File name:

Win64OpenSSL_Light-3_3_1.exe

Full analysis: https://app.any.run/tasks/f356116a-1a2b-4a68-a900-7c990406bde9
Verdict: Malicious activity
Analysis date: July 18, 2024, 13:43:14
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B0A83835D91BBC2893AD14A0832B6584

SHA1:

9941722D5D7465F875694C59088051AE502B90F6

SHA256:

FCE75265329B7AA9A2990C6568BED5336185CD413710D4BC5B56CB6563A2FEE6

SSDEEP:

98304:9EAQ3xO7Q1kkhHhyGiLHHoB6o1FM1hKmC/p9vOCupwMtLVG2WJHR1WFoCeycC6WN:iPFocMocl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Win64OpenSSL_Light-3_3_1.exe (PID: 7536)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 2928)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
    • Creates a writable file in the system directory

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Win64OpenSSL_Light-3_3_1.exe (PID: 7536)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 2928)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
    • Reads security settings of Internet Explorer

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 5272)
    • Reads the date of Windows installation

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 5272)
    • Reads the Windows owner or organization settings

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
  • INFO

    • Create files in a temporary directory

      • Win64OpenSSL_Light-3_3_1.exe (PID: 7536)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 2928)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
    • Checks supported languages

      • Win64OpenSSL_Light-3_3_1.exe (PID: 7536)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 5272)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 2928)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
    • Reads the computer name

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 5272)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
    • Process checks computer location settings

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 5272)
    • Creates files in the program directory

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
    • Creates a software uninstall entry

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41984
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xaad0
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.3.1.0
ProductVersionNumber: 3.3.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OpenSSL Win64 Installer Team
FileDescription: OpenSSL Light (64-bit) Setup
FileVersion: 3.3.1
LegalCopyright:
ProductName: OpenSSL Light (64-bit)
ProductVersion: 3.3.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
124
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start win64openssl_light-3_3_1.exe win64openssl_light-3_3_1.tmp no specs win64openssl_light-3_3_1.exe win64openssl_light-3_3_1.tmp slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2928"C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" /SPAWNWND=$302DA /NOTIFYWND=$702D6 C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe
Win64OpenSSL_Light-3_3_1.tmp
User:
admin
Company:
OpenSSL Win64 Installer Team
Integrity Level:
HIGH
Description:
OpenSSL Light (64-bit) Setup
Exit code:
0
Version:
3.3.1
Modules
Images
c:\users\admin\appdata\local\temp\win64openssl_light-3_3_1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5272"C:\Users\admin\AppData\Local\Temp\is-7VLGP.tmp\Win64OpenSSL_Light-3_3_1.tmp" /SL5="$702D6,5167959,58368,C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" C:\Users\admin\AppData\Local\Temp\is-7VLGP.tmp\Win64OpenSSL_Light-3_3_1.tmpWin64OpenSSL_Light-3_3_1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7vlgp.tmp\win64openssl_light-3_3_1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7536"C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe
explorer.exe
User:
admin
Company:
OpenSSL Win64 Installer Team
Integrity Level:
MEDIUM
Description:
OpenSSL Light (64-bit) Setup
Exit code:
0
Version:
3.3.1
Modules
Images
c:\users\admin\appdata\local\temp\win64openssl_light-3_3_1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7580"C:\Users\admin\AppData\Local\Temp\is-7DR0P.tmp\Win64OpenSSL_Light-3_3_1.tmp" /SL5="$40248,5167959,58368,C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" /SPAWNWND=$302DA /NOTIFYWND=$702D6 C:\Users\admin\AppData\Local\Temp\is-7DR0P.tmp\Win64OpenSSL_Light-3_3_1.tmp
Win64OpenSSL_Light-3_3_1.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7dr0p.tmp\win64openssl_light-3_3_1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
8064C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
5 080
Read events
5 045
Write events
29
Delete events
6

Modification events

(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
9C1D00009C2B1E7418D9DA01
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
CF4B5E9DC4B7EBC27E3ABEECCB9EA1C6270B95508B1BD8E37BA46A3144A3F8C1
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\OpenSSL-Win64\bin\openssl.exe
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
048BCEA61FD57BEE7140A66F34C1033A292B68008DA2EF8D0AE9C855733B22FC
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.6.1 (a)
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\OpenSSL-Win64
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\OpenSSL-Win64\
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: Icon Group
Value:
OpenSSL
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
34
Suspicious files
3
Text files
83
Unknown types
0

Dropped files

PID
Process
Filename
Type
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\Common Files\SSL\is-O4ROV.tmptext
MD5:5B561A90362B8EB9127C792C3F5902E0
SHA256:F1C1803D13D1D0B755B13B23C28BD4E20E07BAF9F2B744C9337BA5866AA0EC3B
7580Win64OpenSSL_Light-3_3_1.tmpC:\Users\admin\AppData\Local\Temp\is-K0F3V.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\unins000.exeexecutable
MD5:952EEA88C679D06BB2D7475661BE6D66
SHA256:446A8701CD05E78ABA98EEDB5CA1B5D3DF1E509F2D803A8BD8119DE24B7A560A
2928Win64OpenSSL_Light-3_3_1.exeC:\Users\admin\AppData\Local\Temp\is-7DR0P.tmp\Win64OpenSSL_Light-3_3_1.tmpexecutable
MD5:1AFBD25DB5C9A90FE05309F7C4FBCF09
SHA256:3BB0EE5569FE5453C6B3FA25AA517B925D4F8D1F7BA3475E58FA09C46290658C
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\Common Files\SSL\ct_log_list.cnftext
MD5:5B561A90362B8EB9127C792C3F5902E0
SHA256:F1C1803D13D1D0B755B13B23C28BD4E20E07BAF9F2B744C9337BA5866AA0EC3B
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\is-2A4UO.tmpexecutable
MD5:952EEA88C679D06BB2D7475661BE6D66
SHA256:446A8701CD05E78ABA98EEDB5CA1B5D3DF1E509F2D803A8BD8119DE24B7A560A
7536Win64OpenSSL_Light-3_3_1.exeC:\Users\admin\AppData\Local\Temp\is-7VLGP.tmp\Win64OpenSSL_Light-3_3_1.tmpexecutable
MD5:1AFBD25DB5C9A90FE05309F7C4FBCF09
SHA256:3BB0EE5569FE5453C6B3FA25AA517B925D4F8D1F7BA3475E58FA09C46290658C
7580Win64OpenSSL_Light-3_3_1.tmpC:\Users\admin\AppData\Local\Temp\is-K0F3V.tmp\_isetup\_isdecmp.dllexecutable
MD5:FD4743E2A51DD8E0D44F96EAE1853226
SHA256:6535BA91FCCA7174C3974B19D9AB471F322C2BF49506EF03424517310080BE1B
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\bin\PEM\ca-key.pemtext
MD5:A60DA154BAF6E9B0DC1EDD91121FF45B
SHA256:3490491A6A38D202A29BA250F717B8E3065EB1EE3E16D9E5E9171D3F8F2BF8B5
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\bin\PEM\is-CH2U0.tmptext
MD5:A60DA154BAF6E9B0DC1EDD91121FF45B
SHA256:3490491A6A38D202A29BA250F717B8E3065EB1EE3E16D9E5E9171D3F8F2BF8B5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
13
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4032
svchost.exe
239.255.255.250:1900
whitelisted
4716
svchost.exe
40.126.32.72:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1796
backgroundTaskHost.exe
20.74.47.205:443
MICROSOFT-CORP-MSN-AS-BLOCK
FR
unknown
2760
svchost.exe
40.113.103.199:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7856
svchost.exe
4.209.32.198:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1796
backgroundTaskHost.exe
20.223.36.55:443
fd.api.iris.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3552
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4716
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
login.live.com
  • 40.126.32.72
  • 40.126.32.133
  • 40.126.32.138
  • 20.190.160.17
  • 40.126.32.134
  • 40.126.32.140
  • 20.190.160.20
  • 40.126.32.136
whitelisted
google.com
  • 142.250.184.206
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
www.bing.com
  • 92.123.104.15
  • 92.123.104.22
  • 92.123.104.17
  • 92.123.104.16
  • 92.123.104.13
  • 92.123.104.20
  • 92.123.104.21
  • 92.123.104.14
  • 92.123.104.18
whitelisted

Threats

No threats detected
No debug info