What is Bomgar2.exe?

Bomgar2.exe is usually located in the 'c:\downloads\' folder.

Some of the anti-virus scanners at VirusTotal detected Bomgar2.exe.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

Bomgar2.exe does not have any version or vendor information.

Digital signatures [?]

Bomgar2.exe is not signed.

VirusTotal report

16 of the 69 anti-virus programs at VirusTotal detected the Bomgar2.exe file. That's a 23% detection rate.

ScannerDetection Name
Acronis suspicious
AegisLab Trojan.Win32.Generic.4!c
Avast Win32:Malware-gen
AVG Win32:Malware-gen
ClamAV Win.Malware.Generic-6917225-0
CrowdStrike win/malicious_confidence_60% (W)
Cylance Unsafe
Cyren W32/Trojan.VLJF-9020
Endgame malicious (high confidence)
FireEye Generic.mg.84b7c343eca0b085
Invincea heuristic
McAfee Artemis!84B7C343ECA0
McAfee-GW-Edition BehavesLike.Win32.Backdoor.wc
Microsoft Trojan:Win32/Zpevdo.A
Trapmine malicious.high.ml.score
Yandex Trojan.PowerShell!
16 of the 69 anti-virus programs detected the Bomgar2.exe file.

Sandbox Report

The following information was gathered by executing the file inside Cuckoo Sandbox.

Summary

Successfully executed process in sandbox.

Summary

{
    "file_created": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarC5FE.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab68F1.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabC5FD.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabEE88.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab6903.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab68D0.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarEE89.tmp",
        "C:\\Bomgar\\__tmp_rar_sfx_access_check_31297046",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarC620.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar7DC8.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab6924.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar68D1.tmp",
        "C:\\Bomgar\\bomgar-scc-win32.msi",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabC61F.tmp",
        "C:\\Bomgar\\BomgarInstall2.vbs",
        "C:\\Bomgar\\bom.bat",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab7DC7.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar6904.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar68F2.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar6925.tmp"
    ],
    "file_recreated": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarC5FE.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab68F1.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabC5FD.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabEE88.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab6903.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab68D0.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarEE89.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\TarC620.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar7DC8.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab6924.tmp",
        "\\Device\\KsecDD",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar68D1.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\CabC61F.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab7DC7.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar6904.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar68F2.tmp",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar6925.tmp"
    ],
    "regkey_written": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\HRZR_PGYFRFFVBA",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\\Blob",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet"
    ],
    "dll_loaded": [
        "C:\\Windows\\system32\\sfc.dll",
        "API-MS-Win-Security-LSALookup-L1-1-0.dll",
        "DNSAPI.dll",
        "UxTheme.dll",
        "C:\\Windows\\system32\\ole32.dll",
        "dwmapi.dll",
        "C:\\Windows\\SysWOW64\\SHLWAPI.DLL",
        "cryptsp.dll",
        "C:\\Windows\\system32\\uxtheme.dll",
        "ncrypt.dll",
        "API-MS-WIN-Service-Management-L2-1-0.dll",
        "PROPSYS.dll",
        "crypt32.dll",
        "C:\\Windows\\SysWOW64\\bcryptprimitives.dll",
        "SspiCli.dll",
        "advapi32.dll",
        "COMCTL32",
        "ole32.dll",
        "SHLWAPI.dll",
        "USER32.dll",
        "C:\\Windows\\SysWOW64\\wshext.dll",
        "C:\\Windows\\syswow64\\CRYPT32.dll",
        "WINTRUST.dll",
        "WindowsCodecs.dll",
        "C:\\Windows\\system32\\version.dll",
        "SHELL32.dll",
        "C:\\Windows\\System32\\wship6.dll",
        "C:\\Windows\\system32\\shell32.dll",
        "CFGMGR32.dll",
        "C:\\Windows\\SysWOW64\\KERNEL32.DLL",
        "C:\\Windows\\System32\\wshtcpip.dll",
        "C:\\Windows\\system32\\riched20.dll",
        "urlmon.dll",
        "api-ms-win-appmodel-runtime-l1-1-1",
        "apphelp.dll",
        "kernel32.dll",
        "SensApi.dll",
        "ntdll.dll",
        "

Dropped

[
    {
        "yara": [],
        "sha1": "c864b62490653c2f87f2f984471f1ba9e83d2563",
        "name": "917cd20faf84ad86_bom.bat",
        "filepath": "C:\\Bomgar\\bom.bat",
        "type": "DOS batch file, ASCII text, with CRLF line terminators",
        "sha256": "917cd20faf84ad86510a04aba1c78fd3b3c9b30e0071346c4d58566d464e542c",
        "urls": [],
        "crc32": "911D6812",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/917cd20faf84ad86_bom.bat",
        "ssdeep": null,
        "size": 130,
        "sha512": "fc6478682002afe02ab1d0108905812cf251d437e718de092fc80e58b662fb235ac9cba258492f283acf73175a76850ac63b745cb8b4c94839475ce82f0ecbb6",
        "pids": [
            2732
        ],
        "md5": "8be863f69f003cf025ab8226d206e734"
    },
    {
        "yara": [],
        "sha1": "da39a3ee5e6b4b0d3255bfef95601890afd80709",
        "name": "e3b0c44298fc1c14___tmp_rar_sfx_access_check_31297046",
        "type": "empty",
        "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855",
        "urls": [],
        "crc32": "00000000",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/e3b0c44298fc1c14___tmp_rar_sfx_access_check_31297046",
        "ssdeep": null,
        "size": 0,
        "sha512": "cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e",
        "md5": "d41d8cd98f00b204e9800998ecf8427e"
    },
    {
        "yara": [],
        "sha1": "d0b15e096f355cd16c357992c806c7b3e0be1992",
        "name": "52a830db287b96d2_bomgar-scc-win32.msi",
        "filepath": "C:\\Bomgar\\bomgar-scc-win32.msi",
        "type": "Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: The Bomgar Jump Client, Author: Bomgar, Keywords: Installer, Comments: The Bomgar Jump Client, Template: Intel;1033, Revision Number: {227DB9E5-EE48-45C1-B4EB-13B3B89F4A3D}, Create Time\/Date: Mon Jan 22 16:34:08 2018, Last Saved Time\/Date: Mon Jan 22 16:34:08 2018, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML (3.7.1224.0), Security: 2",
        "sha256": "52a830db287b96d2cec056d885cef9c941591ea700c61f9c78fdbc0a349b296a",
        "urls": [
            "http:\/\/s.symcb.com\/universal-root.crl0",
            "http:\/\/s2.symcb.com0",
            "https:\/\/d.symcb.com\/cps0%",
            "http:\/\/sv.symcb.com\/sv.crt0",
            "http:\/\/ts-ocsp.ws.symantec.com0",
            "http:\/\/sv.symcb.com\/sv.crl0a",
            "http:\/\/www.bomgar.com\/0",
            "http:\/\/ts-aia.ws.symantec.com\/sha256-tss-ca.cer0(",
            "http:\/\/sv.symcd.com0",
            "http:\/\/www.symauth.com\/rpa00",
            "http:\/\/s1.symcb.com\/pca3-g5.crl0",
            "http:\/\/www.symauth.com\/cps0(",
            "https:\/\/d.symcb.com\/rpa0.",
            "https:\/\/d.symcb.com\/rpa0",
            "http:\/\/s.symcd.com06",
            "http:\/\/ts-crl.ws.symantec.com\/sha256-tss-ca.crl0"
        ],
        "crc32": "3DC91A74",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/52a830db287b96d2_bomgar-scc-win32.msi",
        "ssdeep": null,
        "size": 2965504,
        "sha512": "e943df5219d6115e20d7867a407630cc6a878fb382403f4d2f54c52e55bef1cfa90cd18b65d0edd85f9667a741ed40281374f9dce85a0be435718f2d07f5dd0e",
        "pids": [
            2732
        ],
        "md5": "f37cb76805ceb99a16f195127e3cc22c"
    },
    {
        "yara": [],
        "sha1": "cf925fc512b936fe7d44ceb6e999e4a020ed6ff0",
        "name": "4c9c4d831d61c8c3_Cab68D0.tmp",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\Cab68D0.tmp",
        "type": "Microsoft Cabinet archive data, 56952 bytes, 1 file",
        "sha256": "4c9c4d831d61c8c38b2513f9b431ef4f4cf6af9fb18a2317cd2178d6e0997822",
        "urls": [],
        "crc32": "5168F337",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/4c9c4d831d61c8c3_Cab68D0.tmp",
        "ssdeep": null,
        "size": 56952,
        "sha512": "65dc435f6d3e1afd347ba1617a3eee59c6660f221faa36456a09e307d434d7276e8095e8aa34d59933e685a9f84564ec783e59ae9658791f7ebdbbc2eda32f7a",
        "pids": [
            2360
        ],
        "md5": "04d79a0dc77a8f449cbff6252862d398"
    },
    {
        "yara": [],
        "sha1": "5a7bbbc2e08d176a580d10e6a5fe3efd304889c8",
        "name": "1a8ec0b866d68159_bomgarinstall2.vbs",
        "filepath": "C:\\Bomgar\\BomgarInstall2.vbs",
        "type": "ASCII text, with CRLF line terminators",
        "sha256": "1a8ec0b866d68159a5ad2b77adc531e7d118b86891f6bbeba1b83af1b4325d12",
        "urls": [],
        "crc32": "B93FA7A0",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/1a8ec0b866d68159_bomgarinstall2.vbs",
        "ssdeep": null,
        "size": 3942,
        "sha512": "9adec16d77b219a46296edafc86934cd978ec4247c2ff0a6470f0506368f6f3571045d2024bd63da9a722f8e5adfec2d9959160bba95bd39d68a761f5b9bee0d",
        "pids": [
            2732
        ],
        "md5": "066b7633db20d9d9da85bae3ba340559"
    },
    {
        "yara": [],
        "sha1": "c64ad224b877cd5bbdcdb1799b71f3682602d231",
        "name": "b0a39e28d93f7822_Tar68D1.tmp",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\Tar68D1.tmp",
        "type": "data",
        "sha256": "b0a39e28d93f7822fe6cac1e082c7adc581dcd2b61eb9f536e74bd14a75b27bc",
        "urls": [
            "http:\/\/www.microsoft.com\/pkiops\/certs\/Microsoft%20Certificate%20Trust%20List%20PCA(3).crt0",
            "http:\/\/www.microsoft.com\/pki\/certs\/MicRooCerAut_2010-06-23.crt07",
            "http:\/\/www.microsoft.com\/pki\/certs\/MicCerLisCA2011_2011-03-29.crt0",
            "http:\/\/www.microsoft.com\/pki\/certs\/MicrosoftRootCert.crt0",
            "http:\/\/www.microsoft.com\/pkiops\/crl\/Microsoft%20Certificate%20Trust%20List%20PCA(3).crl0u"
        ],
        "crc32": "B495BE07",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/4548\/files\/b0a39e28d93f7822_Tar68D1.tmp",
        "ssdeep": null,
        "size": 138525,
        "sha512": "0663fb22bcefd0ac5f090104322a8c0dc1ceb77a168b589d7dbb9a74d109daf38beac97dab715220abab08c355496f5719159e17995248caa19eff45bc2a5d46",
        "pids": [
            2360
        ],
        "md5": "0e34ebf89b843b303f0fb5f194be9d28"
    }
]

Generic

[
    {
        "process_path": "C:\\Windows\\SysWOW64\\taskkill.exe",
        "process_name": "taskkill.exe",
        "pid": 1508,
        "summary": {
            "dll_loaded": [
                "C:\\Windows\\system32\\Winsta.dll",
                "OLEAUT32.dll"
            ],
            "file_opened": [
                "C:\\Windows\\System32\\wbem\\en-US\\wmiutils.dll.mui",
                "C:\\Windows\\SysWOW64\\en-US\\KERNELBASE.dll.mui"
            ],
            "regkey_opened": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32",
                "HKEY_CURRENT_USER\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}",
                "HKEY_CURRENT_USER\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\WBEM\\CIMOM",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32"
            ],
            "wmi_query": [
                "SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process"
            ],
            "guid": [
                "{4590f812-1d3a-11d0-891f-00aa004b2e24}",
                "{00000003-0000-0000-c000-000000000046}",
                "{eb87e1bd-3233-11d2-aec9-00c04fb68820}",
                "{4590f811-1d3a-11d0-891f-00aa004b2e24}",
                "{44aca674-e8fc-11d0-a07c-00c04fb68820}",
                "{eb87e1bc-3233-11d2-aec9-00c04fb68820}",
                "{674b6698-ee92-11d0-ad71-00c04fd8fdff}",
                "{8bc3f05e-d86b-11d0-a075-00c04fb68820}",
                "{7c857801-7381-11cf-884d-00aa004b2e24}",
                "{d5f569d0-593b-101a-b569-08002b2dbf7a}",
                "{f309ad18-d86a-11d0-a075-00c04fb68820}",
                "{dc12a687-737f-11cf-884d-00aa004b2e24}"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\WBEM\\CIMOM\\EnableObjectValidation",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{423EC01E-2E35-11D2-B604-00104B703EFD}\\ProxyStubClsid32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\WBEM\\CIMOM\\Logging",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\WMR\\Disable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\\ProxyStubClsid32\\(Default)"
            ]
        },
        "first_seen": 1577346889.4685,
        "ppid": 1516
    },
    {
        "process_path": "C:\\Windows\\explorer.exe",
        "process_name": "explorer.exe",
        "pid": 1788,
        "summary": {
            "regkey_written": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\HRZR_PGYFRFFVBA",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr"
            ],
            "file_opened": [
                "C:\\Windows\\SysWOW64\\",
                "C:\\Windows\\",
                "C:\\"
            ],
            "file_exists": [
                "C:\\cuckoo_1508.ini",
                "C:\\Config.Msi",
                "C:\\cuckoo_1788.ini",
                "C:\\Windows\\SysWOW64\\taskkill.exe",
                "C:\\ProgramData"
            ],
            "file_failed": [
                "C:\\cuckoo_1508.ini",
                "C:\\Config.Msi",
                "C:\\cuckoo_1788.ini"
            ],
            "guid": [
                "{76765b11-3f95-4af2-ac9d-ea55d8994f1a}",
                "{00000000-0000-0000-c000-000000000046}",
                "{660b90c8-73a9-4b58-8cae-355b7f55341b}",
                "{46a6eeff-908e-4dc6-92a6-64be9177b41c}"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.msi\\Content Type",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msi.Package\\BrowseInPlace",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.msi\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msi.Package\\DocObject",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msi.Package\\NeverShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msi.Package\\AlwaysShowExt",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Msi.Package\\IsShortcut"
            ]
        },
        "first_seen": 1577346858.984125,
        "ppid": 1740
    },
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\c62d73f85370422f102f45dd139a8fab5aa65f2bcc6483d4632c73107ee3b71a.bin",
        "process_name": "c62d73f85370422f102f45dd139a8fab5aa65f2bcc6483d4632c73107ee3b71a.bin",
        "pid": 2732,
        "summary": {
            "file_created": [
                "C:\\Bomgar\\bom.bat",
                "C:\\Bomgar\\bomgar-scc-win32.msi",
                "C:\\Bomgar\\BomgarInstall2.vbs",
                "C:\\Bomgar\\__tmp_rar_sfx_access_check_31297046"
            ],
            "directory_created": [
                "C:\\Bomgar",
                "C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches"
            ],
            "dll_loaded": [
                "C:\\Windows\\system32\\sfc.dll",
                "C:\\Windows\\system32\\riched20.dll",
                "kernel32",
                "kernel32.dll",
                "UxTheme.dll",
                "C:\\Windows\\system32\\rsaenh.dll",
                "C:\\Windows\\system32\\ole32.dll",
                "C:\\Windows\\system32\\sfc_os.dll",
                "dwmapi.dll",
                "C:\\Windows\\WinSxS\\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\\gdiplus.dll",
                "C:\\Windows\\system32\\DXGIDebug.dll",
                "ntmarta.dll",
                "

Signatures

[
    {
        "markcount": 8,
        "families": [],
        "description": "Queries for the computername",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1577346788.56225,
                    "tid": 3016,
                    "flags": {}
                },
                "pid": 1516,
                "type": "call",
                "cid": 781
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1577346889.04625,
                    "tid": 3016,
                    "flags": {}
                },
                "pid": 1516,
                "type": "call",
                "cid": 1861
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameA",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1577346889.12425,
                    "tid": 3016,
                    "flags": {}
                },
                "pid": 1516,
                "type": "call",
                "cid": 1978
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1577346889.12425,
                    "tid": 3016,
                    "flags": {}
                },
                "pid": 1516,
                "type": "call",
                "cid": 1979
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1577346825.42175,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 6226
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameA",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1577346858.96875,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 6921
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1577346858.96875,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 6922
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetComputerNameW",
                    "return_value": 1,
                    "arguments": {
                        "computer_name": "CUCKPC"
                    },
                    "time": 1577346889.5625,
                    "tid": 304,
                    "flags": {}
                },
                "pid": 1508,
                "type": "call",
                "cid": 68
            }
        ],
        "references": [],
        "name": "antivm_queries_computername"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Checks if process is being debugged by a debugger",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741789,
                    "api": "IsDebuggerPresent",
                    "return_value": 0,
                    "arguments": {},
                    "time": 1577346789.10875,
                    "tid": 2772,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 164
            }
        ],
        "references": [],
        "name": "checks_debugger"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Command line console output was observed",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteConsoleW",
                    "return_value": 1,
                    "arguments": {
                        "buffer": "ERROR: The process with PID 1508 (child process of PID 1516) could not be terminated.\nReason: The process cannot terminate itself.\n",
                        "console_handle": "0x0000000b"
                    },
                    "time": 1577346889.6085,
                    "tid": 304,
                    "flags": {}
                },
                "pid": 1508,
                "type": "call",
                "cid": 427
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteConsoleW",
                    "return_value": 1,
                    "arguments": {
                        "buffer": "SUCCESS: The process with PID 1516 (child process of PID 2732) has been terminated.\n",
                        "console_handle": "0x00000007"
                    },
                    "time": 1577346889.6085,
                    "tid": 304,
                    "flags": {}
                },
                "pid": 1508,
                "type": "call",
                "cid": 437
            }
        ],
        "references": [],
        "name": "console_output"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "This executable has a PDB path",
        "severity": 1,
        "marks": [
            {
                "category": "pdb_path",
                "ioc": "D:\\Projects\\WinRAR\\sfx\\build\\sfxrar32\\Release\\sfxrar.pdb",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "has_pdb"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GlobalMemoryStatusEx",
                    "return_value": 1,
                    "arguments": {},
                    "time": 1577346825.42175,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 6221
            }
        ],
        "references": [],
        "name": "antivm_memory_available"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
        "severity": 1,
        "marks": [
            {
                "category": "section",
                "ioc": ".gfids",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_features"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "The file contains an unknown PE resource name possibly indicative of a packer",
        "severity": 1,
        "marks": [
            {
                "category": "resource name",
                "ioc": "PNG",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_unknown_resource_name"
    },
    {
        "markcount": 0,
        "families": [],
        "description": "One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.",
        "severity": 2,
        "marks": [],
        "references": [],
        "name": "dumped_buffer"
    },
    {
        "markcount": 29,
        "families": [],
        "description": "Allocates read-write-execute memory (usually to unpack itself)",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x749e1000"
                    },
                    "time": 1577346789.07775,
                    "tid": 2772,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 2
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x750c1000"
                    },
                    "time": 1577346789.09375,
                    "tid": 2772,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 67
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x74b81000"
                    },
                    "time": 1577346789.12475,
                    "tid": 2772,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 324
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70f41000"
                    },
                    "time": 1577346789.14075,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 417
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70f31000"
                    },
                    "time": 1577346789.14075,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 419
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70f11000"
                    },
                    "time": 1577346789.14075,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 421
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x75ce1000"
                    },
                    "time": 1577346789.17175,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 725
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x74f91000"
                    },
                    "time": 1577346789.18775,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 887
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70ec1000"
                    },
                    "time": 1577346789.20275,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 1441
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70ea1000"
                    },
                    "time": 1577346789.20275,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 1443
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70e61000"
                    },
                    "time": 1577346789.20275,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 1453
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70e21000"
                    },
                    "time": 1577346790.99975,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 1910
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x75b61000"
                    },
                    "time": 1577346790.99975,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 1912
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70e01000"
                    },
                    "time": 1577346791.01575,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 2017
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70df1000"
                    },
                    "time": 1577346791.01575,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 2029
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70de1000"
                    },
                    "time": 1577346791.09375,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 2509
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70d81000"
                    },
                    "time": 1577346791.10875,
                    "tid": 304,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 2637
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70d31000"
                    },
                    "time": 1577346791.10875,
                    "tid": 304,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 2639
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x77311000"
                    },
                    "time": 1577346791.10875,
                    "tid": 304,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 2658
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x77b61000"
                    },
                    "time": 1577346791.10875,
                    "tid": 304,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 2660
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70d21000"
                    },
                    "time": 1577346791.10875,
                    "tid": 304,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 2710
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70ce1000"
                    },
                    "time": 1577346791.12475,
                    "tid": 304,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 2753
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70ca1000"
                    },
                    "time": 1577346791.12475,
                    "tid": 304,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 2842
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x70c11000"
                    },
                    "time": 1577346796.32775,
                    "tid": 304,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 3092
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x74f51000"
                    },
                    "time": 1577346825.39075,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 5958
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "region_size": 2097152,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "allocation_type": 8192,
                        "base_address": "0x04700000"
                    },
                    "time": 1577346825.39075,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_RESERVE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 5994
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 1,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "allocation_type": 4096,
                        "base_address": "0x048c0000"
                    },
                    "time": 1577346825.39075,
                    "tid": 2296,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 5996
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x74ef1000"
                    },
                    "time": 1577346825.45275,
                    "tid": 2772,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 6484
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2360,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 64,
                        "process_handle": "0xffffffff",
                        "base_address": "0x77351000"
                    },
                    "time": 1577346825.45275,
                    "tid": 2772,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE"
                    }
                },
                "pid": 2360,
                "type": "call",
                "cid": 6486
            }
        ],
        "references": [],
        "name": "allocates_rwx"
    },
    {
        "markcount": 0,
        "families": [],
        "description": "Checks whether any human activity is being performed by constantly checking whether the foreground window changed",
        "severity": 2,
        "marks": [],
        "references": [
            "https:\/\/www.virusbtn.com\/virusbulletin\/archive\/2015\/09\/vb201509-custom-packer.dkb"
        ],
        "name": "antisandbox_foregroundwindows"
    },
    {
        "markcount": 4,
        "families": [],
        "description": "Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetDiskFreeSpaceExW",
                    "return_value": 1,
                    "arguments": {
                        "root_path": "C:\\",
                        "free_bytes_available": 23508987904,
                        "total_number_of_free_bytes": 23508987904,
                        "total_number_of_bytes": 34252779520
                    },
                    "time": 1577346789.17175,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 604
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetDiskFreeSpaceW",
                    "return_value": 1,
                    "arguments": {
                        "root_path": "C:\\",
                        "sectors_per_cluster": 8,
                        "number_of_free_clusters": 5739499,
                        "total_number_of_clusters": 8362495,
                        "bytes_per_sector": 512
                    },
                    "time": 1577346789.17175,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 605
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetDiskFreeSpaceExW",
                    "return_value": 1,
                    "arguments": {
                        "root_path": "C:\\",
                        "free_bytes_available": 23508316160,
                        "total_number_of_free_bytes": 23508316160,
                        "total_number_of_bytes": 34252779520
                    },
                    "time": 1577346825.48375,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 6701
            },
            {
                "call": {
                    "category": "misc",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GetDiskFreeSpaceW",
                    "return_value": 1,
                    "arguments": {
                        "root_path": "C:\\",
                        "sectors_per_cluster": 8,
                        "number_of_free_clusters": 5739335,
                        "total_number_of_clusters": 8362495,
                        "bytes_per_sector": 512
                    },
                    "time": 1577346825.48375,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 6702
            }
        ],
        "references": [],
        "name": "antivm_disk_size"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Drops a binary and executes it",
        "severity": 2,
        "marks": [
            {
                "category": "file",
                "ioc": "C:\\Bomgar\\BomgarInstall2.vbs",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Bomgar\\bom.bat",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "dropper"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Executes one or more WMI queries",
        "severity": 2,
        "marks": [
            {
                "category": "wmi",
                "ioc": "Select * from Win32_Process where name like 'bomgar-scc.exe'",
                "type": "ioc",
                "description": null
            },
            {
                "category": "wmi",
                "ioc": "SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "has_wmi"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Checks adapter addresses which can be used to detect virtual network interfaces",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "network",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741772,
                    "api": "GetAdaptersAddresses",
                    "return_value": 111,
                    "arguments": {
                        "flags": 15,
                        "family": 0
                    },
                    "time": 1577346791.12475,
                    "tid": 304,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 2846
            }
        ],
        "references": [],
        "name": "antivm_network_adapters"
    },
    {
        "markcount": 17,
        "families": [],
        "description": "Checks for the Locally Unique Identifier on the system for a suspicious privilege",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeShutdownPrivilege"
                    },
                    "time": 1577346789.14075,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 442
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeCreateTokenPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5603
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeAssignPrimaryTokenPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5604
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeMachineAccountPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5608
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeTcbPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5609
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeSecurityPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5610
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeTakeOwnershipPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5611
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeLoadDriverPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5612
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeBackupPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5619
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeRestorePrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5620
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeShutdownPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5621
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5622
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeRemoteShutdownPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5626
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeEnableDelegationPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5629
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeManageVolumePrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5630
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeCreateGlobalPrivilege"
                    },
                    "time": 1577346825.31275,
                    "tid": 2296,
                    "flags": {}
                },
                "pid": 2360,
                "type": "call",
                "cid": 5632
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1577346889.5625,
                    "tid": 304,
                    "flags": {}
                },
                "pid": 1508,
                "type": "call",
                "cid": 49
            }
        ],
        "references": [],
        "name": "privilege_luid_check"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Terminates another process",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "process",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 1168,
                    "nt_status": -1072365560,
                    "api": "NtTerminateProcess",
                    "return_value": 0,
                    "arguments": {
                        "status_code": "0x00000001",
                        "process_identifier": 1516,
                        "process_handle": "0x0000017c"
                    },
                    "time": 1577346889.6085,
                    "tid": 304,
                    "flags": {}
                },
                "pid": 1508,
                "type": "call",
                "cid": 432
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtTerminateProcess",
                    "return_value": 0,
                    "arguments": {
                        "status_code": "0x00000001",
                        "process_identifier": 1516,
                        "process_handle": "0x0000017c"
                    },
                    "time": 1577346889.6085,
                    "tid": 304,
                    "flags": {}
                },
                "pid": 1508,
                "type": "call",
                "cid": 433
            }
        ],
        "references": [],
        "name": "terminates_remote_process"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Uses Windows utilities for basic Windows functionality",
        "severity": 2,
        "marks": [
            {
                "category": "cmdline",
                "ioc": "taskkill.exe \/F \/IM wscript.exe \/T",
                "type": "ioc",
                "description": null
            },
            {
                "category": "cmdline",
                "ioc": "\"C:\\Windows\\System32\\taskkill.exe\" \/F \/IM wscript.exe \/T",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [
            "http:\/\/blog.jpcert.or.jp\/2016\/01\/windows-commands-abused-by-attackers.html"
        ],
        "name": "uses_windows_utilities"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Attempts to create or modify system certificates",
        "severity": 3,
        "marks": [
            {
                "category": "registry",
                "ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\\Blob",
                "type": "ioc",
                "description": null
            },
            {
                "category": "registry",
                "ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\8F43288AD272F3103B6FB1428485EA3014C0BCFE\\Blob",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "modifies_certificates"
    },
    {
        "markcount": 4,
        "families": [],
        "description": "One or more martian processes was created",
        "severity": 3,
        "marks": [
            {
                "parent_process": "wscript.exe",
                "type": "generic",
                "martian_process": "taskkill.exe \/F \/IM wscript.exe \/T"
            },
            {
                "parent_process": "wscript.exe",
                "type": "generic",
                "martian_process": "C:\\Bomgar\\bom.bat"
            },
            {
                "parent_process": "wscript.exe",
                "type": "generic",
                "martian_process": "\"C:\\Windows\\System32\\taskkill.exe\" \/F \/IM wscript.exe \/T"
            },
            {
                "parent_process": "wscript.exe",
                "type": "generic",
                "martian_process": "\"C:\\Bomgar\\bom.bat\" "
            }
        ],
        "references": [],
        "name": "process_martian"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Resumed a suspended thread in a remote process potentially indicative of process injection",
        "severity": 3,
        "marks": [
            {
                "category": "Process injection",
                "ioc": "Process 2732 resumed a thread in remote process 1516",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtResumeThread",
                    "return_value": 0,
                    "arguments": {
                        "thread_handle": "0x00000258",
                        "suspend_count": 1,
                        "process_identifier": 1516
                    },
                    "time": 1577346788.233875,
                    "tid": 1676,
                    "flags": {}
                },
                "pid": 2732,
                "type": "call",
                "cid": 2272
            }
        ],
        "references": [
            "www.endgame.com\/blog\/technical-blog\/ten-process-injection-techniques-technical-survey-common-and-trending-process"
        ],
        "name": "injection_resumethread"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "The process wscript.exe wrote an executable file to disk which it then attempted to execute",
        "severity": 6,
        "marks": [
            {
                "category": "file",
                "ioc": "C:\\Windows\\SysWOW64\\wscript.exe",
                "type": "ioc",
                "description": null
            },
            {
                "category": "file",
                "ioc": "C:\\Windows\\System32\\taskkill.exe",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "suspicious_write_exe"
    }
]

Yara

The Yara rules did not detect anything in the file.

Network

{
    "tls": [],
    "udp": [
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 546,
            "time": 3.078572988510132,
            "dport": 137,
            "sport": 137
        },
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 27906,
            "time": 9.079013109207153,
            "dport": 138,
            "sport": 138
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 29750,
            "time": 44.94968605041504,
            "dport": 5355,
            "sport": 49556
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 30070,
            "time": 9.258134126663208,
            "dport": 5355,
            "sport": 49840
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 30390,
            "time": 35.57154202461243,
            "dport": 5355,
            "sport": 50202
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 30710,
            "time": 63.378835916519165,
            "dport": 5355,
            "sport": 50952
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 31030,
            "time": 3.0123281478881836,
            "dport": 5355,
            "sport": 51001
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 31358,
            "time": 74.99384903907776,
            "dport": 5355,
            "sport": 51670
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 31678,
            "time": 14.51257610321045,
            "dport": 5355,
            "sport": 52259
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 31998,
            "time": 1.030930995941162,
            "dport": 5355,
            "sport": 53595
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 32326,
            "time": 3.020951986312866,
            "dport": 5355,
            "sport": 53848
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 32654,
            "time": 58.643681049346924,
            "dport": 5355,
            "sport": 54025
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 32974,
            "time": 28.792181968688965,
            "dport": 5355,
            "sport": 54237
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 33294,
            "time": 1.540647029876709,
            "dport": 5355,
            "sport": 54255
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 33622,
            "time": 21.949700117111206,
            "dport": 5355,
            "sport": 54335
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 33942,
            "time": -0.09189796447753906,
            "dport": 5355,
            "sport": 55314
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 34270,
            "time": 71.10877704620361,
            "dport": 5355,
            "sport": 55385
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 34590,
            "time": 6.644366979598999,
            "dport": 5355,
            "sport": 55880
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 34910,
            "time": 52.3165340423584,
            "dport": 5355,
            "sport": 56347
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 35230,
            "time": 38.14212512969971,
            "dport": 5355,
            "sport": 56353
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 35550,
            "time": 61.79014301300049,
            "dport": 5355,
            "sport": 56388
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 35870,
            "time": 65.95328211784363,
            "dport": 5355,
            "sport": 58056
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 36190,
            "time": 61.2177300453186,
            "dport": 5355,
            "sport": 58651
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 36510,
            "time": 28.242484092712402,
            "dport": 5355,
            "sport": 58989
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 36830,
            "time": 68.5362799167633,
            "dport": 5355,
            "sport": 59113
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 37150,
            "time": 54.88320207595825,
            "dport": 5355,
            "sport": 59490
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 37470,
            "time": 25.650329113006592,
            "dport": 5355,
            "sport": 59548
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 37790,
            "time": 31.391716957092285,
            "dport": 5355,
            "sport": 60071
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 38110,
            "time": 47.514729022979736,
            "dport": 5355,
            "sport": 60575
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 38430,
            "time": 32.9899320602417,
            "dport": 5355,
            "sport": 62601
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 38750,
            "time": 64.34856414794922,
            "dport": 5355,
            "sport": 63089
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 39070,
            "time": 19.345186948776245,
            "dport": 5355,
            "sport": 63506
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 39390,
            "time": 30.40806007385254,
            "dport": 5355,
            "sport": 63646
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 39710,
            "time": 11.920993089675903,
            "dport": 5355,
            "sport": 64017
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 40030,
            "time": 1.0517950057983398,
            "dport": 1900,
            "sport": 1900
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 59440,
            "time": 1.052065134048462,
            "dport": 3702,
            "sport": 49152
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 67824,
            "time": 3.125354051589966,
            "dport": 1900,
            "sport": 53598
        }
    ],
    "dns_servers": [],
    "http": [],
    "icmp": [],
    "smtp": [],
    "tcp": [],
    "smtp_ex": [],
    "mitm": [],
    "hosts": [],
    "pcap_sha256": "b2ed9fdb2d4c87436b8c3ccf960c33f59765ec94862daacf501cd006d390e60b",
    "dns": [],
    "http_ex": [],
    "domains": [],
    "dead_hosts": [],
    "sorted_pcap_sha256": "15b3ef7e544b0a831687b77be41c919438b4e3f2992322c8ca00b5c84ec493d1",
    "irc": [],
    "https_ex": []
}

Screenshots

Screenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandbox

Bomgar2.exe removal instructions

The instructions below shows how to remove Bomgar2.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the Bomgar2.exe file for removal, restart your computer and scan it again to verify that Bomgar2.exe has been successfully removed. Here are the removal instructions in more detail:

  1. Start FreeFixer and press the Start Scan button. The scan will finish in approximately five minutes.
    Screenshot of Start Scan button
  2. When the scan is finished, locate Bomgar2.exe in the scan result and tick the checkbox next to the Bomgar2.exe file. Do not check any other file for removal unless you are 100% sure you want to delete it. Tip: Press CTRL-F to open up FreeFixer's search dialog to quickly locate Bomgar2.exe in the scan result.
    Red arrow point on the unwanted file
    c:\downloads\Bomgar2.exe
  3. Scroll down to the bottom of the scan result and press the Fix button. FreeFixer will now delete the Bomgar2.exe file.
    Screenshot of Fix button
  4. Restart your computer.
  5. Start FreeFixer and scan your computer again. If Bomgar2.exe still remains in the scan result, proceed with the next step. If Bomgar2.exe is gone from the scan result you're done.
  6. If Bomgar2.exe still remains in the scan result, check its checkbox again in the scan result and click Fix.
  7. Restart your computer.
  8. Start FreeFixer and scan your computer again. Verify that Bomgar2.exe no longer appear in the scan result.
Please select the option that best describe your thoughts on the removal instructions given above








Hashes [?]

PropertyValue
MD584b7c343eca0b085d1e597622544409e
SHA256c62d73f85370422f102f45dd139a8fab5aa65f2bcc6483d4632c73107ee3b71a

Error Messages

These are some of the error messages that can appear related to bomgar2.exe:

bomgar2.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

bomgar2.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.

bomgar2.exe has stopped working.

End Program - bomgar2.exe. This program is not responding.

bomgar2.exe is not a valid Win32 application.

bomgar2.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.

What will you do with Bomgar2.exe?

To help other users, please let us know what you will do with Bomgar2.exe:



Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

No comments posted yet.

Leave a reply