File name:

rustdesk-1.2.2-x86-sciter.exe

Full analysis: https://app.any.run/tasks/c68e4457-e3e1-4014-9498-e2a55fa4008b
Verdict: Malicious activity
Analysis date: April 03, 2024, 11:27:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
remote
rustdesk
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C035A713E9DF9DAD1FBC8794418A3D3C

SHA1:

7CC307BE6AD3ED34F40B278C8D650A634D8217B4

SHA256:

6D4C7C6A671B05BB380E65B62A8CD3137A22FA397B9DC6CA069D6E2C7D762720

SSDEEP:

196608:PEbfNOhqZTTK8bDJoED2PeylYVUDMlOFLtv+h5x8GjysquSE8Ja:PEbfNOhqZTOKDwPbn4Yx0xnqDRJa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • rustdesk-1.2.2-x86-sciter.exe (PID: 120)
    • RUSTDESK has been detected (SURICATA)

      • rustdesk.exe (PID: 3940)
  • SUSPICIOUS

    • Uses TASKKILL.EXE to kill process

      • rustdesk-1.2.2-x86-sciter.exe (PID: 120)
      • cmd.exe (PID: 1972)
    • Starts CMD.EXE for commands execution

      • rustdesk.exe (PID: 3940)
    • Connects to unusual port

      • rustdesk.exe (PID: 3940)
  • INFO

    • Checks supported languages

      • rustdesk.exe (PID: 3940)
      • rustdesk-1.2.2-x86-sciter.exe (PID: 120)
    • Creates files or folders in the user directory

      • rustdesk-1.2.2-x86-sciter.exe (PID: 120)
      • rustdesk.exe (PID: 3940)
    • Reads the computer name

      • rustdesk.exe (PID: 3940)
    • Reads the machine GUID from the registry

      • rustdesk.exe (PID: 3940)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:08:22 02:10:15+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 308736
InitializedDataSize: 8280064
UninitializedDataSize: -
EntryPoint: 0x3d617
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rustdesk-1.2.2-x86-sciter.exe no specs taskkill.exe no specs #RUSTDESK rustdesk.exe cmd.exe no specs taskkill.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Users\admin\AppData\Local\Temp\rustdesk-1.2.2-x86-sciter.exe" C:\Users\admin\AppData\Local\Temp\rustdesk-1.2.2-x86-sciter.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rustdesk-1.2.2-x86-sciter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1972"cmd" /c "taskkill /F /IM RuntimeBroker_rustdesk.exe"C:\Windows\System32\cmd.exerustdesk.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
128
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1976taskkill /F /IM RuntimeBroker_rustdesk.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
3500"taskkill" /F /IM RuntimeBroker_rustdesk.exeC:\Windows\System32\taskkill.exerustdesk-1.2.2-x86-sciter.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
3940"C:\Users\admin\AppData\Local\rustdesk\.\rustdesk.exe"C:\Users\admin\AppData\Local\rustdesk\rustdesk.exe
rustdesk-1.2.2-x86-sciter.exe
User:
admin
Integrity Level:
MEDIUM
Description:
RustDesk
Version:
1.2.2
Modules
Images
c:\users\admin\appdata\local\rustdesk\rustdesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sas.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
Total events
1 792
Read events
1 792
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
0
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
120rustdesk-1.2.2-x86-sciter.exeC:\Users\admin\AppData\Local\rustdesk\rustdesk.exeexecutable
MD5:
SHA256:
120rustdesk-1.2.2-x86-sciter.exeC:\Users\admin\AppData\Local\rustdesk\sciter.dllexecutable
MD5:
SHA256:
3940rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk2.3940_ThreadId(28)_1712143658373125000text
MD5:
SHA256:
3940rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk2.toml
MD5:
SHA256:
3940rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.3940_ThreadId(15)_1712143658388750000text
MD5:
SHA256:
3940rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.tomltext
MD5:
SHA256:
3940rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.3940_ThreadId(33)_1712143658388750000text
MD5:
SHA256:
3940rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.3940_ThreadId(18)_1712143658404375000text
MD5:
SHA256:
3940rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk2.3940_ThreadId(15)_1712143658451250000text
MD5:
SHA256:
3940rustdesk.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.3940_ThreadId(15)_1712143658451250000text
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
8
DNS requests
3
Threats
7

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3940
rustdesk.exe
108.61.171.103:21116
rs-ny.rustdesk.com
unknown
3940
rustdesk.exe
108.61.171.103:21115
rs-ny.rustdesk.com
AS-CHOOPA
DE
unknown

DNS requests

Domain
IP
Reputation
rs-ny.rustdesk.com
  • 108.61.171.103
unknown
rs-sg.rustdesk.com
  • 127.0.0.1
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Misc activity
ET INFO RustDesk Domain in DNS Lookup
1080
svchost.exe
Misc activity
ET INFO RustDesk Relay Domain in DNS Lookup
1080
svchost.exe
Misc activity
ET INFO RustDesk Relay Domain in DNS Lookup
1080
svchost.exe
Misc activity
ET INFO RustDesk Domain in DNS Lookup
3940
rustdesk.exe
Misc activity
ET INFO RustDesk Register Public Key
1080
svchost.exe
Misc activity
ET INFO RustDesk Domain in DNS Lookup
1080
svchost.exe
Misc activity
ET INFO RustDesk Relay Domain in DNS Lookup
No debug info