File name:

AnyDesk.exe

Full analysis: https://app.any.run/tasks/2213db79-ab74-41e5-8666-9046f0e878f7
Verdict: Malicious activity
Analysis date: February 14, 2024, 08:59:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9603CAD726F04B638B9797C46C162077

SHA1:

4A014126222D142651B17F45DBBA0E8921824908

SHA256:

BBBEDD933AC156B476E1B3EDB3E09501C604A79C4FF1A917DF779A9F1BEC5CCA

SSDEEP:

98304:qXmE4VsBBiNN6CmYTQ3dJcDIVHi2ylUnL2/kvGruBJ0ro2unTPy/p1d8x++tMxpL:eBCblQ/uEWBwBM4D4

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AnyDesk.exe (PID: 3864)
      • AnyDesk.exe (PID: 3892)
  • SUSPICIOUS

    • Found AnyDesk certificate that may have been compromised

      • AnyDesk.exe (PID: 3864)
      • AnyDesk.exe (PID: 3892)
      • AnyDesk.exe (PID: 3732)
    • Application launched itself

      • AnyDesk.exe (PID: 3864)
    • Reads the Internet Settings

      • AnyDesk.exe (PID: 3732)
    • Executable content was dropped or overwritten

      • AnyDesk.exe (PID: 3892)
  • INFO

    • Reads the computer name

      • AnyDesk.exe (PID: 3864)
      • AnyDesk.exe (PID: 3892)
      • AnyDesk.exe (PID: 3732)
    • Process checks whether UAC notifications are on

      • AnyDesk.exe (PID: 3864)
    • Checks supported languages

      • AnyDesk.exe (PID: 3864)
      • AnyDesk.exe (PID: 3892)
      • AnyDesk.exe (PID: 3732)
    • Reads the machine GUID from the registry

      • AnyDesk.exe (PID: 3864)
      • AnyDesk.exe (PID: 3892)
    • Creates files or folders in the user directory

      • AnyDesk.exe (PID: 3864)
    • Reads CPU info

      • AnyDesk.exe (PID: 3864)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:19 08:02:57+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 10752
InitializedDataSize: 5460480
UninitializedDataSize: 19275264
EntryPoint: 0x1ce5
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 8.0.4.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: AnyDesk Software GmbH
FileDescription: AnyDesk
FileVersion: 8.0.4
ProductName: AnyDesk
ProductVersion: 8
LegalCopyright: (C) 2022 AnyDesk Software GmbH
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start anydesk.exe no specs anydesk.exe no specs anydesk.exe

Process information

PID
CMD
Path
Indicators
Parent process
3732"C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" --local-controlC:\Users\admin\AppData\Local\Temp\AnyDesk.exeAnyDesk.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
0
Version:
8.0.4
Modules
Images
c:\users\admin\appdata\local\temp\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3864"C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" C:\Users\admin\AppData\Local\Temp\AnyDesk.exeexplorer.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
0
Version:
8.0.4
Modules
Images
c:\users\admin\appdata\local\temp\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3892"C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" --local-serviceC:\Users\admin\AppData\Local\Temp\AnyDesk.exe
AnyDesk.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
0
Version:
8.0.4
Modules
Images
c:\users\admin\appdata\local\temp\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
3 391
Read events
3 391
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
3
Unknown types
2

Dropped files

PID
Process
Filename
Type
3892AnyDesk.exeC:\Users\admin\AppData\Roaming\AnyDesk\system.conftext
MD5:0C04AD1083DC5C7C45E3EE2CD344AE38
SHA256:6452273C017DB7CBE0FFC5B109BBF3F8D3282FB91BFA3C5EABC4FB8F1FC98CB0
3864AnyDesk.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-msbinary
MD5:33664807CFB7932EE4F606302D827A51
SHA256:0D108C1CDAEE752F79B6A49F0081CFC24E660B623D9EACC68E6FC7D93AA6F0C8
3892AnyDesk.exeC:\Users\admin\AppData\Roaming\AnyDesk\service.conftext
MD5:8866F0AD3D548337982D350820CF0AAB
SHA256:3CF8799157C5C025B841EFF5BE6E4C9C1D5BE4581CA8819A11E44455259F1A70
3864AnyDesk.exeC:\Users\admin\AppData\Roaming\AnyDesk\user.conftext
MD5:A787C308BD30D6D844E711D7579BE552
SHA256:8A395011A6A877D3BDD53CC8688EF146160DAB9D42140EB4A70716AD4293A440
3864AnyDesk.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NKN13R2AZ19BWABL70IL.tempbinary
MD5:33664807CFB7932EE4F606302D827A51
SHA256:0D108C1CDAEE752F79B6A49F0081CFC24E660B623D9EACC68E6FC7D93AA6F0C8
3892AnyDesk.exeC:\Users\admin\AppData\Local\Temp\gcapi.dllexecutable
MD5:1CE7D5A1566C8C449D0F6772A8C27900
SHA256:73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
2
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3892
AnyDesk.exe
37.59.29.33:443
boot.net.anydesk.com
OVH SAS
FR
unknown
3892
AnyDesk.exe
37.59.29.33:80
boot.net.anydesk.com
OVH SAS
FR
unknown
3892
AnyDesk.exe
51.178.91.235:443
relay-3d17eb18.net.anydesk.com
OVH SAS
FR
unknown

DNS requests

Domain
IP
Reputation
boot.net.anydesk.com
  • 37.59.29.33
unknown
relay-3d17eb18.net.anydesk.com
  • 51.178.91.235
unknown

Threats

PID
Process
Class
Message
3892
AnyDesk.exe
Misc activity
ET POLICY SSL/TLS Certificate Observed (AnyDesk Remote Desktop Software)
No debug info