File name:

VNC-5.1.1-Windows.exe

Full analysis: https://app.any.run/tasks/fc3b47bf-891a-4f9d-a519-3cdcc5cb3ba5
Verdict: Malicious activity
Analysis date: March 05, 2024, 22:48:15
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

924E0D6BB21BEF9CE9D541BF00793945

SHA1:

59782734F4D5C6D787A88E15F11C6CDE2A868400

SHA256:

773B4F01820A2B5811E99F567796B9B79F10FA8F8CF2DA5C0132A4F12EBF86C6

SSDEEP:

98304:AW4QVTX+g/e0XeODLWvHKDTypQc6NiMq+Jec2RwxYBParkysTioZuNuWLi7us6rR:OU2Mu2IChm/T4oOVERw2694g

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • VNC-5.1.1-Windows.exe (PID: 2752)
      • VNC-5.1.1-Windows.exe (PID: 3864)
      • VNC-5.1.1-Windows.tmp (PID: 3848)
      • drvinst.exe (PID: 2968)
      • drvinst.exe (PID: 1848)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 2968)
      • drvinst.exe (PID: 1848)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • VNC-5.1.1-Windows.exe (PID: 2752)
      • VNC-5.1.1-Windows.exe (PID: 3864)
      • VNC-5.1.1-Windows.tmp (PID: 3848)
      • drvinst.exe (PID: 2968)
      • drvinst.exe (PID: 1848)
    • Reads the Windows owner or organization settings

      • VNC-5.1.1-Windows.tmp (PID: 3848)
    • Process drops legitimate windows executable

      • VNC-5.1.1-Windows.tmp (PID: 3848)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2968)
      • drvinst.exe (PID: 1848)
    • Drops a system driver (possible attempt to evade defenses)

      • drvinst.exe (PID: 2968)
      • drvinst.exe (PID: 1848)
    • Checks Windows Trust Settings

      • drvinst.exe (PID: 2968)
      • drvinst.exe (PID: 1848)
    • Executes as Windows Service

      • vncservice.exe (PID: 2656)
    • Reads the Internet Settings

      • vncserverui.exe (PID: 572)
      • vncserverui.exe (PID: 2768)
  • INFO

    • Create files in a temporary directory

      • VNC-5.1.1-Windows.exe (PID: 3864)
      • VNC-5.1.1-Windows.exe (PID: 2752)
      • VNC-5.1.1-Windows.tmp (PID: 3848)
    • Checks supported languages

      • VNC-5.1.1-Windows.tmp (PID: 4052)
      • VNC-5.1.1-Windows.exe (PID: 3864)
      • VNC-5.1.1-Windows.exe (PID: 2752)
      • VNC-5.1.1-Windows.tmp (PID: 3848)
      • bootstrapinstallerhelper32.exe (PID: 3948)
      • drvinst.exe (PID: 2968)
      • drvinst.exe (PID: 1848)
      • vncserver.exe (PID: 4072)
      • vncservice.exe (PID: 2656)
      • vncserverui.exe (PID: 572)
      • vncpipehelper.exe (PID: 268)
      • vncserverui.exe (PID: 2768)
      • vncpipehelper.exe (PID: 3376)
    • Reads the computer name

      • VNC-5.1.1-Windows.tmp (PID: 4052)
      • VNC-5.1.1-Windows.tmp (PID: 3848)
      • bootstrapinstallerhelper32.exe (PID: 3948)
      • drvinst.exe (PID: 2968)
      • drvinst.exe (PID: 1848)
      • vncservice.exe (PID: 2656)
      • vncserver.exe (PID: 4072)
      • vncserverui.exe (PID: 572)
      • vncserverui.exe (PID: 2768)
    • Reads the machine GUID from the registry

      • bootstrapinstallerhelper32.exe (PID: 3948)
      • drvinst.exe (PID: 2968)
      • drvinst.exe (PID: 1848)
      • vncservice.exe (PID: 2656)
      • vncserver.exe (PID: 4072)
      • vncserverui.exe (PID: 572)
      • vncserverui.exe (PID: 2768)
    • Reads the software policy settings

      • drvinst.exe (PID: 2968)
      • drvinst.exe (PID: 1848)
    • Creates files in the program directory

      • VNC-5.1.1-Windows.tmp (PID: 3848)
    • Reads CPU info

      • vncserver.exe (PID: 4072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0x9c40
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: RealVNC Ltd
FileDescription: VNC® Setup
FileVersion:
LegalCopyright: Copyright © 2002-2014 RealVNC Ltd.
ProductName: VNC Server
ProductVersion: 5.1.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
81
Monitored processes
15
Malicious processes
5
Suspicious processes
3

Behavior graph

Click at the process to see the details
start vnc-5.1.1-windows.exe vnc-5.1.1-windows.tmp no specs vnc-5.1.1-windows.exe vnc-5.1.1-windows.tmp bootstrapinstallerhelper32.exe no specs msiexec.exe no specs msiexec.exe no specs drvinst.exe drvinst.exe vncservice.exe no specs vncserver.exe no specs vncpipehelper.exe no specs vncserverui.exe vncpipehelper.exe no specs vncserverui.exe

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Program Files\RealVNC\VNC Server\vncpipehelper.exe" -hash 56354659e2b0879093095ab09bfddda4a14afd87 RealVNC.SYSTEM.vncserver.vncpipehelper.1683127844 "C:\Program Files\RealVNC\VNC Server\vncserverui.exe" service 0xfffffff6C:\Program Files\RealVNC\VNC Server\vncpipehelper.exevncserver.exe
User:
admin
Company:
RealVNC Ltd
Integrity Level:
MEDIUM
Description:
VNC® Server
Exit code:
0
Version:
5.1.1 (r117550)
Modules
Images
c:\program files\realvnc\vnc server\vncpipehelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\program files\realvnc\vnc server\vncserverui.exe
572"C:\Program Files\RealVNC\VNC Server\vncserverui.exe" service 0xfffffff6C:\Program Files\RealVNC\VNC Server\vncserverui.exe
vncpipehelper.exe
User:
admin
Company:
RealVNC Ltd
Integrity Level:
MEDIUM
Description:
VNC® Server
Exit code:
3221225477
Version:
5.1.1 (r117550)
Modules
Images
c:\program files\realvnc\vnc server\vncserverui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
1848DrvInst.exe "2" "211" "ROOT\DISPLAY\0000" "C:\Windows\INF\oem2.inf" "vncmirror.inf:VNCMirror.Mfg:vncmirror:1.8.0.0:vnc_mirror_driver" "693484cff" "000003BC" "000005F8" "000005FC"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
2656"C:\Program Files\RealVNC\VNC Server\vncservice.exe" vncserverC:\Program Files\RealVNC\VNC Server\vncservice.exeservices.exe
User:
SYSTEM
Company:
RealVNC Ltd
Integrity Level:
SYSTEM
Description:
VNC® Service
Exit code:
0
Version:
5.1.1 (r117550)
Modules
Images
c:\program files\realvnc\vnc server\vncservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
2752"C:\Users\admin\AppData\Local\Temp\VNC-5.1.1-Windows.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\VNC-5.1.1-Windows.exe
VNC-5.1.1-Windows.tmp
User:
admin
Company:
RealVNC Ltd
Integrity Level:
HIGH
Description:
VNC® Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\vnc-5.1.1-windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2768"C:\Program Files\RealVNC\VNC Server\vncserverui.exe" service 0xfffffff6C:\Program Files\RealVNC\VNC Server\vncserverui.exe
vncpipehelper.exe
User:
admin
Company:
RealVNC Ltd
Integrity Level:
MEDIUM
Description:
VNC® Server
Exit code:
0
Version:
5.1.1 (r117550)
Modules
Images
c:\program files\realvnc\vnc server\vncserverui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
2960"C:\Windows\system32\MsiExec.exe" /i "C:\Users\admin\AppData\Local\Temp\is-TG6SO.tmp\VNC-Server-5.1.1-Windows-32bit.msi" SHOWLICENSE=0 WARNLICENSE=0 ADDLOCAL=FeatureServer,FeaturePrinterDriver,FeatureMirrorDriver SERVERDIR="C:\Program Files\RealVNC\VNC Server" /qn REBOOT=ReallySuppress FORCELICENSEWIZARDCHECK=1C:\Windows\System32\msiexec.exeVNC-5.1.1-Windows.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2968DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{62194ef8-a5ce-10b2-87ca-a94c77dec27f}\vncmirror.inf" "0" "6d4acb377" "000005C8" "WinSta0\Default" "000004BC" "208" "C:\Program Files\RealVNC\VNC Server\Mirror Driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
3212"C:\Windows\system32\MsiExec.exe" /i "C:\Users\admin\AppData\Local\Temp\is-TG6SO.tmp\VNC-Viewer-5.1.1-Windows-32bit.msi" SHOWLICENSE=0 WARNLICENSE=0 VIEWERDIR="C:\Program Files\RealVNC\VNC Viewer" ADDLOCAL=FeatureViewer REMOVE=FeatureDesktopShortcut /qn REBOOT=ReallySuppressC:\Windows\System32\msiexec.exeVNC-5.1.1-Windows.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3376"C:\Program Files\RealVNC\VNC Server\vncpipehelper.exe" -hash 02d48a2ecc6b524d16f8f92475304fa9608d68b4 RealVNC.SYSTEM.vncserver.vncpipehelper.636145798 "C:\Program Files\RealVNC\VNC Server\vncserverui.exe" service 0xfffffff6C:\Program Files\RealVNC\VNC Server\vncpipehelper.exevncserver.exe
User:
admin
Company:
RealVNC Ltd
Integrity Level:
MEDIUM
Description:
VNC® Server
Exit code:
0
Version:
5.1.1 (r117550)
Modules
Images
c:\program files\realvnc\vnc server\vncpipehelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
Total events
10 773
Read events
10 699
Write events
63
Delete events
11

Modification events

(PID) Process:(3212) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
116
(PID) Process:(2968) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\184\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2968) drvinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
(PID) Process:(2968) drvinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2968) drvinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2968) drvinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
190000000100000010000000BCC80DAA2F98A4692805BFF4CBB372EB0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB61400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D7200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(1848) drvinst.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\184\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1848) drvinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles
Operation:writeName:%SystemPath%\system32\DRIVERS\vncmirror.sys
Value:
5
(PID) Process:(1848) drvinst.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles
Operation:writeName:%SystemPath%\system32\vncmirror.dll
Value:
5
(PID) Process:(1848) drvinst.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\GroupOrderList
Operation:writeName:Video
Value:
03000000010000000200000003000000
Executable files
18
Suspicious files
8
Text files
0
Unknown types
8

Dropped files

PID
Process
Filename
Type
3848VNC-5.1.1-Windows.tmpC:\Users\admin\AppData\Local\Temp\is-TG6SO.tmp\is-QAGFA.tmp
MD5:
SHA256:
3848VNC-5.1.1-Windows.tmpC:\Users\admin\AppData\Local\Temp\is-TG6SO.tmp\VNC-Server-5.1.1-Windows-32bit.msi
MD5:
SHA256:
3848VNC-5.1.1-Windows.tmpC:\Users\admin\AppData\Local\Temp\is-TG6SO.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2968drvinst.exeC:\Windows\System32\DriverStore\FileRepository\vncmirror.inf_x86_neutral_7c9040649e5c641a\vncmirror.PNFpnf
MD5:20141852ACC1A12EEBD4150B33710CEA
SHA256:58C17065A511C5DA14BE9F2A70C8F89283AE88341E3A620ED9082BBCC26AA765
2968drvinst.exeC:\Windows\System32\DriverStore\Temp\{2b2165ca-8a8a-0698-6372-547776573d71}\nt_x86\SET5F70.tmpexecutable
MD5:814DED6A705FEFBCDD8A50E7B449463F
SHA256:54D49AE185DCD7FE19BAC91DC58E68EBE123E9EDC9A511914E012FBB3F955E3A
3848VNC-5.1.1-Windows.tmpC:\Users\admin\AppData\Local\Temp\is-TG6SO.tmp\bootstrapinstallerhelper32.exeexecutable
MD5:2F34914480DEA3323F6F6F79931D503C
SHA256:0E1C2D2141FF010986BE86810F51A162B33422E27F084C54955FDA4B5F22A33F
3848VNC-5.1.1-Windows.tmpC:\Users\admin\AppData\Local\Temp\is-TG6SO.tmp\is-CM424.tmpexecutable
MD5:E0E243FBDE8DB0E96224611D8056B5CB
SHA256:95DD86DF3A5226BF877CA04299ACC98AAFC681D535F5D342752EBD0F46756073
2968drvinst.exeC:\Windows\System32\DriverStore\Temp\{2b2165ca-8a8a-0698-6372-547776573d71}\SET5F92.tmpbinary
MD5:936AE4FBF64DD5CC571397ED70793F7E
SHA256:9478F41FB0E284B85BAC4426791EEB330F6590712CB1A5E7BE84014A28357317
3848VNC-5.1.1-Windows.tmpC:\Users\admin\AppData\Local\Temp\is-TG6SO.tmp\VNC-Viewer-5.1.1-Windows-32bit.msiexecutable
MD5:E0E243FBDE8DB0E96224611D8056B5CB
SHA256:95DD86DF3A5226BF877CA04299ACC98AAFC681D535F5D342752EBD0F46756073
2968drvinst.exeC:\Windows\System32\DriverStore\Temp\{2b2165ca-8a8a-0698-6372-547776573d71}\nt_x86\vncmirror.dllexecutable
MD5:814DED6A705FEFBCDD8A50E7B449463F
SHA256:54D49AE185DCD7FE19BAC91DC58E68EBE123E9EDC9A511914E012FBB3F955E3A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info