File name:

Win64OpenSSL_Light-3_3_1.exe

Full analysis: https://app.any.run/tasks/3d5dee33-ecac-421b-a253-84e360f699e9
Verdict: Malicious activity
Analysis date: July 29, 2024, 14:24:55
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B0A83835D91BBC2893AD14A0832B6584

SHA1:

9941722D5D7465F875694C59088051AE502B90F6

SHA256:

FCE75265329B7AA9A2990C6568BED5336185CD413710D4BC5B56CB6563A2FEE6

SSDEEP:

98304:9EAQ3xO7Q1kkhHhyGiLHHoB6o1FM1hKmC/p9vOCupwMtLVG2WJHR1WFoCeycC6WN:iPFocMocl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Win64OpenSSL_Light-3_3_1.exe (PID: 3944)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 6772)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 2368)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Win64OpenSSL_Light-3_3_1.exe (PID: 3944)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 6772)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 2368)
    • Reads security settings of Internet Explorer

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 4288)
    • Reads the date of Windows installation

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 4288)
    • Reads the Windows owner or organization settings

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 2368)
  • INFO

    • Checks supported languages

      • Win64OpenSSL_Light-3_3_1.exe (PID: 3944)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 6772)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 2368)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 4288)
    • Create files in a temporary directory

      • Win64OpenSSL_Light-3_3_1.exe (PID: 3944)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 6772)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 2368)
    • Reads the computer name

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 4288)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 2368)
    • Process checks computer location settings

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 4288)
    • Creates files in the program directory

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 2368)
    • Creates a software uninstall entry

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 2368)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41984
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xaad0
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.3.1.0
ProductVersionNumber: 3.3.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OpenSSL Win64 Installer Team
FileDescription: OpenSSL Light (64-bit) Setup
FileVersion: 3.3.1
LegalCopyright:
ProductName: OpenSSL Light (64-bit)
ProductVersion: 3.3.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
151
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start win64openssl_light-3_3_1.exe win64openssl_light-3_3_1.tmp no specs win64openssl_light-3_3_1.exe win64openssl_light-3_3_1.tmp slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2368"C:\Users\admin\AppData\Local\Temp\is-VIOC3.tmp\Win64OpenSSL_Light-3_3_1.tmp" /SL5="$E03C2,5167959,58368,C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" /SPAWNWND=$2B0052 /NOTIFYWND=$903A4 C:\Users\admin\AppData\Local\Temp\is-VIOC3.tmp\Win64OpenSSL_Light-3_3_1.tmp
Win64OpenSSL_Light-3_3_1.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-vioc3.tmp\win64openssl_light-3_3_1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3944"C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe
explorer.exe
User:
admin
Company:
OpenSSL Win64 Installer Team
Integrity Level:
MEDIUM
Description:
OpenSSL Light (64-bit) Setup
Exit code:
0
Version:
3.3.1
Modules
Images
c:\users\admin\appdata\local\temp\win64openssl_light-3_3_1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4288"C:\Users\admin\AppData\Local\Temp\is-00AK2.tmp\Win64OpenSSL_Light-3_3_1.tmp" /SL5="$903A4,5167959,58368,C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" C:\Users\admin\AppData\Local\Temp\is-00AK2.tmp\Win64OpenSSL_Light-3_3_1.tmpWin64OpenSSL_Light-3_3_1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-00ak2.tmp\win64openssl_light-3_3_1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6772"C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" /SPAWNWND=$2B0052 /NOTIFYWND=$903A4 C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe
Win64OpenSSL_Light-3_3_1.tmp
User:
admin
Company:
OpenSSL Win64 Installer Team
Integrity Level:
HIGH
Description:
OpenSSL Light (64-bit) Setup
Exit code:
0
Version:
3.3.1
Modules
Images
c:\users\admin\appdata\local\temp\win64openssl_light-3_3_1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7132C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
5 049
Read events
5 024
Write events
19
Delete events
6

Modification events

(PID) Process:(2368) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
400900002752C819C3E1DA01
(PID) Process:(2368) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
94AE3ACE915F9F8DEE39E4823B71685D6AD47B0AE2A755935E41D7177FAB8520
(PID) Process:(2368) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(2368) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\OpenSSL-Win64\bin\openssl.exe
(PID) Process:(2368) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
E710CCAD62FDB9D04B3AC86FE7D41E19A72ACB7A7841FCF228B0AB59FBF1B2C8
(PID) Process:(2368) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.6.1 (a)
(PID) Process:(2368) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\OpenSSL-Win64
(PID) Process:(2368) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\OpenSSL-Win64\
(PID) Process:(2368) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: Icon Group
Value:
OpenSSL
(PID) Process:(2368) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
34
Suspicious files
2
Text files
81
Unknown types
3

Dropped files

PID
Process
Filename
Type
3944Win64OpenSSL_Light-3_3_1.exeC:\Users\admin\AppData\Local\Temp\is-00AK2.tmp\Win64OpenSSL_Light-3_3_1.tmpexecutable
MD5:1AFBD25DB5C9A90FE05309F7C4FBCF09
SHA256:3BB0EE5569FE5453C6B3FA25AA517B925D4F8D1F7BA3475E58FA09C46290658C
2368Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\Common Files\SSL\is-S0AHI.tmptext
MD5:5B561A90362B8EB9127C792C3F5902E0
SHA256:F1C1803D13D1D0B755B13B23C28BD4E20E07BAF9F2B744C9337BA5866AA0EC3B
2368Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\Common Files\SSL\ct_log_list.cnftext
MD5:5B561A90362B8EB9127C792C3F5902E0
SHA256:F1C1803D13D1D0B755B13B23C28BD4E20E07BAF9F2B744C9337BA5866AA0EC3B
2368Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\is-6K6GK.tmpexecutable
MD5:952EEA88C679D06BB2D7475661BE6D66
SHA256:446A8701CD05E78ABA98EEDB5CA1B5D3DF1E509F2D803A8BD8119DE24B7A560A
2368Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\bin\PEM\ca-cert.srltext
MD5:307E629E5C5C1C4D31A678949D81548E
SHA256:8460DEB84917C63E1FDB019B02D4332CEAAD0821EDC248ABB69A26FDAF2BB0D8
2368Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\Common Files\SSL\openssl-vms.cnftext
MD5:4E7F115DB5EE9CFEECEE44319927BE9F
SHA256:3F3EAF93AE9C57D37F19C6CA7383123813724CCF109318594D5CC09C8F0F03A4
2368Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\bin\PEM\ca-key.pemtext
MD5:A60DA154BAF6E9B0DC1EDD91121FF45B
SHA256:3490491A6A38D202A29BA250F717B8E3065EB1EE3E16D9E5E9171D3F8F2BF8B5
2368Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\bin\PEM\is-O8QIG.tmptext
MD5:377334238578965DE872E01690988532
SHA256:A4C9B015F67947C38833FA9B2C0A07D4EE4136955FFA3A28A1E34BE048F9B957
2368Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\Common Files\SSL\openssl.cnftext
MD5:E8AFC6A3F874E6D772B1C5902CE1E09E
SHA256:3A0C65FF954AFF207420846926D31D1B6056BE525A0F3D38DFF21F5B89F90688
6772Win64OpenSSL_Light-3_3_1.exeC:\Users\admin\AppData\Local\Temp\is-VIOC3.tmp\Win64OpenSSL_Light-3_3_1.tmpexecutable
MD5:1AFBD25DB5C9A90FE05309F7C4FBCF09
SHA256:3BB0EE5569FE5453C6B3FA25AA517B925D4F8D1F7BA3475E58FA09C46290658C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
64
DNS requests
31
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4424
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4132
OfficeClickToRun.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
3676
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4172
SystemSettings.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
2796
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5368
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4172
SystemSettings.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5368
SearchApp.exe
131.253.33.254:443
a-ring-fallback.msedge.net
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4
System
192.168.100.255:138
whitelisted
5368
SearchApp.exe
104.126.37.131:443
www.bing.com
Akamai International B.V.
DE
unknown
6964
slui.exe
40.91.76.224:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6012
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6564
slui.exe
40.91.76.224:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3952
svchost.exe
239.255.255.250:1900
whitelisted
5368
SearchApp.exe
104.126.37.128:443
www.bing.com
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
t-ring-fdv2.msedge.net
  • 13.107.237.254
unknown
a-ring-fallback.msedge.net
  • 131.253.33.254
unknown
www.bing.com
  • 104.126.37.131
  • 104.126.37.128
  • 104.126.37.145
  • 104.126.37.130
  • 104.126.37.146
  • 104.126.37.184
  • 104.126.37.123
  • 104.126.37.136
  • 104.126.37.144
  • 104.126.37.186
  • 104.126.37.177
  • 104.126.37.176
  • 104.126.37.178
  • 104.126.37.171
  • 2.23.209.161
  • 2.23.209.156
  • 2.23.209.153
  • 2.23.209.160
  • 2.23.209.155
  • 2.23.209.158
  • 2.23.209.151
  • 2.23.209.157
  • 2.23.209.162
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.110
whitelisted
fp-afd-nocache-ccp.azureedge.net
  • 13.107.246.45
whitelisted
login.live.com
  • 20.190.159.68
  • 40.126.31.71
  • 20.190.159.4
  • 20.190.159.23
  • 20.190.159.71
  • 20.190.159.0
  • 40.126.31.69
  • 20.190.159.75
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
fd.api.iris.microsoft.com
  • 20.74.47.205
whitelisted

Threats

No threats detected
No debug info