File name:

UltraVNC_1436_X86_Setup.exe

Full analysis: https://app.any.run/tasks/2cfc93c1-e9e8-484f-9dde-6fd79f478f19
Verdict: Malicious activity
Analysis date: February 27, 2024, 05:40:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D9CF5D0DFEC10FA8EE808D36863F0B80

SHA1:

B641E1BA788485121898A462DE3B3FAE3A3B7F55

SHA256:

2E006C089A3C262D5D0C02F0EEC9A8D23F9C3109A07E07DB93E95E6452FC3684

SSDEEP:

98304:p+cD4dnB4urewpsgy13Il2Q7YKub6Q6WG4HN/Px0vZiq8ylKi1McKFE7eCZdppso:5phvATNaGV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • UltraVNC_1436_X86_Setup.exe (PID: 4052)
      • UltraVNC_1436_X86_Setup.exe (PID: 1492)
      • UltraVNC_1436_X86_Setup.tmp (PID: 3460)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • UltraVNC_1436_X86_Setup.tmp (PID: 3460)
    • Executable content was dropped or overwritten

      • UltraVNC_1436_X86_Setup.exe (PID: 1492)
      • UltraVNC_1436_X86_Setup.exe (PID: 4052)
      • UltraVNC_1436_X86_Setup.tmp (PID: 3460)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • UltraVNC_1436_X86_Setup.tmp (PID: 3460)
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 1384)
      • UltraVNC_1436_X86_Setup.exe (PID: 4052)
      • UltraVNC_1436_X86_Setup.tmp (PID: 3460)
      • UltraVNC_1436_X86_Setup.tmp (PID: 3652)
      • UltraVNC_1436_X86_Setup.exe (PID: 1492)
      • setpasswd.exe (PID: 3936)
      • winvnc.exe (PID: 2832)
      • setcad.exe (PID: 2860)
    • Reads the computer name

      • wmpnscfg.exe (PID: 1384)
      • UltraVNC_1436_X86_Setup.tmp (PID: 3460)
      • UltraVNC_1436_X86_Setup.tmp (PID: 3652)
      • winvnc.exe (PID: 2832)
    • Create files in a temporary directory

      • UltraVNC_1436_X86_Setup.tmp (PID: 3460)
      • UltraVNC_1436_X86_Setup.exe (PID: 1492)
      • UltraVNC_1436_X86_Setup.exe (PID: 4052)
    • Creates files in the program directory

      • UltraVNC_1436_X86_Setup.tmp (PID: 3460)
    • Creates a software uninstall entry

      • UltraVNC_1436_X86_Setup.tmp (PID: 3460)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 330752
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.4.3.6
ProductVersionNumber: 1.4.3.6
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: uvnc bvba
FileDescription: UltraVNC installer
FileVersion: 1.4.3.6
LegalCopyright: UltraVnc Team
OriginalFileName:
ProductName: UltraVNC
ProductVersion: 1.4.3.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
12
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ultravnc_1436_x86_setup.exe ultravnc_1436_x86_setup.tmp no specs ultravnc_1436_x86_setup.exe ultravnc_1436_x86_setup.tmp setpasswd.exe no specs setcad.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs winvnc.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1384"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1492"C:\Users\admin\AppData\Local\Temp\UltraVNC_1436_X86_Setup.exe" /SPAWNWND=$16013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\UltraVNC_1436_X86_Setup.exe
UltraVNC_1436_X86_Setup.tmp
User:
admin
Company:
uvnc bvba
Integrity Level:
HIGH
Description:
UltraVNC installer
Exit code:
0
Version:
1.4.3.6
Modules
Images
c:\users\admin\appdata\local\temp\ultravnc_1436_x86_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2072"C:\Windows\system32\netsh" firewall add allowedprogram "C:\Program Files\uvnc bvba\UltraVNC\vncviewer.exe" "vncviewer.exe" ENABLE ALLC:\Windows\System32\netsh.exeUltraVNC_1436_X86_Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2756"C:\Windows\system32\netsh" firewall add portopening TCP 5800 vnc5800C:\Windows\System32\netsh.exeUltraVNC_1436_X86_Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2832"C:\Program Files\uvnc bvba\UltraVNC\winvnc.exe"C:\Program Files\uvnc bvba\UltraVNC\winvnc.exeUltraVNC_1436_X86_Setup.tmp
User:
admin
Company:
UltraVNC
Integrity Level:
MEDIUM
Description:
VNC server
Exit code:
0
Version:
1.4.3.6
Modules
Images
c:\program files\uvnc bvba\ultravnc\winvnc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
2860"C:\Program Files\uvnc bvba\UltraVNC\setcad.exe"C:\Program Files\uvnc bvba\UltraVNC\setcad.exeUltraVNC_1436_X86_Setup.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\uvnc bvba\ultravnc\setcad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
3164"C:\Windows\system32\netsh" firewall add allowedprogram "C:\Program Files\uvnc bvba\UltraVNC\winvnc.exe" "winvnc.exe" ENABLE ALLC:\Windows\System32\netsh.exeUltraVNC_1436_X86_Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
3460"C:\Users\admin\AppData\Local\Temp\is-K363K.tmp\UltraVNC_1436_X86_Setup.tmp" /SL5="$100130,4009536,1073664,C:\Users\admin\AppData\Local\Temp\UltraVNC_1436_X86_Setup.exe" /SPAWNWND=$16013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-K363K.tmp\UltraVNC_1436_X86_Setup.tmp
UltraVNC_1436_X86_Setup.exe
User:
admin
Company:
uvnc bvba
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-k363k.tmp\ultravnc_1436_x86_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3652"C:\Users\admin\AppData\Local\Temp\is-I5MOC.tmp\UltraVNC_1436_X86_Setup.tmp" /SL5="$E0170,4009536,1073664,C:\Users\admin\AppData\Local\Temp\UltraVNC_1436_X86_Setup.exe" C:\Users\admin\AppData\Local\Temp\is-I5MOC.tmp\UltraVNC_1436_X86_Setup.tmpUltraVNC_1436_X86_Setup.exe
User:
admin
Company:
uvnc bvba
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-i5moc.tmp\ultravnc_1436_x86_setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3936"C:\Program Files\uvnc bvba\UltraVNC\setpasswd.exe"C:\Program Files\uvnc bvba\UltraVNC\setpasswd.exeUltraVNC_1436_X86_Setup.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\uvnc bvba\ultravnc\setpasswd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
Total events
6 473
Read events
6 233
Write events
234
Delete events
6

Modification events

(PID) Process:(3460) UltraVNC_1436_X86_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
840D0000E4ECC4853F69DA01
(PID) Process:(3460) UltraVNC_1436_X86_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
7B21E5890287E6E9F660257731E27376B4F4F60D44F193A2B039671C1230A80D
(PID) Process:(3460) UltraVNC_1436_X86_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3460) UltraVNC_1436_X86_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\uvnc bvba\UltraVNC\winvnc.exe
(PID) Process:(3460) UltraVNC_1436_X86_Setup.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
C8059CA6349E42F96099235356910C7E96E21404613D9628FD8CDDF5E8BA7129
(PID) Process:(3460) UltraVNC_1436_X86_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.2
(PID) Process:(3460) UltraVNC_1436_X86_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\uvnc bvba\UltraVNC
(PID) Process:(3460) UltraVNC_1436_X86_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\uvnc bvba\UltraVNC\
(PID) Process:(3460) UltraVNC_1436_X86_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:Inno Setup: Icon Group
Value:
UltraVNC
(PID) Process:(3460) UltraVNC_1436_X86_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
50
Suspicious files
18
Text files
9
Unknown types
1

Dropped files

PID
Process
Filename
Type
4052UltraVNC_1436_X86_Setup.exeC:\Users\admin\AppData\Local\Temp\is-I5MOC.tmp\UltraVNC_1436_X86_Setup.tmpexecutable
MD5:90448E0E93D5262ADE3E5188535DF4D5
SHA256:18D4FE90B2579C2CDF4B90629883CA1B783402B21D3BA3E337FF3C02D2C70DE0
3460UltraVNC_1436_X86_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-O4PH5.tmp\isdonate.bmpimage
MD5:6239A3BF88132514BF3D879352639195
SHA256:C925160C8686390A4420FF9C35DED0654E2B7D4B432B0BF18290B843FC2E5B12
1492UltraVNC_1436_X86_Setup.exeC:\Users\admin\AppData\Local\Temp\is-K363K.tmp\UltraVNC_1436_X86_Setup.tmpexecutable
MD5:90448E0E93D5262ADE3E5188535DF4D5
SHA256:18D4FE90B2579C2CDF4B90629883CA1B783402B21D3BA3E337FF3C02D2C70DE0
3460UltraVNC_1436_X86_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\is-KLFTF.tmpexecutable
MD5:90448E0E93D5262ADE3E5188535DF4D5
SHA256:18D4FE90B2579C2CDF4B90629883CA1B783402B21D3BA3E337FF3C02D2C70DE0
3460UltraVNC_1436_X86_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\unins000.exeexecutable
MD5:90448E0E93D5262ADE3E5188535DF4D5
SHA256:18D4FE90B2579C2CDF4B90629883CA1B783402B21D3BA3E337FF3C02D2C70DE0
3460UltraVNC_1436_X86_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\is-7UT29.tmptext
MD5:93FF192EEAA61CF46D31FC78B91487E7
SHA256:71AB490CD1D4D9809E75432ECFF0661CCCBEF9333204E7FC1B3622378A01CF58
3460UltraVNC_1436_X86_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\is-S2F19.tmptext
MD5:978EE2045410822FD5B06109C1EBA856
SHA256:911502502D24192B7C90A2C3391CB7CA91497E4CC9FB316E09D18EABD271C246
3460UltraVNC_1436_X86_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\Readme.txttext
MD5:978EE2045410822FD5B06109C1EBA856
SHA256:911502502D24192B7C90A2C3391CB7CA91497E4CC9FB316E09D18EABD271C246
3460UltraVNC_1436_X86_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\Whatsnew.rtftext
MD5:93FF192EEAA61CF46D31FC78B91487E7
SHA256:71AB490CD1D4D9809E75432ECFF0661CCCBEF9333204E7FC1B3622378A01CF58
3460UltraVNC_1436_X86_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\Licence.rtftext
MD5:CBDC78243472C2303526DE8FEADE0883
SHA256:0E1A2BDD813D817CF81D7E76D2C27DDE02986D41370147D785C4617BD9C91080
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info