Report - AnyDesk_setup.exe

UPX PE32 PE File
ScreenShot
Created 2024.02.07 15:58 Machine s1_win7_x6401
Filename AnyDesk_setup.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score Not founds Behavior Score
5.4
ZERO API file : clean
VT API (file) 2 detected (Revoked, AnyDesk, Compromise, Detected)
md5 75eecc3a8b215c465f541643e9c4f484
sha256 ec33d8ee9c3881b8fcea18f9f862d5926d994553aec1b65081d925afd3e8b028
ssdeep 98304:j5ObAu2pmits24nYhQCWQdaQQo/mJPv4KYZPKBhYI5RuN4OL2wIjcsJWNg3:IAnRu24nR5QcTvYdmPuWOL2TcQWe3
imphash
impfuzzy 3::
  Network IP location

Signature (14cnts)

Level Description
watch A process attempted to delay the analysis task.
watch Attempts to remove evidence of file being downloaded from the Internet
watch Checks the CPU name from registry
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice Executes one or more WMI queries
notice File has been identified by 2 AntiVirus engines on VirusTotal as malicious
notice Queries for potentially installed applications
notice Searches running processes potentially to identify processes for sandbox evasion
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks amount of memory in system
info Queries for the computername
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info This executable has a PDB path

Rules (3cnts)

Level Name Description Collection
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
boot.net.anydesk.com LU G-Core Labs S.A. 92.223.88.41 clean
92.223.88.232 LU G-Core Labs S.A. 92.223.88.232 clean

Suricata ids

PE API

IAT(Import Address Table) is none

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure