Malicious

Disposition

Recommended action: Do not release this file. Escalate or handle according to your malware process.

This disposition is based only on facts present in the CAPE JSON. It is not a guarantee that a file is safe.

How This Was Determined

Malicious Indicators

Possible IOC / Review Indicators

Lower-Risk Facts

Important Notes

VirusTotal

Stored CAPE result: Unable to complete connection to VirusTotal. Status code: 429

Manual lookup: Open SHA256 in VirusTotal

File Details

File nameRealVNC Viewer Installer.exe
File typePE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Size1294880
MD5d9e783f14f5b6fd0d50b3a38cc04d684
SHA10bb21ef812674e044e206c8a5ead4c7525214178
SHA25695da32e16ab3235d7613ebada477a92f56dd1cf1321f0a96548666ad1d177cfa
VirusTotal lookupOpen SHA256 in VirusTotal

Sandbox Run Details

Task ID26
Started2026-06-18 12:49:59
Ended2026-06-18 12:54:37
Duration278 seconds
Packageexe
Routeinternet
Machinecuckoo1
CAPE score7.0
CAPE statusMalicious

YARA / AV Indicators

SourceRule / DetectionDescription / Evidence
No YARA hits recorded.
No CAPE YARA hits recorded.
No ClamAV hits recorded.

CAPE Signatures

SeverityConfidenceSignatureDescription
360%antisandbox_unhookTries to unhook or modify Windows functions monitored by CAPE
3100%antivm_displayAttempts to query display device information, possibly to determine if the process is running in a virtualized environment
3100%unbacked_process_mitigation_alterationManipulated process mitigation policies (CFG/DEP/hard error modes) from dynamically allocated (unbacked) memory
3100%unbacked_api_resolutionManually resolves API addresses from dynamically allocated (unbacked) memory, indicative of shellcode or an unpacker
3100%unbacked_library_loadLoads a new DLL where the caller address originates from dynamically allocated (unbacked) memory
320%unbacked_memory_protection_alterationAltered memory protections from dynamically allocated (unbacked) memory, indicative of self-modifying shellcode or memory patching
3100%unbacked_mutex_creationCreated or queried a mutex from dynamically allocated (unbacked) memory, indicative of a fileless payload checking or creating an infection marker
380%unbacked_com_instantiationAttempted to use a COM object (CoCreateInstance) from dynamically allocated (unbacked) memory, possibly for WMI reconnaissance or DCOM lateral movement
340%unbacked_crypto_operationsInvoked native Windows cryptographic APIs from dynamically allocated (unbacked) memory, possible encryption/decryption of payloads, c2, files or data
3100%unbacked_file_droppingWrote data to the filesystem from dynamically allocated (unbacked) memory
3100%unbacked_registry_modificationAttempted to modify the Windows registry from dynamically allocated (unbacked) memory
3100%unbacked_service_manipulationAttempted to interact with the Service Control Manager from dynamically allocated (unbacked) memory
3100%unbacked_token_manipulationAttempted to open, duplicate, or impersonate an access token from dynamically allocated (unbacked) memory, indicative credential theft or lateral movement
3100%unbacked_bind_shellBound a network socket to listen for inbound connections from dynamically allocated (unbacked) memory, indicating a fileless TCP bind shell or P2P
3100%unbacked_dns_resolutionAttempted to resolve a domain name from dynamically allocated (unbacked) memory
3100%unbacked_memory_network_connectionNetwork connection initiated from dynamically allocated (unbacked) memory, indicative of fileless C2 activity
3100%pe_deep_entrypointThe PE entry point is located unusually far into section, indicative of an appended packer stub that jumps to the original entry point (OEP)
380%static_pe_anomalyAnomalous binary characteristics
3100%pe_compile_timestompingBinary compilation timestomping detected
2100%antisandbox_sleepA process attempted to delay the analysis task.
280%privilege_elevation_checkQueries process token information to check for Administrator privileges or UAC elevation status
250%query_fips_reconnaissanceQueried the FIPS cryptography policy, can be used to adapt C2 network encryption or by legitimate encryption software
220%mountpoints_volume_discoveryQueries the mount points and then resolves volume paths to enumerate storage devices
280%registers_vectored_exception_handlerRegisters a vectored exception handler (VEH), possibly to hijack execution flow
250%creates_suspended_processCreates a process in a suspended state, likely for injection
2100%resumethread_remote_processResumed a thread in another process
2100%contains_pe_overlayThe PE file contains an overlay
220%discover_registry_mount_pointsQueries registry mount points to identify historical or connected removable/network drives
250%injection_rwxCreates RWX memory
280%uses_windows_utilitiesUses Windows utilities for basic functionality

Behavior Summary

Executed commands / child processes5
File writes10
File deletes6
Registry writes21
Created services0
Started services0
CAPE payload-like items5
CAPE extracted configs0
Dropped/related files captured2
Network indicators21

Executed Commands / Child Processes

"C:\WINDOWS\system32\BackgroundTaskHost.exe" -ServerName:BackgroundTaskHost.WebAccountProvider
"C:\Program Files\WindowsApps\Microsoft.DesktopAppInstaller_1.21.10120.0_x64__8wekyb3d8bbwe\WindowsPackageManagerServer.exe" -Embedding
"C:\Program Files\WindowsApps\Microsoft.WindowsStore_22604.1401.8.0_x64__8wekyb3d8bbwe\WinStore.App.exe" -ServerName:App.AppXc75wvwned5vhz4xyxxecvgdjhdkgsdza.mca
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding

File Writes

C:\Users\IT\AppData\Local\Temp\TmpCE7E.tmp
C:\Users\IT\AppData\Local\Temp\TmpCF99.tmp
C:\Users\IT\AppData\Local\Temp\Microsoft.Management.Deployment.winmd
\Device\RasAcd
C:\Users\IT\AppData\Local\Microsoft\Windows\INetCache\IE\WPFDD94.tmp
\??\DamCtrl
C:\ProgramData\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\S-1-5-21-3021741035-2986501292-914809479-1000\SystemAppData\Helium\Cache\11c658b040efd7c1.dat
\Device\VRegDriver
\Device\NamedPipe\Sessions\1\AppContainerNamedObjects\S-1-15-2-2473817148-3930944034-1235795307-187980641-3967865409-1804095407-1113801530
C:\Users\IT\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\DiagOutputDir\WinGetCOM-2026-06-18-12-53-46.550.log

Registry Writes

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\RealVNC Viewer Installer_RASAPI32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealVNC Viewer Installer_RASAPI32\EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealVNC Viewer Installer_RASAPI32\EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealVNC Viewer Installer_RASAPI32\EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealVNC Viewer Installer_RASAPI32\FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealVNC Viewer Installer_RASAPI32\ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealVNC Viewer Installer_RASAPI32\MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealVNC Viewer Installer_RASAPI32\FileDirectory

...and 9 more.

Created Services

None recorded.

Started Services

None recorded.

CAPE Extracted Items

Payload-like Items

/opt/CAPEv2/storage/analyses/26/CAPE/3a9b566a116f1f2baaa38d03142083aa9b9691d34c676f64331f31307c9974f7
/opt/CAPEv2/storage/analyses/26/CAPE/a8b55b9728d935a026d0513e3ef1c1676b3c694f9f05ade67612e6f13ea04d5c
/opt/CAPEv2/storage/analyses/26/CAPE/df03bf51ea6b69b2f8cc8c86ff0c0d4af376c5dab01a99798454e0e559c246b9
/opt/CAPEv2/storage/analyses/26/CAPE/9eddcf92af646965bac30f3e90ffa90f2009a4a12ee11bd673ea5f60105abe6e
/opt/CAPEv2/storage/analyses/26/CAPE/8a99873e9f8b08aab651e6303c56bc06beba6f8c10bf283fa6fb488fee9b463b

Extracted Configs

None recorded.

Network Activity

Network activity was recorded.

{'ip': '40.126.7.35', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': '', 'inaddrarpa': '', 'ports': [443]}
{'ip': '40.126.28.18', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': '', 'inaddrarpa': '', 'ports': [443]}
{'ip': '20.190.135.19', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': '', 'inaddrarpa': '', 'ports': [443]}
{'ip': '20.190.135.18', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': '', 'inaddrarpa': '', 'ports': [443]}
{'ip': '20.190.135.5', 'country_name': 'unknown', 'asn': '', 'asn_name': '', 'hostname': '', 'inaddrarpa': '', 'ports': [443]}
10.10.69.139
20.59.87.227

Generated 2026-06-18T12:55:01 from /opt/CAPEv2/storage/analyses/26/reports/report.json