RAT

mRemoteNG

mRemoteNG is a remote monitoring and management (RMM) tool. More information will be added as it becomes available.

Tool overview

Category
RAT
Research authors
Not recorded
Created
2024-08-02
Last modified
2026-06-16
Privileges
Not recorded
Free / availability
Not recorded
Verification required
Not recorded
Supported platforms
Not recorded

Executables & installation paths

Filename
Not recorded
OriginalFileName
Not recorded
Description
Not recorded

Installation paths

mRemoteNG.exe
C:\Program Files (x86)\mRemoteNG\*
*\mRemoteNG\*
*\mRemoteNG.exe
c:\Program Files (x86)%\mRemoteNG
*%\mRemoteNG
mRemoteNG-Installer-*.msi

Code signing

signer name
David Sparer
certificate thumbprint
DEFFB77C09F5ADC3691A0EA8A36E2617577AF8AB
tbs sha256
80840828E6440160B4977E9AA21613D0452E7B272AF7D32B5007AB419E61CD25
tbs sha1
Not recorded
signer name
Open Source Developer, Dimitrij Gorodeckij
certificate thumbprint
93F35DA1E0F1E59DB3455D29AF83CE90FAC249F4
tbs sha256
C85CE1021CB17FCD3C004433B22F1018A75AEBCD8413CD4BBC2D78AE8C8878EB
tbs sha1
Not recorded
signer name
David Sparer
certificate thumbprint
N/A
tbs sha256
99443F90AB887671A05644A2E854F307E68508B3E7BCB7852EF6AC1DDFBA55FA
tbs sha1
Not recorded
signer name
Simon Tatham
certificate thumbprint
N/A
tbs sha256
Not recorded
tbs sha1
Not recorded
tbs sha384
47D33AA6FC96754AAB657A6EC79291F7D98D12E39010E6060EF3770042343B1C2BADA6B732510F090C1A592CAE653579

search names

7zip.exe
mremoteng.dll
mremoteng.exe

company names

signer names

David Sparer
Open Source Developer, Dimitrij Gorodeckij
Simon Tatham

File hashes

authenticode
  • file name
    mRemoteNG.dll
    sha256
    482D78559F3E0A3AEC8BF79B0E0C168F800F6B139E4128479C41193EAFAAC1AF
    sha1
    1C317C6177EE99D84C5D563C8C3A960F73CD6096
  • file name
    7zip.exe
    sha256
    4EF18639D8D70955EC4820948FEBF02C4B7716B3048172955AB164CD562894C1
    sha1
    E8BDC8FF6F566BDE26438CB2D0507FAEFB1939C5
  • file name
    mRemoteNG.dll
    sha256
    AE488CB60C974C072DB559BF3145D17C4D7F552720CA8F0AA7D2662E9849A3EB
    sha1
    BA2020535A1E6BAE3594A019AEF3D72479FA2D52
  • file name
    mRemoteNG.exe
    sha256
    0AF3EE69684F0BAAFC16E77385D39FAE0FA67C71F92CF39680F1FB28C3F1EDBB
    sha1
    E2D90B145DBD83902D7181F084A200B76E2554A0
page
  • file name
    mRemoteNG.dll
    sha256
    8CA9E203261D960AB18E6328B80BDF8B9BCAE8CC33DAFA3604C146BD0CB28184
    sha1
    892C5F2F52D2560173B0A18292FE7C3F23554F47
  • file name
    7zip.exe
    sha256
    81D39F11817B00E1A7C3C4A231D0F194CB28B71FA2858E1801CCB043479D2B1E
    sha1
    C832238CE751692DFF2664A475C601694BEB8E4B
  • file name
    mRemoteNG.dll
    sha256
    03DA1F5410534F288B3D67C251576555BACB4DA3FF22DC46012C18524412A3F9
    sha1
    6D818BA71DAA614966A19A0CC215B3A9523BB8A0
  • file name
    mRemoteNG.exe
    sha256
    F41D38027B95545762BE5F7C19193235D6BAF39E20D2F9C9AFAD70BFBA9E8944
    sha1
    86779603005DCA848CF51C10E48B086EC11159C6

FORENSIC EVIDENCE

Disk artifacts

File
C:\Users\*\AppData\Roaming\mRemoteNG\mRemoteNG.log
Description
mRemoteNG log file
OS
Windows
File
C:\Users\*\AppData\Roaming\mRemoteNG\confCons.xml
Description
mRemoteNG configuration file
OS
Windows
File
C:\Users\*\AppData\*\mRemoteNG\**10\user.config
Description
mRemoteNG user configuration file
OS
Windows

FORENSIC EVIDENCE

Network artifacts

Description
Known remote domains
Domains
  • user_managed
  • mremoteng.org
Ports
Not recorded

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/mremoteng_network_sigma.yml
Description
Detects potential network activity of mRemoteNG RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/mremoteng_files_sigma.yml
Description
Detects potential files activity of mRemoteNG RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/mremoteng_processes_sigma.yml
Description
Detects potential processes activity of mRemoteNG RMM tool

References