RMM

Access Remote PC

Access Remote PC is a remote monitoring and management (RMM) tool. More information will be added as it becomes available.

Tool overview

Category
RMM
Research authors
Not recorded
Created
2024-08-02
Last modified
2024-08-02
Privileges
Not recorded
Free / availability
Yes
Verification required
Yes
Supported platforms
AndroidLinuxWindowsiOSmacOS

Executables & installation paths

Filename
Not recorded
OriginalFileName
Not recorded
Description
Not recorded

Installation paths

C:\Program Files (x86)\RemotePC\*

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files (x86)\RemotePC\RemotePCUIU.exe
Description
RemotePC service binary
OS
Windows
File
C:\Program Files (x86)\RemotePC\*
Description
Multiple files and binaries related to RemotePC installation
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
RemotePC Performance Service
ImagePath
"C:\\Program Files (x86)\\RemotePC\\RemotePCPerformance\\RPCPerformanceService.exe"
Description
Service installation event as result of RemotePC installation.
EventID
4688
ProviderName
Microsoft-Security-Auditing
LogFile
Security.evtx
CommandLine
sc create RPCService start=auto binpath="C:\\Program Files (x86)\\RemotePC\\RemotePCService.exe"
Description
Executing command to install RemotePC service.
EventID
4688
ProviderName
Microsoft-Security-Auditing
LogFile
Security.evtx
CommandLine
C:\\Windows\\system32\\schtasks /create /SC DAILY /st 12:00 /TN "RPCPerformanceHealthCheck" /TR "C:\\Program Files (x86)\\RemotePC\\RemotePCPerformance\\RPCPerformanceDownloader.exe" /rl HIGHEST /ru system
Description
Executing command to create RemotePC HealthCheck scheduled task.
EventID
4688
ProviderName
Microsoft-Security-Auditing
LogFile
Security.evtx
CommandLine
C:\Windows\regedit.exe /s C:\Program Files (x86)\RemotePC\Register.reg
Description
Executing command to install various registry changes related to RemotePC.
EventID
4688
ProviderName
Microsoft-Security-Auditing
LogFile
Security.evtx
CommandLine
netsh advfirewall firewall add rule name="RemotePCDesktop" enable=yes dir=in action=allow profile=any program="C:\Program Files (x86)\RemotePC\RemotePCDesktop.exe" description="This program is used for File Transfer and is part of RemotePC product."
Description
Executing command to add local firewall rule to allow inbound traffic for RemotePC.

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/access_remote_pc_files_sigma.yml
Description
Detects potential files activity of Access Remote PC RMM tool

References

Not recorded

Acknowledgements

Person
Daniel Koifman
Handle
@koifsec