| File name: | AnyDeskportable.exe |
| Full analysis: | https://app.any.run/tasks/22210ee9-7a1a-4ea7-901d-887358266ca0 |
| Verdict: | Malicious activity |
| Analysis date: | May 03, 2024, 13:13:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 37E172BE64B12F3207300D11B74656B8 |
| SHA1: | 1895D7C4F785F92E48B5191FD812822593CBC73F |
| SHA256: | BC747E3BF7B6E02C09F3D18BDD0E64EEF62B940B2F16C9C72E647EEC85CF0138 |
| SSDEEP: | 98304:JUTRUa7PCXSORUNi9RLzauQ3GPeYXiqKVZeTKcvNS/iWSi4oN9+mMSGmyDpR60WJ:R7InM1zcV |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:09:22 08:14:12+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 10752 |
| InitializedDataSize: | 5457408 |
| UninitializedDataSize: | 19262976 |
| EntryPoint: | 0x1ce5 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 8.0.3.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Unknown (0) |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | AnyDesk Software GmbH |
| FileDescription: | AnyDesk |
| FileVersion: | 8.0.3 |
| ProductName: | AnyDesk |
| ProductVersion: | 8 |
| LegalCopyright: | (C) 2022 AnyDesk Software GmbH |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1112 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2312 | "C:\Users\admin\Desktop\AnyDeskportable.exe" | C:\Users\admin\Desktop\AnyDeskportable.exe | — | AnyDeskportable.exe | |||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Version: 8.0.3 Modules
| |||||||||||||||
| 3968 | "C:\Users\admin\Desktop\AnyDeskportable.exe" | C:\Users\admin\Desktop\AnyDeskportable.exe | — | explorer.exe | |||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Version: 8.0.3 Modules
| |||||||||||||||
| 4080 | "C:\Users\admin\Desktop\AnyDeskportable.exe" --local-service | C:\Users\admin\Desktop\AnyDeskportable.exe | AnyDeskportable.exe | ||||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Version: 8.0.3 Modules
| |||||||||||||||
| 4088 | "C:\Users\admin\Desktop\AnyDeskportable.exe" --local-control | C:\Users\admin\Desktop\AnyDeskportable.exe | — | AnyDeskportable.exe | |||||||||||
User: admin Company: AnyDesk Software GmbH Integrity Level: MEDIUM Description: AnyDesk Version: 8.0.3 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3968 | AnyDeskportable.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\455ENCVY7OQIRPXFNK8P.temp | — | |
MD5:— | SHA256:— | |||
| 3968 | AnyDeskportable.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms | binary | |
MD5:A363F61E638D33C1BDC83ADC8D786975 | SHA256:D5BB9724A36F5CBC3BA6B551F86157ADD5194B2BF1EAD6D15A6A203A282060D1 | |||
| 4080 | AnyDeskportable.exe | C:\Users\admin\AppData\Roaming\AnyDesk\system.conf | text | |
MD5:0C04AD1083DC5C7C45E3EE2CD344AE38 | SHA256:6452273C017DB7CBE0FFC5B109BBF3F8D3282FB91BFA3C5EABC4FB8F1FC98CB0 | |||
| 4080 | AnyDeskportable.exe | C:\Users\admin\Desktop\gcapi.dll | executable | |
MD5:1CE7D5A1566C8C449D0F6772A8C27900 | SHA256:73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF | |||
| 4080 | AnyDeskportable.exe | C:\Users\admin\AppData\Local\Temp\gcapi.dll | executable | |
MD5:1CE7D5A1566C8C449D0F6772A8C27900 | SHA256:73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF | |||
| 4080 | AnyDeskportable.exe | C:\Users\admin\AppData\Roaming\AnyDesk\service.conf | text | |
MD5:2846F0FB9B383E9726B62046BBD540F4 | SHA256:0F93F6FCC224227FB4EF594D92ECA9A1A2C868AE7BED2D8FCCCBF10FF14C2CF7 | |||
| 3968 | AnyDeskportable.exe | C:\Users\admin\AppData\Roaming\AnyDesk\user.conf | text | |
MD5:A787C308BD30D6D844E711D7579BE552 | SHA256:8A395011A6A877D3BDD53CC8688EF146160DAB9D42140EB4A70716AD4293A440 | |||
| 2312 | AnyDeskportable.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms~RF106eb9.TMP | binary | |
MD5:A363F61E638D33C1BDC83ADC8D786975 | SHA256:D5BB9724A36F5CBC3BA6B551F86157ADD5194B2BF1EAD6D15A6A203A282060D1 | |||
| 2312 | AnyDeskportable.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\81M0NWAP9N5R6H9NOOOE.temp | binary | |
MD5:A363F61E638D33C1BDC83ADC8D786975 | SHA256:D5BB9724A36F5CBC3BA6B551F86157ADD5194B2BF1EAD6D15A6A203A282060D1 | |||
| 2312 | AnyDeskportable.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms | binary | |
MD5:A363F61E638D33C1BDC83ADC8D786975 | SHA256:D5BB9724A36F5CBC3BA6B551F86157ADD5194B2BF1EAD6D15A6A203A282060D1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4080 | AnyDeskportable.exe | POST | 200 | 18.65.39.39:80 | http://api.playanext.com/httpapi | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4080 | AnyDeskportable.exe | 195.181.174.173:443 | boot.net.anydesk.com | Datacamp Limited | DE | unknown |
4080 | AnyDeskportable.exe | 138.199.36.120:443 | relay-aa05867a.net.anydesk.com | Datacamp Limited | DE | unknown |
4080 | AnyDeskportable.exe | 18.65.39.39:80 | api.playanext.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
boot.net.anydesk.com |
| unknown |
relay-aa05867a.net.anydesk.com |
| unknown |
api.playanext.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
4080 | AnyDeskportable.exe | Potential Corporate Privacy Violation | ET USER_AGENTS AnyDesk Remote Desktop Software User-Agent |