URL:

boot.net.anydesk.com

Full analysis: https://app.any.run/tasks/5c198d70-f758-4b60-9c46-97c5ddf10643
Verdict: Malicious activity
Analysis date: November 23, 2023, 12:17:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
remote
anydesk
Indicators:
MD5:

B78753CC3F5C614CB652BD788E4A1638

SHA1:

358EC32C0BD6AB9D2E7B1524A1C471A5457E8F6C

SHA256:

309E520B8B8CE3D79716F4676C5FF4971671BD5E3258D3679DB0C93C5769B798

SSDEEP:

3:vAtELcBuI:vb+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AnyDesk.exe (PID: 2060)
    • ANYDESK has been detected (SURICATA)

      • AnyDesk.exe (PID: 2060)
  • SUSPICIOUS

    • Cleans NTFS data stream (Zone Identifier)

      • AnyDesk.exe (PID: 3648)
    • Application launched itself

      • AnyDesk.exe (PID: 3648)
    • Reads the Internet Settings

      • AnyDesk.exe (PID: 1376)
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3836)
      • AnyDesk.exe (PID: 3648)
      • AnyDesk.exe (PID: 2060)
      • AnyDesk.exe (PID: 1376)
    • The process uses the downloaded file

      • iexplore.exe (PID: 3128)
      • AnyDesk.exe (PID: 3648)
    • Application launched itself

      • iexplore.exe (PID: 3128)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3836)
      • AnyDesk.exe (PID: 3648)
      • AnyDesk.exe (PID: 2060)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3836)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3836)
      • AnyDesk.exe (PID: 3648)
      • AnyDesk.exe (PID: 1376)
      • AnyDesk.exe (PID: 2060)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 3484)
      • iexplore.exe (PID: 3128)
    • Creates files or folders in the user directory

      • AnyDesk.exe (PID: 3648)
      • AnyDesk.exe (PID: 2060)
    • Process checks are UAC notifies on

      • AnyDesk.exe (PID: 3648)
    • Process checks computer location settings

      • AnyDesk.exe (PID: 2060)
      • AnyDesk.exe (PID: 1376)
    • Reads CPU info

      • AnyDesk.exe (PID: 3648)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe wmpnscfg.exe no specs anydesk.exe no specs #ANYDESK anydesk.exe anydesk.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1376"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exe" --local-controlC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exeAnyDesk.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
0
Version:
8.0.6
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2060"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exe" --local-serviceC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exe
AnyDesk.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
0
Version:
8.0.6
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3128"C:\Program Files\Internet Explorer\iexplore.exe" "boot.net.anydesk.com"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3484"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3128 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
3648"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\AnyDesk.exeiexplore.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
0
Version:
8.0.6
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\po2hn1x2\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3836"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
18 829
Read events
18 762
Write events
64
Delete events
3

Modification events

(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3128) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
5
Suspicious files
52
Text files
156
Unknown types
0

Dropped files

PID
Process
Filename
Type
3484iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\en[1].htmhtml
MD5:5E332E86040668A7D47FB2B7E320FDA6
SHA256:42F37A72488908DCC45283406732B43D28747080BA7CCDB653B048E34A84AA45
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\question-circle-e166ca[1].svgimage
MD5:7FC58DB25CBA7307F89001252AD2AEF5
SHA256:3330C7F08DAC89038E39B55513CFD7EB8A6CCE1D8CFA8DD736BA189633517A3D
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\video-js.min-3b9d55[1].csstext
MD5:0964BDE5B86BFDED7D27A536E510E4A2
SHA256:5D5CFFC72F4A801E6C120D6B43FF5C5FCE428B9F342A0BD97F22393BDA0B31A8
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\phone-circle-186093[1].svgimage
MD5:A7961531348A4E4BEED81A703E641A58
SHA256:9F4062D0DE4435E6C5CA94B1691AE5758F8482B45E4DA1096A7B1EA2C1C1B4B1
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\arrow-down-1-38c71c[1].svgimage
MD5:F34BFC90D8AC778C90A149BC41D184ED
SHA256:DBF755E337DD778370F30A4E20C7EFB0568F26B5D462B1F040BD9A43D2A21480
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\slick.min-e6e4f1[1].csstext
MD5:6A62AD0F300504C583E7797C79C2D8AB
SHA256:50AD448A8A5720BF8A5617DB15AF31AE60163DE06331576F60C6244C012FFC72
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\arrow-up-38ccc5[1].svgimage
MD5:4FAD3BB8147F8CC7DE6C94AF81D3565B
SHA256:81C8B9A900D6CA0B844590E8139065D35816CC7EEB329F3356F09746DFA67E12
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\slick-theme.min-7c2e6e[1].csstext
MD5:8A027447D99592734DA0715287305E13
SHA256:E21AA5B0D3FD28CEBED9E03C5544F4924E11B0C453792ED018720CF8C679B0B6
3484iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\anydesk-logo-white-red-ec4e3a[1].pngimage
MD5:97F8AB201B4ECBD73ED7EF16A458E3CF
SHA256:5D0901D0C77B47D62FBBD4831FB046A355E2B657BA4D3F88B7821378905175B1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
44
DNS requests
23
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3484
iexplore.exe
GET
200
8.247.185.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5f0e922e4b9c4d0d
unknown
compressed
4.66 Kb
unknown
3484
iexplore.exe
GET
185.229.191.39:80
http://boot.net.anydesk.com/
unknown
unknown
3484
iexplore.exe
GET
200
8.247.185.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2747dc4fd30729d5
unknown
compressed
4.66 Kb
unknown
3484
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA0HeCoTP8b5pXKW4TH%2F0Xk%3D
unknown
binary
471 b
unknown
3484
iexplore.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
3484
iexplore.exe
GET
200
142.250.186.67:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D
unknown
binary
724 b
unknown
3484
iexplore.exe
GET
200
192.229.221.95:80
http://status.geotrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS6FKmrgWTGr7Q8nSk4Oub50ler6QQUlE%2FUXYvkpOKmgP792PkA76O%2BAlcCEAKT82mqg12gZB8hVZGTFVE%3D
unknown
binary
471 b
unknown
3128
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAqvpsXKY8RRQeo74ffHUxc%3D
unknown
binary
471 b
unknown
2060
AnyDesk.exe
POST
200
18.245.86.79:80
http://api.playanext.com/httpapi
unknown
unknown
3484
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAo3h2ReX7SMIk79G%2B0UDDw%3D
unknown
binary
1.47 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3484
iexplore.exe
185.229.191.39:80
boot.net.anydesk.com
Datacamp Limited
NL
unknown
3484
iexplore.exe
18.245.60.8:443
anydesk.com
US
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
3484
iexplore.exe
8.247.185.126:80
ctldl.windowsupdate.com
LEVEL3
US
unknown
3484
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3484
iexplore.exe
167.235.224.171:443
ad-wa.anydesk.com
Hetzner Online GmbH
DE
unknown
3484
iexplore.exe
172.217.23.104:443
www.googletagmanager.com
GOOGLE
US
unknown
3484
iexplore.exe
142.250.186.67:80
ocsp.pki.goog
GOOGLE
US
whitelisted
3484
iexplore.exe
104.18.130.236:443
cdn.cookielaw.org
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
boot.net.anydesk.com
  • 185.229.191.39
unknown
anydesk.com
  • 18.245.60.8
  • 18.245.60.125
  • 18.245.60.91
  • 18.245.60.96
whitelisted
ctldl.windowsupdate.com
  • 8.247.185.126
  • 8.238.172.126
  • 67.27.141.254
  • 8.238.155.254
  • 67.27.141.126
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ad-wa.anydesk.com
  • 167.235.224.171
unknown
www.googletagmanager.com
  • 172.217.23.104
whitelisted
ocsp.pki.goog
  • 142.250.186.67
whitelisted
status.geotrust.com
  • 192.229.221.95
whitelisted
cdn.cookielaw.org
  • 104.18.130.236
  • 104.18.131.236
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted

Threats

PID
Process
Class
Message
2060
AnyDesk.exe
Misc activity
ET POLICY SSL/TLS Certificate Observed (AnyDesk Remote Desktop Software)
2060
AnyDesk.exe
Potential Corporate Privacy Violation
ET USER_AGENTS AnyDesk Remote Desktop Software User-Agent
No debug info