RMM

GetScreen

GetScreen is a remote monitoring and management (RMM) tool that enables remote desktop access and unattended persistent access via service installation. It can be installed via command line and registers itself as a Windows service named "Getscreen.me".

Tool overview

Category
RMM
Research authors
PixelTommy & Guzzy (SagaLabs & itm8 ARC)
Created
2024-08-02
Last modified
2026-05-04
Privileges
Admin
Free / availability
Not recorded
Verification required
Not recorded
Supported platforms
Windows

Capabilities

Remote ControlUnattended AccessGUI SupportCommand line Support

Executables & installation paths

Filename
getscreen.exe
OriginalFileName
getscreen.exe
Description
Getscreen.me agent (ProductName/InternalName: Getscreen.me, CompanyName: Point B Ltd). Distributed as a UPX-packed PE32 (x86) GUI executable from https://getscreen.me/download/getscreen-x86.exe. Current binaries (file version 3.5.0+) are signed by POINT B LTD (Cyprus, registered HE 430957) on a GlobalSign GCC R45 EV CodeSigning chain. Older 2020-2021 era binaries were signed by OOO "GET SKRIN SOFTVER" on a COMODO RSA Extended Validation Code Signing CA chain (now expired).

Installation paths

C:\ProgramData\Getscreen.me\
C:\Users\*\AppData\Local\Getscreen.me\
C:\Program Files\Getscreen.me\
C:\Users\*\Downloads\getscreen-x86.exe
C:\Users\*\Downloads\getscreen.upd.exe

Code signing

signer name
Kopetra Ltd.
certificate thumbprint
8371992440D77154BB64BF0872E861D6372F70E8
tbs sha256
18450D4DFF502326C24240AA0A1A1971DA4DC7C96D3613B64180FDCE318A710A
tbs sha1
Not recorded

search names

2025-12-14_6f3bd1ad8919f9cd6ab1752009741a86_amadey_darkgate_elex_glassworm_helldown_hijackloader_luca-stealer_lynx_njrat
getscreen.me
rfbhr3zzo.exe

company names

signer names

Kopetra Ltd.

File hashes

authenticode
  • file name
    rfbhr3zzo.exe
    sha256
    05C954C3A8FB10AAA661264282C52975EA1C74A32B8433CED2555B2CF25EFF60
    sha1
    92AFA21260BC69868A680E6052BC572A19FC88EC
  • file name
    Getscreen.me
    sha256
    925EF1C48B8179F2623519434DBB7CD72E5CA92633EDB7841449AC415B61AB49
    sha1
    0CE759DD9ACC3250F8D237E10DACB6FEA5A1C3F3
  • file name
    2025-12-14_6f3bd1ad8919f9cd6ab1752009741a86_amadey_darkgate_elex_glassworm_helldown_hijackloader_luca-stealer_lynx_njrat
    sha256
    35E306C5BA02B38E3E693E1EEBEEEE44144606DFB68A4C6E516319958EDD907B
    sha1
    2379071527D41E23C58CE5CED0344DD3C220C4EA
page
  • file name
    Getscreen.me
    sha256
    4ABE10F84D0F58D30A0D8EAE3092987E72507D63253A1D3B190FE7A65263B0BF
    sha1
    10B8E5D5EE6A573F000233DEF7E7C42136B6BE58
  • file name
    2025-12-14_6f3bd1ad8919f9cd6ab1752009741a86_amadey_darkgate_elex_glassworm_helldown_hijackloader_luca-stealer_lynx_njrat
    sha256
    CAC3DA59CBE1207100FCF9DD22A16756767EBA54AAE765BBE760C0E929A5C27B
    sha1
    C73D2C372F8DDB0A11F1AFD84E7CF1D529DD8786

FORENSIC EVIDENCE

Disk artifacts

File
C:\ProgramData\Getscreen.me\<date>.log
Description
General application log file containing timestamps in UTC. The date and year must be correlated from the filename, as a new log is created for each day.
OS
Windows
Example
  • 11:52:18.642 INFO Capture capture stopped
  • 11:56:05.638 INFO ConfigStore loaded config from `C:\ProgramData\Getscreen.me\settings.dat`
  • 11:56:06.239 INFO Signaling start connection to 'getscreen.me/signal/agent'
  • 11:56:06.417 INFO Socket connected to getscreen.me:443
  • 11:56:06.953 INFO Signaling registered as 4895701
  • 11:56:07.128 INFO Signaling successful register as '87c34ca23391@tutamail.com'
  • 11:56:07.142 INFO Install start installation
  • 11:56:07.152 INFO Install copy file 'C:\Users\Public\Videos\getscreen.exe' -> 'C:\Program Files\Getscreen.me\getscreen.exe'
  • 11:56:07.257 INFO Service service 'Getscreen.me' installed'
File
C:\ProgramData\Getscreen.me\<date>.gui.log
Description
Operator interaction log. Records all actions performed by the operator on the remote host, including control mode activity and interactive file explorer usage. Timestamps are in UTC and must be correlated with the filename for full date context.
OS
Windows
Example
  • 12:42:53.770 INFO Gui send event event-application-status: '{\"value\":\"connect\"}'
  • 12:42:53.802 INFO Gui send event event-active-session: '{\"value\":[{\"id\":\"189333\",\"active\":true,\"ip\":\"94.156.14.71\",\"country\":\"Bulgaria\",\"region\":\"Sofia-grad\",\"city\":\"Sofia\",\"browser\":\"Firefox\",\"link\":\"https://go.getscreen.me/j33-l1h-3ib\",\"login\":\"Christian Henriksen\",\"start\":0.0,\"stop\":0.0,\"mode\":\"file\",\"plan\":{\"name\":\"free\",\"status\":\"active\"}}]}'
  • 12:42:55.111 INFO Gui send event event-application-status: '{\"value\":\"active\"}'
  • 12:45:40.370 INFO Gui send event event-notify-dowload: '{\"value\":\"C:\\\\Users\\\\christian\\\\Downloads\\\\invoice-124513.pdf\"}'
  • 12:46:44.115 INFO Gui send event event-notify-upload: '{\"value\":\"C:\\\\Users\\\\christian\\\\Downloads\\\\Advanced_Port_Scanner_2.5.3869.exe\"}'
  • 12:50:24.557 INFO Gui send event event-session-info: '{\"active\":false,\"ip\":\"94.156.14.71\",\"country\":\"Bulgaria\",\"region\":\"Sofia-grad\",\"city\":\"Sofia\",\"browser\":\"Firefox\",\"link\":\"https://go.getscreen.me/j33-l1h-3ib\",\"login\":\"Christian Henriksen\",\"start\":1775997775.0,\"stop\":1775998224.0,\"mode\":\"file\"}'
  • 12:50:24.583 INFO Gui send event event-confirm-request: '{\"session\":\"189333\",\"mode\":\"connect\",\"status\":\"rejected\",\"name\":\"\",\"email\":\"\",\"company\":\"\",\"location\":\"\",\"ip\":\"\",\"user_agent\":\"\",\"timeout\":0.0,\"path\":\"\"}}'
File
C:\ProgramData\Getscreen.me\session.inf
Description
Contains a list of previous sessions with source IP, country, region, city and start/end time in epoch format.
OS
Windows
Example
  • 94.156.14.105;Bulgaria;Sofia-grad;Sofia;1775995673;1775995861
  • 94.156.14.80;Bulgaria;Sofia-grad;Sofia;1775996986;1775996993
  • 94.156.14.44;Bulgaria;Sofia-grad;Sofia;1775997614;1775997752
  • 94.156.14.71;Bulgaria;Sofia-grad;Sofia;1775997775;1775998224
File
C:\Users\*\AppData\Local\Getscreen.me
Description
Local application data directory.
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
Getscreen.me
ImagePath
C:\Program Files\Getscreen.me\getscreen.exe
Description
Service installation event as a result of GetScreen installation. The persistent service typically points at the elevation helper under %ProgramData%, e.g. '"C:\ProgramData\Getscreen.me\<random28chars>-elevate.exe" -elevate \\.\pipe\elevateGS512<random28chars>' where the random alpha string is generated per-install.
EventID
4697
ProviderName
Microsoft-Security-Auditing
LogFile
Security.evtx
ServiceName
Getscreen.me
ImagePath
C:\Program Files\Getscreen.me\getscreen.exe
Description
Service installation event as a result of GetScreen installation. ImagePath may also reference the elevation helper under %ProgramData% (see EventID 7045 description).

FORENSIC EVIDENCE

Registry artifacts

Path
HKU\{SID}\Software\GetScreen
Description
Application settings including language preferences.
Path
HKU\{SID}\Software\GetScreen\Getscreen.me
Description
Application-specific settings.
Path
HKLM\System\CurrentControlSet\Services\GetscreenSV
Description
Service registry key created when Getscreen.me installs persistence (SCM service key name is 'GetscreenSV', friendly name 'Getscreen.me'). The ImagePath value typically points at a per-install elevation helper such as '"C:\ProgramData\Getscreen.me\<random28chars>-elevate.exe" -elevate \\.\pipe\elevateGS512<random28chars>'.

FORENSIC EVIDENCE

Network artifacts

Description
Known remote domains
Domains
  • getscreen.me
  • GetScreen.me
  • *.getscreen.me
  • go.getscreen.me
  • image.getscreen.me
  • px-*.getscreen.me
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
ServiceName
Value
Getscreen.me
Type
ServiceName
Value
GetscreenSV
Type
NamedPipe
Value
PCommand*GetScreen.meout
Type
NamedPipe
Value
\\.\pipe\elevateGS512*
Type
NamedPipe
Value
\\.\pipe\PCommand*Getscreen.me*
Type
CommandLine
Value
getscreen.exe -install -register 87c34ca23sss391@tutamail.com
Type
CommandLine
Value
getscreen-x86.exe -gpipe \\.\pipe\PCommand*Getscreen.me* -gui
Type
CommandLine
Value
*-elevate.exe -elevate \\.\pipe\elevateGS512*
Type
SHA256
Value
611835aa02303ffa12762d412882a9fc7249ce1e52b931c0e8e58891c553548c
Type
Authentihash
Value
c547fa46ec6345b04fb131b77b918d3aad455701b4dd152f6f4f612ba8fcc545
Type
PublisherCertSubject
Value
CN=POINT B LTD, O=POINT B LTD, L=Limassol, ST=Limassol, C=CY (jurisdictionC=CY, serialNumber=HE 430957, businessCategory=Private Organization)
Type
PublisherCertIssuer
Value
CN=GlobalSign GCC R45 EV CodeSigning CA 2020, O=GlobalSign nv-sa, C=BE
Type
PublisherCertSerial
Value
7ae0e9c1cfe2dce0e21c4327
Type
PublisherCertTBSSha256
Value
3696C8A244152307EA16EA1613ED0ECAFD138F3AF475C5A03B5B80A77E5E240C

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/getscreen_network_sigma.yml
Description
Detects potential network activity of GetScreen RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/getscreen_processes_sigma.yml
Description
Detects potential processes activity of GetScreen RMM tool

References