download:

BvSshClient-914.exe

Full analysis: https://app.any.run/tasks/1983e7b1-c5e3-482e-b97f-07bc39fcfde2
Verdict: Malicious activity
Analysis date: January 28, 2022, 06:45:10
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

6F97536601BDC086A5CAD41437101F91

SHA1:

3DBD3D5C99EDDD7D835D0395D413D82C66342F74

SHA256:

56AF5494DDA49E51311748FBE3C0ACDCEEDB4FAEA260E576D8AFBBEA780EF449

SSDEEP:

786432:ny3j3A6Nr+KqiO2Jw6618iVUwqtJo7m8Xh:y3jFJ+Kq966XmJJjM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads the Task Scheduler COM API

      • BvSshClient-914.exe (PID: 3404)
      • BvWinFspMgr.exe (PID: 1176)
    • Application was dropped or rewritten from another process

      • BvEventSource.exe (PID: 1536)
      • BvWinFspMgr.exe (PID: 1176)
      • BvSsh.exe (PID: 2572)
    • Drops executable file immediately after starts

      • BvWinFspMgr.exe (PID: 1176)
    • Changes settings of System certificates

      • msiexec.exe (PID: 3844)
    • Loads dropped or rewritten executable

      • msiexec.exe (PID: 3844)
      • BvSsh.exe (PID: 2572)
  • SUSPICIOUS

    • Checks supported languages

      • BvSshClient-914.exe (PID: 3404)
      • BvEventSource.exe (PID: 1536)
      • BvWinFspMgr.exe (PID: 1176)
      • BvSsh.exe (PID: 2572)
    • Reads the computer name

      • BvSshClient-914.exe (PID: 3404)
      • BvWinFspMgr.exe (PID: 1176)
      • BvSsh.exe (PID: 2572)
    • Creates a directory in Program Files

      • BvSshClient-914.exe (PID: 3404)
      • msiexec.exe (PID: 3844)
    • Drops a file that was compiled in debug mode

      • BvSshClient-914.exe (PID: 3404)
      • BvWinFspMgr.exe (PID: 1176)
      • msiexec.exe (PID: 3844)
    • Creates files in the Windows directory

      • BvSshClient-914.exe (PID: 3404)
      • BvWinFspMgr.exe (PID: 1176)
      • msiexec.exe (PID: 3844)
    • Drops a file with too old compile date

      • BvSshClient-914.exe (PID: 3404)
    • Drops a file with a compile date too recent

      • BvSshClient-914.exe (PID: 3404)
      • msiexec.exe (PID: 3844)
    • Creates files in the program directory

      • BvSshClient-914.exe (PID: 3404)
      • msiexec.exe (PID: 3844)
    • Executable content was dropped or overwritten

      • BvSshClient-914.exe (PID: 3404)
      • BvWinFspMgr.exe (PID: 1176)
      • msiexec.exe (PID: 3844)
    • Creates files in the driver directory

      • BvWinFspMgr.exe (PID: 1176)
    • Creates or modifies windows services

      • BvWinFspMgr.exe (PID: 1176)
    • Executed as Windows Service

      • msiexec.exe (PID: 3844)
    • Starts Microsoft Installer

      • BvSshClient-914.exe (PID: 3404)
    • Reads Windows owner or organization settings

      • msiexec.exe (PID: 3844)
    • Adds / modifies Windows certificates

      • msiexec.exe (PID: 3844)
    • Reads the Windows organization settings

      • msiexec.exe (PID: 3844)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 3844)
      • BvSshClient-914.exe (PID: 3404)
    • Changes default file association

      • BvSshClient-914.exe (PID: 3404)
    • Searches for installed software

      • BvSsh.exe (PID: 2572)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 2740)
      • msiexec.exe (PID: 3844)
    • Reads the computer name

      • msiexec.exe (PID: 3844)
      • msiexec.exe (PID: 2740)
    • Reads settings of System Certificates

      • msiexec.exe (PID: 3844)
      • BvSsh.exe (PID: 2572)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 3844)
      • BvSsh.exe (PID: 2572)
    • Manual execution by user

      • BvSsh.exe (PID: 2572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

SpecialBuild: -
ProductVersion: 9.14
ProductName: Bitvise SSH Client
PrivateBuild: -
OriginalFileName: BvSshClient-Inst.exe
LegalTrademarks: -
LegalCopyright: Copyright (C) 2000-2022 by Bitvise Limited.
InternalName: BvSshClient-Inst
FileVersion: 9.14.0.0
FileDescription: Bitvise SSH Client Installer
CompanyName: Bitvise Limited
Comments: -
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 9.14.0.0
FileVersionNumber: 9.14.0.0
Subsystem: Windows command line
SubsystemVersion: 5.1
ImageVersion: -
OSVersion: 5.1
EntryPoint: 0x805e0
UninitializedDataSize: -
InitializedDataSize: 24461312
CodeSize: 730624
LinkerVersion: 14
PEType: PE32
TimeStamp: 2022:01:23 05:22:19+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_CUI
Compilation Date: 23-Jan-2022 04:22:19
Detected languages:
  • English - United States
Debug artifacts:
  • D:\repos\main\SSH2\Release\pdbs\BvSshClient-Inst.pdb
Comments: -
CompanyName: Bitvise Limited
FileDescription: Bitvise SSH Client Installer
FileVersion: 9.14.0.0
InternalName: BvSshClient-Inst
LegalCopyright: Copyright (C) 2000-2022 by Bitvise Limited.
LegalTrademarks: -
OriginalFilename: BvSshClient-Inst.exe
PrivateBuild: -
ProductName: Bitvise SSH Client
ProductVersion: 9.14
SpecialBuild: -

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000128

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 6
Time date stamp: 23-Jan-2022 04:22:19
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x000B25EA
0x000B2600
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.408
.rdata
0x000B4000
0x0003CB88
0x0003CC00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.54503
.data
0x000F1000
0x00005A7C
0x00003E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.92365
.tls
0x000F7000
0x00000009
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0.0203931
.rsrc
0x000F8000
0x01704AA8
0x01704C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.99984
.reloc
0x017FD000
0x0000C9B8
0x0000CA00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.61114

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.17906
2172
UNKNOWN
English - United States
RT_MANIFEST
2
3.92461
16936
UNKNOWN
English - United States
RT_ICON
3
4.28185
9640
UNKNOWN
English - United States
RT_ICON
4
4.68644
6760
UNKNOWN
English - United States
RT_ICON
5
4.81062
4264
UNKNOWN
English - United States
RT_ICON
6
4.46317
2440
UNKNOWN
English - United States
RT_ICON
7
4.88346
1720
UNKNOWN
English - United States
RT_ICON
8
5.02886
1128
UNKNOWN
English - United States
RT_ICON
9
4.26047
4264
UNKNOWN
English - United States
RT_ICON
10
4.46317
2440
UNKNOWN
English - United States
RT_ICON

Imports

ADVAPI32.dll
GDI32.dll
KERNEL32.dll
OLEAUT32.dll
PSAPI.DLL
SHELL32.dll
SHLWAPI.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
7
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start start bvsshclient-914.exe bveventsource.exe no specs bvwinfspmgr.exe msiexec.exe no specs msiexec.exe bvssh.exe bvsshclient-914.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1176"C:\Windows\BvWinFspMgr.exe" InstallC:\Windows\BvWinFspMgr.exe
BvSshClient-914.exe
User:
admin
Company:
Bitvise Limited
Integrity Level:
HIGH
Description:
Bitvise WinFsp Driver Management Utility
Exit code:
0
Version:
1.01
Modules
Images
c:\windows\bvwinfspmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\gdi32.dll
1536"C:\Windows\system32\BvEventSource.exe" registerC:\Windows\system32\BvEventSource.exeBvSshClient-914.exe
User:
admin
Company:
Bitvise Limited
Integrity Level:
HIGH
Description:
Bitvise Log Event Source Utility
Exit code:
0
Version:
1.02
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\bveventsource.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2572"C:\Program Files\Bitvise SSH Client\BvSsh.exe" C:\Program Files\Bitvise SSH Client\BvSsh.exe
Explorer.EXE
User:
admin
Company:
Bitvise Limited
Integrity Level:
MEDIUM
Description:
Bitvise SSH Client
Exit code:
0
Version:
9.14.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\bitvise ssh client\bvssh.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
2740msiexec.exe /i "C:\Program Files\Bitvise SSH Client\FlowSshNet32.msi" INSTALLDIR="C:\Program Files\Bitvise SSH Client" /quiet /norestart MSIRESTARTMANAGERCONTROL="Disable"C:\Windows\system32\msiexec.exeBvSshClient-914.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3216"C:\Users\admin\AppData\Local\Temp\BvSshClient-914.exe" C:\Users\admin\AppData\Local\Temp\BvSshClient-914.exeExplorer.EXE
User:
admin
Company:
Bitvise Limited
Integrity Level:
MEDIUM
Description:
Bitvise SSH Client Installer
Exit code:
3221226540
Version:
9.14.0.0
Modules
Images
c:\users\admin\appdata\local\temp\bvsshclient-914.exe
c:\windows\system32\ntdll.dll
3404"C:\Users\admin\AppData\Local\Temp\BvSshClient-914.exe" C:\Users\admin\AppData\Local\Temp\BvSshClient-914.exe
Explorer.EXE
User:
admin
Company:
Bitvise Limited
Integrity Level:
HIGH
Description:
Bitvise SSH Client Installer
Exit code:
0
Version:
9.14.0.0
Modules
Images
c:\users\admin\appdata\local\temp\bvsshclient-914.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3844C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows� installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
12 781
Read events
12 407
Write events
360
Delete events
14

Modification events

(PID) Process:(3404) BvSshClient-914.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Bitvise\Installers
Operation:writeName:Bitvise SSH Client Installer
Value:
"C:\Users\admin\AppData\Local\Temp\BvSshClient-914.exe" -acceptEULA -installDir="C:\Program Files\Bitvise SSH Client" -interactive -runWhenDone
(PID) Process:(3404) BvSshClient-914.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:Bitvise-WWLib-CRegSafeModify-Guard-45150DC24C566C9D69E778BD71FF42F8585C46D2
Value:
0
(PID) Process:(1536) BvEventSource.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Bitvise Installer
Operation:writeName:EventMessageFile
Value:
C:\Windows\system32\BvEventSource.exe
(PID) Process:(1536) BvEventSource.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Bitvise Installer
Operation:writeName:TypesSupported
Value:
7
(PID) Process:(1176) BvWinFspMgr.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinFsp.Np\NetworkProvider
Operation:writeName:Name
Value:
Windows File System Proxy
(PID) Process:(1176) BvWinFspMgr.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinFsp.Np\NetworkProvider
Operation:writeName:DeviceName
Value:
\Device\WinFsp.Mup
(PID) Process:(1176) BvWinFspMgr.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinFsp.Np\NetworkProvider
Operation:writeName:ProviderPath
Value:
C:\Windows\system32\BvWinFsp.dll
(PID) Process:(1176) BvWinFspMgr.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinFsp.Np
Operation:writeName:Group
Value:
NetworkProvider
(PID) Process:(1176) BvWinFspMgr.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\NetworkProvider\Order
Operation:writeName:Bitvise-WWLib-CRegSafeModify-Guard-C5345DCA0963EE040B510A93871A4774F8DA2611
Value:
0
(PID) Process:(1176) BvWinFspMgr.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\NetworkProvider\Order
Operation:writeName:ProviderOrder
Value:
WinFsp.Np,RDPNP,LanmanWorkstation,webclient
Executable files
58
Suspicious files
8
Text files
5
Unknown types
14

Dropped files

PID
Process
Filename
Type
3404BvSshClient-914.exeC:\Program Files\Bitvise SSH Client\CiWinCng32.dllexecutable
MD5:
SHA256:
3404BvSshClient-914.exeC:\Program Files\Bitvise SSH Client\Countries.binbs
MD5:
SHA256:
3404BvSshClient-914.exeC:\Program Files\Bitvise SSH Client\uninst.exeexecutable
MD5:
SHA256:
3404BvSshClient-914.exeC:\Program Files\Bitvise SSH Client\BvSsh.exeexecutable
MD5:
SHA256:
3404BvSshClient-914.exeC:\Program Files\Bitvise SSH Client\BvDump32.exeexecutable
MD5:
SHA256:
3404BvSshClient-914.exeC:\Program Files\Bitvise SSH Client\BscInstalledResources.htmhtml
MD5:
SHA256:
3404BvSshClient-914.exeC:\Program Files\Bitvise SSH Client\BvSshCtrl.cpptext
MD5:
SHA256:
3404BvSshClient-914.exeC:\Program Files\Bitvise SSH Client\BvSshCtrl.exeexecutable
MD5:
SHA256:
3404BvSshClient-914.exeC:\Program Files\Bitvise SSH Client\totermw.exeexecutable
MD5:
SHA256:
3404BvSshClient-914.exeC:\Program Files\Bitvise SSH Client\BscActCode.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
3
DNS requests
3
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2572
BvSsh.exe
GET
200
104.18.30.182:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEChOOcFLOG2InHKZ5YzQWlc%3D
US
der
727 b
whitelisted
2572
BvSsh.exe
GET
200
95.140.236.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d8826548d56b5756
GB
compressed
4.70 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2572
BvSsh.exe
18.188.178.2:443
bitvise.com
US
unknown
2572
BvSsh.exe
104.18.30.182:80
ocsp.usertrust.com
Cloudflare Inc
US
suspicious
95.140.236.0:80
ctldl.windowsupdate.com
Limelight Networks, Inc.
GB
whitelisted

DNS requests

Domain
IP
Reputation
bitvise.com
  • 18.188.178.2
whitelisted
ctldl.windowsupdate.com
  • 95.140.236.0
  • 95.140.236.128
whitelisted
ocsp.usertrust.com
  • 104.18.30.182
  • 104.18.31.182
whitelisted

Threats

No threats detected
No debug info