File name:

tvnserver.exe

Full analysis: https://app.any.run/tasks/db0e680b-5e4f-48e3-816d-3a65452541fc
Verdict: Malicious activity
Analysis date: June 05, 2024, 07:03:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3D2CDBC35FAE937903C8B53D1B5175DD

SHA1:

154A94C20903E2EB27BE1CDFF98A8AEAA658B242

SHA256:

0D3F199C9873F1C7D7F282903199A5252370727FA9B6E74F530D5957CFD8B7B9

SSDEEP:

49152:A3kOBc0ihBk90yfY5SZzuNkHwZb2+cio+YtEAgWsJKpOW3:AZBc0uBk90yfcSZzuNkmb2+ciAWKp5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • tvnserver.exe (PID: 3968)
  • SUSPICIOUS

    • Application launched itself

      • tvnserver.exe (PID: 3968)
  • INFO

    • Process checks registry keys that may contain credentials

      • tvnserver.exe (PID: 3968)
    • Checks supported languages

      • tvnserver.exe (PID: 4012)
      • tvnserver.exe (PID: 3968)
    • Reads the computer name

      • tvnserver.exe (PID: 3968)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:01:16 10:10:39+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 1932288
InitializedDataSize: 631808
UninitializedDataSize: -
EntryPoint: 0xe7ba5
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.0
ProductVersionNumber: 2.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Windows NT
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin2 (Eastern European)
CompanyName: Delta India Electronics.
FileDescription: DeltaVNC Server for Windows
FileVersion: 2.0.0.0
InternalName: DeltaVNCServer
LegalCopyright: Copyright (C) 2010-2012 Delta India Electronics.
OriginalFileName: DeltaVNCServer.exe
ProductName: DeltaVNC
ProductVersion: 2.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start tvnserver.exe no specs tvnserver.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3968"C:\Users\admin\AppData\Local\Temp\tvnserver.exe" C:\Users\admin\AppData\Local\Temp\tvnserver.exeexplorer.exe
User:
admin
Company:
Delta India Electronics.
Integrity Level:
MEDIUM
Description:
DeltaVNC Server for Windows
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\tvnserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wtsapi32.dll
4012"C:\Users\admin\AppData\Local\Temp\tvnserver.exe" -controlapp -slaveC:\Users\admin\AppData\Local\Temp\tvnserver.exetvnserver.exe
User:
admin
Company:
Delta India Electronics.
Integrity Level:
MEDIUM
Description:
DeltaVNC Server for Windows
Version:
2.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\tvnserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wtsapi32.dll
Total events
483
Read events
483
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info