URL:

boot.net.anydesk.com

Full analysis: https://app.any.run/tasks/5c198d70-f758-4b60-9c46-97c5ddf10643
Verdict: Malicious activity
Analysis date: November 23, 2023, 12:17:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
remote
anydesk
Indicators:
MD5:

B78753CC3F5C614CB652BD788E4A1638

SHA1:

358EC32C0BD6AB9D2E7B1524A1C471A5457E8F6C

SHA256:

309E520B8B8CE3D79716F4676C5FF4971671BD5E3258D3679DB0C93C5769B798

SSDEEP:

3:vAtELcBuI:vb+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AnyDesk.exe (PID: 2060)
    • ANYDESK has been detected (SURICATA)

      • AnyDesk.exe (PID: 2060)
  • SUSPICIOUS

    • Cleans NTFS data stream (Zone Identifier)

      • AnyDesk.exe (PID: 3648)
    • Application launched itself

      • AnyDesk.exe (PID: 3648)
    • Reads the Internet Settings

      • AnyDesk.exe (PID: 1376)
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3836)
      • AnyDesk.exe (PID: 3648)
      • AnyDesk.exe (PID: 1376)
      • AnyDesk.exe (PID: 2060)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3836)
      • AnyDesk.exe (PID: 3648)
      • AnyDesk.exe (PID: 1376)
      • AnyDesk.exe (PID: 2060)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3128)
      • AnyDesk.exe (PID: 3648)
    • Application launched itself

      • iexplore.exe (PID: 3128)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 3484)
      • iexplore.exe (PID: 3128)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3836)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3836)
      • AnyDesk.exe (PID: 3648)
      • AnyDesk.exe (PID: 2060)
    • Creates files or folders in the user directory

      • AnyDesk.exe (PID: 3648)
      • AnyDesk.exe (PID: 2060)
    • Process checks are UAC notifies on

      • AnyDesk.exe (PID: 3648)
    • Reads CPU info

      • AnyDesk.exe (PID: 3648)
    • Process checks computer location settings

      • AnyDesk.exe (PID: 2060)
      • AnyDesk.exe (PID: 1376)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs anydesk.exe no specs #ANYDESK anydesk.exe anydesk.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1376"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exe" --local-controlC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exeAnyDesk.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
0
Version:
8.0.6
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2060"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exe" --local-serviceC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exe
AnyDesk.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
0
Version:
8.0.6
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3128"C:\Program Files\Internet Explorer\iexplore.exe" "boot.net.anydesk.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3484"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3128 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3648"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exeiexplore.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
0
Version:
8.0.6
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3836"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
18 829
Read events
18 762
Write events
64
Delete events
3

Modification events

(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
5
Suspicious files
52
Text files
156
Unknown types
0

Dropped files

PID
Process
Filename
Type
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:B580B5A97EF5F5B7F444F147CC166BE2
SHA256:16283EE38FD5F9F1A3BC861E7095347BE6E8C8A4436388975E66FF7EC5547A34
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\en[1].htmhtml
MD5:5E332E86040668A7D47FB2B7E320FDA6
SHA256:42F37A72488908DCC45283406732B43D28747080BA7CCDB653B048E34A84AA45
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_430EA0912164D1B129D6E1DC07C63959binary
MD5:4FA54785A04568FBB06A3B48A81C3236
SHA256:D1AF2F0D10BD4E296E6626814DAF36B0854AB8A286870E71948F4D83E421A3DA
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\arrow-down-1-38c71c[1].svgimage
MD5:F34BFC90D8AC778C90A149BC41D184ED
SHA256:DBF755E337DD778370F30A4E20C7EFB0568F26B5D462B1F040BD9A43D2A21480
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\anydesk-logo-white-red-ec4e3a[1].pngimage
MD5:97F8AB201B4ECBD73ED7EF16A458E3CF
SHA256:5D0901D0C77B47D62FBBD4831FB046A355E2B657BA4D3F88B7821378905175B1
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\made-in-germany-white-84af46[1].svgimage
MD5:B679453EEAA2F4DC1AC5255C968579F8
SHA256:C1D8BC6B10E1B1F12F049649825F6AA7336A7863E14330CE5146910E71F6A27F
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_430EA0912164D1B129D6E1DC07C63959binary
MD5:D2461E3989AD8C76E0E7DA02D4CDB620
SHA256:AADC34E8D7B86CF7739720A518180EF6ACD1BCD64BB4F394D25DD5644F376791
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\video-js.min-3b9d55[1].csstext
MD5:0964BDE5B86BFDED7D27A536E510E4A2
SHA256:5D5CFFC72F4A801E6C120D6B43FF5C5FCE428B9F342A0BD97F22393BDA0B31A8
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\arrow-up-38ccc5[1].svgimage
MD5:4FAD3BB8147F8CC7DE6C94AF81D3565B
SHA256:81C8B9A900D6CA0B844590E8139065D35816CC7EEB329F3356F09746DFA67E12
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
44
DNS requests
23
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3484
iexplore.exe
GET
185.229.191.39:80
http://boot.net.anydesk.com/
NL
unknown
3484
iexplore.exe
GET
200
8.247.185.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5f0e922e4b9c4d0d
US
compressed
4.66 Kb
unknown
3484
iexplore.exe
GET
200
8.247.185.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2747dc4fd30729d5
US
compressed
4.66 Kb
unknown
3484
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA0HeCoTP8b5pXKW4TH%2F0Xk%3D
US
binary
471 b
unknown
3484
iexplore.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
US
binary
724 b
unknown
3484
iexplore.exe
GET
200
192.229.221.95:80
http://status.geotrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS6FKmrgWTGr7Q8nSk4Oub50ler6QQUlE%2FUXYvkpOKmgP792PkA76O%2BAlcCEAKT82mqg12gZB8hVZGTFVE%3D
US
binary
471 b
unknown
3484
iexplore.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
US
binary
1.41 Kb
unknown
3484
iexplore.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQChuVoVf7HVAxLxWCb2kXo7
US
binary
472 b
unknown
2060
AnyDesk.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
US
unknown
3484
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
US
binary
1.47 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3484
iexplore.exe
185.229.191.39:80
boot.net.anydesk.com
Datacamp Limited
NL
unknown
3484
iexplore.exe
18.245.60.8:443
anydesk.com
US
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
3484
iexplore.exe
8.247.185.126:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3484
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3484
iexplore.exe
167.235.224.171:443
ad-wa.anydesk.com
Hetzner Online GmbH
DE
unknown
3484
iexplore.exe
172.217.23.104:443
www.googletagmanager.com
GOOGLE
US
unknown
3484
iexplore.exe
142.250.186.67:80
ocsp.pki.goog
GOOGLE
US
whitelisted
3484
iexplore.exe
104.18.130.236:443
cdn.cookielaw.org
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
boot.net.anydesk.com
  • 185.229.191.39
unknown
anydesk.com
  • 18.245.60.8
  • 18.245.60.125
  • 18.245.60.91
  • 18.245.60.96
whitelisted
ctldl.windowsupdate.com
  • 8.247.185.126
  • 8.238.172.126
  • 67.27.141.254
  • 8.238.155.254
  • 67.27.141.126
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ad-wa.anydesk.com
  • 167.235.224.171
unknown
www.googletagmanager.com
  • 172.217.23.104
whitelisted
ocsp.pki.goog
  • 142.250.186.67
whitelisted
status.geotrust.com
  • 192.229.221.95
whitelisted
cdn.cookielaw.org
  • 104.18.130.236
  • 104.18.131.236
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted

Threats

PID
Process
Class
Message
2060
AnyDesk.exe
Misc activity
ET POLICY SSL/TLS Certificate Observed (AnyDesk Remote Desktop Software)
2060
AnyDesk.exe
Potential Corporate Privacy Violation
ET USER_AGENTS AnyDesk Remote Desktop Software User-Agent
No debug info