| File name: | openvpn-connect-v2-windows.msi |
| Full analysis: | https://app.any.run/tasks/2867f010-e3f6-4ef0-9978-0ee93b3da592 |
| Verdict: | Malicious activity |
| Analysis date: | March 21, 2024, 10:54:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-msi |
| File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: OpenVPN Connect, Author: OpenVPN Technologies, Keywords: Installer, Comments: This installer database contains the logic and data required to install OpenVPN Connect., Template: Intel;1033, Revision Number: {033D05BB-D940-477B-8C73-9CF2C7D16A29}, Create Time/Date: Tue Sep 22 09:48:10 2020, Last Saved Time/Date: Tue Sep 22 09:48:10 2020, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.1.2318), Security: 2 |
| MD5: | 342A7EE74901F008B9B769CA05F04734 |
| SHA1: | 2EE3055D0A16910C960A1C9730F8688058BCE2D8 |
| SHA256: | F65DD0EA784DD63632BE64F89B1F83D51C199FD7319888883780CB9E975C325A |
| SSDEEP: | 196608:VaIAytTDU5hguRIf10M5QwIG/oIpB0q1EB/03wUZMFoXXfH4l:LTw5hguif10c2JIpBJw/ETXwl |
| .msi | | | Microsoft Windows Installer (98.5) |
|---|---|---|
| .msi | | | Microsoft Installer (100) |
| CodePage: | Windows Latin 1 (Western European) |
|---|---|
| Title: | Installation Database |
| Subject: | OpenVPN Connect |
| Author: | OpenVPN Technologies |
| Keywords: | Installer |
| Comments: | This installer database contains the logic and data required to install OpenVPN Connect. |
| Template: | Intel;1033 |
| RevisionNumber: | {033D05BB-D940-477B-8C73-9CF2C7D16A29} |
| CreateDate: | 2020:09:22 09:48:10 |
| ModifyDate: | 2020:09:22 09:48:10 |
| Pages: | 200 |
| Words: | 2 |
| Software: | Windows Installer XML Toolset (3.11.1.2318) |
| Security: | Read-only recommended |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 492 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{43a22f53-7885-69dd-d460-0b5084afb259} Global\{484a8e87-64cf-7e4a-0ca9-8c58bcd6012d} C:\Windows\System32\DriverStore\Temp\{1da5404c-8c54-5b25-677a-616a2eb2730f}\oemvista.inf C:\Windows\System32\DriverStore\Temp\{1da5404c-8c54-5b25-677a-616a2eb2730f}\tapoas.cat | C:\Windows\System32\rundll32.exe | — | drvinst.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 948 | ovpntray | C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\ovpntray.exe | — | capiws.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1692 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\openvpn-connect-v2-windows.msi" | C:\Windows\System32\msiexec.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2040 | DrvInst.exe "2" "211" "ROOT\NET\0000" "C:\Windows\INF\oem2.inf" "oemvista.inf:tapoas:tapoas.ndi:9.0.0.21:tapoas" "6fd423e43" "000003F8" "000005E0" "000005E8" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2560 | "C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe" | C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 2780 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{4e549619-7980-087f-88a2-b01edb0e312e}\oemvista.inf" "0" "6fd423e43" "000003F8" "WinSta0\Default" "00000550" "208" "c:\program files\openvpn technologies\openvpn client\driver\win32.6" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3940 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1692) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3940) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000003E799F327E7BDA01640F000020070000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3940) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000003E799F327E7BDA01640F0000400D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3940) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000003E799F327E7BDA01640F0000BC030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3940) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 40000000000000003E799F327E7BDA01640F0000CC0F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3940) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 400000000000000098DBA1327E7BDA01640F0000400D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3940) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 400000000000000098DBA1327E7BDA01640F000020070000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3940) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 4000000000000000F23DA4327E7BDA01640F0000CC0F0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3940) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000004CA0A6327E7BDA01640F0000BC030000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3940) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5} |
| Operation: | write | Name: | PROVIDER_BEGINPREPARE (Enter) |
Value: 4000000000000000CA2C18347E7BDA01640F0000BC03000001040000010000000000000000000000217903ED6E930C4480074991B2EE8CE50000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2780 | drvinst.exe | C:\Windows\System32\DriverStore\Temp\{1da5404c-8c54-5b25-677a-616a2eb2730f}\SET4011.tmp | executable | |
MD5:331371A2D47EDA2A57007D853AD60D8E | SHA256:F75679569DA653814794507449B078478829A87B0EB4CA0B3F259C5ADDF6BC7E | |||
| 2780 | drvinst.exe | C:\Windows\System32\DriverStore\Temp\{1da5404c-8c54-5b25-677a-616a2eb2730f}\tapoas.cat | cat | |
MD5:754285FD3D86EE8EE4167ECF84329A6C | SHA256:0818FBEDC5FEF0AAD1A5739754304BE39E22B6641EE2984A085CB5E0F3FF26A9 | |||
| 2780 | drvinst.exe | C:\Windows\INF\oem2.inf | binary | |
MD5:07039D2F96A24FD96B117AB9471987D4 | SHA256:EA1E4D0F98B6263D0E66F02C6017A29D30BEF2FC7D045C251069F7D08164D02C | |||
| 2780 | drvinst.exe | C:\Windows\System32\DriverStore\INFCACHE.1 | binary | |
MD5:6FBA08FCA40C5E921471583411E6F880 | SHA256:C5467A2A62F9EFF8F4F8B9CC5C5A39D1925CE8A86A9B8131499C2798DF30130A | |||
| 2780 | drvinst.exe | C:\Windows\System32\DriverStore\infstor.dat | binary | |
MD5:079F08F5D0BCDF7CA5DAD231199C9707 | SHA256:CB6BC0B5DFFD95412AB0DCA6B857AD6579EEE2716B76552D00167F6D4D3AB7FB | |||
| 2040 | drvinst.exe | C:\Windows\INF\setupapi.ev1 | binary | |
MD5:3BD92DE0F92849A18939DEF12F019768 | SHA256:C9A449318542F2CDD5AE25A03BF661BAC9E9F69E02DAE32E149C64A3BEDA45CC | |||
| 2780 | drvinst.exe | C:\Windows\System32\DriverStore\infpub.dat | binary | |
MD5:CAE03FE708381B7A02FE360F745740B5 | SHA256:E28C297CEF9285B6A0B9BD221D8BE796A3053A59DCE2A98F980F83A8872AE03D | |||
| 2780 | drvinst.exe | C:\Windows\System32\DriverStore\FileRepository\oemvista.inf_x86_neutral_fed7dbd61207f546\oemvista.PNF | pnf | |
MD5:7985D088386B7040FBFE7103DCA55E27 | SHA256:500C9FEA260070FDD8EF945A4FF21C142716706DEC914FFB091BEC95B24BDDB0 | |||
| 2040 | drvinst.exe | C:\Windows\INF\oem2.PNF | binary | |
MD5:5E8178FBDCD23FDC9A72067AE6B47FD9 | SHA256:EE6B4D291EE94FD701C2C8A4AD0D3AFD3796CEB3C209B6BCA4C5B883606CBDBA | |||
| 2780 | drvinst.exe | C:\Windows\System32\DriverStore\INFCACHE.2 | binary | |
MD5:ABB638661D737D9457D78D28C4145066 | SHA256:7602F549ABBAC7DE5CD8125329869D02A0C82AA8C9AAF78011162175AA319261 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |