Suspicious Binary Writes Via AnyDesk

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects AnyDesk writing binary files to disk other than "gcapi.dll". According to RedCanary research it is highly abnormal for AnyDesk to write executable files to disk besides gcapi.dll, which is a legitimate DLL that is part of the Google Chrome web browser used to interact with the Google Cloud API. (See reference section for more details)

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "File Created or Modified" AND (PROCESSNAME endswith "\AnyDesk.exe,\AnyDeskMSI.exe" AND (FILENAME endswith ".dll,.exe" OR OBJECTNAME endswith ".dll,.exe")) AND (FILENAME notendswith "\gcapi.dll" AND OBJECTNAME notendswith "\gcapi.dll") select Action1.HOSTNAME,Action1.MESSAGE,Action1.USERNAME,Action1.DOMAIN,Action1.OBJECTNAME,Action1.FILENAME,Action1.PROCESSNAME

Detection

Execution Mode

realtime

Log Sources

Windows

Author

Nasreddine Bencherchali (Nextron Systems)