File name:

PuTTYPortable_0.83_English.paf.exe

Full analysis: https://app.any.run/tasks/ce71f3ea-2d66-485c-85d2-349be86cf4ac
Verdict: Malicious activity
Analysis date: July 02, 2025, 12:59:24
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
putty
rmm-tool
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

710ADA266BBB007A4CB0E6D057DA3D76

SHA1:

DA72A6B8993A6ECB01B0458C974C4A52D4C81C3A

SHA256:

7A19751ED16E5A355BDB3F415DF9F28F47EC87B608A59D691256A8983F6D3987

SSDEEP:

49152:EyZXEnER4bX2JW3OIa7jFYwjWcTa/FyKIRz1tcQQl2Z2sh9QaENxGj6Oh9P9+x95:EaXQE2q3VFYeWcO/sKIR6MZ2s/QaErBF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • PuTTYPortable.exe (PID: 6780)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
    • The process creates files with name similar to system file names

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
    • Executable content was dropped or overwritten

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
    • There is functionality for taking screenshot (YARA)

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
    • Reads security settings of Internet Explorer

      • PuTTYPortable.exe (PID: 6780)
    • PUTTY has been detected

      • PUTTY.EXE (PID: 7104)
  • INFO

    • Checks supported languages

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
      • PUTTY.EXE (PID: 7104)
    • Create files in a temporary directory

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
    • The sample compiled with english language support

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
    • Reads the computer name

      • PuTTYPortable_0.83_English.paf.exe (PID: 3400)
      • PuTTYPortable.exe (PID: 6780)
      • PUTTY.EXE (PID: 7104)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:56:02+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 412160
UninitializedDataSize: 16384
EntryPoint: 0x3665
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.83.0.0
ProductVersionNumber: 0.83.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: For additional details, visit PortableApps.com
CompanyName: PortableApps.com
FileDescription: PuTTY Portable
FileVersion: 0.83.0.0
InternalName: PuTTY Portable
LegalCopyright: 2007-2025 PortableApps.com, PortableApps.com Installer 3.8.14.0
LegalTrademarks: PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFileName: PuTTYPortable_0.83_English.paf.exe
PortableAppscomAppID: PuTTYPortable
PortableAppscomFormatVersion: 3.8
PortableAppscomInstallerVersion: 3.8.14.0
ProductName: PuTTY Portable
ProductVersion: 0.83.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start puttyportable_0.83_english.paf.exe puttyportable.exe THREAT putty.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3400"C:\Users\admin\AppData\Local\Temp\PuTTYPortable_0.83_English.paf.exe" C:\Users\admin\AppData\Local\Temp\PuTTYPortable_0.83_English.paf.exe
explorer.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PuTTY Portable
Exit code:
0
Version:
0.83.0.0
Modules
Images
c:\users\admin\appdata\local\temp\puttyportable_0.83_english.paf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4104C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6780"C:\Users\admin\Desktop\PuTTYPortable\PuTTYPortable.exe"C:\Users\admin\Desktop\PuTTYPortable\PuTTYPortable.exe
PuTTYPortable_0.83_English.paf.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PuTTY Portable (PortableApps.com Launcher)
Version:
2.2.9.0
Modules
Images
c:\users\admin\desktop\puttyportable\puttyportable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7104"C:\Users\admin\Desktop\PuTTYPortable\App\putty\putty.exe"C:\Users\admin\Desktop\PuTTYPortable\App\putty\PUTTY.EXE
PuTTYPortable.exe
User:
admin
Company:
Simon Tatham
Integrity Level:
MEDIUM
Description:
SSH, Telnet, Rlogin, and SUPDUP client
Version:
Release 0.83 (with embedded help)
Modules
Images
c:\users\admin\desktop\puttyportable\app\putty\putty.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
Total events
2 353
Read events
2 349
Write events
4
Delete events
0

Modification events

(PID) Process:(3400) PuTTYPortable_0.83_English.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
121
(PID) Process:(3400) PuTTYPortable_0.83_English.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts
Operation:writeName:LastUpdate
Value:
4C2D656800000000
(PID) Process:(3400) PuTTYPortable_0.83_English.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Width
Value:
318
(PID) Process:(3400) PuTTYPortable_0.83_English.paf.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:Browse For Folder Height
Value:
288
Executable files
13
Suspicious files
1
Text files
25
Unknown types
1

Dropped files

PID
Process
Filename
Type
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\AppData\Local\Temp\nse4BE0.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\AppData\Local\Temp\nse4BE0.tmp\nsDialogs.dllexecutable
MD5:B7D61F3F56ABF7B7FF0D4E7DA3AD783D
SHA256:89A82C4849C21DFE765052681E1FAD02D2D7B13C8B5075880C52423DCA72A912
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\PuTTYPortable.exeexecutable
MD5:28CB527A7C83797B1FC472B5A7744E8A
SHA256:780A0AE4EF1FD7435309FDB1D1067676D6B197B70E81098E91E86A18D76C34BA
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\App\AppInfo\appicon_16.pngimage
MD5:77ACA5FAA13DDB0C23983443ED91E072
SHA256:3838F62CA15C88A148532ADFF1A376756338DE0A77E9B70CEC04F95D8DBC82D4
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\help.htmlhtml
MD5:AF54ABE5ED8EBF62E35EEA395EAAFEDC
SHA256:1475AEFE93504F08223805891877347BE536BE2DA8D3EA5E1C17B631837CD63B
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\App\AppInfo\appicon.icoimage
MD5:10F94954AF528FFEA75B62808232DA2F
SHA256:E4B1554ED61918830AE8A1913D6B803EBF898D2D91875892CDE147290F2A2EFC
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\App\AppInfo\appicon_32.pngimage
MD5:5065DDDEA450DD6843FD2AF2A70FC3E1
SHA256:454C5FCEC4A73F4D39072ED9812967ADC102B8322F3AA101DFA1ECEBA6BB6F02
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\App\AppInfo\appinfo.iniini
MD5:0226F823E7B3B4A7695C0C2334EA696F
SHA256:13E01952D6805741A6CE32859CACD1D3AECDBB0F8D8AFA41B329D83F544F6C05
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\App\AppInfo\appicon_128.pngimage
MD5:196510BEAA3687DB5F398E6F6F978CCE
SHA256:EDE5FFEA9376B1B29BE140B76BF233C760FD8F3D6428EDEA696A6FB9AC8A4864
3400PuTTYPortable_0.83_English.paf.exeC:\Users\admin\Desktop\PuTTYPortable\App\AppInfo\appicon_75.pngimage
MD5:0D147CD44D1FBB75BAE32C726AB11038
SHA256:6C25A47EE44832728D1F40903FA0B4D46741C75D2912A051B4C86ABAF1275136
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
22
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5284
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6284
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5284
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5104
RUXIMICS.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
2.16.168.114:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
6284
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6284
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 40.126.31.73
  • 40.126.31.2
  • 20.190.159.75
  • 20.190.159.64
  • 20.190.159.23
  • 40.126.31.129
  • 20.190.159.128
  • 40.126.31.130
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
nexusrules.officeapps.live.com
  • 52.111.236.22
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info