File name:

AnyDesk.exe

Full analysis: https://app.any.run/tasks/1eb7717a-13b0-4277-a29d-b14b318ea326
Verdict: Malicious activity
Analysis date: November 03, 2025, 06:08:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
anydesk
antivm
delphi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

53D3D9F1F060EE1478968D81AB07BE24

SHA1:

4A0A36A4644A0B357E7E03673519E3B62377A085

SHA256:

1D61F40D0EC8CCC89DEBCE8406EBBA152834B20A7BAC2B52C8BBFDF893AB6D7D

SSDEEP:

98304:SGH5rXhBPnJRsZprQhREe6zWFm98rVWFPkdIePd39COiDw7P7sd+WU65/EyvsEfj:T1zUC591zszu9Ad

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • ANYDESK mutex has been found

      • AnyDesk.exe (PID: 7544)
      • AnyDesk.exe (PID: 7824)
      • AnyDesk.exe (PID: 7816)
    • Application launched itself

      • AnyDesk.exe (PID: 7544)
    • There is functionality for VM detection VirtualBox (YARA)

      • AnyDesk.exe (PID: 7544)
      • AnyDesk.exe (PID: 7824)
      • AnyDesk.exe (PID: 7816)
    • There is functionality for taking screenshot (YARA)

      • AnyDesk.exe (PID: 7544)
      • AnyDesk.exe (PID: 7816)
      • AnyDesk.exe (PID: 7824)
    • Connects to unusual port

      • AnyDesk.exe (PID: 7816)
  • INFO

    • Checks supported languages

      • AnyDesk.exe (PID: 7544)
      • AnyDesk.exe (PID: 7816)
      • AnyDesk.exe (PID: 7824)
    • The sample compiled with english language support

      • AnyDesk.exe (PID: 7544)
    • Reads the computer name

      • AnyDesk.exe (PID: 7544)
      • AnyDesk.exe (PID: 7824)
      • AnyDesk.exe (PID: 7816)
    • Creates files or folders in the user directory

      • AnyDesk.exe (PID: 7544)
      • AnyDesk.exe (PID: 7816)
    • Process checks whether UAC notifications are on

      • AnyDesk.exe (PID: 7544)
    • Reads the machine GUID from the registry

      • AnyDesk.exe (PID: 7816)
    • Reads CPU info

      • AnyDesk.exe (PID: 7824)
    • Checks proxy server information

      • AnyDesk.exe (PID: 7824)
      • slui.exe (PID: 8064)
    • Compiled with Borland Delphi (YARA)

      • AnyDesk.exe (PID: 7544)
      • AnyDesk.exe (PID: 7816)
      • AnyDesk.exe (PID: 7824)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:04 15:38:43+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 10752
InitializedDataSize: 5479936
UninitializedDataSize: -
EntryPoint: 0x225a9a4
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 9.0.1.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: AnyDesk Software GmbH
FileDescription: AnyDesk - Cracked by IranCrack.com
FileVersion: 9.0.1
ProductName: AnyDesk
ProductVersion: 9
LegalCopyright: (C) 2024 AnyDesk Software GmbH
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
4
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start anydesk.exe no specs anydesk.exe anydesk.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
7544"C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" C:\Users\admin\AppData\Local\Temp\AnyDesk.exeexplorer.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk - Cracked by IranCrack.com
Version:
9.0.1
Modules
Images
c:\users\admin\appdata\local\temp\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7816"C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" --local-serviceC:\Users\admin\AppData\Local\Temp\AnyDesk.exe
AnyDesk.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk - Cracked by IranCrack.com
Version:
9.0.1
Modules
Images
c:\users\admin\appdata\local\temp\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7824"C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" --local-controlC:\Users\admin\AppData\Local\Temp\AnyDesk.exeAnyDesk.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk - Cracked by IranCrack.com
Version:
9.0.1
Modules
Images
c:\users\admin\appdata\local\temp\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
8064C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
5 178
Read events
5 178
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
6
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
7544AnyDesk.exeC:\Users\admin\AppData\Roaming\AnyDesk\user.conftext
MD5:A787C308BD30D6D844E711D7579BE552
SHA256:8A395011A6A877D3BDD53CC8688EF146160DAB9D42140EB4A70716AD4293A440
7816AnyDesk.exeC:\Users\admin\AppData\Roaming\AnyDesk\global_cache\device-id.cachebinary
MD5:C11FCBB3DF2C8B3E1CCA051FBB19D182
SHA256:767E4A38F805B1B44E01311CA2A9DCE3544A837911A339484423B1E0FA74272D
7544AnyDesk.exeC:\Users\admin\AppData\Roaming\AnyDesk\thumbnails\d168b25850bb80ce.png.icoimage
MD5:15D182F89808BE28A9F06BEC51D96BA6
SHA256:B6DB0D114724DD4E317C401903BDDCED316227184C8684668D53933F683F007A
7544AnyDesk.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-msbinary
MD5:819DCEF3BCC4ADA9FC36470ECF730680
SHA256:6B321B536060F5A56EBCCE21CF55F150B5573FE410408E7411BB74FCFCD1222D
7816AnyDesk.exeC:\Users\admin\AppData\Roaming\AnyDesk\service.conftext
MD5:89525F9D4F338D4E3603BFC06F87189E
SHA256:B93ABC08D94353B300DE06484E605ECDD80A02D1A3D5D36DC664035DBA06DA30
7544AnyDesk.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms~RF17a6de.TMPbinary
MD5:819DCEF3BCC4ADA9FC36470ECF730680
SHA256:6B321B536060F5A56EBCCE21CF55F150B5573FE410408E7411BB74FCFCD1222D
7816AnyDesk.exeC:\Users\admin\AppData\Roaming\AnyDesk\system.conftext
MD5:0C04AD1083DC5C7C45E3EE2CD344AE38
SHA256:6452273C017DB7CBE0FFC5B109BBF3F8D3282FB91BFA3C5EABC4FB8F1FC98CB0
7544AnyDesk.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\T18TAINCFM3INYMO9ETV.tempbinary
MD5:73CB1C5C40A3938C4E3DF0EAC0EF78D0
SHA256:BB259351E7CAF0CBD71AC20805CE11400BFA4C9F2AC92750FDF9DA43CAA10EA9
7544AnyDesk.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\92SDYS8FJ25DE8EHNX2N.tempbinary
MD5:819DCEF3BCC4ADA9FC36470ECF730680
SHA256:6B321B536060F5A56EBCCE21CF55F150B5573FE410408E7411BB74FCFCD1222D
7544AnyDesk.exeC:\Users\admin\AppData\Roaming\AnyDesk\thumbnails\d168b25850bb80ce.pngimage
MD5:C8497AC2AD5496EE58704A605CC9BE72
SHA256:C815C14830E70A9253430B2647BF0A87FCF460EA970F6CEC48DBE04D67B665C9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
66
DNS requests
25
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6368
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
7088
SearchApp.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
7560
SIHClient.exe
GET
200
23.3.109.244:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
DE
binary
814 b
whitelisted
5596
MoUsoCoreWorker.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
7560
SIHClient.exe
GET
200
23.3.109.244:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.3.crl
DE
binary
813 b
whitelisted
7560
SIHClient.exe
GET
200
23.3.109.244:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.3.crl
DE
binary
401 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6368
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2316
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5596
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
7088
SearchApp.exe
2.16.241.218:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
7816
AnyDesk.exe
57.128.101.77:443
boot.net.anydesk.com
OVH SAS
FR
suspicious
7816
AnyDesk.exe
51.83.238.212:443
relay-bf60063b.net.anydesk.com
OVH SAS
PL
unknown
6368
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6368
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.159.0
  • 20.190.159.23
  • 40.126.31.71
  • 20.190.159.131
  • 40.126.31.128
  • 40.126.31.0
  • 20.190.159.68
  • 20.190.159.128
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 142.250.185.110
whitelisted
www.bing.com
  • 2.16.241.218
  • 2.16.241.205
  • 2.16.241.201
  • 2.16.241.204
  • 2.16.241.222
  • 2.16.241.216
  • 2.16.241.206
  • 2.16.241.207
whitelisted
boot.net.anydesk.com
  • 57.128.101.74
  • 57.128.101.78
  • 195.181.174.174
  • 57.128.101.75
  • 195.181.174.173
  • 141.95.145.210
  • 37.59.29.33
  • 57.128.101.77
unknown
relay-bf60063b.net.anydesk.com
  • 51.83.238.212
unknown
ocsp.digicert.com
  • 2.17.190.73
  • 23.54.109.203
whitelisted
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.28
  • 23.216.77.6
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 135.232.92.137
whitelisted

Threats

PID
Process
Class
Message
2276
svchost.exe
Misc activity
ET REMOTE_ACCESS Anydesk Relay Domain (net .anydesk .com) in DNS Lookup
2276
svchost.exe
Misc activity
ET REMOTE_ACCESS Anydesk Relay Domain (net .anydesk .com) in DNS Lookup
2276
svchost.exe
Misc activity
ET REMOTE_ACCESS Anydesk Domain (boot .net .anydesk .com) in DNS Lookup
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2276
svchost.exe
Misc activity
ET REMOTE_ACCESS Anydesk Relay Domain (net .anydesk .com) in DNS Lookup
No debug info