File name:

rustdesk-1.2.2-x86-sciter.exe

Full analysis: https://app.any.run/tasks/9eacb39c-c4eb-4e55-a722-983a46fbc8a3
Verdict: Malicious activity
Analysis date: August 24, 2023, 13:28:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C035A713E9DF9DAD1FBC8794418A3D3C

SHA1:

7CC307BE6AD3ED34F40B278C8D650A634D8217B4

SHA256:

6D4C7C6A671B05BB380E65B62A8CD3137A22FA397B9DC6CA069D6E2C7D762720

SSDEEP:

196608:PEbfNOhqZTTK8bDJoED2PeylYVUDMlOFLtv+h5x8GjysquSE8Ja:PEbfNOhqZTOKDwPbn4Yx0xnqDRJa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • rustdesk.exe (PID: 2744)
      • rustdesk.exe (PID: 2108)
    • Application was dropped or rewritten from another process

      • rustdesk.exe (PID: 2744)
      • rustdesk.exe (PID: 2108)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • rustdesk-1.2.2-x86-sciter.exe (PID: 996)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2468)
      • rustdesk-1.2.2-x86-sciter.exe (PID: 996)
    • Starts CMD.EXE for commands execution

      • rustdesk.exe (PID: 2744)
    • Connects to unusual port

      • rustdesk.exe (PID: 2744)
    • Application launched itself

      • rustdesk.exe (PID: 2744)
  • INFO

    • Checks supported languages

      • rustdesk.exe (PID: 2744)
      • rustdesk-1.2.2-x86-sciter.exe (PID: 996)
      • rustdesk.exe (PID: 2108)
    • Creates files or folders in the user directory

      • rustdesk-1.2.2-x86-sciter.exe (PID: 996)
      • rustdesk.exe (PID: 2744)
      • rustdesk.exe (PID: 2108)
    • Reads the computer name

      • rustdesk.exe (PID: 2744)
      • rustdesk.exe (PID: 2108)
    • [YARA] Firewall manipulation strings were found

      • rustdesk.exe (PID: 2744)
    • Reads the machine GUID from the registry

      • rustdesk.exe (PID: 2744)
      • rustdesk.exe (PID: 2108)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

Subsystem: Windows GUI
SubsystemVersion: 6
ImageVersion: -
OSVersion: 6
EntryPoint: 0x3d617
UninitializedDataSize: -
InitializedDataSize: 8280064
CodeSize: 308736
LinkerVersion: 14.29
PEType: PE32
ImageFileCharacteristics: Executable, Large address aware, 32-bit
TimeStamp: 2023:08:22 02:10:15+00:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 22-Aug-2023 02:10:15
Detected languages:
  • English - United States
TLS Callbacks: 1 callback(s) detected.

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000108

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 22-Aug-2023 02:10:15
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LARGE_ADDRESS_AWARE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0004B4DF
0x0004B600
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.49993
.rdata
0x0004D000
0x007C7EA4
0x007C8000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.99628
.data
0x00815000
0x00001450
0x00000A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.1961
.rsrc
0x00817000
0x000186D8
0x00018800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
2.48979
.reloc
0x00830000
0x00003890
0x00003A00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.65638

Resources

Title
Entropy
Size
Codepage
Language
Type
1
3.48575
1128
UNKNOWN
English - United States
RT_ICON
2
2.96178
4264
UNKNOWN
English - United States
RT_ICON
3
2.70777
9640
UNKNOWN
English - United States
RT_ICON
4
2.58276
16936
UNKNOWN
English - United States
RT_ICON
5
2.33551
67624
UNKNOWN
English - United States
RT_ICON
RUSTDESK_ICON
2.80283
76
UNKNOWN
English - United States
RT_GROUP_ICON

Imports

ADVAPI32.dll
KERNEL32.dll
bcrypt.dll
ntdll.dll
ole32.dll
shell32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
6
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start rustdesk-1.2.2-x86-sciter.exe taskkill.exe no specs rustdesk.exe cmd.exe no specs taskkill.exe no specs rustdesk.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
832"taskkill" /F /IM RuntimeBroker_rustdesk.exeC:\Windows\System32\taskkill.exerustdesk-1.2.2-x86-sciter.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
996"C:\Users\admin\AppData\Local\Temp\rustdesk-1.2.2-x86-sciter.exe" C:\Users\admin\AppData\Local\Temp\rustdesk-1.2.2-x86-sciter.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\temp\rustdesk-1.2.2-x86-sciter.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2108"C:\Users\admin\AppData\Local\rustdesk\.\rustdesk.exe" --connect 127.0.0.1C:\Users\admin\AppData\Local\rustdesk\rustdesk.exerustdesk.exe
User:
admin
Integrity Level:
MEDIUM
Description:
RustDesk
Exit code:
0
Version:
1.2.2
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\rustdesk\rustdesk.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\sas.dll
c:\windows\system32\secur32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sspicli.dll
2468"cmd" /c "taskkill /F /IM RuntimeBroker_rustdesk.exe"C:\Windows\System32\cmd.exerustdesk.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
128
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2644taskkill /F /IM RuntimeBroker_rustdesk.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\taskkill.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\version.dll
2744"C:\Users\admin\AppData\Local\rustdesk\.\rustdesk.exe"C:\Users\admin\AppData\Local\rustdesk\rustdesk.exe
rustdesk-1.2.2-x86-sciter.exe
User:
admin
Integrity Level:
MEDIUM
Description:
RustDesk
Exit code:
0
Version:
1.2.2
Modules
Images
c:\users\admin\appdata\local\rustdesk\rustdesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sas.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
Total events
2 539
Read events
2 539
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
0
Text files
17
Unknown types
0

Dropped files

PID
Process
Filename
Type
996rustdesk-1.2.2-x86-sciter.exeC:\Users\admin\AppData\Local\rustdesk\rustdesk.exeexecutable
MD5:F01CEB589199F7D094BD02AFCCFA511C
SHA256:A5BD52B6B4AA632E89169A6AD025F57F7FA9F2101C235EDBF6A8AF75B0BFCD9C
2744rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk2.tomltext
MD5:CBED07D77E87E32D145A57FB532B9C5E
SHA256:7C7014AC13E16DF5048A72A83D248C57AA77E27B5AE773A83B5DAEB8FE4ED4EF
2744rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.2744_ThreadId(16)_1692883723519750000text
MD5:6C4E8F065B3B16E7EE8A7412951CFA2F
SHA256:789396B51D8E514D519CD3F8E27A8FB27A85B5FDA8CE41A46B4FF153B85EB47D
2744rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk_local.2744_ThreadId(1)_1692883757926000000text
MD5:78E0751A78B63AF1505B88AFF5EDEFEB
SHA256:1A310407F76BEBD4328B3E089B057BB7CD81C101C263BC4E79F7500277A77C1E
2744rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk_local.tomltext
MD5:78E0751A78B63AF1505B88AFF5EDEFEB
SHA256:1A310407F76BEBD4328B3E089B057BB7CD81C101C263BC4E79F7500277A77C1E
2744rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.2744_ThreadId(18)_1692883719566625000text
MD5:BCB2375FC67D37D03EAB54E5A8210FC4
SHA256:6FE85D9438DAB4CC94AB704BC73060955FBDFDCF4F199702432E7864B8DF45B4
2744rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk2.2744_ThreadId(28)_1692883722566625000text
MD5:CBED07D77E87E32D145A57FB532B9C5E
SHA256:7C7014AC13E16DF5048A72A83D248C57AA77E27B5AE773A83B5DAEB8FE4ED4EF
2744rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk2.2744_ThreadId(16)_1692883723519750000text
MD5:2A408A7C9318EB373ADCA69D35308644
SHA256:03E54955AB0DA32559C1B0DE7B88A4B66EFCD90C16C958A06D03CBE6FFBA0AA8
2744rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.2744_ThreadId(34)_1692883720363500000text
MD5:257A97703D76A5E76E5666A4610189BF
SHA256:2B7DC96BA8140A2E8359F1F0E536CD6D5E96D4D0E0F2A1F3A157C3C2BBB9E902
996rustdesk-1.2.2-x86-sciter.exeC:\Users\admin\AppData\Local\rustdesk\sciter.dllexecutable
MD5:0BB1500493EC92FC16EB579D1347FCD8
SHA256:E3967FCD45C93E1FEAFE41C17F8D67C5C231A8DBC6BE47FC0CA1DB272C373310
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
11
DNS requests
3
Threats
10

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2744
rustdesk.exe
155.138.247.159:21116
rs-ny.rustdesk.com
AS-CHOOPA
US
unknown
2744
rustdesk.exe
167.179.67.29:21116
rs-sg.rustdesk.com
AS-CHOOPA
JP
unknown
2744
rustdesk.exe
155.138.247.159:21115
rs-ny.rustdesk.com
AS-CHOOPA
US
unknown

DNS requests

Domain
IP
Reputation
rs-ny.rustdesk.com
  • 155.138.247.159
unknown
rs-sg.rustdesk.com
  • 167.179.67.29
unknown

Threats

PID
Process
Class
Message
1088
svchost.exe
Misc activity
ET INFO RustDesk Domain in DNS Lookup
1088
svchost.exe
Misc activity
ET INFO RustDesk Relay Domain in DNS Lookup
1088
svchost.exe
Misc activity
ET INFO RustDesk Domain in DNS Lookup
1088
svchost.exe
Misc activity
ET INFO RustDesk Relay Domain in DNS Lookup
2744
rustdesk.exe
Misc activity
ET INFO RustDesk Register Public Key
2744
rustdesk.exe
Misc activity
ET INFO RustDesk Register Public Key
1088
svchost.exe
Misc activity
ET INFO RustDesk Domain in DNS Lookup
1088
svchost.exe
Misc activity
ET INFO RustDesk Relay Domain in DNS Lookup
2744
rustdesk.exe
Misc activity
ET INFO RustDesk Register Public Key
2744
rustdesk.exe
Misc activity
ET INFO RustDesk Get Software Update URL
No debug info