| File name: | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe |
| Full analysis: | https://app.any.run/tasks/7de20ad4-220e-4ad4-9104-58e643f9985c |
| Verdict: | Malicious activity |
| Analysis date: | March 01, 2024, 03:23:38 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows |
| MD5: | 3BBD22C37F71BB9D66372685AB73F66B |
| SHA1: | 0DA51CF5721B43C96AD4BD4CF5C31BD6E07A715A |
| SHA256: | EE983D44583999A02C6A640AEA2AE5C3C15F081C34E5074B63733E3CC09B2BB0 |
| SSDEEP: | 196608:Rcm7ySzpChz1U5SuF/dT1CqiFxLNJ9JxBmLEBzP:OOAhzC5SuYlj9pmwBzP |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2023:11:18 00:33:44+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.29 |
| CodeSize: | 332288 |
| InitializedDataSize: | 20554240 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x424e0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.2.4.39 |
| ProductVersionNumber: | 1.2.4.39 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | com.carriez |
| FileDescription: | rustdesk |
| FileVersion: | 1.2.4+39 |
| InternalName: | rustdesk |
| LegalCopyright: | Copyright (C) 2023 com.carriez. All rights reserved. |
| OriginalFileName: | rustdesk.exe |
| ProductName: | rustdesk |
| ProductVersion: | 1.2.4+39 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 436 | cscript "C:\Users\admin\AppData\Local\Temp\RustDesk_tray_shortcut.vbs" | C:\Windows\System32\cscript.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Console Based Script Host Exit code: 0 Version: 5.812.10240.16384 Modules
| |||||||||||||||
| 728 | "C:\Users\admin\AppData\Local\rustdesk\.\rustdesk.exe" --install | C:\Users\admin\AppData\Local\rustdesk\rustdesk.exe | — | rustdesk.exe | |||||||||||
User: admin Company: com.carriez Integrity Level: MEDIUM Description: rustdesk Exit code: 3221225547 Version: 1.2.4+39 Modules
| |||||||||||||||
| 756 | "C:\Users\admin\AppData\Local\rustdesk\.\rustdesk.exe" | C:\Users\admin\AppData\Local\rustdesk\rustdesk.exe | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | ||||||||||||
User: admin Company: com.carriez Integrity Level: MEDIUM Description: rustdesk Exit code: 3221225547 Version: 1.2.4+39 Modules
| |||||||||||||||
| 780 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 876 | reg add HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\RustDesk /f /v UninstallString /t REG_SZ /d "\"C:\Program Files\RustDesk\RustDesk.exe\" --uninstall" | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 876 | reg add HKEY_CLASSES_ROOT\.rustdesk\shell\open\command /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1128 | reg add HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\RustDesk /f /v WindowsInstaller /t REG_DWORD /d 0 | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1128 | reg add HKEY_CLASSES_ROOT\rustdesk /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1156 | "taskkill" /F /IM RuntimeBroker_rustdesk.exe | C:\Windows\System32\taskkill.exe | — | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1304 | reg add HKEY_CLASSES_ROOT\rustdesk\shell\open\command /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (728) rustdesk.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (728) rustdesk.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (728) rustdesk.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (728) rustdesk.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (4176) reg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RustDesk |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\RustDesk\RustDesk.exe | |||
| (PID) Process: | (7064) reg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RustDesk |
| Operation: | write | Name: | DisplayName |
Value: RustDesk | |||
| (PID) Process: | (2604) reg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RustDesk |
| Operation: | write | Name: | DisplayVersion |
Value: 1.2.4 | |||
| (PID) Process: | (1972) reg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RustDesk |
| Operation: | write | Name: | Version |
Value: 1.2.4 | |||
| (PID) Process: | (6264) reg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RustDesk |
| Operation: | write | Name: | BuildDate |
Value: 2023-11-18 00:22 | |||
| (PID) Process: | (3024) reg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RustDesk |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\RustDesk | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5260 | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | C:\Users\admin\AppData\Local\rustdesk\data\app.so | — | |
MD5:— | SHA256:— | |||
| 5260 | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | C:\Users\admin\AppData\Local\rustdesk\desktop_drop_plugin.dll | executable | |
MD5:8285D6C3B2D89A68D6D52C3EECDED7CA | SHA256:09DB635DAA9DA7FC4A2AD070EE61331C0CAC5D1F6CB0DB4A5144149294F7D66B | |||
| 5260 | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | C:\Users\admin\AppData\Local\rustdesk\uni_links_desktop_plugin.dll | executable | |
MD5:98483A84CF654953BB248B47484CFA7B | SHA256:1C076CA22763FB20A45A288D441B29C70EE05739F2668EFB6AFB7E54CA4A1AFD | |||
| 5260 | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | C:\Users\admin\AppData\Local\rustdesk\flutter_custom_cursor_plugin.dll | executable | |
MD5:D3FECEA627CDA20B3A969807B55F2784 | SHA256:96A3CC71D828D36CE76EA5CAB03B7B4DA7F482CB306373A6859BF6304712638E | |||
| 5260 | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | C:\Users\admin\AppData\Local\rustdesk\data\flutter_assets\AssetManifest.bin | binary | |
MD5:002B5638865D866FA93C2A3AD176B5D1 | SHA256:717CE6C1E49FA785974D3D59E53DF492F61112D3339B1A955C46856D0F845250 | |||
| 5260 | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | C:\Users\admin\AppData\Local\rustdesk\data\flutter_assets\AssetManifest.json | binary | |
MD5:1C8250AFB2523DCD4EC6728D7CA964CD | SHA256:337AB8D87321626E87F273F973E7E0ED35A621D727178ABF9940035CB869EC12 | |||
| 5260 | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | C:\Users\admin\AppData\Local\rustdesk\data\icudtl.dat | binary | |
MD5:CF772CF9F6CA67F592FE47DA2A15ADB1 | SHA256:AC44CCC3F61BF630BB20FB8043D86CFE4C8995D06B460084400DB45D70497B30 | |||
| 5260 | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | C:\Users\admin\AppData\Local\rustdesk\window_size_plugin.dll | executable | |
MD5:B1E5D49FABDE0E019B2D2D1DEAA702E0 | SHA256:1AD1A842D900EFEF7BE22CC30960056EBACA4981A028058CF30998A76730DD53 | |||
| 5260 | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | C:\Users\admin\AppData\Local\rustdesk\screen_retriever_plugin.dll | executable | |
MD5:67CB40E2637E41B519D1619BE3D6B462 | SHA256:3C537768F16F344A141687DE39BB91BD05B71FFEF2D2A3E03345F44311813E3A | |||
| 5260 | ee983d44583999a02c6a640aea2ae5c3c15f081c34e5074b63733e3cc09b2bb0.exe | C:\Users\admin\AppData\Local\rustdesk\desktop_multi_window_plugin.dll | executable | |
MD5:721CB805D53C7477589E4C34C4BB1B78 | SHA256:A6D554CFBA31D9519C2A1631D51C9637FB9924266A7A91E6C990722ADC0C873E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5928 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | binary | 471 b | unknown |
5444 | svchost.exe | GET | 200 | 2.16.164.49:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | binary | 1.01 Kb | unknown |
884 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D | unknown | binary | 471 b | unknown |
2464 | svchost.exe | GET | 200 | 2.19.105.18:80 | http://x1.c.lencr.org/ | unknown | binary | 717 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5444 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6896 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5928 | svchost.exe | 20.190.160.17:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3848 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
5928 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
756 | rustdesk.exe | 108.61.171.103:21116 | rs-ny.rustdesk.com | AS-CHOOPA | DE | unknown |
756 | rustdesk.exe | 108.61.171.103:21115 | rs-ny.rustdesk.com | AS-CHOOPA | DE | unknown |
5444 | svchost.exe | 2.16.164.49:80 | crl.microsoft.com | Akamai International B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
rs-ny.rustdesk.com |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
github.com |
| shared |
www.bing.com |
| whitelisted |
arc.msn.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2136 | svchost.exe | Misc activity | ET INFO RustDesk Domain in DNS Lookup |
2136 | svchost.exe | Misc activity | ET INFO RustDesk Relay Domain in DNS Lookup |
756 | rustdesk.exe | Misc activity | ET INFO RustDesk Register Public Key |