#ANYRUN
November 19, 2025 at 10:37 AM
hyprland. quite nice!!
#unixporn #archlinux
December 1, 2024 at 1:11 AM
"Play Ransomware" published by AnyRun. #Play, #DPRK, #CTI https://any.run/malware-trends/play/
February 10, 2025 at 1:30 PM
(Sharing in collab with AnyRun)
Using AnyRun, I was able to run this PERFECTLY NORMAL WeChat Installer:
0/69 VT score, Signed by "Commander Software Solutions Oy"
While running it, it required me to complete a captcha and also install .NET runtime.
1/2
November 24, 2024 at 11:01 PM
~Anyrun~
Phishing exposure reaches 69.9% across five US industries, increasingly targeting credentials, sessions, and tokens.
-
IOCs: Tycoon, Sneaky2FA, EvilProxy
-
#IdentityAttack #Phishing #ThreatIntel
US Industry Phishing Risk
any.run
September 23, 2026 at 4:01 PM
Anyrun
December 20, 2024 at 10:40 PM
Mastering Malware Analysis: A SOC Analyst’s Guide to Dynamic Analysis with AnyRun
Mastering Malware Analysis: A SOC Analyst’s Guide to Dynamic Analysis with AnyRun
Introduction As an SOC analyst, I’ll guide you through a dynamic malware analysis using AnyRun. In this article, we’ll cover how to leverage AnyRun’s interactive sandbox to analyze a malicious file, explore its behavior, and interpret key outputs. Learn step-by-step how to upload malware, navigate the platform, and uncover critical insights to bolster your cybersecurity defenses. You can take advantage of sandbox services/products to quickly analyze malware. AnyRun is an interactive sandbox that you can use when you want to analyze malware quickly. AnyRun has options for paid or free use. If you want to take advantage of it for free, all your analysis is visible to others; therefore, we do not recommend that you upload files that may contain personal data to AnyRun. Additionally, the free plan has limitations, including a time restriction on usage. How can we use AnyRun for our malware analysis? What kind of outputs can we get? Let’s examine it together. Let’s download the malware with hash 80b51e872031a2befeb9a0a13e6fc480 to analyze via AbuseCH (Click here to download) . We have to click on the “ + ” (New Task) button on the left menu to upload the malware we downloaded. You can take advantage of sandbox services/products to quickly analyze malware. AnyRun is an interactive sandbox that you can use when you want to analyze malware quickly. AnyRun has options for paid or free use. If you want to take advantage of it for free, all your analysis is visible to others; therefore, we do not recommend that you upload files that may contain personal data to AnyRun. Additionally, the free plan has usage time restrictions. How can we use AnyRun for our malware analysis? What kind of outputs can we get? Let’s examine it together. Let’s download the malware with hash 80b51e872031a2befeb9a0a13e6fc480 to analyze via AbuseCH (Click here to download) . We have to click on the “ + ” (New Task) button on the left menu to upload the malware we downloaded. You can take advantage of sandbox services / products to quickly analyze malware. AnyRun is an interactive sandbox that you can use when you want to analyze malware quickly. AnyRun has options for paid or free use. If you want to take advantage of it for free, all your analysis is visible to others; therefore, we do not recommend that you upload files that may contain personal data to AnyRun. Additionally, the free plan has usage time restrictions. How can we use AnyRun for our malware analysis? What kind of outputs can we get? Let’s examine it together. Let’s download the malware with hash 80b51e872031a2befeb9a0a13e6fc480 to analyze via AbuseCH (Click here to download) . We have to click on the “ + ” (New Task) button on the left menu to upload the malware we downloaded. he malware is in the section marked “2” in the image above. You can take advantage of sandbox services/products to quickly analyze malware. AnyRun is an interactive sandbox that you can use when you want to analyze malware quickly. AnyRun has options for paid or free use. If you want to take advantage of it for free, all your analysis is visible to others; therefore, we do not recommend that you upload files that may contain personal data to AnyRun. In addition, the free plan has restrictions such as usage time. How can we use AnyRun for our malware analysis? what kind of outputs can we get? Let’s examine it together. Let’s download the malware with hash 80b51e872031a2befeb9a0a13e6fc480 to analyze via AbuseCH (Click here to download) . We have to click on the “ + ” (New Task) button on the left menu to upload the malware we downloaded. With the “ More Info ” button on this panel, a page with detailed information about the process is opened. When we want to reach detailed information, we can use this section. When the process information with 2680 ID is examined, the malware: Uses Task Scheduler, Writes a program to the file system whose compilation time is too old, Writes many files to the user directory When we examine the process with ID 2616 , we see that it is schtasks.exe belonging to Task Scheduler . When we examine the “ Command Line ” parameters, we see that it creates a scheduled task named “ Updates\neHneiobyhcrJJ ”. The configurations for this schedule task are in the file “ tmp5383.tmp ”. When we examine the scheduled task configuration file named tmp5383.tmp , we see that the program named “ neHneiobyhcrJJ.exe ” will run. When we examine the process with ID  3140 : This malware is recognized by AnyRun as AgentTesla . Steals credentials, Creating files in the user directory When we examine the network connections made from panel number 3, we see that malware connects to smtp.godforeu.com . With the help of the button on the right of the panel, we can examine the incoming/outgoing data. When the network activities of the malware are examined, we find that the malware exfiltrates data with the SMTP protocol. If you want to examine, you can reach the analysis made here (Click here) . Mastering Malware Analysis: A SOC Analyst’s Guide to Dynamic Analysis with AnyRun was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
infosecwriteups.com
June 25, 2025 at 10:32 AM
~Anyrun~
CSuite uses device-code phishing and legitimate RMM tools to hijack Microsoft 365 sessions and remotely access US and EU organizations.
-
IOCs: maillive[.]sbs, 207[.]189[.]19[.]40:26688, gddfzxa[.]online
-
#Phishing #RemoteAccess #ThreatIntel
CSuite Phishing Operation
any.run
September 22, 2026 at 12:34 PM
2025-01-09 (Thursday): Now this is more like it! Real #malspam with real #malware. Even if the infection traffic looks like it's an #Matiex or #SnakeLogger or #AgentTesla variant that exfiltrates data through api.telegram[.]org.

#AnyRun analysis of the malware EXE at: app.any.run/tasks/8ffd01...
January 9, 2025 at 5:14 AM
🐧 **Anyrun – Wayland-native application launcher**

Anyrun is a Wayland-native application launcher inspired by KRunner. It offers a highly extensible plugin architecture The post Anyrun – Wayland-native application launcher appeared first on LinuxL...

📰 Source: LinuxLinks
🔗 Link […]
Original post on igeek.gamer-geek-news.com
igeek.gamer-geek-news.com
August 9, 2026 at 5:42 PM
Some other launchers that are promising are: vicinae, gauntlet, anyrun, sherlock, raycast-linux

But none of them are quite there yet
August 22, 2025 at 8:26 PM
"Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup" published by AnyRun. #ITWorker, #FamousChollima https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two
Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup
any.run
August 10, 2026 at 11:26 PM
www.reddit.com/r/cybersecur...

From the anyrun team:
From the cybersecurity community on Reddit
Explore this post and more from the cybersecurity community
www.reddit.com
April 25, 2025 at 1:32 PM
"In this article, we’ll uncover an entire North Korean infiltration operation aimed at deploying remote IT workers across different companies in the American financial and crypto/Web3 sectors, with the objective of conducting corporate espionage and generating funding".

medium.com/@anyrun/smil...
Smile, You’re on Camera: A Live Stream from Inside Lazarus Group’s IT Workers Scheme
See how a North Korean IT worker scheme was exposed using real-time monitoring inside ANY.RUN’s sandbox.
medium.com
August 26, 2026 at 10:43 AM
Researchers from BCA Ltd, NorthScan & Anyrun set a trap for Lazarus Group’s Famous Chollima team(North Korean hackers) got caught live.
thehackernews.com/2025/12/rese...
December 2, 2025 at 7:51 PM
"How We Caught Lazarus's IT Workers Scheme Live on Camera" published by AnyRun. #ITWorker, #FamousChollima, #DPRK, #CTI https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/
December 4, 2025 at 5:30 PM
5. Hudsonrock [ Filtrado ]

www.hudsonrock.com/threat-intel...

6. AbuseIPdb [ Comprobar IP ]

abuseipdb.com

7. Anyrun [ Reportes Ataques ]

app.any.run

8. BgpTools [ ASN / DNS ]

bgp.tools

9. Archiveorg [ Histórico Web ]

archive.org
https://hudsonrock.com/threat-intelli…
April 26, 2025 at 6:45 AM
~Anyrun~
Fake tax and document lures deliver signed RMM tools for hands-on access.
-
IOCs: fillingconfirmation[.]vercel[.]app, docshared[.]org, dashboarduat[.]paynnow[.]com
-
#Phishing #RMM #ThreatIntel
46-Country RMM Phishing Campaign
any.run
August 29, 2026 at 1:11 PM
MB: bazaar.abuse.ch/samp...

AnyRun: app.any.run/tasks/4a...

Triage: tria.ge/260126-wxm1j...

Thanks to everyone who has volunteered analyzing files, making submissions, or used the database.

Special thanks to @anyrun_app for a sandbox that is easy to use and review.
2/2
January 26, 2026 at 6:43 PM
🚨North Korean Hackers Tricked by Fake Remote-Work Laptops

North Korean operators were caught in real time after researchers from BCA LTD, NorthScan, and ANYRUN lured Lazarus Group’s Famous Chollima team with fake remote-work laptops.
December 3, 2025 at 6:40 AM