#32235 [Huntress Detection] CRITICAL - ISOLATED - Incident on FRP-PatXPS (Farran Realty Partners)
Resolved
Created Feb 5, 2025, 3:43 PM
Resolved Feb 5, 2025, 5:56 PM
Huntress (internal)
Feb 5, 2025, 3:43 PM
Artichoke Support - Peet (internal)
Feb 5, 2025, 4:43 PM
The following remediation plan was approved by [email protected]: Assisted Remediations: Kill Process: ["Path: C:\\Users\\jpcorrick\\Downloads\\support.Client.exe", "Pid: 23236"] Kill Process: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\ScreenConnect.ClientService.exe", "Pid: 22888"] Kill Process: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\ScreenConnect.ClientService.exe", "Pid: 20544"] Kill Process: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\ScreenConnect.ClientService.exe", "Pid: 18724"] Kill Process: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\ScreenConnect.ClientService.exe", "Pid: 15544"] Kill Process: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\ScreenConnect.ClientService.exe", "Pid: 4412"] Kill Process: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\ScreenConnect.WindowsClient.exe", "Pid: 26516"] Kill Process: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\ScreenConnect.ClientService.exe", "Pid: 21252"] Delete File: ["Path: c:\\users\\jpcorrick\\appdata\\local\\apps\\2.0\\v5xod0ol.z9v\\025691br.4vt\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\screenconnect.windowsclient.exe"] Kill Process: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\ScreenConnect.WindowsClient.exe", "Pid: 26516"] Delete File: ["Path: C:\\Users\\jpcorrick\\Downloads\\support.Client.exe"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\Client.Override.en-US.resources"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\Client.Override.resources"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\Client.en-US.resources"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\Client.resources"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.Client.cdf-ms"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.Client.dll"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.Client.manifest"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.ClientService.cdf-ms"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.ClientService.dll"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.ClientService.exe"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.ClientService.manifest"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.Core.cdf-ms"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.Core.dll"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.Core.manifest"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.Windows.cdf-ms"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.Windows.dll"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.Windows.manifest"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.WindowsBackstageShell.exe"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.WindowsBackstageShell.exe.config"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.WindowsClient.cdf-ms"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.WindowsClient.exe"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.WindowsClient.exe.cdf-ms"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.WindowsClient.exe.config"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.WindowsClient.exe.manifest"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.WindowsClient.manifest"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.WindowsFileManager.exe"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\ScreenConnect.WindowsFileManager.exe.config"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\app.config"] Delete File: ["Path: C:\\Users\\jpcorrick\\AppData\\Local\\Apps\\2.0\\V5XOD0OL.Z9V\\025691BR.4VT\\scre..tion_25b0fbb6ef7eb094_0018.0003_804b30f232b53ee1\\\\user.config"] Reboot the Host: ["Remediation: A reboot is required to complete the remediation plan"]
| Started | Ended | Hours | Notes |
|---|---|---|---|
| No time entries | |||