File name:

Reset_AnyDesk_ID_Address.exe

Full analysis: https://app.any.run/tasks/aa6675e2-4e7c-4c25-b543-563066b02ef1
Verdict: Malicious activity
Analysis date: November 12, 2024, 08:14:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

978467B7292C52FADD154211EE412B21

SHA1:

83916769C470EC21BFCBD32A70F983E6797F6970

SHA256:

B17140FF5AE2D2F1BE23E252EF09D95FCEE380DC20E1C55588BFF8B6B2A9CF87

SSDEEP:

24576:ps8uCqXG8K70lrfYW5VkP3dRbZSgzJ9UnwG:VuCqXG8KCrfYW5VkvdRbZSgzJ9Unw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • cmd.exe (PID: 4092)
      • net.exe (PID: 2220)
      • cmd.exe (PID: 2296)
      • net.exe (PID: 3236)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • Reset_AnyDesk_ID_Address.exe (PID: 1876)
  • INFO

    • Reads mouse settings

      • Reset_AnyDesk_ID_Address.exe (PID: 1876)
    • Checks supported languages

      • Reset_AnyDesk_ID_Address.exe (PID: 1876)
    • Manual execution by a user

      • WINWORD.EXE (PID: 4056)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (39.3)
.exe | Win32 EXE Yoda's Crypter (38.6)
.dll | Win32 Dynamic Link Library (generic) (9.5)
.exe | Win32 Executable (generic) (6.5)
.exe | Generic Win/DOS Executable (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:09:13 08:20:40+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 356352
InitializedDataSize: 143360
UninitializedDataSize: 671744
EntryPoint: 0xfb050
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 3.3.14.5
ProductVersionNumber: 3.3.14.5
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Unicode
FileVersion: 3.3.14.5
Comments: Reset_AnyDesk_ID_Address
FileDescription: Reset AnyDesk ID Address Skills dG Guo
ProductName: Reset_AnyDesk_ID_Address
ProductVersion: 3.3.14.5
CompanyName: Skills dG Guo
LegalCopyright: ©1999-2018 Jonathan Bennett & AutoIt Team
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
10
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start reset_anydesk_id_address.exe cmd.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs winword.exe no specs reset_anydesk_id_address.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1876"C:\Users\admin\AppData\Local\Temp\Reset_AnyDesk_ID_Address.exe" C:\Users\admin\AppData\Local\Temp\Reset_AnyDesk_ID_Address.exe
explorer.exe
User:
admin
Company:
Skills dG Guo
Integrity Level:
HIGH
Description:
Reset AnyDesk ID Address Skills dG Guo
Exit code:
0
Version:
3.3.14.5
Modules
Images
c:\users\admin\appdata\local\temp\reset_anydesk_id_address.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
1968C:\Windows\system32\net1 start AnyDeskC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
2220net stop AnyDeskC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
2296C:\Windows\system32\cmd.exe /c net start AnyDeskC:\Windows\System32\cmd.exeReset_AnyDesk_ID_Address.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2828C:\Windows\system32\cmd.exe /c del C:\ProgramData\AnyDesk\service.confC:\Windows\System32\cmd.exeReset_AnyDesk_ID_Address.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3212"C:\Users\admin\AppData\Local\Temp\Reset_AnyDesk_ID_Address.exe" C:\Users\admin\AppData\Local\Temp\Reset_AnyDesk_ID_Address.exeexplorer.exe
User:
admin
Company:
Skills dG Guo
Integrity Level:
MEDIUM
Description:
Reset AnyDesk ID Address Skills dG Guo
Exit code:
3221226540
Version:
3.3.14.5
Modules
Images
c:\users\admin\appdata\local\temp\reset_anydesk_id_address.exe
c:\windows\system32\ntdll.dll
3236net start AnyDeskC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
3688C:\Windows\system32\net1 stop AnyDeskC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
4056"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\stagegarden.rtf"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
4092C:\Windows\system32\cmd.exe /c net stop AnyDeskC:\Windows\System32\cmd.exeReset_AnyDesk_ID_Address.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
2 756
Read events
2 325
Write events
122
Delete events
309

Modification events

(PID) Process:(4056) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName:`)/
Value:
60292F00D80F0000010000000000000000000000
(PID) Process:(4056) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(4056) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(4056) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(4056) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(4056) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(4056) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
(PID) Process:(4056) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
Off
(PID) Process:(4056) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
Off
(PID) Process:(4056) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
Off
Executable files
1
Suspicious files
4
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
4056WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR49B1.tmp.cvr
MD5:
SHA256:
4056WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\stagegarden.rtf.LNKbinary
MD5:70B435B360067FA5C6A3F5691FBB2F8F
SHA256:7755979ED9812E910675A7F7B4A575B9CC9B34E75704345AE3F6497722A2DC21
4056WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmbinary
MD5:C80FE13B44981DEAE99C8979E9454E9A
SHA256:943698CCEB741DDDA43C63A31CCF19352E6FA11C1ECF1AFB1CA93564E58043D0
4056WINWORD.EXEC:\Users\admin\Desktop\~$agegarden.rtfbinary
MD5:C02DBF35FBB4ABFC8C3CE168AAFEEBF9
SHA256:541AA1CDE4570FBDE0E66F31CB06D293BF620B344212D26B399D5A983EB06FB5
4056WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:EC20D86271035525396A361B85FA4467
SHA256:EBC6BDBDEEAEEFD5896A45772F21879862B41780ACF06CCAFEC5422E5D708168
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
239.255.255.250:3702
whitelisted
4
System
192.168.100.255:138
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted

Threats

No threats detected
No debug info