RMM
Jump Desktop
Jump Desktop is a remote monitoring and management (RMM) tool. More information will be added as it becomes available.
Tool overview
- Category
- RMM
- Research authors
- Not recorded
- Created
- 2024-08-02
- Last modified
- 2025-12-14
- Privileges
- Not recorded
- Free / availability
- Not recorded
- Verification required
- Not recorded
- Supported platforms
- Not recorded
Executables & installation paths
- Filename
- Not recorded
- OriginalFileName
- Not recorded
- Description
- Not recorded
Installation paths
jumpclient.exe
jumpdesktop.exe
jumpservice.exe
jumpconnect.exe
jumpupdater.exe
Code signing
- signer name
- PhaseFive Systems LLC
- certificate thumbprint
- N/A
- tbs sha256
- 1BF55DAA063110C36CA3667802D5FAB3FC46D99873BB470CE1E0DD395354BEB6
- tbs sha1
- Not recorded
- signer name
- Phase Five Systems LLC
- certificate thumbprint
- N/A
- tbs sha256
- 603F50F6A334218C4ED384ACF9AA88190B3DFC029D54453C27D3167E48C152A0
- tbs sha1
- Not recorded
- signer name
- PhaseFive Systems LLC
- certificate thumbprint
- N/A
- tbs sha256
- Not recorded
- tbs sha1
- Not recorded
- tbs sha384
- 427CA734B98DF79C7BB95E4520DBFA6A12155FA52D1F7358A60F15A9904BDC6A95EA04123C2C81437EF981F89E5351CC
- signer name
- PhaseFive Systems LLC
- certificate thumbprint
- C5FB19F11FEA6AA9A7A61FF4D327ACA054E7145A
- src file sha256
- 880b3e0e54169ab6e32e9cb9d4c20c234dfc2d0dfeaee6faf68d4257941cf1ed
- src file path
- downloaded_files/jump_desktop/880b3e0e54169ab6e32e9cb9d4c20c234dfc2d0dfeaee6faf68d4257941cf1ed
- src file company
- Phase Five Systems
search names
jumpconnect.exe
jumpconnectcore.dll
jumpupdater
vespra.exe
winkill.exe
company names
signer names
Phase Five Systems LLC
PhaseFive Systems LLC
File hashes
- authenticode
- file name
- WinKill.exe
- sha256
- D22A7440AC93F2ED3857F99AF0740E8F4038D061B8D33928F952B5DD1DF6D9BA
- sha1
- 37339CE3C4B94F5E583ACA18E06620BE26C3AD94
- file name
- JumpUpdater
- sha256
- 0E3F9202416DA42E7223E9FD77792996BE56A7A6F1169FEF3F1CA96B7D534312
- sha1
- 900CE766130609452A35EBA3251CB6B0992F080B
- file name
- JumpConnectCore.dll
- sha256
- EBB553A616BBB7BEFA8C0ED0B72BDE1E8CED079786357ADCA5F48F80FD187418
- sha1
- A1155A615AC27185AC8C2359C85C9A51971515E4
- file name
- JumpConnect.exe
- sha256
- 0E4949B1752AABCA178C61784766B69F2FF1631B4F7745DB0A9C792F22DDC34C
- sha1
- 8DA38187F5511E9FB1493D767CD543E15D787CCE
- file name
- JumpConnect.exe
- sha256
- C8E05EDECC32DC21156B150DDAA607068129968518876BCC98E6E75A4A628B99
- sha1
- B24F381CB79CEE27A5B62BAFBF016CB03A8E9E0F
- file name
- vespra.exe
- sha256
- D9DBAD65C7AF9F04B890B18A080604A632BE2B9A8F4896E526470C8BA3919C42
- sha1
- C920B9DDAC8CCE83BC5B316261D16A9FBD2B1408
- page
- file name
- WinKill.exe
- sha256
- 41898FDA5DA79105D2BA6A06348F36258156D905B2215F201F91727D104E72BA
- sha1
- 4777BF27ABE31CBDF780EC83411A167BB7264500
- file name
- JumpUpdater
- sha256
- D42825615C9AA55BC1952E578C904F01528D6E8F60C5A1CD4CACDEA255D57B8D
- sha1
- 501900D68D3C7C05A8A7781E4C92B9862B16A538
- file name
- JumpConnectCore.dll
- sha256
- 0D59525F58B5228DFEBFF7A4FF8AE2EF69D8F6B21A29A902CBC4DF09C349C196
- sha1
- 2212678443DAF27CDAA473E85F6C728D18E9DD18
- file name
- JumpConnect.exe
- sha256
- EBAC7E547E2DECA642BFC0D4950E8D56F3474B67CDCB397F01E88E6667219C6E
- sha1
- D8CBB63766CD6196AAFA7988B1F15F74450D9E61
FORENSIC EVIDENCE
Network artifacts
- Description
- Known remote domains
- Domains
- *.jumpdesktop.com
- jumpdesktop.com
- jumpto.me
- *.jumpto.me
- Ports
- Not recorded
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/jump_desktop_network_sigma.yml
- Description
- Detects potential network activity of Jump Desktop RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/jump_desktop_processes_sigma.yml
- Description
- Detects potential processes activity of Jump Desktop RMM tool