Suspicious Binary Writes Via AnyDesk
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects AnyDesk writing binary files to disk other than "gcapi.dll". According to RedCanary research it is highly abnormal for AnyDesk to write executable files to disk besides gcapi.dll, which is a legitimate DLL that is part of the Google Chrome web browser used to interact with the Google Cloud API. (See reference section for more details)
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "File Created or Modified" AND (PROCESSNAME endswith "\AnyDesk.exe,\AnyDeskMSI.exe" AND (FILENAME endswith ".dll,.exe" OR OBJECTNAME endswith ".dll,.exe")) AND (FILENAME notendswith "\gcapi.dll" AND OBJECTNAME notendswith "\gcapi.dll") select Action1.HOSTNAME,Action1.MESSAGE,Action1.USERNAME,Action1.DOMAIN,Action1.OBJECTNAME,Action1.FILENAME,Action1.PROCESSNAME
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Nasreddine Bencherchali (Nextron Systems)


