| File name: | VNC-Server-7.9.0-Windows-32.MSI |
| Full analysis: | https://app.any.run/tasks/275fd918-9a4b-492a-ad6b-a35c15a75d8d |
| Verdict: | Malicious activity |
| Analysis date: | January 12, 2024, 01:09:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: RealVNC Server 7.9.0, Author: RealVNC, Keywords: Installer, Comments: Copyright RealVNC Ltd., Create Time/Date: Tue Jan 9 18:35:50 2024, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 4, Template: Intel;1033, Last Saved By: Intel;3082, Revision Number: {0DFE713A-2452-49FC-B0B7-A684BC8ACCDC}7.9.0.51979;{020308ED-2AD7-4086-BF7B-1C7374774EBD}7.9.0.51979;{2AD32FA2-CA3B-4C90-91EB-5F5FF9E91C2B}, Number of Pages: 200, Number of Characters: 131135 |
| MD5: | D68AFB7F9D85AE9978EF7AA7E1CF7911 |
| SHA1: | 7C7ABF08403B0E87A3BE34965550F5ED4D61D090 |
| SHA256: | 1574234DC6D838E1B0FFB627F451251B3A0BD360B35254D9D016148B447AB5D0 |
| SSDEEP: | 98304:iaa5ybHnJCL7kbFd1isS4vOxaXTdqj5GEV3Ck7xR5uK7nYLGtDG8Rf9F4x4xB+qi:+rMw4Rz6EuNK4biKJ8znRD |
| .msi | | | Microsoft Windows Installer (81.9) |
|---|---|---|
| .mst | | | Windows SDK Setup Transform Script (9.2) |
| .msp | | | Windows Installer Patch (7.6) |
| .msi | | | Microsoft Installer (100) |
| LastPrinted: | 2009:12:11 11:47:44 |
|---|---|
| ModifyDate: | 2020:09:18 14:06:51 |
| CodePage: | Windows Latin 1 (Western European) |
| RevisionNumber: | {6C23E969-BE0D-444C-BFD3-4DD03148DB03} |
| Words: | 2 |
| Subject: | RealVNC Server 7.9.0 |
| Author: | RealVNC |
| LastModifiedBy: | - |
| Software: | Windows Installer XML Toolset (3.11.2.4516) |
| Template: | ;1033 |
| Comments: | Copyright © RealVNC Ltd. |
| Title: | Installation Database |
| Keywords: | Installer |
| Security: | Read-only recommended |
| CreateDate: | 2024:01:12 01:09:08 |
| Pages: | 200 |
| Characters: | 131135 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 532 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1192 | "C:\Program Files\RealVNC\VNC Server\vncserver.exe" -createHostId | C:\Program Files\RealVNC\VNC Server\vncserver.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: RealVNC Integrity Level: SYSTEM Description: VNC® Server Exit code: 0 Version: 7.9.0 (r51979) Modules
| |||||||||||||||
| 1356 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1904 | DrvInst.exe "2" "211" "ROOT\DISPLAY\0000" "C:\Windows\INF\oem2.inf" "vncmirror.inf:VNCMirror.Mfg:vncmirror:1.8.0.0:vnc_mirror_driver" "693484cff" "000004BC" "000005E4" "000005E0" | C:\Windows\System32\drvinst.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2044 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Desktop\VNC-Server-7.9.0-Windows-32.MSI" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2068 | C:\Windows\system32\MsiExec.exe -Embedding F571AD1B5312515FC2D91C47172046C0 C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2384 | C:\Windows\system32\MsiExec.exe -Embedding 8B054957125231E13CA4E9C15942C000 | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2436 | "C:\Program Files\RealVNC\VNC Server\vncserver.exe" -service -addFirewallException | C:\Program Files\RealVNC\VNC Server\vncserver.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: RealVNC Integrity Level: SYSTEM Description: VNC® Server Exit code: 0 Version: 7.9.0 (r51979) Modules
| |||||||||||||||
| 2440 | C:\Windows\system32\MsiExec.exe -Embedding A738915C346E89E8F9AA273385D49CC6 E Global\MSI0000 | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2492 | "C:\Program Files\RealVNC\VNC Server\vncserver.exe" -unregister | C:\Program Files\RealVNC\VNC Server\vncserver.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: RealVNC Integrity Level: SYSTEM Description: VNC® Server Exit code: 0 Version: 7.9.0 (r51979) Modules
| |||||||||||||||
| (PID) Process: | (1356) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000009F5A7BD72FB0D90164030000840D0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1356) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000009F5A7BD72FB0D90164030000840D0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1356) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 73 | |||
| (PID) Process: | (1356) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000008543C5D72FB0D90164030000840D0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1356) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Leave) |
Value: 4000000000000000D1ABF1D82FB0D90164030000840D0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1356) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Enter) |
Value: 4000000000000000D1ABF1D82FB0D90164030000840D0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1356) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Leave) |
Value: 4000000000000000475C02D92FB0D90164030000840D0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1356) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Leave) |
Value: 4000000000000000E57701DA2FB0D90164030000840D0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1356) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Leave) |
Value: 4000000000000000E57701DA2FB0D90164030000840D0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1356) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore |
| Operation: | write | Name: | FirstRun |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1356 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 1356 | msiexec.exe | C:\Windows\Installer\e3dc0.msi | — | |
MD5:— | SHA256:— | |||
| 1356 | msiexec.exe | C:\Windows\Installer\MSI440A.tmp | — | |
MD5:— | SHA256:— | |||
| 1356 | msiexec.exe | C:\Program Files\RealVNC\VNC Server\SetupCache\VNC-Server-7.9.0-Windows-32bit.msi | — | |
MD5:— | SHA256:— | |||
| 1356 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{789552b6-5484-4a3b-8f95-6aaf64d11e38}_OnDiskSnapshotProp | binary | |
MD5:82074E3B57CF394205E4AA3B9F745866 | SHA256:9BB0EC929B79767594722F4F1B73B5B0985CF9D81999603D991C784F2AC64613 | |||
| 1356 | msiexec.exe | C:\Program Files\RealVNC\VNC Server\Printer Driver\VNCprint.ppd | text | |
MD5:B1C831AA6B1E0462E1E687D05F5AEDD8 | SHA256:80ABB946B07351A6C6F89C3AE585A6C3A086951FBB84498B9765DDB51DFC44C9 | |||
| 1356 | msiexec.exe | C:\Program Files\RealVNC\VNC Server\Mirror Driver\vncmirror-nt_x86.cat | binary | |
MD5:A51662A71E40BFC6FA0A80D9B3734A1E | SHA256:E1CB4F8A9ACD744FBF3D4DB5FA79EF224A33CC42A5093C42E36C9A50E5118ED1 | |||
| 1356 | msiexec.exe | C:\Program Files\RealVNC\VNC Server\wm_hooks.dll | executable | |
MD5:7085E5708436EDA721BACFBD15B5E22C | SHA256:3ED50BBA28314B232DE9ABE2F6667DFF3A14DC11EEE9CAD91C6D9A3720CDADDD | |||
| 1356 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:82074E3B57CF394205E4AA3B9F745866 | SHA256:9BB0EC929B79767594722F4F1B73B5B0985CF9D81999603D991C784F2AC64613 | |||
| 1356 | msiexec.exe | C:\Program Files\RealVNC\VNC Server\SetupCache\VNC-Server-7.9.0-Windows-32bit.msiKey | — | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3000 | vncserver.exe | 146.101.60.86:443 | update-check.realvnc.com | Telstra Europe Ltd | GB | unknown |
3000 | vncserver.exe | 165.254.191.229:443 | hb-c.services.vnc.com | NTT-LTD-2914 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
update-check.realvnc.com |
| unknown |
hb-c.services.vnc.com |
| unknown |