
Reverse engineering write-up of Python shellcode that APC-injects into AnyDesk, exfiltrates to a C2 over HTTPS with AES/RSA, and persists via Registry GUID keys.
This x64dbg view reveals that the Python shellcode uses file operations (CreateFileW, DeleteFileA/W) and JMP trampolines to dynamically call Windows APIs.
CreateFileW – Creates or opens a file (payload drop).DeleteFileA / DeleteFileW – Deletes files (trace cleanup).DefineDosDeviceW – Defines a DOS device (drive manipulation).jmp qword ptr ds:[<API>] – dynamically resolves API addresses.INT3 (0xCC) – Anti-debug traps.C:\Users\dkaan\OneDrive\Desktop\output\shellcode.exe.
x64dbg view showing CreateFileW, DeleteFileA/W, and JMP trampolines.
This x64dbg view reveals that the Python shellcode calls GetCommandLineW to read command-line arguments, while using INT3 traps for anti-debugging.
jmp qword ptr ds:[<GetCommandLineW>] – JMP trampoline to GetCommandLineW.&"Sun" – A command-line argument string.mov [rsp+8], rbx, sub rsp, 0x20, xor ebx, ebx.test rdx, rdx, je kernel32.7FFBEC730A9.mov rdx, rsi, mov r8, rdi.GetCommandLineW at runtime.
x64dbg view showing GetCommandLineW, command-line parsing, and INT3 traps.
Process Hacker memory analysis reveals that the Python shellcode performs APC Injection into AnyDesk.exe and uses advanced cryptographic algorithms for data exfiltration.
AnyDesk.exe (PID 8064) – a legitimate remote desktop tool.AES for x86 / AES for Intel AES-NI – symmetric encryption.RSA for x86 – asymmetric encryption.SHA256 block transform – hashing.RC4 for x86 – stream cipher.Vector Permutation AES – SIMD-accelerated AES.GHASH for x86 – GCM authentication.Montgomery Multiplication – RSA acceleration.ECP_NISTZ256 for x86 – elliptic curve cryptography.CreateRemoteThread – no new thread is created.
Process Hacker view showing AnyDesk injection and cryptographic algorithms (AES, RSA, SHA256, RC4).
TCPView analysis reveals that the Python shellcode uses AnyDesk.exe to exfiltrate data to 141.227.178.79 over port 443 (HTTPS).
AnyDesk.exe (PID 5068) – legitimate remote desktop tool.141.227.178.79443 (HTTPS – blends with legitimate traffic).Established (active connection).
TCPView view showing AnyDesk.exe connecting to 141.227.178.79 over port 443.
Simplewall analysis reveals that although the Python shellcode attempts to exfiltrate data to 141.227.178.79 via port 443 (HTTPS) using AnyDesk.exe, it tries to establish a connection to another legitimate address (92.38.180.106) when blocked.
AnyDesk.exe (PID 5068) – legitimate remote desktop tool.92.38.180.106443 (HTTPS – blends with legitimate traffic).Blocked (blocked connection).
Simplewall wiew showing Anydesk.exe blocked to 92.38.180.106 over port 443.
Registry analysis reveals that the Python shellcode creates GUID-based keys under HKLM\SYSTEM\CurrentControlSet\Control\ for persistence.
{bf1a281b-ad7b-4476-ac95-f47682990ce7} – randomly generated GUIDs.GLOBALROOT\Device\HarddiskVolumeShadowCopy5\WINDOWS\system32\config\components.09 00 00 00 – architecture identifier.30 00 2e 00 30 00 2e 00 2e 00 36 00 – "0.0.0.6" in Unicode.