Detection rules › Sigma

Suspicious Binary Writes Via AnyDesk

Status
test
Severity
high
Log source
category file_event, product windows
Author
Nasreddine Bencherchali (Nextron Systems)
Source
github.com/SigmaHQ/sigma

Detects AnyDesk writing binary files to disk other than "gcapi.dll". According to RedCanary research it is highly abnormal for AnyDesk to write executable files to disk besides gcapi.dll, which is a legitimate DLL that is part of the Google Chrome web browser used to interact with the Google Cloud API. (See reference section for more details)

MITRE ATT&CK coverage

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 11: FileCreate

Rule body

title: Suspicious Binary Writes Via AnyDesk
id: 2d367498-5112-4ae5-a06a-96e7bc33a211
status: test
description: |
    Detects AnyDesk writing binary files to disk other than "gcapi.dll".
    According to RedCanary research it is highly abnormal for AnyDesk to write executable files to disk besides gcapi.dll,
    which is a legitimate DLL that is part of the Google Chrome web browser used to interact with the Google Cloud API. (See reference section for more details)
references:
    - https://redcanary.com/blog/misbehaving-rats/
    - https://thedfirreport.com/2025/02/24/confluence-exploit-leads-to-lockbit-ransomware/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-09-28
modified: 2025-02-24
tags:
    - attack.command-and-control
    - attack.t1219.002
logsource:
    product: windows
    category: file_event
detection:
    selection:
        Image|endswith:
            - '\AnyDesk.exe'
            - '\AnyDeskMSI.exe'
        TargetFilename|endswith:
            - '.dll'
            - '.exe'
    filter_dlls:
        TargetFilename|endswith: '\gcapi.dll'
    condition: selection and not 1 of filter_*
falsepositives:
    - Unknown
level: high

Stages and Predicates

Stage 0: condition

selection and not 1 of filter_*

Stage 1: selection

selection:
    Image|endswith:
        - '\AnyDesk.exe'
        - '\AnyDeskMSI.exe'
    TargetFilename|endswith:
        - '.dll'
        - '.exe'

Stage 2: not filter_dlls

filter_dlls:
    TargetFilename|endswith: '\gcapi.dll'

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
TargetFilenameends_with\gcapi.dllexcludes:TargetFilename field:"TargetFilename" value:"\gcapi.dll"

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
Imageends_with
  • \AnyDesk.exe corpus 5 (sigma 5)
  • \AnyDeskMSI.exe corpus 4 (sigma 4)
field:"Image" kind:ends_with
TargetFilenameends_with
  • .dll corpus 24 (sigma 24)
  • .exe corpus 21 (sigma 20, splunk 1)
field:"TargetFilename" kind:ends_with