Suspicious Binary Writes Via AnyDesk

 Original Source: [Sigma source]
Title: Suspicious Binary Writes Via AnyDesk
Status: test
Description:Detects AnyDesk writing binary files to disk other than "gcapi.dll". According to RedCanary research it is highly abnormal for AnyDesk to write executable files to disk besides gcapi.dll, which is a legitimate DLL that is part of the Google Chrome web browser used to interact with the Google Cloud API. (See reference section for more details)
References:
  -https://redcanary.com/blog/misbehaving-rats/
  -https://thedfirreport.com/2025/02/24/confluence-exploit-leads-to-lockbit-ransomware/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-28
modified:2025-02-24
Tags:
  • -'attack.command-and-control'
  • -'attack.t1219.002'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith:
      -'\AnyDesk.exe'
      -'\AnyDeskMSI.exe'

    TargetFilename|endswith:
      -'.dll'
      -'.exe'

  filter_dlls:
    TargetFilename|endswith: '\gcapi.dll'
  condition:selection and not 1 of filter_*
Falsepositives:
  -Unknown
Level: high