| File name: | AnyDesk.exe |
| Full analysis: | https://app.any.run/tasks/e3dd2669-7971-49b3-a532-85b6ac651d46 |
| Verdict: | Malicious activity |
| Analysis date: | September 12, 2024, 15:48:14 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C8246DC58903007CCF749A8AD70F5587 |
| SHA1: | 0B8B0EC823C7CA36BF821B75E2B92D16868DA05E |
| SHA256: | 347E7D26F98DE9AC2E998739D695028FA761C3F035DBE5890731E30E53A955B3 |
| SSDEEP: | 98304:MSNXXPh3aoHMpKCsnjdT38CcmNzRhpp5KADCjP4HGGpABg9wisEoaDv8yz3gUYXh:XtJ7gG6H4pQR |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:07:22 15:09:51+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 10752 |
| InitializedDataSize: | 5336064 |
| UninitializedDataSize: | 19210240 |
| EntryPoint: | 0x1ce5 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 8.0.12.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Unknown (0) |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | AnyDesk Software GmbH |
| FileDescription: | AnyDesk |
| FileVersion: | 8.0.12 |
| ProductName: | AnyDesk |
| ProductVersion: | 8 |
| LegalCopyright: | (C) 2022 AnyDesk Software GmbH |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 236 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6040 -childID 5 -isForBrowser -prefsHandle 5216 -prefMapHandle 5492 -prefsLen 31161 -prefMapSize 244343 -jsInitHandle 1516 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {5a6ebdcb-3051-4c60-a6c5-062efffd436d} 2228 "\\.\pipe\gecko-crash-server-pipe.2228" 28d17f24bd0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 780 | "C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" --local-service | C:\Users\admin\AppData\Local\Temp\AnyDesk.exe | AnyDesk.exe | ||||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Exit code: 0 Version: 8.0.12 Modules
| |||||||||||||||
| 2228 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2492 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=10336 -childID 27 -isForBrowser -prefsHandle 10388 -prefMapHandle 10392 -prefsLen 32028 -prefMapSize 244343 -jsInitHandle 1516 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {676476d0-43bc-4f57-8e3f-fee5672c6fea} 2228 "\\.\pipe\gecko-crash-server-pipe.2228" 28d178b0d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2820 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=10088 -childID 29 -isForBrowser -prefsHandle 10984 -prefMapHandle 10980 -prefsLen 32028 -prefMapSize 244343 -jsInitHandle 1516 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {99c3cfac-7373-420b-82ff-1cb8b1129a09} 2228 "\\.\pipe\gecko-crash-server-pipe.2228" 28d178b0f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 3352 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=9272 -childID 26 -isForBrowser -prefsHandle 10420 -prefMapHandle 10416 -prefsLen 32028 -prefMapSize 244343 -jsInitHandle 1516 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {aba1c83d-71b4-4cb9-b7d2-1fa332d79cba} 2228 "\\.\pipe\gecko-crash-server-pipe.2228" 28d178b0bd0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 3996 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=11452 -childID 31 -isForBrowser -prefsHandle 11444 -prefMapHandle 11440 -prefsLen 32028 -prefMapSize 244343 -jsInitHandle 1516 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {649fee7f-082f-462c-aa63-5589f8eb0956} 2228 "\\.\pipe\gecko-crash-server-pipe.2228" 28d1f962150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 4068 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7644 -childID 13 -isForBrowser -prefsHandle 8052 -prefMapHandle 7416 -prefsLen 32028 -prefMapSize 244343 -jsInitHandle 1516 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {bb67e256-6ff5-4630-ad26-819156ff9b58} 2228 "\\.\pipe\gecko-crash-server-pipe.2228" 28d15c64d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 4084 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1912 -parentBuildID 20240213221259 -prefsHandle 1836 -prefMapHandle 1824 -prefsLen 30537 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {21cc73b2-72a8-4845-8320-7ef188fe0b08} 2228 "\\.\pipe\gecko-crash-server-pipe.2228" 28d0cee5410 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 1 Version: 123.0 Modules
| |||||||||||||||
| 4284 | "C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" --local-control | C:\Users\admin\AppData\Local\Temp\AnyDesk.exe | — | AnyDesk.exe | |||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Exit code: 0 Version: 8.0.12 Modules
| |||||||||||||||
| (PID) Process: | (2228) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6176 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\user.conf | text | |
MD5:A787C308BD30D6D844E711D7579BE552 | SHA256:8A395011A6A877D3BDD53CC8688EF146160DAB9D42140EB4A70716AD4293A440 | |||
| 780 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\system.conf | text | |
MD5:0C04AD1083DC5C7C45E3EE2CD344AE38 | SHA256:6452273C017DB7CBE0FFC5B109BBF3F8D3282FB91BFA3C5EABC4FB8F1FC98CB0 | |||
| 6176 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PDKIGRUOO9K8IO5ELGOH.temp | binary | |
MD5:0E09178357A7CB624059E7B5345CA41F | SHA256:8F76F6DCC1CD05B862F3B302791F337F744CBACFF457E741FFCE8CA624A29634 | |||
| 6176 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms | binary | |
MD5:0E09178357A7CB624059E7B5345CA41F | SHA256:8F76F6DCC1CD05B862F3B302791F337F744CBACFF457E741FFCE8CA624A29634 | |||
| 2228 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:297E88D7CEB26E549254EC875649F4EB | SHA256:8B75D4FB1845BAA06122888D11F6B65E6A36B140C54A72CC13DF390FD7C95702 | |||
| 2228 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 2228 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 2228 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 780 | AnyDesk.exe | C:\Users\admin\AppData\Roaming\AnyDesk\service.conf | text | |
MD5:885497879F2356B7B5317BD4DFF7CC23 | SHA256:DBBA58E888DA2951C729EC722896DED7BA4577F71914FA674E77F06A7AA42673 | |||
| 780 | AnyDesk.exe | C:\Users\admin\AppData\Local\Temp\gcapi.dll | executable | |
MD5:1CE7D5A1566C8C449D0F6772A8C27900 | SHA256:73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
2228 | firefox.exe | POST | 200 | 95.101.54.144:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
2228 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
2228 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
2228 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
1492 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
3296 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
2228 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
2228 | firefox.exe | POST | 200 | 95.101.54.202:80 | http://r11.o.lencr.org/ | unknown | — | — | unknown |
2228 | firefox.exe | POST | 200 | 95.101.54.144:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7008 | svchost.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
3260 | svchost.exe | 40.113.110.67:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
780 | AnyDesk.exe | 195.181.174.174:443 | boot.net.anydesk.com | Datacamp Limited | DE | whitelisted |
780 | AnyDesk.exe | 208.115.231.110:443 | relay-414b0d34.net.anydesk.com | LIMESTONENETWORKS | US | whitelisted |
1492 | svchost.exe | 40.126.31.67:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1492 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
boot.net.anydesk.com |
| whitelisted |
relay-414b0d34.net.anydesk.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2256 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
2228 | firefox.exe | Not Suspicious Traffic | INFO [ANY.RUN] Global content delivery network (unpkg .com) |