrar32\\Release\\sfxrar.pdb",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "has_pdb"
},
{
"markcount": 1,
"families": [],
"description": "Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available",
"severity": 1,
"marks": [
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "GlobalMemoryStatusEx",
"return_value": 1,
"arguments": {},
"time": 1577346825.42175,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 6221
}
],
"references": [],
"name": "antivm_memory_available"
},
{
"markcount": 1,
"families": [],
"description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
"severity": 1,
"marks": [
{
"category": "section",
"ioc": ".gfids",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "pe_features"
},
{
"markcount": 1,
"families": [],
"description": "The file contains an unknown PE resource name possibly indicative of a packer",
"severity": 1,
"marks": [
{
"category": "resource name",
"ioc": "PNG",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "pe_unknown_resource_name"
},
{
"markcount": 0,
"families": [],
"description": "One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.",
"severity": 2,
"marks": [],
"references": [],
"name": "dumped_buffer"
},
{
"markcount": 29,
"families": [],
"description": "Allocates read-write-execute memory (usually to unpack itself)",
"severity": 2,
"marks": [
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x749e1000"
},
"time": 1577346789.07775,
"tid": 2772,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 2
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x750c1000"
},
"time": 1577346789.09375,
"tid": 2772,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 67
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x74b81000"
},
"time": 1577346789.12475,
"tid": 2772,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 324
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70f41000"
},
"time": 1577346789.14075,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 417
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70f31000"
},
"time": 1577346789.14075,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 419
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70f11000"
},
"time": 1577346789.14075,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 421
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x75ce1000"
},
"time": 1577346789.17175,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 725
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x74f91000"
},
"time": 1577346789.18775,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 887
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70ec1000"
},
"time": 1577346789.20275,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 1441
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70ea1000"
},
"time": 1577346789.20275,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 1443
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70e61000"
},
"time": 1577346789.20275,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 1453
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70e21000"
},
"time": 1577346790.99975,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 1910
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x75b61000"
},
"time": 1577346790.99975,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 1912
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70e01000"
},
"time": 1577346791.01575,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 2017
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70df1000"
},
"time": 1577346791.01575,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 2029
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70de1000"
},
"time": 1577346791.09375,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 2509
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70d81000"
},
"time": 1577346791.10875,
"tid": 304,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 2637
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70d31000"
},
"time": 1577346791.10875,
"tid": 304,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 2639
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x77311000"
},
"time": 1577346791.10875,
"tid": 304,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 2658
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x77b61000"
},
"time": 1577346791.10875,
"tid": 304,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 2660
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70d21000"
},
"time": 1577346791.10875,
"tid": 304,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 2710
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70ce1000"
},
"time": 1577346791.12475,
"tid": 304,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 2753
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70ca1000"
},
"time": 1577346791.12475,
"tid": 304,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 2842
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x70c11000"
},
"time": 1577346796.32775,
"tid": 304,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 3092
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x74f51000"
},
"time": 1577346825.39075,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 5958
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtAllocateVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"region_size": 2097152,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"protection": 64,
"process_handle": "0xffffffff",
"allocation_type": 8192,
"base_address": "0x04700000"
},
"time": 1577346825.39075,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE",
"allocation_type": "MEM_RESERVE"
}
},
"pid": 2360,
"type": "call",
"cid": 5994
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtAllocateVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"region_size": 4096,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 1,
"protection": 64,
"process_handle": "0xffffffff",
"allocation_type": 4096,
"base_address": "0x048c0000"
},
"time": 1577346825.39075,
"tid": 2296,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE",
"allocation_type": "MEM_COMMIT"
}
},
"pid": 2360,
"type": "call",
"cid": 5996
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x74ef1000"
},
"time": 1577346825.45275,
"tid": 2772,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 6484
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2360,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 4096,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x77351000"
},
"time": 1577346825.45275,
"tid": 2772,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2360,
"type": "call",
"cid": 6486
}
],
"references": [],
"name": "allocates_rwx"
},
{
"markcount": 0,
"families": [],
"description": "Checks whether any human activity is being performed by constantly checking whether the foreground window changed",
"severity": 2,
"marks": [],
"references": [
"https:\/\/www.virusbtn.com\/virusbulletin\/archive\/2015\/09\/vb201509-custom-packer.dkb"
],
"name": "antisandbox_foregroundwindows"
},
{
"markcount": 4,
"families": [],
"description": "Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation",
"severity": 2,
"marks": [
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetDiskFreeSpaceExW",
"return_value": 1,
"arguments": {
"root_path": "C:\\",
"free_bytes_available": 23508987904,
"total_number_of_free_bytes": 23508987904,
"total_number_of_bytes": 34252779520
},
"time": 1577346789.17175,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 604
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetDiskFreeSpaceW",
"return_value": 1,
"arguments": {
"root_path": "C:\\",
"sectors_per_cluster": 8,
"number_of_free_clusters": 5739499,
"total_number_of_clusters": 8362495,
"bytes_per_sector": 512
},
"time": 1577346789.17175,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 605
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetDiskFreeSpaceExW",
"return_value": 1,
"arguments": {
"root_path": "C:\\",
"free_bytes_available": 23508316160,
"total_number_of_free_bytes": 23508316160,
"total_number_of_bytes": 34252779520
},
"time": 1577346825.48375,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 6701
},
{
"call": {
"category": "misc",
"status": 1,
"stacktrace": [],
"api": "GetDiskFreeSpaceW",
"return_value": 1,
"arguments": {
"root_path": "C:\\",
"sectors_per_cluster": 8,
"number_of_free_clusters": 5739335,
"total_number_of_clusters": 8362495,
"bytes_per_sector": 512
},
"time": 1577346825.48375,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 6702
}
],
"references": [],
"name": "antivm_disk_size"
},
{
"markcount": 2,
"families": [],
"description": "Drops a binary and executes it",
"severity": 2,
"marks": [
{
"category": "file",
"ioc": "C:\\Bomgar\\BomgarInstall2.vbs",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Bomgar\\bom.bat",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "dropper"
},
{
"markcount": 2,
"families": [],
"description": "Executes one or more WMI queries",
"severity": 2,
"marks": [
{
"category": "wmi",
"ioc": "Select * from Win32_Process where name like 'bomgar-scc.exe'",
"type": "ioc",
"description": null
},
{
"category": "wmi",
"ioc": "SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "has_wmi"
},
{
"markcount": 1,
"families": [],
"description": "Checks adapter addresses which can be used to detect virtual network interfaces",
"severity": 2,
"marks": [
{
"call": {
"category": "network",
"status": 0,
"stacktrace": [],
"last_error": 0,
"nt_status": -1073741772,
"api": "GetAdaptersAddresses",
"return_value": 111,
"arguments": {
"flags": 15,
"family": 0
},
"time": 1577346791.12475,
"tid": 304,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 2846
}
],
"references": [],
"name": "antivm_network_adapters"
},
{
"markcount": 17,
"families": [],
"description": "Checks for the Locally Unique Identifier on the system for a suspicious privilege",
"severity": 2,
"marks": [
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeShutdownPrivilege"
},
"time": 1577346789.14075,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 442
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeCreateTokenPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5603
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeAssignPrimaryTokenPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5604
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeMachineAccountPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5608
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeTcbPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5609
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeSecurityPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5610
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeTakeOwnershipPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5611
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeLoadDriverPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5612
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeBackupPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5619
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeRestorePrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5620
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeShutdownPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5621
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeDebugPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5622
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeRemoteShutdownPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5626
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeEnableDelegationPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5629
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeManageVolumePrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5630
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeCreateGlobalPrivilege"
},
"time": 1577346825.31275,
"tid": 2296,
"flags": {}
},
"pid": 2360,
"type": "call",
"cid": 5632
},
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "LookupPrivilegeValueW",
"return_value": 1,
"arguments": {
"system_name": "",
"privilege_name": "SeDebugPrivilege"
},
"time": 1577346889.5625,
"tid": 304,
"flags": {}
},
"pid": 1508,
"type": "call",
"cid": 49
}
],
"references": [],
"name": "privilege_luid_check"
},
{
"markcount": 2,
"families": [],
"description": "Terminates another process",
"severity": 2,
"marks": [
{
"call": {
"category": "process",
"status": 0,
"stacktrace": [],
"last_error": 1168,
"nt_status": -1072365560,
"api": "NtTerminateProcess",
"return_value": 0,
"arguments": {
"status_code": "0x00000001",
"process_identifier": 1516,
"process_handle": "0x0000017c"
},
"time": 1577346889.6085,
"tid": 304,
"flags": {}
},
"pid": 1508,
"type": "call",
"cid": 432
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtTerminateProcess",
"return_value": 0,
"arguments": {
"status_code": "0x00000001",
"process_identifier": 1516,
"process_handle": "0x0000017c"
},
"time": 1577346889.6085,
"tid": 304,
"flags": {}
},
"pid": 1508,
"type": "call",
"cid": 433
}
],
"references": [],
"name": "terminates_remote_process"
},
{
"markcount": 2,
"families": [],
"description": "Uses Windows utilities for basic Windows functionality",
"severity": 2,
"marks": [
{
"category": "cmdline",
"ioc": "taskkill.exe \/F \/IM wscript.exe \/T",
"type": "ioc",
"description": null
},
{
"category": "cmdline",
"ioc": "\"C:\\Windows\\System32\\taskkill.exe\" \/F \/IM wscript.exe \/T",
"type": "ioc",
"description": null
}
],
"references": [
"http:\/\/blog.jpcert.or.jp\/2016\/01\/windows-commands-abused-by-attackers.html"
],
"name": "uses_windows_utilities"
},
{
"markcount": 2,
"families": [],
"description": "Attempts to create or modify system certificates",
"severity": 3,
"marks": [
{
"category": "registry",
"ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\\Blob",
"type": "ioc",
"description": null
},
{
"category": "registry",
"ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "modifies_certificates"
},
{
"markcount": 4,
"families": [],
"description": "One or more martian processes was created",
"severity": 3,
"marks": [
{
"parent_process": "wscript.exe",
"type": "generic",
"martian_process": "taskkill.exe \/F \/IM wscript.exe \/T"
},
{
"parent_process": "wscript.exe",
"type": "generic",
"martian_process": "C:\\Bomgar\\bom.bat"
},
{
"parent_process": "wscript.exe",
"type": "generic",
"martian_process": "\"C:\\Windows\\System32\\taskkill.exe\" \/F \/IM wscript.exe \/T"
},
{
"parent_process": "wscript.exe",
"type": "generic",
"martian_process": "\"C:\\Bomgar\\bom.bat\" "
}
],
"references": [],
"name": "process_martian"
},
{
"markcount": 2,
"families": [],
"description": "Resumed a suspended thread in a remote process potentially indicative of process injection",
"severity": 3,
"marks": [
{
"category": "Process injection",
"ioc": "Process 2732 resumed a thread in remote process 1516",
"type": "ioc",
"description": null
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtResumeThread",
"return_value": 0,
"arguments": {
"thread_handle": "0x00000258",
"suspend_count": 1,
"process_identifier": 1516
},
"time": 1577346788.233875,
"tid": 1676,
"flags": {}
},
"pid": 2732,
"type": "call",
"cid": 2272
}
],
"references": [
"www.endgame.com\/blog\/technical-blog\/ten-process-injection-techniques-technical-survey-common-and-trending-process"
],
"name": "injection_resumethread"
},
{
"markcount": 2,
"families": [],
"description": "The process wscript.exe wrote an executable file to disk which it then attempted to execute",
"severity": 6,
"marks": [
{
"category": "file",
"ioc": "C:\\Windows\\SysWOW64\\wscript.exe",
"type": "ioc",
"description": null
},
{
"category": "file",
"ioc": "C:\\Windows\\System32\\taskkill.exe",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "suspicious_write_exe"
}
]Yara
The Yara rules did not detect anything in the file.
Network
{
"tls": [],
"udp": [
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 546,
"time": 3.078572988510132,
"dport": 137,
"sport": 137
},
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 27906,
"time": 9.079013109207153,
"dport": 138,
"sport": 138
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 29750,
"time": 44.94968605041504,
"dport": 5355,
"sport": 49556
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 30070,
"time": 9.258134126663208,
"dport": 5355,
"sport": 49840
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 30390,
"time": 35.57154202461243,
"dport": 5355,
"sport": 50202
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 30710,
"time": 63.378835916519165,
"dport": 5355,
"sport": 50952
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 31030,
"time": 3.0123281478881836,
"dport": 5355,
"sport": 51001
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 31358,
"time": 74.99384903907776,
"dport": 5355,
"sport": 51670
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 31678,
"time": 14.51257610321045,
"dport": 5355,
"sport": 52259
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 31998,
"time": 1.030930995941162,
"dport": 5355,
"sport": 53595
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 32326,
"time": 3.020951986312866,
"dport": 5355,
"sport": 53848
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 32654,
"time": 58.643681049346924,
"dport": 5355,
"sport": 54025
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 32974,
"time": 28.792181968688965,
"dport": 5355,
"sport": 54237
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 33294,
"time": 1.540647029876709,
"dport": 5355,
"sport": 54255
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 33622,
"time": 21.949700117111206,
"dport": 5355,
"sport": 54335
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 33942,
"time": -0.09189796447753906,
"dport": 5355,
"sport": 55314
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 34270,
"time": 71.10877704620361,
"dport": 5355,
"sport": 55385
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 34590,
"time": 6.644366979598999,
"dport": 5355,
"sport": 55880
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 34910,
"time": 52.3165340423584,
"dport": 5355,
"sport": 56347
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 35230,
"time": 38.14212512969971,
"dport": 5355,
"sport": 56353
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 35550,
"time": 61.79014301300049,
"dport": 5355,
"sport": 56388
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 35870,
"time": 65.95328211784363,
"dport": 5355,
"sport": 58056
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 36190,
"time": 61.2177300453186,
"dport": 5355,
"sport": 58651
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 36510,
"time": 28.242484092712402,
"dport": 5355,
"sport": 58989
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 36830,
"time": 68.5362799167633,
"dport": 5355,
"sport": 59113
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 37150,
"time": 54.88320207595825,
"dport": 5355,
"sport": 59490
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 37470,
"time": 25.650329113006592,
"dport": 5355,
"sport": 59548
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 37790,
"time": 31.391716957092285,
"dport": 5355,
"sport": 60071
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 38110,
"time": 47.514729022979736,
"dport": 5355,
"sport": 60575
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 38430,
"time": 32.9899320602417,
"dport": 5355,
"sport": 62601
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 38750,
"time": 64.34856414794922,
"dport": 5355,
"sport": 63089
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 39070,
"time": 19.345186948776245,
"dport": 5355,
"sport": 63506
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 39390,
"time": 30.40806007385254,
"dport": 5355,
"sport": 63646
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 39710,
"time": 11.920993089675903,
"dport": 5355,
"sport": 64017
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 40030,
"time": 1.0517950057983398,
"dport": 1900,
"sport": 1900
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 59440,
"time": 1.052065134048462,
"dport": 3702,
"sport": 49152
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 67824,
"time": 3.125354051589966,
"dport": 1900,
"sport": 53598
}
],
"dns_servers": [],
"http": [],
"icmp": [],
"smtp": [],
"tcp": [],
"smtp_ex": [],
"mitm": [],
"hosts": [],
"pcap_sha256": "b2ed9fdb2d4c87436b8c3ccf960c33f59765ec94862daacf501cd006d390e60b",
"dns": [],
"http_ex": [],
"domains": [],
"dead_hosts": [],
"sorted_pcap_sha256": "15b3ef7e544b0a831687b77be41c919438b4e3f2992322c8ca00b5c84ec493d1",
"irc": [],
"https_ex": []
}Screenshots





Bomgar2.exe removal instructions
The instructions below shows how to remove Bomgar2.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the Bomgar2.exe file for removal, restart your computer and scan it again to verify that Bomgar2.exe has been successfully removed. Here are the removal instructions in more detail:
- Download and install FreeFixer: http://www.freefixer.com/download.html
- When the scan is finished, locate Bomgar2.exe in the scan result and tick the checkbox next to the Bomgar2.exe file. Do not check any other file for removal unless you are 100% sure you want to delete it. Tip: Press CTRL-F to open up FreeFixer's search dialog to quickly locate Bomgar2.exe in the scan result.

c:\downloads\Bomgar2.exe
- Restart your computer.
- Start FreeFixer and scan your computer again. If Bomgar2.exe still remains in the scan result, proceed with the next step. If Bomgar2.exe is gone from the scan result you're done.
- If Bomgar2.exe still remains in the scan result, check its checkbox again in the scan result and click Fix.
- Restart your computer.
- Start FreeFixer and scan your computer again. Verify that Bomgar2.exe no longer appear in the scan result.
Hashes [?]
Property Value MD5 84b7c343eca0b085d1e597622544409e SHA256 c62d73f85370422f102f45dd139a8fab5aa65f2bcc6483d4632c73107ee3b71a
Error Messages
These are some of the error messages that can appear related to bomgar2.exe:
bomgar2.exe has encountered a problem and needs to close. We are sorry for the inconvenience.
bomgar2.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.
bomgar2.exe has stopped working.
End Program - bomgar2.exe. This program is not responding.
bomgar2.exe is not a valid Win32 application.
bomgar2.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.
What will you do with Bomgar2.exe?
To help other users, please let us know what you will do with Bomgar2.exe:
Comments
Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.
I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.
No comments posted yet.
Leave a reply