File name:

UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr

Full analysis: https://app.any.run/tasks/e5adb815-adc6-4dee-b960-1d30e90c3f16
Verdict: Malicious activity
Threats:

A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.

Analysis date: December 12, 2023, 07:21:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
rat
remcos
remote
keylogger
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

4F0C56459B4F0E8F51502E434D1FFC24

SHA1:

B36E6BD0CF69D7B0258ACE48F01FEFF65A6FB4C5

SHA256:

AE86206A568D280D3E030EC9649148FF98B59C6E3CD25E78094CC53631B674D7

SSDEEP:

49152:ZfFRLv6Y8U1EapkU1/GaYCAMvyCyBFAP3VThnRewqDI4M:ZdRLv6tFGT13bvQBWP33RAU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Known privilege escalation attack

      • dllhost.exe (PID: 272)
    • Drops the executable file immediately after the start

      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2652)
    • REMCOS has been detected (SURICATA)

      • AnyDesk.exe (PID: 616)
    • Changes the autorun value in the registry

      • AnyDesk.exe (PID: 616)
    • Actions looks like stealing of personal data

      • AnyDesk.exe (PID: 2408)
      • AnyDesk.exe (PID: 1716)
      • AnyDesk.exe (PID: 2916)
    • Uses NirSoft utilities to collect credentials

      • AnyDesk.exe (PID: 2916)
      • AnyDesk.exe (PID: 1716)
    • Steals credentials

      • AnyDesk.exe (PID: 2916)
      • AnyDesk.exe (PID: 1716)
    • Steals credentials from Web Browsers

      • AnyDesk.exe (PID: 2916)
    • REMCOS has been detected (YARA)

      • AnyDesk.exe (PID: 616)
  • SUSPICIOUS

    • Application launched itself

      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2092)
      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 3028)
      • AnyDesk.exe (PID: 616)
      • AnyDesk.exe (PID: 2264)
    • Process drops legitimate windows executable

      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2652)
    • Starts itself from another location

      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2652)
    • Reads the Internet Settings

      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2652)
      • AnyDesk.exe (PID: 616)
    • Connects to unusual port

      • AnyDesk.exe (PID: 616)
    • Writes files like Keylogger logs

      • AnyDesk.exe (PID: 616)
    • Accesses Microsoft Outlook profiles

      • AnyDesk.exe (PID: 1716)
  • INFO

    • Reads the computer name

      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 3028)
      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 1828)
      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2092)
      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2652)
      • AnyDesk.exe (PID: 616)
      • AnyDesk.exe (PID: 2264)
      • AnyDesk.exe (PID: 1716)
      • AnyDesk.exe (PID: 2916)
      • AnyDesk.exe (PID: 2408)
    • Checks supported languages

      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 3028)
      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 1828)
      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2092)
      • AnyDesk.exe (PID: 2264)
      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2652)
      • AnyDesk.exe (PID: 616)
      • AnyDesk.exe (PID: 1716)
      • AnyDesk.exe (PID: 2408)
      • AnyDesk.exe (PID: 2916)
    • Reads the machine GUID from the registry

      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 3028)
      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 1828)
      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2092)
      • AnyDesk.exe (PID: 616)
      • AnyDesk.exe (PID: 2264)
      • AnyDesk.exe (PID: 2408)
      • AnyDesk.exe (PID: 2916)
    • Reads Environment values

      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2652)
      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 1828)
      • AnyDesk.exe (PID: 616)
    • Creates files in the program directory

      • UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe (PID: 2652)
      • AnyDesk.exe (PID: 616)
    • Checks proxy server information

      • AnyDesk.exe (PID: 616)
    • Creates files or folders in the user directory

      • AnyDesk.exe (PID: 616)
    • Create files in a temporary directory

      • AnyDesk.exe (PID: 1716)
      • AnyDesk.exe (PID: 2408)
      • AnyDesk.exe (PID: 2916)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Remcos

(PID) Process(616) AnyDesk.exe
C2 (1)104.250.180.178:7902
BotnetRemoteHost
Options
Connect_interval1
Install_flagTrue
Install_HKCU\RunTrue
Install_HKLM\RunTrue
Install_HKLM\Explorer\Run1
Install_HKLM\Winlogon\Shell100000
Setup_path%LOCALAPPDATA%
Copy_fileAnyDesk.exe
Startup_valueFalse
Hide_fileFalse
Mutex_nameAnyDesk-8BNQK6
Keylog_flag1
Keylog_path%LOCALAPPDATA%
Keylog_filelogs.dat
Keylog_cryptFalse
Hide_keylogFalse
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_path%APPDATA%
Screenshot_fileScreenshots
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path%ProgramFiles%
Audio_dirMicRecords
Connect_delay0
Copy_dirAnyDesk
Keylog_dirAnyDesk
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:12 07:18:26+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 887296
InitializedDataSize: 2560
UninitializedDataSize: -
EntryPoint: 0xda946
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: Microsoft Corporation
FileDescription: performance Monitor
FileVersion: 1.0.0.0
InternalName: mZe.exe
LegalCopyright: ©Microsoft Corporation. All rights reserved.
LegalTrademarks: -
OriginalFileName: mZe.exe
ProductName: performance Monitor
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
13
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start updated (delay notice) - cif hamburg by sea - etc 1219 , so 6722.doc.scr.exe no specs updated (delay notice) - cif hamburg by sea - etc 1219 , so 6722.doc.scr.exe no specs CMSTPLUA no specs updated (delay notice) - cif hamburg by sea - etc 1219 , so 6722.doc.scr.exe no specs updated (delay notice) - cif hamburg by sea - etc 1219 , so 6722.doc.scr.exe no specs anydesk.exe no specs #REMCOS anydesk.exe anydesk.exe anydesk.exe no specs anydesk.exe anydesk.exe no specs anydesk.exe no specs anydesk.exe

Process information

PID
CMD
Path
Indicators
Parent process
272C:\Windows\SysWOW64\DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}C:\Windows\SysWOW64\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
616"C:\ProgramData\AnyDesk\AnyDesk.exe"C:\ProgramData\AnyDesk\AnyDesk.exe
AnyDesk.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
performance Monitor
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\programdata\anydesk\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Remcos
(PID) Process(616) AnyDesk.exe
C2 (1)104.250.180.178:7902
BotnetRemoteHost
Options
Connect_interval1
Install_flagTrue
Install_HKCU\RunTrue
Install_HKLM\RunTrue
Install_HKLM\Explorer\Run1
Install_HKLM\Winlogon\Shell100000
Setup_path%LOCALAPPDATA%
Copy_fileAnyDesk.exe
Startup_valueFalse
Hide_fileFalse
Mutex_nameAnyDesk-8BNQK6
Keylog_flag1
Keylog_path%LOCALAPPDATA%
Keylog_filelogs.dat
Keylog_cryptFalse
Hide_keylogFalse
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_path%APPDATA%
Screenshot_fileScreenshots
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path%ProgramFiles%
Audio_dirMicRecords
Connect_delay0
Copy_dirAnyDesk
Keylog_dirAnyDesk
1716C:\ProgramData\AnyDesk\AnyDesk.exe /stext "C:\Users\admin\AppData\Local\Temp\jebvfxibrcnlkccsv"C:\ProgramData\AnyDesk\AnyDesk.exe
AnyDesk.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
performance Monitor
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\programdata\anydesk\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1764C:\ProgramData\AnyDesk\AnyDesk.exe /stext "C:\Users\admin\AppData\Local\Temp\jebvfxibrcnlkccsv"C:\ProgramData\AnyDesk\AnyDesk.exeAnyDesk.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
performance Monitor
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\programdata\anydesk\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1828"C:\Users\admin\AppData\Local\Temp\UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe"C:\Users\admin\AppData\Local\Temp\UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exeUPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
performance Monitor
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\updated (delay notice) - cif hamburg by sea - etc 1219 , so 6722.doc.scr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2092"C:\Users\admin\AppData\Local\Temp\UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe" C:\Users\admin\AppData\Local\Temp\UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exedllhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
performance Monitor
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\updated (delay notice) - cif hamburg by sea - etc 1219 , so 6722.doc.scr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\mscoree.dll
2264"C:\ProgramData\AnyDesk\AnyDesk.exe" C:\ProgramData\AnyDesk\AnyDesk.exeUPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
performance Monitor
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\programdata\anydesk\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\mscoree.dll
2408C:\ProgramData\AnyDesk\AnyDesk.exe /stext "C:\Users\admin\AppData\Local\Temp\tygggptdnkfquiywmjmw"C:\ProgramData\AnyDesk\AnyDesk.exe
AnyDesk.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
performance Monitor
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\programdata\anydesk\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2652"C:\Users\admin\AppData\Local\Temp\UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe"C:\Users\admin\AppData\Local\Temp\UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exeUPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
performance Monitor
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\updated (delay notice) - cif hamburg by sea - etc 1219 , so 6722.doc.scr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2664C:\ProgramData\AnyDesk\AnyDesk.exe /stext "C:\Users\admin\AppData\Local\Temp\jebvfxibrcnlkccsv"C:\ProgramData\AnyDesk\AnyDesk.exeAnyDesk.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
performance Monitor
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\programdata\anydesk\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
1 552
Read events
1 522
Write events
30
Delete events
0

Modification events

(PID) Process:(272) dllhost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(272) dllhost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(272) dllhost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(272) dllhost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2652) UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2652) UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2652) UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2652) UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(616) AnyDesk.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:AnyDesk-8BNQK6
Value:
"C:\ProgramData\AnyDesk\AnyDesk.exe"
(PID) Process:(616) AnyDesk.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:AnyDesk-8BNQK6
Value:
"C:\ProgramData\AnyDesk\AnyDesk.exe"
Executable files
1
Suspicious files
2
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2916AnyDesk.exeC:\Users\admin\AppData\Local\Temp\bhv88BD.tmp
MD5:
SHA256:
616AnyDesk.exeC:\ProgramData\AnyDesk\logs.datbinary
MD5:73DFF83B774EC468D9201E37B9FED886
SHA256:782B5DDAB19DA568AB134388F81BEB992AD6C395DCCB616E2320FC174043D303
1716AnyDesk.exeC:\Users\admin\AppData\Local\Temp\jebvfxibrcnlkccsvtext
MD5:7FB9A9AD0FD9B1E0108ED71FBB276048
SHA256:7D63C301317E144B0133A72250AE2D8E09AF65A92E6A807EC58A71939FE530A9
616AnyDesk.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K78MRVB5\json[1].jsonbinary
MD5:5397BC77CD47A757D20789A9B4AE4AE5
SHA256:B6951956FB7000F1C9ECFEB84F2343B9EF170DE6869B1CB185A93FE967DC055A
2652UPDATED (DELAY NOTICE) - CIF Hamburg by Sea - ETC 1219 , SO 6722.DOC.scr.exeC:\ProgramData\AnyDesk\AnyDesk.exeexecutable
MD5:4F0C56459B4F0E8F51502E434D1FFC24
SHA256:AE86206A568D280D3E030EC9649148FF98B59C6E3CD25E78094CC53631B674D7
2916AnyDesk.exeC:\Users\admin\AppData\Local\Temp\ycvdfexiduvyiotext
MD5:2D9139D0CBF8301AE9DAD9173A0A6357
SHA256:2AFE12053A281037E21B2C83109E366E151B4848E9D5357E7B5AE6100CC1C481
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
8
DNS requests
1
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
616
AnyDesk.exe
GET
200
178.237.33.50:80
http://geoplugin.net/json.gp
unknown
binary
949 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
616
AnyDesk.exe
104.250.180.178:7902
Voxility LLP
DE
malicious
616
AnyDesk.exe
178.237.33.50:80
geoplugin.net
Schuberg Philis B.V.
NL
malicious

DNS requests

Domain
IP
Reputation
geoplugin.net
  • 178.237.33.50
malicious

Threats

PID
Process
Class
Message
616
AnyDesk.exe
Malware Command and Control Activity Detected
ET JA3 Hash - Remcos 3.x TLS Connection
616
AnyDesk.exe
A Network Trojan was detected
REMOTE [ANY.RUN] REMCOS JA3 Hash
616
AnyDesk.exe
Malware Command and Control Activity Detected
ET JA3 Hash - Remcos 3.x TLS Connection
616
AnyDesk.exe
A Network Trojan was detected
REMOTE [ANY.RUN] REMCOS JA3 Hash
1 ETPRO signatures available at the full report
No debug info