| File name: | Remote Tool.zip |
| Full analysis: | https://app.any.run/tasks/8f6b57e9-be03-4de5-a989-c28892025e02 |
| Verdict: | Malicious activity |
| Analysis date: | September 30, 2020, 21:10:35 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract |
| MD5: | 4984CAF731D7DE43713869D779860571 |
| SHA1: | 8224E5FB3319B30EAF1E102ABEBC03CDFD083AC4 |
| SHA256: | 747DFDE1FBC9D53D797696E71E0EC2DB226D3943171DFB081688F84188BF8BAC |
| SSDEEP: | 12288:0K0cx+YeQxW6Jj0N7Mz2Uhy4jV6gxq5WNmcnrCH1pHvZWMOMndn7tU7fJlwYYH2m:57+YeP61Wgz2Ay8kw2H1Rv5PdcfJlwY+ |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | 0x0001 |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2020:09:30 21:09:13 |
| ZipCRC: | 0x659f5854 |
| ZipCompressedSize: | 720268 |
| ZipUncompressedSize: | 743469 |
| ZipFileName: | vnc-4.0-x86_win32.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 860 | "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -unregister -register | C:\Program Files\RealVNC\VNC4\WinVNC4.exe | — | is-PLIBB.tmp | |||||||||||
User: admin Company: RealVNC Ltd. Integrity Level: HIGH Description: VNC Server for Win32 Exit code: 0 Version: 4.0 Modules
| |||||||||||||||
| 2132 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Remote Tool.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.60.0 Modules
| |||||||||||||||
| 2420 | "C:\Users\admin\Desktop\vnc-4.0-x86_win32.exe" | C:\Users\admin\Desktop\vnc-4.0-x86_win32.exe | explorer.exe | ||||||||||||
User: admin Company: RealVNC Ltd. Integrity Level: HIGH Description: VNC Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 2436 | "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -stop | C:\Program Files\RealVNC\VNC4\WinVNC4.exe | — | is-PLIBB.tmp | |||||||||||
User: admin Company: RealVNC Ltd. Integrity Level: HIGH Description: VNC Server for Win32 Exit code: 0 Version: 4.0 Modules
| |||||||||||||||
| 2536 | "C:\Users\admin\Desktop\vnc-4.0-x86_win32.exe" | C:\Users\admin\Desktop\vnc-4.0-x86_win32.exe | — | explorer.exe | |||||||||||
User: admin Company: RealVNC Ltd. Integrity Level: MEDIUM Description: VNC Setup Exit code: 3221226540 Version: Modules
| |||||||||||||||
| 2664 | "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -start | C:\Program Files\RealVNC\VNC4\WinVNC4.exe | — | is-PLIBB.tmp | |||||||||||
User: admin Company: RealVNC Ltd. Integrity Level: HIGH Description: VNC Server for Win32 Exit code: 0 Version: 4.0 Modules
| |||||||||||||||
| 3400 | "C:\Users\admin\AppData\Local\Temp\is-ILH0M.tmp\is-PLIBB.tmp" /SL4 $4012A C:\Users\admin\Desktop\vnc-4.0-x86_win32.exe 511279 50688 | C:\Users\admin\AppData\Local\Temp\is-ILH0M.tmp\is-PLIBB.tmp | vnc-4.0-x86_win32.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3512 | "C:\Program Files\RealVNC\VNC4\vncconfig.exe" -service | C:\Program Files\RealVNC\VNC4\vncconfig.exe | — | is-PLIBB.tmp | |||||||||||
User: admin Company: RealVNC Ltd. Integrity Level: HIGH Description: VNC Server Configuration Applet for Win32 Exit code: 0 Version: 4.0 Modules
| |||||||||||||||
| 3684 | "C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service | C:\Program Files\RealVNC\VNC4\WinVNC4.exe | — | services.exe | |||||||||||
User: SYSTEM Company: RealVNC Ltd. Integrity Level: SYSTEM Description: VNC Server for Win32 Exit code: 0 Version: 4.0 Modules
| |||||||||||||||
| (PID) Process: | (2132) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2132) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2132) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\13B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2132) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Remote Tool.zip | |||
| (PID) Process: | (2132) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2132) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2132) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2132) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2132) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop | |||
| (PID) Process: | (2132) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface |
| Operation: | write | Name: | ShowPassword |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3400 | is-PLIBB.tmp | C:\Program Files\RealVNC\VNC4\is-P4DSM.tmp | — | |
MD5:— | SHA256:— | |||
| 3400 | is-PLIBB.tmp | C:\Program Files\RealVNC\VNC4\is-P5COT.tmp | — | |
MD5:— | SHA256:— | |||
| 3400 | is-PLIBB.tmp | C:\Program Files\RealVNC\VNC4\is-H0OK9.tmp | — | |
MD5:— | SHA256:— | |||
| 3400 | is-PLIBB.tmp | C:\Program Files\RealVNC\VNC4\is-2GJ4D.tmp | — | |
MD5:— | SHA256:— | |||
| 3400 | is-PLIBB.tmp | C:\Program Files\RealVNC\VNC4\is-NHRP9.tmp | — | |
MD5:— | SHA256:— | |||
| 3400 | is-PLIBB.tmp | C:\Program Files\RealVNC\VNC4\is-0V3MQ.tmp | — | |
MD5:— | SHA256:— | |||
| 3400 | is-PLIBB.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealVNC\VNC Server 4 (User-Mode)\Run VNC Server.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3400 | is-PLIBB.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealVNC\VNC Server 4 (User-Mode)\Configure User-Mode Settings.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3400 | is-PLIBB.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealVNC\VNC Server 4 (Service-Mode)\Register VNC Service.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3400 | is-PLIBB.tmp | C:\Users\admin\AppData\Local\Temp\is-089C3.tmp\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||