| File name: | anydesk-6-3-5 (1).exe |
| Full analysis: | https://app.any.run/tasks/cb5b22cd-e729-4ffb-a6fc-0a17ef21abf8 |
| Verdict: | Malicious activity |
| Analysis date: | April 10, 2025, 23:28:31 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | 6E7870B45E169115126717A1FA6D1D0B |
| SHA1: | 0AB652CF761CCB7483069C6A560948DF802C0479 |
| SHA256: | 36D9E08B2F2599E2886F2959D3EF4171CEEBE8E3435B07905D21D6CA8CC7744B |
| SSDEEP: | 98304:jsFstewsNHtiW3MEwvWpC5wfuvOWfrpsEhvBQ0UC28hvgkDMD5QXVC11Z1ZX563k:Yw0+Hdv |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:11:08 21:41:12+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 10752 |
| InitializedDataSize: | 3742208 |
| UninitializedDataSize: | 10908672 |
| EntryPoint: | 0x1ce9 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.3.5.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Unknown (0) |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | AnyDesk Software GmbH |
| FileDescription: | AnyDesk |
| FileVersion: | 6.3.5 |
| ProductName: | AnyDesk |
| ProductVersion: | 6.3 |
| LegalCopyright: | (C) 2021 AnyDesk Software GmbH |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1096 | "C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe" --backend | C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe | anydesk-6-3-5 (1).exe | ||||||||||||
User: SYSTEM Company: AnyDesk Software GmbH Integrity Level: SYSTEM Description: AnyDesk Version: 6.3.5 Modules
| |||||||||||||||
| 1852 | "C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe" --local-control | C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe | — | anydesk-6-3-5 (1).exe | |||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Version: 6.3.5 Modules
| |||||||||||||||
| 2516 | "C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe" --local-service | C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe | anydesk-6-3-5 (1).exe | ||||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Version: 6.3.5 Modules
| |||||||||||||||
| 6516 | "C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe" | C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe | — | explorer.exe | |||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Version: 6.3.5 Modules
| |||||||||||||||
| 7484 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7520 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | — | SppExtComObj.Exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 8040 | "C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe" --backend | C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe | — | anydesk-6-3-5 (1).exe | |||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Exit code: 0 Version: 6.3.5 Modules
| |||||||||||||||
| 8160 | "C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe" --backproxy-system | C:\Users\admin\AppData\Local\Temp\anydesk-6-3-5 (1).exe | anydesk-6-3-5 (1).exe | ||||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: HIGH Description: AnyDesk Exit code: 251659336 Version: 6.3.5 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6516 | anydesk-6-3-5 (1).exe | C:\Users\admin\AppData\Roaming\AnyDesk\user.conf | text | |
MD5:5059D0251F3292C45A54E0AB40CCA733 | SHA256:88D22B3A6A8BCB3AB03CFAC5EEF7FDF1CF4C99E17576D05997D2F0DFC96B8189 | |||
| 2516 | anydesk-6-3-5 (1).exe | C:\Users\admin\AppData\Local\Temp\gcapi.dll | executable | |
MD5:1CE7D5A1566C8C449D0F6772A8C27900 | SHA256:73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF | |||
| 6516 | anydesk-6-3-5 (1).exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\4ZNKLLEPZCI021Z0Y5SY.temp | binary | |
MD5:67B330EBE1732BF205C42AC0833454B2 | SHA256:3016106E7A65D535E78A7B85C347794EE96666A4CCB755BAC7EE77971A058E5E | |||
| 2516 | anydesk-6-3-5 (1).exe | C:\Users\admin\AppData\Roaming\AnyDesk\system.conf | text | |
MD5:D9F4B843E7D7625BF3E920A884B9CA16 | SHA256:AF0FA43C92D94A92C26A8EF7D98412953F770066E38B66F128FDF57CE6D77705 | |||
| 6516 | anydesk-6-3-5 (1).exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms | binary | |
MD5:67B330EBE1732BF205C42AC0833454B2 | SHA256:3016106E7A65D535E78A7B85C347794EE96666A4CCB755BAC7EE77971A058E5E | |||
| 2516 | anydesk-6-3-5 (1).exe | C:\Users\admin\AppData\Roaming\AnyDesk\service.conf | text | |
MD5:816F9F36A866BD834A8A0F04FDF9975E | SHA256:ACB587B12CFC37DDB0C36DB721C718BB125ED78122BC76EFDBA23530DD1A78A5 | |||
| 2516 | anydesk-6-3-5 (1).exe | C:\Users\admin\AppData\Roaming\AnyDesk\connection_trace.txt | binary | |
MD5:3C8F1C057D610AC0B474CC861D14C127 | SHA256:2A1367AB9951DBF696A7038A1997B43E8D8C5E6CAA0815FE42FEFA8BFACFF749 | |||
| 8160 | anydesk-6-3-5 (1).exe | C:\Users\admin\AppData\Roaming\AnyDesk\ad.trace | text | |
MD5:B5B2EDCEB8B2CD62C266D562EB26CA89 | SHA256:4E408DD278DFDC12AF2FBC8E32BC2CB3F76FBF1ABECA2A506A4A6DC89CC49977 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.60.159.66:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.60.159.66:80 | crl.microsoft.com | Akamai International B.V. | US | whitelisted |
2516 | anydesk-6-3-5 (1).exe | 57.129.37.75:443 | boot-01.net.anydesk.com | — | FR | whitelisted |
2516 | anydesk-6-3-5 (1).exe | 57.129.37.75:80 | boot-01.net.anydesk.com | — | FR | whitelisted |
2516 | anydesk-6-3-5 (1).exe | 57.129.37.75:6568 | boot-01.net.anydesk.com | — | FR | whitelisted |
2112 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2516 | anydesk-6-3-5 (1).exe | 185.229.191.39:443 | boot-02.net.anydesk.com | Datacamp Limited | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2516 | anydesk-6-3-5 (1).exe | 185.229.191.39:80 | boot-02.net.anydesk.com | Datacamp Limited | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
boot-01.net.anydesk.com |
| whitelisted |
boot-02.net.anydesk.com |
| whitelisted |
relay-4c30280e.net.anydesk.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Misc activity | ET REMOTE_ACCESS Anydesk Relay Domain (net .anydesk .com) in DNS Lookup |
2196 | svchost.exe | Misc activity | ET REMOTE_ACCESS Anydesk Relay Domain (net .anydesk .com) in DNS Lookup |
2196 | svchost.exe | Misc activity | ET REMOTE_ACCESS Anydesk Relay Domain (net .anydesk .com) in DNS Lookup |