File name:

stunnel-5.75-win64-installer.exe

Full analysis: https://app.any.run/tasks/0faf2f4d-6108-4bea-9503-669a78a40e62
Verdict: Malicious activity
Analysis date: June 06, 2025, 16:35:31
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, Nullsoft Installer self-extracting archive, 7 sections
MD5:

68E4F6C658A643317A70CDF1AEAC8E43

SHA1:

EC7544C66CB17F1B3B78B628FF236444E426DDCE

SHA256:

18EC3B83BDA9143C79479ECDC1E3ECF515EEB8A8B11E6EA3A6856CD77399317D

SSDEEP:

98304:bpYkX6yyppWPoWP6RGchxt0e5Q1JKxMiyA/v+t8h8jPydz21nyYlBMmmw1fUT5aU:dVE2UafGO2V

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • stunnel-5.75-win64-installer.exe (PID: 6584)
    • There is functionality for taking screenshot (YARA)

      • stunnel-5.75-win64-installer.exe (PID: 6584)
    • The process creates files with name similar to system file names

      • stunnel-5.75-win64-installer.exe (PID: 6584)
    • Executable content was dropped or overwritten

      • stunnel-5.75-win64-installer.exe (PID: 6584)
    • Creates a software uninstall entry

      • stunnel-5.75-win64-installer.exe (PID: 6584)
    • Reads the date of Windows installation

      • stunnel.exe (PID: 8008)
    • Reads security settings of Internet Explorer

      • stunnel.exe (PID: 8008)
    • Start notepad (likely ransomware note)

      • stunnel.exe (PID: 8008)
  • INFO

    • Checks supported languages

      • stunnel-5.75-win64-installer.exe (PID: 6584)
      • openssl.exe (PID: 5304)
      • openssl.exe (PID: 6992)
      • stunnel.exe (PID: 8008)
      • stunnel.exe (PID: 7824)
    • Creates files in the program directory

      • stunnel-5.75-win64-installer.exe (PID: 6584)
      • openssl.exe (PID: 5304)
      • openssl.exe (PID: 6992)
    • The sample compiled with english language support

      • stunnel-5.75-win64-installer.exe (PID: 6584)
    • Reads the computer name

      • stunnel-5.75-win64-installer.exe (PID: 6584)
      • stunnel.exe (PID: 8008)
    • Reads the machine GUID from the registry

      • openssl.exe (PID: 5304)
      • openssl.exe (PID: 6992)
      • stunnel.exe (PID: 8008)
      • stunnel.exe (PID: 7824)
    • Create files in a temporary directory

      • stunnel-5.75-win64-installer.exe (PID: 6584)
    • Manual execution by a user

      • stunnel.exe (PID: 8008)
      • stunnel.exe (PID: 7824)
    • Process checks computer location settings

      • stunnel.exe (PID: 8008)
    • Checks proxy server information

      • slui.exe (PID: 4008)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 5008)
    • Reads the software policy settings

      • slui.exe (PID: 4008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:04:02 06:31:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.44
CodeSize: 37888
InitializedDataSize: 63488
UninitializedDataSize: 129024
EntryPoint: 0x45d8
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
10
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start stunnel-5.75-win64-installer.exe openssl.exe no specs conhost.exe no specs openssl.exe no specs conhost.exe no specs slui.exe stunnel.exe no specs stunnel.exe no specs notepad.exe stunnel-5.75-win64-installer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3268\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeopenssl.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4008C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4988\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeopenssl.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5008"C:\Windows\System32\notepad.exe" "C:\Program Files (x86)\stunnel\config\stunnel.conf"C:\Windows\System32\notepad.exe
stunnel.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5304"C:\Program Files (x86)\stunnel\bin\openssl.exe" fipsinstall -module "C:\Program Files (x86)\stunnel\ossl-modules\fips.dll" -out "C:\Program Files (x86)\stunnel\config\fipsmodule.cnf" -provider_name fipsC:\Program Files (x86)\stunnel\bin\openssl.exestunnel-5.75-win64-installer.exe
User:
admin
Company:
The OpenSSL Project, https://www.openssl.org/
Integrity Level:
HIGH
Description:
OpenSSL application
Exit code:
0
Version:
3.4.1
Modules
Images
c:\program files (x86)\stunnel\bin\openssl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\program files (x86)\stunnel\bin\libssp-0.dll
c:\windows\system32\advapi32.dll
6584"C:\Users\admin\AppData\Local\Temp\stunnel-5.75-win64-installer.exe" C:\Users\admin\AppData\Local\Temp\stunnel-5.75-win64-installer.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\stunnel-5.75-win64-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6992"C:\Program Files (x86)\stunnel\bin\openssl.exe" req -new -x509 -days 365 -config "C:\Program Files (x86)\stunnel\config\openssl.cnf" -out "C:\Program Files (x86)\stunnel\config\stunnel.pem" -keyout "C:\Program Files (x86)\stunnel\config\stunnel.pem"C:\Program Files (x86)\stunnel\bin\openssl.exestunnel-5.75-win64-installer.exe
User:
admin
Company:
The OpenSSL Project, https://www.openssl.org/
Integrity Level:
HIGH
Description:
OpenSSL application
Exit code:
0
Version:
3.4.1
Modules
Images
c:\program files (x86)\stunnel\bin\openssl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\program files (x86)\stunnel\bin\libssl-3-x64.dll
c:\program files (x86)\stunnel\bin\libssp-0.dll
7284"C:\Users\admin\AppData\Local\Temp\stunnel-5.75-win64-installer.exe" C:\Users\admin\AppData\Local\Temp\stunnel-5.75-win64-installer.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\stunnel-5.75-win64-installer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7824"C:\Program Files (x86)\stunnel\bin\stunnel.exe" C:\Program Files (x86)\stunnel\bin\stunnel.exeexplorer.exe
User:
admin
Company:
Michal Trojnara
Integrity Level:
MEDIUM
Description:
stunnel - TLS offloading and load-balancing proxy
Exit code:
0
Version:
5.75
Modules
Images
c:\program files (x86)\stunnel\bin\stunnel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\program files (x86)\stunnel\bin\libssl-3-x64.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
8008"C:\Program Files (x86)\stunnel\bin\stunnel.exe" C:\Program Files (x86)\stunnel\bin\stunnel.exeexplorer.exe
User:
admin
Company:
Michal Trojnara
Integrity Level:
MEDIUM
Description:
stunnel - TLS offloading and load-balancing proxy
Version:
5.75
Modules
Images
c:\program files (x86)\stunnel\bin\stunnel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
2 081
Read events
2 072
Write events
9
Delete events
0

Modification events

(PID) Process:(6584) stunnel-5.75-win64-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NSIS_stunnel
Operation:writeName:Install_Mode
Value:
AllUsers
(PID) Process:(6584) stunnel-5.75-win64-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NSIS_stunnel
Operation:writeName:Install_Dir
Value:
C:\Program Files (x86)\stunnel
(PID) Process:(6584) stunnel-5.75-win64-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\stunnel
Operation:writeName:DisplayName
Value:
stunnel installed for AllUsers
(PID) Process:(6584) stunnel-5.75-win64-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\stunnel
Operation:writeName:DisplayVersion
Value:
5.75
(PID) Process:(6584) stunnel-5.75-win64-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\stunnel
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\stunnel\bin\stunnel.exe
(PID) Process:(6584) stunnel-5.75-win64-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\stunnel
Operation:writeName:Publisher
Value:
Michal Trojnara
(PID) Process:(6584) stunnel-5.75-win64-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\stunnel
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\stunnel\uninstall.exe" /AllUsers
(PID) Process:(6584) stunnel-5.75-win64-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\stunnel
Operation:writeName:NoModify
Value:
1
(PID) Process:(6584) stunnel-5.75-win64-installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\stunnel
Operation:writeName:NoRepair
Value:
1
Executable files
19
Suspicious files
0
Text files
15
Unknown types
15

Dropped files

PID
Process
Filename
Type
6584stunnel-5.75-win64-installer.exeC:\Users\admin\AppData\Local\Temp\nsgF730.tmp\UserInfo.dllexecutable
MD5:A2D8DED92E4815A45F45E19ACDCADFCF
SHA256:1B4111285F7A365FDBBE6AAB4066CB9538FBF2835D59367B5BFBF9220069AC10
6584stunnel-5.75-win64-installer.exeC:\Program Files (x86)\stunnel\bin\libssl-3-x64.dllexecutable
MD5:FFED2AEA061A22351CF226B09FBF74A8
SHA256:E9200C4E25D85A392F959DCBA8FF8081F422C1368FCA51E4551249577037D7E2
6584stunnel-5.75-win64-installer.exeC:\Users\admin\AppData\Local\Temp\nsgF730.tmp\nsDialogs.dllexecutable
MD5:A396D30099517546B62C0AA673929F93
SHA256:3564CE8B510ACFE456F7135E0C1AC1F71CFA39C787909192BE8F8ED40DCBE305
6584stunnel-5.75-win64-installer.exeC:\Users\admin\AppData\Local\Temp\nsgF730.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
6584stunnel-5.75-win64-installer.exeC:\Program Files (x86)\stunnel\bin\libgcc_s_seh-1.dllexecutable
MD5:6CCC6742A93C17C1B8FFAD43A1D1B7AC
SHA256:713CE990F573B430CADC118ADFA9D3F20FE7EDD8438877A974B4F25116C6D37A
6584stunnel-5.75-win64-installer.exeC:\Users\admin\AppData\Local\Temp\nsgF730.tmp\System.dllexecutable
MD5:4FD5A2CD0C65C6552FEA0CC11938F251
SHA256:54167AE0968E05910EF8DCD8BBC345AFE3DAD810FD3C9D2D3F47AD4CAFFC456D
6584stunnel-5.75-win64-installer.exeC:\Program Files (x86)\stunnel\config\ca-certs.pemtext
MD5:002406BA296687320B4C9EF806A048B7
SHA256:518CFC77F6784E5944FCA0029B798DE19EB5A5DD4F9C1CD5C0E5500AE81E4E23
6584stunnel-5.75-win64-installer.exeC:\Program Files (x86)\stunnel\config\stunnel.conftext
MD5:774DABAE35A634CFDA15D56D5C00C6BB
SHA256:0BBDB5949ED9C277EBA98A16A50E031853E997EDFD078FE7637BCA59D9CE4D94
6584stunnel-5.75-win64-installer.exeC:\Program Files (x86)\stunnel\bin\stunnel.exeexecutable
MD5:43AA51189A739BF5BBDDAF5D8AD3B4B5
SHA256:B4A34D9CB1643620C18A1ED9B575F8F90A5B7D026CA454E0D6CEC19BEE580C3B
6584stunnel-5.75-win64-installer.exeC:\Program Files (x86)\stunnel\bin\libssp-0.dllexecutable
MD5:125F4EB498AE0D44CECC36282E93C3FE
SHA256:B56A997DC204096B919436ECC6F4533A4B0C141E2E4162C1355163BC8D9ACD35
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
22
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
868 b
whitelisted
7600
svchost.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
868 b
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
4652
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
4652
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2064
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
7600
svchost.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
7600
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.159.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.181.238
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
login.live.com
  • 20.190.159.131
  • 20.190.159.129
  • 40.126.31.129
  • 40.126.31.67
  • 20.190.159.2
  • 20.190.159.73
  • 40.126.31.1
  • 20.190.159.0
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info