File name:

PuTTYPortable_0.83_English.paf.exe

Full analysis: https://app.any.run/tasks/ce71f3ea-2d66-485c-85d2-349be86cf4ac
Verdict: Malicious activity
Analysis date: July 02, 2025, 12:59:24
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
putty
rmm-tool
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

710ADA266BBB007A4CB0E6D057DA3D76

SHA1:

DA72A6B8993A6ECB01B0458C974C4A52D4C81C3A

SHA256:

7A19751ED16E5A355BDB3F415DF9F28F47EC87B608A59D691256A8983F6D3987

SSDEEP:

49152:EyZXEnER4bX2JW3OIa7jFYwjWcTa/FyKIRz1tcQQl2Z2sh9QaENxGj6Oh9P9+x95:EaXQE2q3VFYeWcO/sKIR6MZ2s/QaErBF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • PuTTYPortable.exe (PID: 6780)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
    • The process creates files with name similar to system file names

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
    • Executable content was dropped or overwritten

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
    • Reads security settings of Internet Explorer

      • PuTTYPortable.exe (PID: 6780)
    • PUTTY has been detected

      • PUTTY.EXE (PID: 7104)
    • There is functionality for taking screenshot (YARA)

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
  • INFO

    • The sample compiled with english language support

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
    • Checks supported languages

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
      • PUTTY.EXE (PID: 7104)
    • Create files in a temporary directory

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
    • Reads the computer name

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
      • PUTTY.EXE (PID: 7104)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:56:02+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 412160
UninitializedDataSize: 16384
EntryPoint: 0x3665
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.83.0.0
ProductVersionNumber: 0.83.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: For additional details, visit PortableApps.com
CompanyName: PortableApps.com
FileDescription: PuTTY Portable
FileVersion: 0.83.0.0
InternalName: PuTTY Portable
LegalCopyright: 2007-2025 PortableApps.com, PortableApps.com Installer 3.8.14.0
LegalTrademarks: PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFileName: PuTTYPortable_0.83_English.paf.exe
PortableAppscomAppID: PuTTYPortable
PortableAppscomFormatVersion: 3.8
PortableAppscomInstallerVersion: 3.8.14.0
ProductName: PuTTY Portable
ProductVersion: 0.83.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start puttyportable_0.83_english.paf.exe puttyportable.exe THREAT putty.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3400"C:\Users\admin\AppData\Local\Temp\PuTTYPortable_0.83_English.paf.exe" C:\Users\admin\AppData\Local\Temp\PuTTYPortable_0.83_English.paf.exe
explorer.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PuTTY Portable
Exit code:
0
Version:
0.83.0.0
Modules
Images
c:\users\admin\appdata\local\temp\puttyportable_0.83_english.paf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4104C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6780"C:\Users\admin\Desktop\PuTTYPortable\PuTTYPortable.exe"C:\Users\admin\Desktop\PuTTYPortable\PuTTYPortable.exe
PuTTYPortable_0.83_English.paf.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PuTTY Portable (PortableApps.com Launcher)
Version:
2.2.9.0
Modules
Images
c:\users\admin\desktop\puttyportable\puttyportable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7104"C:\Users\admin\Desktop\PuTTYPortable\App\putty\putty.exe"C:\Users\admin\Desktop\PuTTYPortable\App\putty\PUTTY.EXE
PuTTYPortable.exe
User:
admin
Company:
Simon Tatham
Integrity Level:
MEDIUM
Description:
SSH, Telnet, Rlogin, and SUPDUP client
Version:
Release 0.83 (with embedded help)
Modules
Images
c:\users\admin\desktop\puttyportable\app\putty\putty.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
Total events
2 353
Read events
2 349
Write events
4
Delete events
0

Modification events

(PID) Process:(3400) PuTTYPortable_0.83_English.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
121
(PID) Process:(3400) PuTTYPortable_0.83_English.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts
Operation:writeName:LastUpdate
Value:
4C2D656800000000
(PID) Process:(3400) PuTTYPortable_0.83_English.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(3400) PuTTYPortable_0.83_English.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
Executable files
13
Suspicious files
1
Text files
25
Unknown types
1

Dropped files

PID
Process
Filename
Type
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\AppData\Local\Temp\nse4BE0.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\AppData\Local\Temp\nse4BE0.tmp\modern-wizard.bmpimage
MD5:4DF53EFCAA2C52F39618B2AAD77BB552
SHA256:EE13539F3D66CC0592942EA1A4C35D8FD9AF67B1A7F272D0D791931E6E9CE4EB
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\AppData\Local\Temp\nse4BE0.tmp\nsDialogs.dllexecutable
MD5:B7D61F3F56ABF7B7FF0D4E7DA3AD783D
SHA256:89A82C4849C21DFE765052681E1FAD02D2D7B13C8B5075880C52423DCA72A912
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\PuTTYPortable.exeexecutable
MD5:28CB527A7C83797B1FC472B5A7744E8A
SHA256:780A0AE4EF1FD7435309FDB1D1067676D6B197B70E81098E91E86A18D76C34BA
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\help.htmlhtml
MD5:AF54ABE5ED8EBF62E35EEA395EAAFEDC
SHA256:1475AEFE93504F08223805891877347BE536BE2DA8D3EA5E1C17B631837CD63B
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\AppData\Local\Temp\nse4BE0.tmp\modern-header.bmpimage
MD5:8BD2FC53EDA7B2ACAB282B23DAE497C2
SHA256:9AB6A194565DD66BC8C4872E8C670487303D4690C5FEE33DB41A591A6BBFCE2D
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\AppData\Local\Temp\nse4BE0.tmp\w7tbp.dllexecutable
MD5:9A3031CC4CEF0DBA236A28EECDF0AFB5
SHA256:53BB519E3293164947AC7CBD7E612F637D77A7B863E3534BA1A7E39B350D3C00
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\App\AppInfo\appicon_75.pngimage
MD5:0D147CD44D1FBB75BAE32C726AB11038
SHA256:6C25A47EE44832728D1F40903FA0B4D46741C75D2912A051B4C86ABAF1275136
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\App\AppInfo\Launcher\PuTTYPortable.iniini
MD5:D9DAF4CB6F0BBEB941EEADCAA1B37DD6
SHA256:22E2E5C3AE8F4B6DF73B9B294CF728244A1200A87777846E5F5E3EBCAFDC842B
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\App\AppInfo\appicon_128.pngimage
MD5:196510BEAA3687DB5F398E6F6F978CCE
SHA256:EDE5FFEA9376B1B29BE140B76BF233C760FD8F3D6428EDEA696A6FB9AC8A4864
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
22
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6284
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5284
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5284
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5104
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
2.16.168.114:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
6284
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6284
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 40.126.31.73
  • 40.126.31.2
  • 20.190.159.75
  • 20.190.159.64
  • 20.190.159.23
  • 40.126.31.129
  • 20.190.159.128
  • 40.126.31.130
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.22
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info