File name:

VNC-Server-7.9.0-Windows-32.MSI

Full analysis: https://app.any.run/tasks/275fd918-9a4b-492a-ad6b-a35c15a75d8d
Verdict: Malicious activity
Analysis date: January 12, 2024, 01:09:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: RealVNC Server 7.9.0, Author: RealVNC, Keywords: Installer, Comments: Copyright RealVNC Ltd., Create Time/Date: Tue Jan 9 18:35:50 2024, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 4, Template: Intel;1033, Last Saved By: Intel;3082, Revision Number: {0DFE713A-2452-49FC-B0B7-A684BC8ACCDC}7.9.0.51979;{020308ED-2AD7-4086-BF7B-1C7374774EBD}7.9.0.51979;{2AD32FA2-CA3B-4C90-91EB-5F5FF9E91C2B}, Number of Pages: 200, Number of Characters: 131135
MD5:

D68AFB7F9D85AE9978EF7AA7E1CF7911

SHA1:

7C7ABF08403B0E87A3BE34965550F5ED4D61D090

SHA256:

1574234DC6D838E1B0FFB627F451251B3A0BD360B35254D9D016148B447AB5D0

SSDEEP:

98304:iaa5ybHnJCL7kbFd1isS4vOxaXTdqj5GEV3Ck7xR5uK7nYLGtDG8Rf9F4x4xB+qi:+rMw4Rz6EuNK4biKJ8znRD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file in the system directory

      • drvinst.exe (PID: 2580)
      • drvinst.exe (PID: 1904)
      • printerinst.exe (PID: 2748)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • msiexec.exe (PID: 2440)
      • msiexec.exe (PID: 1356)
      • drvinst.exe (PID: 1904)
      • drvinst.exe (PID: 2580)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2580)
      • drvinst.exe (PID: 1904)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 1904)
      • drvinst.exe (PID: 2580)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 1356)
      • msiexec.exe (PID: 2068)
      • msiexec.exe (PID: 2384)
      • drvinst.exe (PID: 2580)
      • msiexec.exe (PID: 2440)
      • vncserver.exe (PID: 2592)
      • printerinst.exe (PID: 2748)
      • vncserver.exe (PID: 2436)
      • drvinst.exe (PID: 1904)
      • vncserver.exe (PID: 2492)
      • vncserver.exe (PID: 2964)
      • vncserver.exe (PID: 3000)
      • vncserver.exe (PID: 1192)
      • vncserverui.exe (PID: 3108)
      • vncserver.exe (PID: 3224)
      • vncagent.exe (PID: 3020)
    • Reads the computer name

      • msiexec.exe (PID: 1356)
      • msiexec.exe (PID: 2068)
      • msiexec.exe (PID: 2384)
      • vncserver.exe (PID: 2592)
      • drvinst.exe (PID: 2580)
      • msiexec.exe (PID: 2440)
      • printerinst.exe (PID: 2748)
      • vncserver.exe (PID: 2436)
      • drvinst.exe (PID: 1904)
      • vncserver.exe (PID: 1192)
      • vncserver.exe (PID: 2492)
      • vncserver.exe (PID: 3000)
      • vncserver.exe (PID: 2964)
      • vncagent.exe (PID: 3020)
      • vncserverui.exe (PID: 3108)
      • vncserver.exe (PID: 3224)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 1356)
      • msiexec.exe (PID: 2068)
      • msiexec.exe (PID: 2384)
      • vncserver.exe (PID: 2592)
      • drvinst.exe (PID: 2580)
      • msiexec.exe (PID: 2440)
      • drvinst.exe (PID: 1904)
      • vncserver.exe (PID: 2436)
      • vncserver.exe (PID: 2492)
      • vncserver.exe (PID: 1192)
      • vncserver.exe (PID: 2964)
      • vncserver.exe (PID: 3000)
      • vncserverui.exe (PID: 3108)
      • vncserver.exe (PID: 3224)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 2044)
      • msiexec.exe (PID: 1356)
      • msiexec.exe (PID: 2440)
      • drvinst.exe (PID: 1904)
      • printerinst.exe (PID: 2748)
      • drvinst.exe (PID: 2580)
    • Application launched itself

      • msiexec.exe (PID: 1356)
    • Executes as Windows Service

      • VSSVC.exe (PID: 532)
      • vncserver.exe (PID: 3000)
    • Create files in a temporary directory

      • msiexec.exe (PID: 1356)
      • msiexec.exe (PID: 2440)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 1356)
      • printerinst.exe (PID: 2748)
    • Creates files in the program directory

      • vncserver.exe (PID: 2592)
      • vncserver.exe (PID: 3000)
    • Reads CPU info

      • vncserver.exe (PID: 3000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (81.9)
.mst | Windows SDK Setup Transform Script (9.2)
.msp | Windows Installer Patch (7.6)
.msi | Microsoft Installer (100)

EXIF

FlashPix

LastPrinted: 2009:12:11 11:47:44
ModifyDate: 2020:09:18 14:06:51
CodePage: Windows Latin 1 (Western European)
RevisionNumber: {6C23E969-BE0D-444C-BFD3-4DD03148DB03}
Words: 2
Subject: RealVNC Server 7.9.0
Author: RealVNC
LastModifiedBy: -
Software: Windows Installer XML Toolset (3.11.2.4516)
Template: ;1033
Comments: Copyright © RealVNC Ltd.
Title: Installation Database
Keywords: Installer
Security: Read-only recommended
CreateDate: 2024:01:12 01:09:08
Pages: 200
Characters: 131135
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
61
Monitored processes
18
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs vssvc.exe no specs msiexec.exe no specs msiexec.exe no specs vncserver.exe no specs drvinst.exe no specs drvinst.exe no specs printerinst.exe no specs vncserver.exe no specs vncserver.exe no specs vncserver.exe no specs vncserver.exe no specs vncserver.exe vncagent.exe no specs vncserver.exe no specs vncserverui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
532C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1192"C:\Program Files\RealVNC\VNC Server\vncserver.exe" -createHostIdC:\Program Files\RealVNC\VNC Server\vncserver.exemsiexec.exe
User:
SYSTEM
Company:
RealVNC
Integrity Level:
SYSTEM
Description:
VNC® Server
Exit code:
0
Version:
7.9.0 (r51979)
Modules
Images
c:\program files\realvnc\vnc server\vncserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
1356C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1904DrvInst.exe "2" "211" "ROOT\DISPLAY\0000" "C:\Windows\INF\oem2.inf" "vncmirror.inf:VNCMirror.Mfg:vncmirror:1.8.0.0:vnc_mirror_driver" "693484cff" "000004BC" "000005E4" "000005E0"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2044"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\VNC-Server-7.9.0-Windows-32.MSI"C:\Windows\System32\msiexec.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2068C:\Windows\system32\MsiExec.exe -Embedding F571AD1B5312515FC2D91C47172046C0 CC:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2384C:\Windows\system32\MsiExec.exe -Embedding 8B054957125231E13CA4E9C15942C000C:\Windows\System32\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2436"C:\Program Files\RealVNC\VNC Server\vncserver.exe" -service -addFirewallExceptionC:\Program Files\RealVNC\VNC Server\vncserver.exemsiexec.exe
User:
SYSTEM
Company:
RealVNC
Integrity Level:
SYSTEM
Description:
VNC® Server
Exit code:
0
Version:
7.9.0 (r51979)
Modules
Images
c:\program files\realvnc\vnc server\vncserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
2440C:\Windows\system32\MsiExec.exe -Embedding A738915C346E89E8F9AA273385D49CC6 E Global\MSI0000C:\Windows\System32\msiexec.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2492"C:\Program Files\RealVNC\VNC Server\vncserver.exe" -unregisterC:\Program Files\RealVNC\VNC Server\vncserver.exemsiexec.exe
User:
SYSTEM
Company:
RealVNC
Integrity Level:
SYSTEM
Description:
VNC® Server
Exit code:
0
Version:
7.9.0 (r51979)
Modules
Images
c:\program files\realvnc\vnc server\vncserver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
Total events
10 646
Read events
10 566
Write events
65
Delete events
15

Modification events

(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
40000000000000009F5A7BD72FB0D90164030000840D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
40000000000000009F5A7BD72FB0D90164030000840D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
73
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
40000000000000008543C5D72FB0D90164030000840D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Leave)
Value:
4000000000000000D1ABF1D82FB0D90164030000840D0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Enter)
Value:
4000000000000000D1ABF1D82FB0D90164030000840D0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppAddInterestingComponents (Leave)
Value:
4000000000000000475C02D92FB0D90164030000840D0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Leave)
Value:
4000000000000000E57701DA2FB0D90164030000840D0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Leave)
Value:
4000000000000000E57701DA2FB0D90164030000840D0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(1356) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
Operation:writeName:FirstRun
Value:
0
Executable files
63
Suspicious files
44
Text files
26
Unknown types
0

Dropped files

PID
Process
Filename
Type
1356msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
1356msiexec.exeC:\Windows\Installer\e3dc0.msi
MD5:
SHA256:
1356msiexec.exeC:\Windows\Installer\MSI440A.tmp
MD5:
SHA256:
1356msiexec.exeC:\Program Files\RealVNC\VNC Server\SetupCache\VNC-Server-7.9.0-Windows-32bit.msi
MD5:
SHA256:
1356msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{789552b6-5484-4a3b-8f95-6aaf64d11e38}_OnDiskSnapshotPropbinary
MD5:82074E3B57CF394205E4AA3B9F745866
SHA256:9BB0EC929B79767594722F4F1B73B5B0985CF9D81999603D991C784F2AC64613
1356msiexec.exeC:\Program Files\RealVNC\VNC Server\Printer Driver\VNCprint.ppdtext
MD5:B1C831AA6B1E0462E1E687D05F5AEDD8
SHA256:80ABB946B07351A6C6F89C3AE585A6C3A086951FBB84498B9765DDB51DFC44C9
1356msiexec.exeC:\Program Files\RealVNC\VNC Server\Mirror Driver\vncmirror-nt_x86.catbinary
MD5:A51662A71E40BFC6FA0A80D9B3734A1E
SHA256:E1CB4F8A9ACD744FBF3D4DB5FA79EF224A33CC42A5093C42E36C9A50E5118ED1
1356msiexec.exeC:\Program Files\RealVNC\VNC Server\wm_hooks.dllexecutable
MD5:7085E5708436EDA721BACFBD15B5E22C
SHA256:3ED50BBA28314B232DE9ABE2F6667DFF3A14DC11EEE9CAD91C6D9A3720CDADDD
1356msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:82074E3B57CF394205E4AA3B9F745866
SHA256:9BB0EC929B79767594722F4F1B73B5B0985CF9D81999603D991C784F2AC64613
1356msiexec.exeC:\Program Files\RealVNC\VNC Server\SetupCache\VNC-Server-7.9.0-Windows-32bit.msiKey
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3000
vncserver.exe
146.101.60.86:443
update-check.realvnc.com
Telstra Europe Ltd
GB
unknown
3000
vncserver.exe
165.254.191.229:443
hb-c.services.vnc.com
NTT-LTD-2914
US
unknown

DNS requests

Domain
IP
Reputation
update-check.realvnc.com
  • 146.101.60.86
unknown
hb-c.services.vnc.com
  • 165.254.191.229
unknown

Threats

No threats detected
No debug info