File name:

rustdesk-1.1.9.exe

Full analysis: https://app.any.run/tasks/4326c13f-4d7b-407b-a2f6-01a053a1183e
Verdict: Malicious activity
Analysis date: January 16, 2025, 15:05:07
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
remote
rustdesk
rust
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

6784BE19A5F870544C8E564C768EFF23

SHA1:

177C876064ED39E9C06C187176F9F783833F1E1D

SHA256:

B654CB0E45016773EDACB532CDDFAA3FAF677ADBBB3BD7B61E31ED0EC23E0C91

SSDEEP:

196608:q3e439qcLO4DOyvek4JELDzDSlYm4QV3j8rqNU:QdKErLDzDSCm4QV3j8rqNU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • RUSTDESK has been detected (SURICATA)

      • rustdesk-1.1.9.exe (PID: 6612)
  • SUSPICIOUS

    • Connects to unusual port

      • rustdesk-1.1.9.exe (PID: 6612)
  • INFO

    • The sample compiled with english language support

      • rustdesk-1.1.9.exe (PID: 6612)
    • Creates files or folders in the user directory

      • rustdesk-1.1.9.exe (PID: 6612)
    • Checks supported languages

      • rustdesk-1.1.9.exe (PID: 6612)
    • Reads the machine GUID from the registry

      • rustdesk-1.1.9.exe (PID: 6612)
    • Application based on Rust

      • rustdesk-1.1.9.exe (PID: 6612)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2022:07:12 18:00:16+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.29
CodeSize: 11186688
InitializedDataSize: 4105216
UninitializedDataSize: -
EntryPoint: 0xa389a8
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.1.9.0
ProductVersionNumber: 1.1.9.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 1.1.9
ProductName: rustdesk
ProductVersion: 1.1.9
LegalCopyright: Copyright © 2022 Purslane, Inc.
FileDescription: RustDesk
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
128
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #RUSTDESK rustdesk-1.1.9.exe

Process information

PID
CMD
Path
Indicators
Parent process
6612"C:\Users\admin\AppData\Local\Temp\rustdesk-1.1.9.exe" C:\Users\admin\AppData\Local\Temp\rustdesk-1.1.9.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
RustDesk
Version:
1.1.9
Modules
Images
c:\users\admin\appdata\local\temp\rustdesk-1.1.9.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
Total events
400
Read events
400
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
6612rustdesk-1.1.9.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk2.6612_ThreadId(9)_1737039914764383400text
MD5:7E65E186C1FD1E4B9634F8D54CDE92D3
SHA256:828AC47651ACDAA5632E40D79FC4DB0F7B87E487976DC68E7680BE93424EC1AE
6612rustdesk-1.1.9.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.6612_ThreadId(13)_1737039914874689800text
MD5:6AA983BC7FE8B7CF3B69418B182A542A
SHA256:935190DDD9A2A8CD27D77CA613E174585DE0EF07FA6DA3EA115EECB593AD5B89
6612rustdesk-1.1.9.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.6612_ThreadId(10)_1737039914925582300text
MD5:14E6164796AE7ADA7B73FD1BB7A21B4E
SHA256:4401763282FE80F52115E019EFE4B3A77171C7AD208CE8815655060824463BB0
6612rustdesk-1.1.9.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk2.tomltext
MD5:7E65E186C1FD1E4B9634F8D54CDE92D3
SHA256:828AC47651ACDAA5632E40D79FC4DB0F7B87E487976DC68E7680BE93424EC1AE
6612rustdesk-1.1.9.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.tomltext
MD5:6AA983BC7FE8B7CF3B69418B182A542A
SHA256:935190DDD9A2A8CD27D77CA613E174585DE0EF07FA6DA3EA115EECB593AD5B89
6612rustdesk-1.1.9.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk2.6612_ThreadId(11)_1737039914956114800text
MD5:CE1FFA0567444E2B47050EA196B559DD
SHA256:7C92BF00D0BF4DC60D2F3EA7597974B5C9162AE3892B489138FD5ED409478084
6612rustdesk-1.1.9.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.6612_ThreadId(13)_1737039914877989100text
MD5:0212D3EC7906C16E79BD1F5D1545D2FC
SHA256:FFBAA985AD477060DBFA27AC07083629D23C06493C665B5BFC642B3E79CB8228
6612rustdesk-1.1.9.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.6612_ThreadId(11)_1737039914970842000text
MD5:521533B960049D4B13CF2B2833AEA9C2
SHA256:24FCD3A0F91410FE5D197D3FCC7DFF07179E013530EEC4EE6A0E302701A3E444
6612rustdesk-1.1.9.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk.6612_ThreadId(11)_1737039914958204400text
MD5:C0959A212B54B554FF4374FA0D08474B
SHA256:B805E49F0DAC4200E0557CC61436A8BDB581EAE318EB8C72C324636C26B106E2
6612rustdesk-1.1.9.exeC:\Users\admin\AppData\Roaming\RustDesk\config\RustDesk_local.6612_ThreadId(1)_1737039914998666800text
MD5:FE15184A9910E06F5A5BD76A0C982DE7
SHA256:E930F4AFAAA9573D22938FDC00B8FDF73ADBD1B82A20E1E0078E5FC2614168F7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
74
DNS requests
20
Threats
19

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
313 b
whitelisted
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
6392
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
DE
binary
471 b
whitelisted
6016
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
GET
200
2.16.164.24:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
6016
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
408 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2.16.164.24:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
6068
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2.21.65.154:443
www.bing.com
Akamai International B.V.
NL
whitelisted
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 2.16.164.24
  • 2.16.164.17
  • 2.16.164.72
  • 2.16.164.49
  • 2.16.164.40
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
www.bing.com
  • 2.21.65.154
  • 2.21.65.132
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
login.live.com
  • 40.126.32.76
  • 40.126.32.140
  • 40.126.32.72
  • 40.126.32.134
  • 40.126.32.74
  • 40.126.32.68
  • 20.190.160.14
  • 40.126.32.133
whitelisted
rs-sg.rustdesk.com
  • 127.0.0.1
malicious
rs-ny.rustdesk.com
  • 209.250.254.15
malicious
rs-cn.rustdesk.com
  • 127.0.0.1
malicious
go.microsoft.com
  • 184.28.89.167
whitelisted

Threats

PID
Process
Class
Message
2192
svchost.exe
Misc activity
ET INFO RustDesk Domain in DNS Lookup
2192
svchost.exe
Misc activity
ET INFO RustDesk Domain in DNS Lookup
2192
svchost.exe
Misc activity
ET INFO RustDesk Relay Domain in DNS Lookup
2192
svchost.exe
Misc activity
ET INFO RustDesk Domain in DNS Lookup
2192
svchost.exe
Misc activity
ET INFO RustDesk Relay Domain in DNS Lookup
2192
svchost.exe
Misc activity
ET INFO RustDesk Relay Domain in DNS Lookup
6612
rustdesk-1.1.9.exe
Misc activity
ET INFO RustDesk Check NAT Type
6612
rustdesk-1.1.9.exe
Misc activity
ET INFO RustDesk Check NAT Type
6612
rustdesk-1.1.9.exe
Misc activity
ET INFO RustDesk Check NAT Type
6612
rustdesk-1.1.9.exe
Misc activity
ET INFO RustDesk Check NAT Type
No debug info