File name:

AnyDesk.exe

Full analysis: https://app.any.run/tasks/9985f1d9-40f9-48d7-b604-5d15caebd526
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: January 15, 2024, 14:54:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

75EECC3A8B215C465F541643E9C4F484

SHA1:

3AD1F800B63640128BFDCC8DBEE909554465EE11

SHA256:

EC33D8EE9C3881B8FCEA18F9F862D5926D994553AEC1B65081D925AFD3E8B028

SSDEEP:

98304:xEhZCn2N8X+7A2qiwQPq5jGbmUX4j98EjlWipPUQAD0hrKKnpdZYki3qe3Bv9PRi:uPqKJ1K/rSOr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AnyDesk.exe (PID: 2124)
      • AnyDesk.exe (PID: 1792)
      • AnyDesk.exe (PID: 2312)
    • Create files in the Startup directory

      • AnyDesk.exe (PID: 1792)
  • SUSPICIOUS

    • Reads the Internet Settings

      • AnyDesk.exe (PID: 2032)
      • AnyDesk.exe (PID: 2124)
      • AnyDesk.exe (PID: 2636)
      • sipnotify.exe (PID: 1764)
      • AnyDesk.exe (PID: 2088)
    • Application launched itself

      • AnyDesk.exe (PID: 2124)
      • AnyDesk.exe (PID: 2312)
    • Executable content was dropped or overwritten

      • AnyDesk.exe (PID: 1792)
      • AnyDesk.exe (PID: 2312)
    • Searches for installed software

      • AnyDesk.exe (PID: 2636)
      • AnyDesk.exe (PID: 2312)
      • AnyDesk.exe (PID: 2632)
      • AnyDesk.exe (PID: 1556)
      • AnyDesk.exe (PID: 2088)
    • Executes as Windows Service

      • AnyDesk.exe (PID: 2312)
    • Creates a software uninstall entry

      • AnyDesk.exe (PID: 2312)
    • Connects to unusual port

      • AnyDesk.exe (PID: 2312)
    • The process executes via Task Scheduler

      • ctfmon.exe (PID: 1748)
      • sipnotify.exe (PID: 1764)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1764)
  • INFO

    • Reads the machine GUID from the registry

      • AnyDesk.exe (PID: 2124)
      • AnyDesk.exe (PID: 296)
      • AnyDesk.exe (PID: 1792)
      • AnyDesk.exe (PID: 2312)
      • AnyDesk.exe (PID: 2632)
    • Creates files or folders in the user directory

      • AnyDesk.exe (PID: 2124)
    • Reads the computer name

      • AnyDesk.exe (PID: 2124)
      • AnyDesk.exe (PID: 2032)
      • AnyDesk.exe (PID: 296)
      • AnyDesk.exe (PID: 1792)
      • AnyDesk.exe (PID: 2312)
      • AnyDesk.exe (PID: 2636)
      • AnyDesk.exe (PID: 1556)
      • AnyDesk.exe (PID: 2632)
      • IMEKLMG.EXE (PID: 2052)
      • IMEKLMG.EXE (PID: 1108)
      • AnyDesk.exe (PID: 2088)
      • wmpnscfg.exe (PID: 2552)
      • wmpnscfg.exe (PID: 2572)
    • Process checks whether UAC notifications are on

      • AnyDesk.exe (PID: 2124)
      • IMEKLMG.EXE (PID: 1108)
      • IMEKLMG.EXE (PID: 2052)
    • Checks supported languages

      • AnyDesk.exe (PID: 2124)
      • AnyDesk.exe (PID: 2032)
      • AnyDesk.exe (PID: 296)
      • AnyDesk.exe (PID: 1792)
      • AnyDesk.exe (PID: 2312)
      • AnyDesk.exe (PID: 2636)
      • AnyDesk.exe (PID: 2632)
      • AnyDesk.exe (PID: 1556)
      • IMEKLMG.EXE (PID: 1108)
      • AnyDesk.exe (PID: 2088)
      • wmpnscfg.exe (PID: 2552)
      • IMEKLMG.EXE (PID: 2052)
      • wmpnscfg.exe (PID: 2572)
    • Reads CPU info

      • AnyDesk.exe (PID: 2124)
      • AnyDesk.exe (PID: 2632)
    • Creates files in the program directory

      • AnyDesk.exe (PID: 1792)
      • AnyDesk.exe (PID: 2312)
    • Manual execution by a user

      • AnyDesk.exe (PID: 2636)
      • AnyDesk.exe (PID: 2632)
      • IMEKLMG.EXE (PID: 1108)
      • IMEKLMG.EXE (PID: 2052)
      • AnyDesk.exe (PID: 2088)
      • wmpnscfg.exe (PID: 2552)
      • wmpnscfg.exe (PID: 2572)
    • Process checks computer location settings

      • AnyDesk.exe (PID: 2312)
      • AnyDesk.exe (PID: 2636)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1764)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:09 08:48:10+01:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 10752
InitializedDataSize: 5496832
UninitializedDataSize: 19445760
EntryPoint: 0x1ce5
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 8.0.6.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: AnyDesk Software GmbH
FileDescription: AnyDesk
FileVersion: 8.0.6
ProductName: AnyDesk
ProductVersion: 8
LegalCopyright: (C) 2022 AnyDesk Software GmbH
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
101
Monitored processes
15
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start anydesk.exe no specs anydesk.exe anydesk.exe anydesk.exe anydesk.exe anydesk.exe no specs anydesk.exe no specs anydesk.exe no specs ctfmon.exe no specs sipnotify.exe imeklmg.exe no specs imeklmg.exe no specs anydesk.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
296"C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" --local-serviceC:\Users\admin\AppData\Local\Temp\AnyDesk.exe
AnyDesk.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
9099
Version:
8.0.6
Modules
Images
c:\users\admin\appdata\local\temp\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1108"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
1556"C:\Program Files\AnyDesk\AnyDesk.exe" --backendC:\Program Files\AnyDesk\AnyDesk.exeAnyDesk.exe
User:
SYSTEM
Company:
AnyDesk Software GmbH
Integrity Level:
SYSTEM
Description:
AnyDesk
Exit code:
1073807364
Version:
8.0.6
Modules
Images
c:\program files\anydesk\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1748C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
1073807364
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1764C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1792"C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" --install "C:\Program Files\AnyDesk" --start-with-win --create-shortcuts --create-taskbar-icon --create-desktop-icon --install-driver:mirror --update-main --svc-conf "C:\Users\admin\AppData\Roaming\AnyDesk\service.conf" --sys-conf "C:\Users\admin\AppData\Roaming\AnyDesk\system.conf" C:\Users\admin\AppData\Local\Temp\AnyDesk.exe
AnyDesk.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
HIGH
Description:
AnyDesk
Exit code:
0
Version:
8.0.6
Modules
Images
c:\users\admin\appdata\local\temp\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2032"C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" --local-controlC:\Users\admin\AppData\Local\Temp\AnyDesk.exe
AnyDesk.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
9099
Version:
8.0.6
Modules
Images
c:\users\admin\appdata\local\temp\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2052"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2088"C:\Program Files\AnyDesk\AnyDesk.exe" --controlC:\Program Files\AnyDesk\AnyDesk.exeexplorer.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
1073807364
Version:
8.0.6
Modules
Images
c:\program files\anydesk\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2124"C:\Users\admin\AppData\Local\Temp\AnyDesk.exe" C:\Users\admin\AppData\Local\Temp\AnyDesk.exeexplorer.exe
User:
admin
Company:
AnyDesk Software GmbH
Integrity Level:
MEDIUM
Description:
AnyDesk
Exit code:
9099
Version:
8.0.6
Modules
Images
c:\users\admin\appdata\local\temp\anydesk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
7 035
Read events
6 994
Write events
39
Delete events
2

Modification events

(PID) Process:(2124) AnyDesk.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2124) AnyDesk.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2124) AnyDesk.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2124) AnyDesk.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1792) AnyDesk.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
(PID) Process:(2312) AnyDesk.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AnyDesk
Operation:writeName:DisplayName
Value:
AnyDesk
(PID) Process:(2312) AnyDesk.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AnyDesk
Operation:writeName:DisplayVersion
Value:
ad 8.0.6
(PID) Process:(2312) AnyDesk.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AnyDesk
Operation:writeName:VersionMajor
Value:
8
(PID) Process:(2312) AnyDesk.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AnyDesk
Operation:writeName:VersionMinor
Value:
0
(PID) Process:(2312) AnyDesk.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AnyDesk
Operation:writeName:VersionBuild
Value:
6
Executable files
3
Suspicious files
11
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
2124AnyDesk.exeC:\Users\admin\AppData\Roaming\AnyDesk\user.conftext
MD5:A787C308BD30D6D844E711D7579BE552
SHA256:8A395011A6A877D3BDD53CC8688EF146160DAB9D42140EB4A70716AD4293A440
2632AnyDesk.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z4HAQLDSXUM0FWI41JX2.tempbinary
MD5:D1F8F3D40F06752D830D96EFBC53D90C
SHA256:DC1F7C4E1B8D9FE653FC04BF2929E46C774BDD20EE93541565B2C32776EB28EB
1792AnyDesk.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnkbinary
MD5:28241ECDA4B751506BAB46F464E15EB3
SHA256:A2BA145749096CA687B31EB3C124CE750B0D4641FA2295DB4E2AFCC07E87E92B
1792AnyDesk.exeC:\Users\Public\Desktop\AnyDesk.lnkbinary
MD5:194A068C55161D7865B005F1895ED20D
SHA256:52FE275312E468CF27DF546316B4571DA5CC91D3A83B04C84FE7B46976D4FCC1
2632AnyDesk.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\75fdacd8330bac18.customDestinations-msbinary
MD5:D1F8F3D40F06752D830D96EFBC53D90C
SHA256:DC1F7C4E1B8D9FE653FC04BF2929E46C774BDD20EE93541565B2C32776EB28EB
1792AnyDesk.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyDesk\AnyDesk.lnkbinary
MD5:90A8411F306DEC9621A9D0C7F53B8DF0
SHA256:E3F5B5D650E15EFC62F95209A21108E238037161EDFFBA3CDC8EF96170ED2A94
1792AnyDesk.exeC:\ProgramData\AnyDesk\service.conftext
MD5:490B013AEAB112846015281830529556
SHA256:56268DD14DBC5A7A38876CB5344BF4D0033372000C689F8A3380E00B525279BC
2312AnyDesk.exeC:\Windows\TEMP\gcapi.dllexecutable
MD5:1CE7D5A1566C8C449D0F6772A8C27900
SHA256:73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF
2312AnyDesk.exeC:\Program Files\AnyDesk\gcapi.dllexecutable
MD5:1CE7D5A1566C8C449D0F6772A8C27900
SHA256:73170761D6776C0DEBACFBBC61B6988CB8270A20174BF5C049768A264BB8FFAF
296AnyDesk.exeC:\Users\admin\AppData\Roaming\AnyDesk\service.conftext
MD5:3A28981B92FC7DFE2FDB8720BEE97BFA
SHA256:9AEB5E691879BAFC8475F9181BD34A4F98C2C346573E61F06427EE1E9338DABE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
124
DNS requests
8
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1764
sipnotify.exe
HEAD
200
88.221.61.151:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133498042681400000
unknown
unknown
2312
AnyDesk.exe
POST
200
18.66.27.89:80
http://api.playanext.com/httpapi
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
296
AnyDesk.exe
57.128.101.74:443
boot.net.anydesk.com
OVH SAS
FR
unknown
296
AnyDesk.exe
57.128.101.74:80
boot.net.anydesk.com
OVH SAS
FR
unknown
296
AnyDesk.exe
51.195.5.155:443
relay-68e3532c.net.anydesk.com
OVH SAS
FR
unknown
2312
AnyDesk.exe
51.195.5.155:443
relay-68e3532c.net.anydesk.com
OVH SAS
FR
unknown
2312
AnyDesk.exe
51.195.5.155:80
relay-68e3532c.net.anydesk.com
OVH SAS
FR
unknown
2312
AnyDesk.exe
138.199.36.118:443
relay-bc82c04d.net.anydesk.com
Datacamp Limited
DE
unknown
2312
AnyDesk.exe
239.255.102.18:50001
unknown

DNS requests

Domain
IP
Reputation
boot.net.anydesk.com
  • 57.128.101.74
unknown
relay-68e3532c.net.anydesk.com
  • 51.195.5.155
unknown
relay-bc82c04d.net.anydesk.com
  • 138.199.36.118
unknown
api.playanext.com
  • 18.66.27.22
  • 18.66.27.44
  • 18.66.27.83
  • 18.66.27.89
whitelisted
query.prod.cms.rt.microsoft.com
  • 88.221.61.151
whitelisted

Threats

PID
Process
Class
Message
296
AnyDesk.exe
Misc activity
ET POLICY SSL/TLS Certificate Observed (AnyDesk Remote Desktop Software)
2312
AnyDesk.exe
Potential Corporate Privacy Violation
ET USER_AGENTS AnyDesk Remote Desktop Software User-Agent
Process
Message
AnyDesk.exe
AnyDesk: Mutex broken!