RMM
GetScreen
GetScreen is a remote monitoring and management (RMM) tool that enables remote desktop access and unattended persistent access via service installation. It can be installed via command line and registers itself as a Windows service named "Getscreen.me".
Tool overview
- Category
- RMM
- Research authors
- PixelTommy & Guzzy (SagaLabs & itm8 ARC)
- Created
- 2024-08-02
- Last modified
- 2026-05-04
- Privileges
- Admin
- Free / availability
- Not recorded
- Verification required
- Not recorded
- Supported platforms
Windows
Capabilities
Executables & installation paths
- Filename
- getscreen.exe
- OriginalFileName
- getscreen.exe
- Description
- Getscreen.me agent (ProductName/InternalName: Getscreen.me, CompanyName: Point B Ltd). Distributed as a UPX-packed PE32 (x86) GUI executable from https://getscreen.me/download/getscreen-x86.exe. Current binaries (file version 3.5.0+) are signed by POINT B LTD (Cyprus, registered HE 430957) on a GlobalSign GCC R45 EV CodeSigning chain. Older 2020-2021 era binaries were signed by OOO "GET SKRIN SOFTVER" on a COMODO RSA Extended Validation Code Signing CA chain (now expired).
Installation paths
C:\ProgramData\Getscreen.me\
C:\Users\*\AppData\Local\Getscreen.me\
C:\Program Files\Getscreen.me\
C:\Users\*\Downloads\getscreen-x86.exe
C:\Users\*\Downloads\getscreen.upd.exe
Code signing
- signer name
- Kopetra Ltd.
- certificate thumbprint
- 8371992440D77154BB64BF0872E861D6372F70E8
- tbs sha256
- 18450D4DFF502326C24240AA0A1A1971DA4DC7C96D3613B64180FDCE318A710A
- tbs sha1
- Not recorded
search names
2025-12-14_6f3bd1ad8919f9cd6ab1752009741a86_amadey_darkgate_elex_glassworm_helldown_hijackloader_luca-stealer_lynx_njrat
getscreen.me
rfbhr3zzo.exe
company names
signer names
Kopetra Ltd.
File hashes
- authenticode
- file name
- rfbhr3zzo.exe
- sha256
- 05C954C3A8FB10AAA661264282C52975EA1C74A32B8433CED2555B2CF25EFF60
- sha1
- 92AFA21260BC69868A680E6052BC572A19FC88EC
- file name
- Getscreen.me
- sha256
- 925EF1C48B8179F2623519434DBB7CD72E5CA92633EDB7841449AC415B61AB49
- sha1
- 0CE759DD9ACC3250F8D237E10DACB6FEA5A1C3F3
- file name
- 2025-12-14_6f3bd1ad8919f9cd6ab1752009741a86_amadey_darkgate_elex_glassworm_helldown_hijackloader_luca-stealer_lynx_njrat
- sha256
- 35E306C5BA02B38E3E693E1EEBEEEE44144606DFB68A4C6E516319958EDD907B
- sha1
- 2379071527D41E23C58CE5CED0344DD3C220C4EA
- page
- file name
- Getscreen.me
- sha256
- 4ABE10F84D0F58D30A0D8EAE3092987E72507D63253A1D3B190FE7A65263B0BF
- sha1
- 10B8E5D5EE6A573F000233DEF7E7C42136B6BE58
- file name
- 2025-12-14_6f3bd1ad8919f9cd6ab1752009741a86_amadey_darkgate_elex_glassworm_helldown_hijackloader_luca-stealer_lynx_njrat
- sha256
- CAC3DA59CBE1207100FCF9DD22A16756767EBA54AAE765BBE760C0E929A5C27B
- sha1
- C73D2C372F8DDB0A11F1AFD84E7CF1D529DD8786
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\ProgramData\Getscreen.me\<date>.log
- Description
- General application log file containing timestamps in UTC. The date and year must be correlated from the filename, as a new log is created for each day.
- OS
- Windows
- Example
- 11:52:18.642 INFO Capture capture stopped
- 11:56:05.638 INFO ConfigStore loaded config from `C:\ProgramData\Getscreen.me\settings.dat`
- 11:56:06.239 INFO Signaling start connection to 'getscreen.me/signal/agent'
- 11:56:06.417 INFO Socket connected to getscreen.me:443
- 11:56:06.953 INFO Signaling registered as 4895701
- 11:56:07.128 INFO Signaling successful register as '87c34ca23391@tutamail.com'
- 11:56:07.142 INFO Install start installation
- 11:56:07.152 INFO Install copy file 'C:\Users\Public\Videos\getscreen.exe' -> 'C:\Program Files\Getscreen.me\getscreen.exe'
- 11:56:07.257 INFO Service service 'Getscreen.me' installed'
- File
- C:\ProgramData\Getscreen.me\<date>.gui.log
- Description
- Operator interaction log. Records all actions performed by the operator on the remote host, including control mode activity and interactive file explorer usage. Timestamps are in UTC and must be correlated with the filename for full date context.
- OS
- Windows
- Example
- 12:42:53.770 INFO Gui send event event-application-status: '{\"value\":\"connect\"}'
- 12:42:53.802 INFO Gui send event event-active-session: '{\"value\":[{\"id\":\"189333\",\"active\":true,\"ip\":\"94.156.14.71\",\"country\":\"Bulgaria\",\"region\":\"Sofia-grad\",\"city\":\"Sofia\",\"browser\":\"Firefox\",\"link\":\"https://go.getscreen.me/j33-l1h-3ib\",\"login\":\"Christian Henriksen\",\"start\":0.0,\"stop\":0.0,\"mode\":\"file\",\"plan\":{\"name\":\"free\",\"status\":\"active\"}}]}'
- 12:42:55.111 INFO Gui send event event-application-status: '{\"value\":\"active\"}'
- 12:45:40.370 INFO Gui send event event-notify-dowload: '{\"value\":\"C:\\\\Users\\\\christian\\\\Downloads\\\\invoice-124513.pdf\"}'
- 12:46:44.115 INFO Gui send event event-notify-upload: '{\"value\":\"C:\\\\Users\\\\christian\\\\Downloads\\\\Advanced_Port_Scanner_2.5.3869.exe\"}'
- 12:50:24.557 INFO Gui send event event-session-info: '{\"active\":false,\"ip\":\"94.156.14.71\",\"country\":\"Bulgaria\",\"region\":\"Sofia-grad\",\"city\":\"Sofia\",\"browser\":\"Firefox\",\"link\":\"https://go.getscreen.me/j33-l1h-3ib\",\"login\":\"Christian Henriksen\",\"start\":1775997775.0,\"stop\":1775998224.0,\"mode\":\"file\"}'
- 12:50:24.583 INFO Gui send event event-confirm-request: '{\"session\":\"189333\",\"mode\":\"connect\",\"status\":\"rejected\",\"name\":\"\",\"email\":\"\",\"company\":\"\",\"location\":\"\",\"ip\":\"\",\"user_agent\":\"\",\"timeout\":0.0,\"path\":\"\"}}'
- File
- C:\ProgramData\Getscreen.me\session.inf
- Description
- Contains a list of previous sessions with source IP, country, region, city and start/end time in epoch format.
- OS
- Windows
- Example
- 94.156.14.105;Bulgaria;Sofia-grad;Sofia;1775995673;1775995861
- 94.156.14.80;Bulgaria;Sofia-grad;Sofia;1775996986;1775996993
- 94.156.14.44;Bulgaria;Sofia-grad;Sofia;1775997614;1775997752
- 94.156.14.71;Bulgaria;Sofia-grad;Sofia;1775997775;1775998224
- File
- C:\Users\*\AppData\Local\Getscreen.me
- Description
- Local application data directory.
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- Getscreen.me
- ImagePath
- C:\Program Files\Getscreen.me\getscreen.exe
- Description
- Service installation event as a result of GetScreen installation. The persistent service typically points at the elevation helper under %ProgramData%, e.g. '"C:\ProgramData\Getscreen.me\<random28chars>-elevate.exe" -elevate \\.\pipe\elevateGS512<random28chars>' where the random alpha string is generated per-install.
- EventID
- 4697
- ProviderName
- Microsoft-Security-Auditing
- LogFile
- Security.evtx
- ServiceName
- Getscreen.me
- ImagePath
- C:\Program Files\Getscreen.me\getscreen.exe
- Description
- Service installation event as a result of GetScreen installation. ImagePath may also reference the elevation helper under %ProgramData% (see EventID 7045 description).
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKU\{SID}\Software\GetScreen
- Description
- Application settings including language preferences.
- Path
- HKU\{SID}\Software\GetScreen\Getscreen.me
- Description
- Application-specific settings.
- Path
- HKLM\System\CurrentControlSet\Services\GetscreenSV
- Description
- Service registry key created when Getscreen.me installs persistence (SCM service key name is 'GetscreenSV', friendly name 'Getscreen.me'). The ImagePath value typically points at a per-install elevation helper such as '"C:\ProgramData\Getscreen.me\<random28chars>-elevate.exe" -elevate \\.\pipe\elevateGS512<random28chars>'.
FORENSIC EVIDENCE
Network artifacts
- Description
- Known remote domains
- Domains
- getscreen.me
- GetScreen.me
- *.getscreen.me
- go.getscreen.me
- image.getscreen.me
- px-*.getscreen.me
- Ports
- 443
FORENSIC EVIDENCE
Other artifacts
- Type
- ServiceName
- Value
- Getscreen.me
- Type
- ServiceName
- Value
- GetscreenSV
- Type
- NamedPipe
- Value
- PCommand*GetScreen.meout
- Type
- NamedPipe
- Value
- \\.\pipe\elevateGS512*
- Type
- NamedPipe
- Value
- \\.\pipe\PCommand*Getscreen.me*
- Type
- CommandLine
- Value
- getscreen.exe -install -register 87c34ca23sss391@tutamail.com
- Type
- CommandLine
- Value
- getscreen-x86.exe -gpipe \\.\pipe\PCommand*Getscreen.me* -gui
- Type
- CommandLine
- Value
- *-elevate.exe -elevate \\.\pipe\elevateGS512*
- Type
- SHA256
- Value
- 611835aa02303ffa12762d412882a9fc7249ce1e52b931c0e8e58891c553548c
- Type
- Authentihash
- Value
- c547fa46ec6345b04fb131b77b918d3aad455701b4dd152f6f4f612ba8fcc545
- Type
- PublisherCertSubject
- Value
- CN=POINT B LTD, O=POINT B LTD, L=Limassol, ST=Limassol, C=CY (jurisdictionC=CY, serialNumber=HE 430957, businessCategory=Private Organization)
- Type
- PublisherCertIssuer
- Value
- CN=GlobalSign GCC R45 EV CodeSigning CA 2020, O=GlobalSign nv-sa, C=BE
- Type
- PublisherCertSerial
- Value
- 7ae0e9c1cfe2dce0e21c4327
- Type
- PublisherCertTBSSha256
- Value
- 3696C8A244152307EA16EA1613ED0ECAFD138F3AF475C5A03B5B80A77E5E240C
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/getscreen_network_sigma.yml
- Description
- Detects potential network activity of GetScreen RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/getscreen_processes_sigma.yml
- Description
- Detects potential processes activity of GetScreen RMM tool