File name:

SSHSecureShellClient-3.2.9.exe

Full analysis: https://app.any.run/tasks/e0c38ce4-bc2b-4184-8b2d-f076aaba3690
Verdict: Malicious activity
Analysis date: August 26, 2024, 10:51:35
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5E105DBD37ABCD4486CED0F3DAF5B5E8

SHA1:

DDBB5CB26D653192C141FF4D589A3FFD05C9D399

SHA256:

8A5A076582904C56ECCB41084B9BDFCF1587F0F9257FE51E3301BBA6220C6D40

SSDEEP:

98304:kNOXWohV+1LrnlQAKQHP9Unw6fAEVFCxBqb+yH2y2tvVKSiv7JuU7pvAwIAfQCYM:ekUkenTGW1+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • SSHSecureShellClient-3.2.9.exe (PID: 6808)
      • IKernel.exe (PID: 5244)
      • Setup.exe (PID: 4976)
      • SSHPackage1.exe (PID: 2180)
    • Executable content was dropped or overwritten

      • SSHPackage1.exe (PID: 2180)
      • IKernel.exe (PID: 5244)
      • SSHSecureShellClient-3.2.9.exe (PID: 6808)
      • Setup.exe (PID: 4976)
    • Creates/Modifies COM task schedule object

      • IKernel.exe (PID: 5244)
    • Application launched itself

      • IKernel.exe (PID: 5244)
  • INFO

    • Create files in a temporary directory

      • SSHPackage1.exe (PID: 2180)
      • SSHSecureShellClient-3.2.9.exe (PID: 6808)
      • Setup.exe (PID: 4976)
      • IKernel.exe (PID: 5244)
    • Checks supported languages

      • SSHSecureShellClient-3.2.9.exe (PID: 6808)
      • SSHPackage1.exe (PID: 2180)
      • Setup.exe (PID: 4976)
      • IKernel.exe (PID: 5524)
      • IKernel.exe (PID: 5244)
      • IKernel.exe (PID: 6648)
    • Reads the computer name

      • SSHPackage1.exe (PID: 2180)
      • Setup.exe (PID: 4976)
      • IKernel.exe (PID: 5524)
      • IKernel.exe (PID: 5244)
      • IKernel.exe (PID: 6648)
    • Creates files in the program directory

      • IKernel.exe (PID: 5244)
      • Setup.exe (PID: 4976)
    • Reads Environment values

      • IKernel.exe (PID: 5244)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2003:01:08 12:15:45+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 5488640
UninitializedDataSize: -
EntryPoint: 0x18ef
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.2.0.0
ProductVersionNumber: 3.2.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: This setup executable contains SSH Secure Shell software and possibly a Customer License to run the software.
CompanyName: SSH Communications Security Corp
FileDescription: SSH Secure Shell Setup
FileVersion: 3.2
InternalName: InstWrapper
LegalCopyright: Copyright © 2003
LegalTrademarks: -
OriginalFileName: InstWrapper.exe
PrivateBuild: -
ProductName: SSH Secure Shell Setup
ProductVersion: 3.x
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
7
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start sshsecureshellclient-3.2.9.exe sshpackage1.exe setup.exe ikernel.exe no specs ikernel.exe ikernel.exe no specs sshsecureshellclient-3.2.9.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2180"C:\Users\admin\AppData\Local\Temp\SSHPackage1.exe" C:\Users\admin\AppData\Local\Temp\SSHPackage1.exe
SSHSecureShellClient-3.2.9.exe
User:
admin
Company:
SSH Communications Security Ltd.
Integrity Level:
HIGH
Version:
1.00.000
Modules
Images
c:\users\admin\appdata\local\temp\sshpackage1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
4976"C:\Users\admin\AppData\Local\Temp\pftB07E~tmp\Disk1\Setup.exe"C:\Users\admin\AppData\Local\Temp\pftB07E~tmp\Disk1\Setup.exe
SSHPackage1.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield (R) Setup Launcher
Version:
6, 30, 100, 1255
Modules
Images
c:\users\admin\appdata\local\temp\pftb07e~tmp\disk1\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
5244C:\PROGRA~2\COMMON~1\INSTAL~1\Engine\6\INTEL3~1\IKernel.exe -EmbeddingC:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
svchost.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield (R) Setup Engine
Version:
6, 31, 100, 1190
Modules
Images
c:\program files (x86)\common files\installshield\engine\6\intel 32\ikernel.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
5524"C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe" -RegServerC:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exeSetup.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield (R) Setup Engine
Exit code:
0
Version:
6, 31, 100, 1190
Modules
Images
c:\program files (x86)\common files\installshield\engine\6\intel 32\ikernel.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
6648"C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iKernel.exe" /REGSERVERC:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exeIKernel.exe
User:
admin
Company:
InstallShield Software Corporation
Integrity Level:
HIGH
Description:
InstallShield (R) Setup Engine
Exit code:
0
Version:
6, 31, 100, 1190
Modules
Images
c:\program files (x86)\common files\installshield\engine\6\intel 32\ikernel.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acspecfc.dll
6808"C:\Users\admin\Desktop\SSHSecureShellClient-3.2.9.exe" C:\Users\admin\Desktop\SSHSecureShellClient-3.2.9.exe
explorer.exe
User:
admin
Company:
SSH Communications Security Corp
Integrity Level:
HIGH
Description:
SSH Secure Shell Setup
Version:
3.2
Modules
Images
c:\users\admin\desktop\sshsecureshellclient-3.2.9.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7052"C:\Users\admin\Desktop\SSHSecureShellClient-3.2.9.exe" C:\Users\admin\Desktop\SSHSecureShellClient-3.2.9.exeexplorer.exe
User:
admin
Company:
SSH Communications Security Corp
Integrity Level:
MEDIUM
Description:
SSH Secure Shell Setup
Exit code:
3221226540
Version:
3.2
Modules
Images
c:\users\admin\desktop\sshsecureshellclient-3.2.9.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
1 538
Read events
1 379
Write events
159
Delete events
0

Modification events

(PID) Process:(5524) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5524) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2068-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5524) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5524) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AA7E2066-CB55-11D2-8094-00104B1F9838}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5524) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5524) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{CC096170-E2CB-11D2-80C8-00104B1F6CEA}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5524) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5524) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C3C1B11-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5524) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
(PID) Process:(5524) IKernel.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8C3C1B13-E59D-11D2-B40B-00A024B9DDDD}\TypeLib
Operation:writeName:Version
Value:
1.0
Executable files
21
Suspicious files
8
Text files
15
Unknown types
2

Dropped files

PID
Process
Filename
Type
2180SSHPackage1.exeC:\Users\admin\AppData\Local\Temp\pftB07E~tmp\pftw1.pkg
MD5:
SHA256:
2180SSHPackage1.exeC:\Users\admin\AppData\Local\Temp\pftB07E~tmp\Disk1\data2.cab
MD5:
SHA256:
2180SSHPackage1.exeC:\Users\admin\AppData\Local\Temp\pftB07E~tmp\Disk1\setup.bmpimage
MD5:F919F5175A2D3BC04E29AF796C583611
SHA256:B38C0B36E87134021DBEAE1669C479ED9BC214995B87E0498DF216C72C1E23F5
2180SSHPackage1.exeC:\Users\admin\AppData\Local\Temp\pftB07E~tmp\Disk1\ikernel.ex_ex_
MD5:4D63BBFF28AFC7A69B6DEFAF048306A7
SHA256:4EB9A6A4C0B1147290C74D2160533E49E043335255BE9A60B6C83638D83E5590
2180SSHPackage1.exeC:\Users\admin\AppData\Local\Temp\pftB07E~tmp\Disk1\Setup.initext
MD5:2AC0AEB6D59C55155B97A687582686AD
SHA256:F97FD0E2B6B3A0A7F02BF6E282D84E71117D763C36FF4769A099139C81EDB59A
2180SSHPackage1.exeC:\Users\admin\AppData\Local\Temp\pftB07E~tmp\Disk1\setup.inxinx
MD5:5F6CB18FA96DF74274BFB207E26D4245
SHA256:3C0AF9FBBA80372B9DFE68467B3CF0B83123E7844FF755F7BD232C6FCD5762C7
6808SSHSecureShellClient-3.2.9.exeC:\Users\admin\AppData\Local\Temp\SSHPackage1.exeexecutable
MD5:B401602D47AE4120E46DC9AE0DC939EE
SHA256:75199AF4285A2B582A21A64D1A0EFC7190954CC5F9854AF84EB54CBD9857E866
2180SSHPackage1.exeC:\Users\admin\AppData\Local\Temp\pftB07E~tmp\Disk1\Setup.exeexecutable
MD5:E0927F427281CCDE747E10F17DF53318
SHA256:B6CCB202D86457955F980237D2E4D6033B369C2497154414DAF349926309CD4D
4976Setup.exeC:\Users\admin\AppData\Local\Temp\IECB32B.tmpex_
MD5:4D63BBFF28AFC7A69B6DEFAF048306A7
SHA256:4EB9A6A4C0B1147290C74D2160533E49E043335255BE9A60B6C83638D83E5590
2180SSHPackage1.exeC:\Users\admin\AppData\Local\Temp\pftB07E~tmp\Disk1\data1.hdrhdr
MD5:D8AE531B02F3BCEE317BFC2655428F4B
SHA256:B58EDB78CD99C55AB87E5E46FFE7497E6F6B14D0F1F0490DCD5022EBFB6B2328
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
14
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5644
RUXIMICS.exe
13.71.55.58:443
MICROSOFT-CORP-MSN-AS-BLOCK
IN
unknown
2120
MoUsoCoreWorker.exe
13.71.55.58:443
MICROSOFT-CORP-MSN-AS-BLOCK
IN
unknown
192.168.100.255:138
whitelisted
6164
svchost.exe
13.71.55.58:443
MICROSOFT-CORP-MSN-AS-BLOCK
IN
unknown
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6164
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4324
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted

Threats

No threats detected
No debug info