Hi Paul,
I ran the RAT identifier program you sent me to on
on a customer's computer. It kicked me out and it
kicked out something called "Parsec"
Looking at the Rat id program's source code, I find:
[PSCustomObject]@{Name = "Parsec"; DisplayName = "Parsec"; ProcessName = "parsecd", "pservice"; ExecutablePath = "Parsec\parsecd.exe", "Parsec\pservice.exe" }
I was unable to find those names or paths anywhere on
his drive or in his registry. And no running program
or service called that or similar.
Hmmmmmmmm. Your take?
-T
On 12/13/2023 11:03 PM, T wrote:
Hi Paul,
I ran the RAT identifier program you sent me to on
on a customer's computer. It kicked me out and it
kicked out something called "Parsec"
Looking at the Rat id program's source code, I find:
[PSCustomObject]@{Name = "Parsec"; DisplayName = "Parsec"; ProcessName = "parsecd", "pservice"; ExecutablePath = "Parsec\parsecd.exe", "Parsec\pservice.exe" }
I was unable to find those names or paths anywhere on
his drive or in his registry. And no running program
or service called that or similar.
Hmmmmmmmm. Your take?
-T
Could it be disguised ?
https://en.wikipedia.org/wiki/Parsec_%28software%29
"In January 2018, Parsec partnered with Hewlett-Packard to create OMEN Game Stream,
a free game streaming service based on Parsec's technology designed specifically for HP Omen PCs."
A RAT Hunter needs continuous maintenance, almost as
badly as an AV needs malware definitions :-)
Paul
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 297 |
Nodes: | 16 (2 / 14) |
Uptime: | 05:05:41 |
Calls: | 6,666 |
Files: | 12,213 |
Messages: | 5,335,947 |