File name:

bbb.exe

Full analysis: https://app.any.run/tasks/ab4adf43-e08a-43db-9c92-dbd92fd525cc
Verdict: Malicious activity
Analysis date: April 15, 2024, 23:43:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

46BE277233CAECE705DE1EFC3481BC09

SHA1:

298B5D8A3F030116735D875EF26EFA181A7E6D01

SHA256:

004DC6F101D149A9DAF185B433B8CE8FD022C2CCC9E29DA62A898E4C92386A9E

SSDEEP:

98304:6jO4INrECaBfiB7K0VzYi+Pu5whELA8WZK0/ToUAnJVRwgdt47WVBzGzTBAI9e0w:nqmSqzD1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • bbb.exe (PID: 1036)
      • bbb.exe (PID: 3128)
  • SUSPICIOUS

    • Application launched itself

      • bbb.exe (PID: 1036)
    • Reads the Internet Settings

      • bbb.exe (PID: 3100)
    • Executable content was dropped or overwritten

      • bbb.exe (PID: 3128)
  • INFO

    • Checks supported languages

      • bbb.exe (PID: 1036)
      • bbb.exe (PID: 3128)
      • bbb.exe (PID: 3100)
      • bbb.exe (PID: 3000)
    • Reads the computer name

      • bbb.exe (PID: 1036)
      • bbb.exe (PID: 3128)
      • bbb.exe (PID: 3100)
      • bbb.exe (PID: 3000)
    • Creates files or folders in the user directory

      • bbb.exe (PID: 1036)
    • Reads the machine GUID from the registry

      • bbb.exe (PID: 1036)
      • bbb.exe (PID: 3128)
      • bbb.exe (PID: 3000)
    • Process checks whether UAC notifications are on

      • bbb.exe (PID: 1036)
    • Reads CPU info

      • bbb.exe (PID: 1036)
      • bbb.exe (PID: 3000)
    • Process checks computer location settings

      • bbb.exe (PID: 3100)
      • bbb.exe (PID: 3128)
    • Manual execution by a user

      • bbb.exe (PID: 3000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:28 10:30:11+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 10752
InitializedDataSize: 5292032
UninitializedDataSize: 19081216
EntryPoint: 0x1ce5
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 8.0.9.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: AnyDesk Software GmbH
FileDescription: AnyDesk
FileVersion: 8.0.9
ProductName: AnyDesk
ProductVersion: 8
LegalCopyright: (C) 2022 AnyDesk Software GmbH
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start bbb.exe no specs bbb.exe no specs bbb.exe bbb.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1036"C:\Users\admin\Desktop\bbb.exe" C:\Users\admin\Desktop\bbb.exeexplorer.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Version:
8.0.9
Modules
Images
c:\users\admin\desktop\bbb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3000"C:\Users\admin\Desktop\bbb.exe" C:\Users\admin\Desktop\bbb.exeexplorer.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Version:
8.0.9
Modules
Images
c:\users\admin\desktop\bbb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3100"C:\Users\admin\Desktop\bbb.exe" --local-controlC:\Users\admin\Desktop\bbb.exebbb.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Version:
8.0.9
Modules
Images
c:\users\admin\desktop\bbb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3128"C:\Users\admin\Desktop\bbb.exe" --local-serviceC:\Users\admin\Desktop\bbb.exe
bbb.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Version:
8.0.9
Modules
Images
c:\users\admin\desktop\bbb.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 530
Read events
1 530
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
2
Text files
3
Unknown types
3

Dropped files

PID
Process
Filename
Type
1036bbb.exeC:\Users\admin\AppData\Roaming\AnyDesk\user.conftext
MD5:
SHA256:
1036bbb.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\98U3Y2MNN0ZK9E8ZPTOZ.tempbinary
MD5:
SHA256:
1036bbb.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-msbinary
MD5:
SHA256:
3128bbb.exeC:\Users\admin\AppData\Roaming\AnyDesk\system.conftext
MD5:
SHA256:
3128bbb.exeC:\Users\admin\AppData\Roaming\AnyDesk\service.conftext
MD5:
SHA256:
3128bbb.exeC:\Users\admin\AppData\Local\Temp\gcapi.dllexecutable
MD5:
SHA256:
3128bbb.exeC:\Users\admin\Desktop\gcapi.dllexecutable
MD5:
SHA256:
3000bbb.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RD047MSC1T36G4Z5ZJ3N.tempbinary
MD5:
SHA256:
3000bbb.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms~RF1aad1a.TMPbinary
MD5:
SHA256:
3000bbb.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-msbinary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
7
DNS requests
4
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3128
bbb.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
3128
bbb.exe
92.223.88.232:443
boot.net.anydesk.com
G-Core Labs S.A.
LU
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3128
bbb.exe
208.115.231.154:443
relay-9f0f90d7.net.anydesk.com
LIMESTONENETWORKS
US
unknown
3128
bbb.exe
18.245.86.79:80
api.playanext.com
US
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
boot.net.anydesk.com
  • 92.223.88.232
unknown
relay-9f0f90d7.net.anydesk.com
  • 208.115.231.154
unknown
api.playanext.com
  • 18.245.86.84
  • 18.245.86.105
  • 18.245.86.26
  • 18.245.86.79
whitelisted

Threats

PID
Process
Class
Message
3128
bbb.exe
Potential Corporate Privacy Violation
ET USER_AGENTS AnyDesk Remote Desktop Software User-Agent
No debug info