File name:

AnyDeskportable.exe

Full analysis: https://app.any.run/tasks/22210ee9-7a1a-4ea7-901d-887358266ca0
Verdict: Malicious activity
Analysis date: May 03, 2024, 13:13:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

37E172BE64B12F3207300D11B74656B8

SHA1:

1895D7C4F785F92E48B5191FD812822593CBC73F

SHA256:

BC747E3BF7B6E02C09F3D18BDD0E64EEF62B940B2F16C9C72E647EEC85CF0138

SSDEEP:

98304:JUTRUa7PCXSORUNi9RLzauQ3GPeYXiqKVZeTKcvNS/iWSi4oN9+mMSGmyDpR60WJ:R7InM1zcV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AnyDeskportable.exe (PID: 3968)
      • AnyDeskportable.exe (PID: 4080)
  • SUSPICIOUS

    • Found AnyDesk certificate that may have been compromised

      • AnyDeskportable.exe (PID: 3968)
      • AnyDeskportable.exe (PID: 4088)
      • AnyDeskportable.exe (PID: 4080)
      • AnyDeskportable.exe (PID: 2312)
    • Application launched itself

      • AnyDeskportable.exe (PID: 3968)
      • AnyDeskportable.exe (PID: 4088)
    • Reads the Internet Settings

      • AnyDeskportable.exe (PID: 4088)
    • Executable content was dropped or overwritten

      • AnyDeskportable.exe (PID: 4080)
    • Potential Corporate Privacy Violation

      • AnyDeskportable.exe (PID: 4080)
  • INFO

    • Checks supported languages

      • AnyDeskportable.exe (PID: 3968)
      • AnyDeskportable.exe (PID: 4088)
      • AnyDeskportable.exe (PID: 4080)
      • wmpnscfg.exe (PID: 1112)
      • AnyDeskportable.exe (PID: 2312)
    • Reads the computer name

      • AnyDeskportable.exe (PID: 3968)
      • AnyDeskportable.exe (PID: 4088)
      • AnyDeskportable.exe (PID: 4080)
      • wmpnscfg.exe (PID: 1112)
      • AnyDeskportable.exe (PID: 2312)
    • Creates files or folders in the user directory

      • AnyDeskportable.exe (PID: 3968)
    • Reads the machine GUID from the registry

      • AnyDeskportable.exe (PID: 3968)
      • AnyDeskportable.exe (PID: 4080)
      • AnyDeskportable.exe (PID: 2312)
    • Process checks whether UAC notifications are on

      • AnyDeskportable.exe (PID: 3968)
    • Reads CPU info

      • AnyDeskportable.exe (PID: 3968)
      • AnyDeskportable.exe (PID: 2312)
    • Process checks computer location settings

      • AnyDeskportable.exe (PID: 4088)
      • AnyDeskportable.exe (PID: 4080)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:09:22 08:14:12+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 10752
InitializedDataSize: 5457408
UninitializedDataSize: 19262976
EntryPoint: 0x1ce5
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 8.0.3.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: AnyDesk Software GmbH
FileDescription: AnyDesk
FileVersion: 8.0.3
ProductName: AnyDesk
ProductVersion: 8
LegalCopyright: (C) 2022 AnyDesk Software GmbH
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
5
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start anydeskportable.exe no specs anydeskportable.exe anydeskportable.exe no specs wmpnscfg.exe no specs anydeskportable.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1112"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2312"C:\Users\admin\Desktop\AnyDeskportable.exe" C:\Users\admin\Desktop\AnyDeskportable.exeAnyDeskportable.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Version:
8.0.3
Modules
Images
c:\users\admin\desktop\anydeskportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3968"C:\Users\admin\Desktop\AnyDeskportable.exe" C:\Users\admin\Desktop\AnyDeskportable.exeexplorer.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Version:
8.0.3
Modules
Images
c:\users\admin\desktop\anydeskportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
4080"C:\Users\admin\Desktop\AnyDeskportable.exe" --local-serviceC:\Users\admin\Desktop\AnyDeskportable.exe
AnyDeskportable.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Version:
8.0.3
Modules
Images
c:\users\admin\desktop\anydeskportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
4088"C:\Users\admin\Desktop\AnyDeskportable.exe" --local-controlC:\Users\admin\Desktop\AnyDeskportable.exeAnyDeskportable.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Version:
8.0.3
Modules
Images
c:\users\admin\desktop\anydeskportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 549
Read events
1 549
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
3
Text files
3
Unknown types
1

Dropped files

PID
Process
Filename
Type
3968AnyDeskportable.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\455ENCVY7OQIRPXFNK8P.temp
MD5:
SHA256:
3968AnyDeskportable.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-msbinary
MD5:A363F61E638D33C1BDC83ADC8D786975
SHA256:D5BB9724A36F5CBC3BA6B551F86157ADD5194B2BF1EAD6D15A6A203A282060D1
4080AnyDeskportable.exeC:\Users\admin\AppData\Roaming\AnyDesk\system.conftext
MD5:0C04AD1083DC5C7C45E3EE2CD344AE38
SHA256:6452273C017DB7CBE0FFC5B109BBF3F8D3282FB91BFA3C5EABC4FB8F1FC98CB0
4080AnyDeskportable.exeC:\Users\admin\Desktop\gcapi.dllexecutable
MD5:1CE7D5A1566C8C449D0F6772A8C27900
SHA256:73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF
4080AnyDeskportable.exeC:\Users\admin\AppData\Local\Temp\gcapi.dllexecutable
MD5:1CE7D5A1566C8C449D0F6772A8C27900
SHA256:73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF
4080AnyDeskportable.exeC:\Users\admin\AppData\Roaming\AnyDesk\service.conftext
MD5:2846F0FB9B383E9726B62046BBD540F4
SHA256:0F93F6FCC224227FB4EF594D92ECA9A1A2C868AE7BED2D8FCCCBF10FF14C2CF7
3968AnyDeskportable.exeC:\Users\admin\AppData\Roaming\AnyDesk\user.conftext
MD5:A787C308BD30D6D844E711D7579BE552
SHA256:8A395011A6A877D3BDD53CC8688EF146160DAB9D42140EB4A70716AD4293A440
2312AnyDeskportable.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-ms~RF106eb9.TMPbinary
MD5:A363F61E638D33C1BDC83ADC8D786975
SHA256:D5BB9724A36F5CBC3BA6B551F86157ADD5194B2BF1EAD6D15A6A203A282060D1
2312AnyDeskportable.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\81M0NWAP9N5R6H9NOOOE.tempbinary
MD5:A363F61E638D33C1BDC83ADC8D786975
SHA256:D5BB9724A36F5CBC3BA6B551F86157ADD5194B2BF1EAD6D15A6A203A282060D1
2312AnyDeskportable.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-msbinary
MD5:A363F61E638D33C1BDC83ADC8D786975
SHA256:D5BB9724A36F5CBC3BA6B551F86157ADD5194B2BF1EAD6D15A6A203A282060D1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
3
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4080
AnyDeskportable.exe
POST
200
18.65.39.39:80
http://api.playanext.com/httpapi
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4080
AnyDeskportable.exe
195.181.174.173:443
boot.net.anydesk.com
Datacamp Limited
DE
unknown
4080
AnyDeskportable.exe
138.199.36.120:443
relay-aa05867a.net.anydesk.com
Datacamp Limited
DE
unknown
4080
AnyDeskportable.exe
18.65.39.39:80
api.playanext.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
boot.net.anydesk.com
  • 195.181.174.173
unknown
relay-aa05867a.net.anydesk.com
  • 138.199.36.120
unknown
api.playanext.com
  • 18.65.39.59
  • 18.65.39.42
  • 18.65.39.23
  • 18.65.39.39
whitelisted

Threats

PID
Process
Class
Message
4080
AnyDeskportable.exe
Potential Corporate Privacy Violation
ET USER_AGENTS AnyDesk Remote Desktop Software User-Agent
No debug info