File name:

AnyDesk (7).exe.zip

Full analysis: https://app.any.run/tasks/6f6100ce-dd71-42aa-9456-374389e13acc
Verdict: Malicious activity
Analysis date: May 21, 2025, 09:27:56
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
anydesk
rmm-tool
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

BF86EE743AA827157BEC32E0C4481B02

SHA1:

0FB419E8753B2E484118DE5B551B27F1D446B5B9

SHA256:

9E1A41F33940979C52C7CDD47B45A176F248F66A587CAAB9CBBB042A2DCE06F5

SSDEEP:

98304:0/l5hvy8GA0k7s7l/ADhKVYorx0lL3xIKX5lii89Kwkl5aNTYCENkdjkdFc9fJJx:eutdABeJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Found AnyDesk certificate that may have been compromised

      • AnyDesk (7).exe (PID: 7512)
      • AnyDesk (7).exe (PID: 7584)
      • AnyDesk (7).exe (PID: 7592)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7280)
    • ANYDESK mutex has been found

      • AnyDesk (7).exe (PID: 7512)
      • AnyDesk (7).exe (PID: 7584)
      • AnyDesk (7).exe (PID: 7592)
    • ANYDESK has been found

      • WinRAR.exe (PID: 7280)
      • AnyDesk (7).exe (PID: 7512)
    • Application launched itself

      • AnyDesk (7).exe (PID: 7512)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 7280)
    • Reads the computer name

      • AnyDesk (7).exe (PID: 7512)
      • AnyDesk (7).exe (PID: 7584)
      • AnyDesk (7).exe (PID: 7592)
    • Creates files or folders in the user directory

      • AnyDesk (7).exe (PID: 7512)
    • Process checks whether UAC notifications are on

      • AnyDesk (7).exe (PID: 7512)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7280)
    • Checks supported languages

      • AnyDesk (7).exe (PID: 7512)
      • AnyDesk (7).exe (PID: 7584)
      • AnyDesk (7).exe (PID: 7592)
    • Reads the machine GUID from the registry

      • AnyDesk (7).exe (PID: 7584)
    • Checks proxy server information

      • AnyDesk (7).exe (PID: 7592)
    • Reads CPU info

      • AnyDesk (7).exe (PID: 7512)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2025:05:21 09:27:36
ZipCRC: 0x9a592059
ZipCompressedSize: 4016313
ZipUncompressedSize: 4038208
ZipFileName: AnyDesk (7).exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
4
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe anydesk (7).exe no specs anydesk (7).exe anydesk (7).exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7280"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\AnyDesk (7).exe.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7512"C:\Users\admin\AppData\Local\Temp\Rar$EXa7280.49825\AnyDesk (7).exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa7280.49825\AnyDesk (7).exeWinRAR.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Version:
7.1.12
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7280.49825\anydesk (7).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\winmm.dll
c:\windows\syswow64\msvcrt.dll
7584"C:\Users\admin\AppData\Local\Temp\Rar$EXa7280.49825\AnyDesk (7).exe" --local-serviceC:\Users\admin\AppData\Local\Temp\Rar$EXa7280.49825\AnyDesk (7).exe
AnyDesk (7).exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Version:
7.1.12
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7280.49825\anydesk (7).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\winmm.dll
c:\windows\syswow64\msvcrt.dll
7592"C:\Users\admin\AppData\Local\Temp\Rar$EXa7280.49825\AnyDesk (7).exe" --local-controlC:\Users\admin\AppData\Local\Temp\Rar$EXa7280.49825\AnyDesk (7).exeAnyDesk (7).exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Version:
7.1.12
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa7280.49825\anydesk (7).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\winmm.dll
c:\windows\syswow64\msvcrt.dll
Total events
2 562
Read events
2 554
Write events
8
Delete events
0

Modification events

(PID) Process:(7280) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7280) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7280) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7280) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AnyDesk (7).exe.zip
(PID) Process:(7280) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7280) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7280) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7280) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
7280WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7280.49825\AnyDesk (7).exeexecutable
MD5:BCA01AF10AAC7833188C47D7FEC17196
SHA256:734F3577AA453FE8E89D6F351A382474A5DAB97204AFF1E194EEE4E9FDFF0A4A
7280WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa7280.49825\checksums.txttext
MD5:1658084EE61EEAE015F41A0CD9CC513C
SHA256:E8134394DE3F5FA3FCEF8D999A81CDB37CF1D3F00BC3DEE8B517F309A8A0B7AD
7512AnyDesk (7).exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JQ9MEJNZFANEQ3JYVMC2.tempbinary
MD5:72D03DC94F684579D8AFF96AD28C0474
SHA256:3B85CF67A310F72CF2F36569F91E3FAD9EA4913921D5C7BE0D7E49A88593DBB1
7512AnyDesk (7).exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-msbinary
MD5:72D03DC94F684579D8AFF96AD28C0474
SHA256:3B85CF67A310F72CF2F36569F91E3FAD9EA4913921D5C7BE0D7E49A88593DBB1
7584AnyDesk (7).exeC:\Users\admin\AppData\Roaming\AnyDesk\service.conftext
MD5:A59ACE2BE5D7819951DD41E281322F8A
SHA256:9CBF8DF7B3B9AC64EDF799118836CFDCB9ECFCE012D034221563DD67919B909D
7512AnyDesk (7).exeC:\Users\admin\AppData\Roaming\AnyDesk\user.conftext
MD5:5059D0251F3292C45A54E0AB40CCA733
SHA256:88D22B3A6A8BCB3AB03CFAC5EEF7FDF1CF4C99E17576D05997D2F0DFC96B8189
7584AnyDesk (7).exeC:\Users\admin\AppData\Roaming\AnyDesk\system.conftext
MD5:0C04AD1083DC5C7C45E3EE2CD344AE38
SHA256:6452273C017DB7CBE0FFC5B109BBF3F8D3282FB91BFA3C5EABC4FB8F1FC98CB0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
21
DNS requests
16
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.20.245.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
SE
binary
825 b
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
8036
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
QA
binary
419 b
whitelisted
8036
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
QA
binary
407 b
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
QA
binary
868 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
300
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2.20.245.139:80
crl.microsoft.com
Akamai International B.V.
SE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7584
AnyDesk (7).exe
92.223.88.7:443
boot.net.anydesk.com
G-Core Labs S.A.
LU
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 2.20.245.139
  • 2.20.245.137
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
boot.net.anydesk.com
  • 185.229.191.39
  • 92.223.88.41
  • 92.223.88.232
  • 185.229.191.44
  • 57.129.37.75
  • 57.129.37.28
  • 195.181.174.167
  • 185.229.190.236
  • 92.223.88.7
whitelisted
relay-1ec46041.net.anydesk.com
  • 216.144.253.178
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.130
  • 20.190.159.71
  • 40.126.31.73
  • 20.190.159.129
  • 20.190.159.128
  • 40.126.31.0
  • 40.126.31.131
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Misc activity
ET REMOTE_ACCESS Anydesk Domain (boot .net .anydesk .com) in DNS Lookup
2196
svchost.exe
Misc activity
ET REMOTE_ACCESS Anydesk Relay Domain (net .anydesk .com) in DNS Lookup
2196
svchost.exe
Misc activity
ET REMOTE_ACCESS Anydesk Relay Domain (net .anydesk .com) in DNS Lookup
No debug info