| File name: | AnyDesk.exe |
| Full analysis: | https://app.any.run/tasks/76520665-8d65-4a13-8867-b931a4cbf507 |
| Verdict: | Malicious activity |
| Analysis date: | June 21, 2025, 14:01:17 |
| OS: | Windows 11 Professional (build: 22000, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | 8A1E50B7BE04571BEE6D04E7CBB7D02D |
| SHA1: | 004CC73B19534CC96D9896A72E52BFD87B00558F |
| SHA256: | 0DCEE93CBBF39F2E1D37024C279B0CD16409F08CC94FAA4FCCD285021022BFDA |
| SSDEEP: | 98304:XXykez5ad1lZ/flbT/oQYohL3emZbw698yAYCSNb1TAmrm5OMCZkc5taUc6F6Rx+:yJm3k+CIejkNd4k |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:01:16 10:19:09+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 10752 |
| InitializedDataSize: | 5552128 |
| UninitializedDataSize: | 18288128 |
| EntryPoint: | 0x1ce5 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 9.0.2.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Unknown (0) |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | AnyDesk Software GmbH |
| FileDescription: | AnyDesk |
| FileVersion: | 9.0.2 |
| ProductName: | AnyDesk |
| ProductVersion: | 9 |
| LegalCopyright: | (C) 2025 AnyDesk Software GmbH |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1040 | "C:\Users\admin\Desktop\AnyDesk.exe" --local-control | C:\Users\admin\Desktop\AnyDesk.exe | — | AnyDesk.exe | |||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Version: 9.0.2 Modules
| |||||||||||||||
| 2340 | "C:\Users\admin\Desktop\AnyDesk.exe" --backend | C:\Users\admin\Desktop\AnyDesk.exe | — | AnyDesk.exe | |||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Exit code: 0 Version: 9.0.2 Modules
| |||||||||||||||
| 3424 | "C:\Users\admin\Desktop\AnyDesk.exe" | C:\Users\admin\Desktop\AnyDesk.exe | — | explorer.exe | |||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Version: 9.0.2 Modules
| |||||||||||||||
| 5404 | "C:\Users\admin\Desktop\AnyDesk.exe" --backproxy-system | C:\Users\admin\Desktop\AnyDesk.exe | AnyDesk.exe | ||||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: HIGH Description: AnyDesk Exit code: 251664264 Version: 9.0.2 Modules
| |||||||||||||||
| 5444 | "C:\Users\admin\Desktop\AnyDesk.exe" --local-service | C:\Users\admin\Desktop\AnyDesk.exe | AnyDesk.exe | ||||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Version: 9.0.2 Modules
| |||||||||||||||
| 6024 | "C:\Users\admin\Desktop\AnyDesk.exe" --backend | C:\Users\admin\Desktop\AnyDesk.exe | AnyDesk.exe | ||||||||||||
User: SYSTEM Company: AnyDesk Software GmbH Integrity Level: SYSTEM Description: AnyDesk Version: 9.0.2 Modules
| |||||||||||||||
| 6140 | C:\Windows\system32\DllHost.exe /Processid:{A4B07E49-6567-4FB8-8D39-01920E3B2357} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 10.0.22000.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5444) AnyDesk.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (5444) AnyDesk.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (5444) AnyDesk.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (5444) AnyDesk.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3424 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\user.conf~RF132696.TMP | — | |
MD5:— | SHA256:— | |||
| 3424 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\user.conf~RF1326c5.TMP | — | |
MD5:— | SHA256:— | |||
| 3424 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\user.conf~RF132703.TMP | — | |
MD5:— | SHA256:— | |||
| 3424 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\user.conf~RF132771.TMP | — | |
MD5:— | SHA256:— | |||
| 3424 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\user.conf~RF132780.TMP | — | |
MD5:— | SHA256:— | |||
| 5444 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\system.conf~RF132917.TMP | — | |
MD5:— | SHA256:— | |||
| 1040 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\user.conf~RF132936.TMP | — | |
MD5:— | SHA256:— | |||
| 5444 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\service.conf~RF132bd6.TMP | — | |
MD5:— | SHA256:— | |||
| 5444 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\service.conf~RF132be5.TMP | — | |
MD5:— | SHA256:— | |||
| 5444 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\system.conf~RF132be5.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2840 | svchost.exe | GET | 200 | 208.89.74.19:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?6e6cb8b88f555144 | unknown | — | — | whitelisted |
2840 | svchost.exe | GET | 200 | 208.89.74.19:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?6f06946a73e04111 | unknown | — | — | whitelisted |
2840 | svchost.exe | GET | 304 | 208.89.74.19:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?0df55b5e376ebda1 | unknown | — | — | whitelisted |
— | — | GET | 200 | 52.123.129.14:443 | https://ecs.office.com/config/v2/Office/officeclicktorun/16.0.16626.20134/Production/CC?&Clientid=%7b80C2A92B-EDEE-479E-8470-DBC6C547F2FB%7d&Application=officeclicktorun&Platform=win32&Version=16.0.16626.20134&MsoVersion=16.0.16626.20134&ProcessName=officec2rclient.exe&Audience=Production&Build=ship&Architecture=x64&OsVersion=10.0&OsBuild=22000&Channel=CC&InstallType=C2R&SessionId=%7b3D1B1C40-7DD9-4A67-87AE-2298A3568BE5%7d&LabMachine=false | unknown | binary | 355 Kb | whitelisted |
1524 | svchost.exe | GET | 200 | 95.101.134.105:80 | http://www.msftconnecttest.com/connecttest.txt | unknown | — | — | whitelisted |
— | — | GET | 200 | 13.107.6.156:443 | https://mrodevicemgr.officeapps.live.com/mrodevicemgrsvc/api/v1/C2RTargetAudienceData?omid=97560490bafb0d49bca6f8f0df91025d&susid=c408ee57-2103-4c34-9e6f-30bdf6c87e50&audienceFFN=492350f6-3a01-4f97-b9c0-c7c6ddf67d60&tid=&osver=Client%7C10.0.22000&offver=16.0.16626.20134&ring=Production&aud=Production&ch=CC&osarch=x64&manstate=6 | unknown | — | — | — |
2840 | svchost.exe | GET | 200 | 23.209.209.135:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
— | — | POST | 200 | 20.190.160.14:443 | https://login.live.com/RST2.srf | unknown | xml | 10.3 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5196 | firefox.exe | 34.120.208.123:443 | incoming.telemetry.mozilla.org | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
2392 | pingsender.exe | 34.120.208.123:443 | incoming.telemetry.mozilla.org | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
1524 | svchost.exe | 95.101.134.96:80 | — | Akamai International B.V. | FR | unknown |
6852 | rundll32.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 104.208.16.92:443 | v10.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3460 | OfficeC2RClient.exe | 52.109.89.18:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
— | — | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5444 | AnyDesk.exe | 141.95.145.210:443 | boot.net.anydesk.com | OVH SAS | FR | whitelisted |
5444 | AnyDesk.exe | 141.95.145.210:80 | boot.net.anydesk.com | OVH SAS | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
incoming.telemetry.mozilla.org |
| whitelisted |
telemetry-incoming.r53-2.services.mozilla.com |
| whitelisted |
v10.events.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
boot.net.anydesk.com |
| whitelisted |
relay-d83d9241.net.anydesk.com |
| whitelisted |
login.live.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ecs.office.com |
| whitelisted |
mrodevicemgr.officeapps.live.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1692 | svchost.exe | Misc activity | ET REMOTE_ACCESS Anydesk Relay Domain (net .anydesk .com) in DNS Lookup |
1692 | svchost.exe | Misc activity | ET REMOTE_ACCESS Anydesk Domain (boot .net .anydesk .com) in DNS Lookup |
1692 | svchost.exe | Misc activity | ET REMOTE_ACCESS Anydesk Relay Domain (net .anydesk .com) in DNS Lookup |
1524 | svchost.exe | Misc activity | ET INFO Microsoft Connection Test |