File name:

Win64OpenSSL_Light-3_3_1.exe

Full analysis: https://app.any.run/tasks/f356116a-1a2b-4a68-a900-7c990406bde9
Verdict: Malicious activity
Analysis date: July 18, 2024, 13:43:14
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B0A83835D91BBC2893AD14A0832B6584

SHA1:

9941722D5D7465F875694C59088051AE502B90F6

SHA256:

FCE75265329B7AA9A2990C6568BED5336185CD413710D4BC5B56CB6563A2FEE6

SSDEEP:

98304:9EAQ3xO7Q1kkhHhyGiLHHoB6o1FM1hKmC/p9vOCupwMtLVG2WJHR1WFoCeycC6WN:iPFocMocl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Win64OpenSSL_Light-3_3_1.exe (PID: 7536)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 2928)
    • Creates a writable file in the system directory

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 5272)
    • Reads security settings of Internet Explorer

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 5272)
    • Executable content was dropped or overwritten

      • Win64OpenSSL_Light-3_3_1.exe (PID: 7536)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 2928)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
    • Reads the Windows owner or organization settings

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
  • INFO

    • Checks supported languages

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 5272)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 7536)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 2928)
    • Reads the computer name

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 5272)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
    • Create files in a temporary directory

      • Win64OpenSSL_Light-3_3_1.exe (PID: 7536)
      • Win64OpenSSL_Light-3_3_1.exe (PID: 2928)
      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
    • Process checks computer location settings

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 5272)
    • Creates files in the program directory

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
    • Creates a software uninstall entry

      • Win64OpenSSL_Light-3_3_1.tmp (PID: 7580)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 41984
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0xaad0
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.3.1.0
ProductVersionNumber: 3.3.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: OpenSSL Win64 Installer Team
FileDescription: OpenSSL Light (64-bit) Setup
FileVersion: 3.3.1
LegalCopyright:
ProductName: OpenSSL Light (64-bit)
ProductVersion: 3.3.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
124
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start win64openssl_light-3_3_1.exe win64openssl_light-3_3_1.tmp no specs win64openssl_light-3_3_1.exe win64openssl_light-3_3_1.tmp slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2928"C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" /SPAWNWND=$302DA /NOTIFYWND=$702D6 C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe
Win64OpenSSL_Light-3_3_1.tmp
User:
admin
Company:
OpenSSL Win64 Installer Team
Integrity Level:
HIGH
Description:
OpenSSL Light (64-bit) Setup
Exit code:
0
Version:
3.3.1
Modules
Images
c:\users\admin\appdata\local\temp\win64openssl_light-3_3_1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5272"C:\Users\admin\AppData\Local\Temp\is-7VLGP.tmp\Win64OpenSSL_Light-3_3_1.tmp" /SL5="$702D6,5167959,58368,C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" C:\Users\admin\AppData\Local\Temp\is-7VLGP.tmp\Win64OpenSSL_Light-3_3_1.tmpWin64OpenSSL_Light-3_3_1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7vlgp.tmp\win64openssl_light-3_3_1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7536"C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe
explorer.exe
User:
admin
Company:
OpenSSL Win64 Installer Team
Integrity Level:
MEDIUM
Description:
OpenSSL Light (64-bit) Setup
Exit code:
0
Version:
3.3.1
Modules
Images
c:\users\admin\appdata\local\temp\win64openssl_light-3_3_1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7580"C:\Users\admin\AppData\Local\Temp\is-7DR0P.tmp\Win64OpenSSL_Light-3_3_1.tmp" /SL5="$40248,5167959,58368,C:\Users\admin\AppData\Local\Temp\Win64OpenSSL_Light-3_3_1.exe" /SPAWNWND=$302DA /NOTIFYWND=$702D6 C:\Users\admin\AppData\Local\Temp\is-7DR0P.tmp\Win64OpenSSL_Light-3_3_1.tmp
Win64OpenSSL_Light-3_3_1.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-7dr0p.tmp\win64openssl_light-3_3_1.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
8064C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
5 080
Read events
5 045
Write events
29
Delete events
6

Modification events

(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
9C1D00009C2B1E7418D9DA01
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
CF4B5E9DC4B7EBC27E3ABEECCB9EA1C6270B95508B1BD8E37BA46A3144A3F8C1
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\OpenSSL-Win64\bin\openssl.exe
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
048BCEA61FD57BEE7140A66F34C1033A292B68008DA2EF8D0AE9C855733B22FC
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.6.1 (a)
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\OpenSSL-Win64
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\OpenSSL-Win64\
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: Icon Group
Value:
OpenSSL
(PID) Process:(7580) Win64OpenSSL_Light-3_3_1.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenSSL Light (64-bit)_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
34
Suspicious files
3
Text files
83
Unknown types
0

Dropped files

PID
Process
Filename
Type
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\Common Files\SSL\openssl.cnftext
MD5:E8AFC6A3F874E6D772B1C5902CE1E09E
SHA256:3A0C65FF954AFF207420846926D31D1B6056BE525A0F3D38DFF21F5B89F90688
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\bin\PEM\is-DCPPF.tmptext
MD5:1AD1509A232D7A91ED07D392C3878BB4
SHA256:A1D0A69A7260D27A140A311A1F9A6E7364859A007F7A18BBD9681CCAA2C55121
7536Win64OpenSSL_Light-3_3_1.exeC:\Users\admin\AppData\Local\Temp\is-7VLGP.tmp\Win64OpenSSL_Light-3_3_1.tmpexecutable
MD5:1AFBD25DB5C9A90FE05309F7C4FBCF09
SHA256:3BB0EE5569FE5453C6B3FA25AA517B925D4F8D1F7BA3475E58FA09C46290658C
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\Common Files\SSL\openssl-vms.cnftext
MD5:4E7F115DB5EE9CFEECEE44319927BE9F
SHA256:3F3EAF93AE9C57D37F19C6CA7383123813724CCF109318594D5CC09C8F0F03A4
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\bin\PEM\ca-cert.srltext
MD5:307E629E5C5C1C4D31A678949D81548E
SHA256:8460DEB84917C63E1FDB019B02D4332CEAAD0821EDC248ABB69A26FDAF2BB0D8
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\Common Files\SSL\is-EQ61A.tmptext
MD5:4E7F115DB5EE9CFEECEE44319927BE9F
SHA256:3F3EAF93AE9C57D37F19C6CA7383123813724CCF109318594D5CC09C8F0F03A4
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\bin\PEM\ca-key.pemtext
MD5:A60DA154BAF6E9B0DC1EDD91121FF45B
SHA256:3490491A6A38D202A29BA250F717B8E3065EB1EE3E16D9E5E9171D3F8F2BF8B5
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\bin\PEM\is-VGARV.tmptext
MD5:307E629E5C5C1C4D31A678949D81548E
SHA256:8460DEB84917C63E1FDB019B02D4332CEAAD0821EDC248ABB69A26FDAF2BB0D8
7580Win64OpenSSL_Light-3_3_1.tmpC:\Users\admin\AppData\Local\Temp\is-K0F3V.tmp\_isetup\_isdecmp.dllexecutable
MD5:FD4743E2A51DD8E0D44F96EAE1853226
SHA256:6535BA91FCCA7174C3974B19D9AB471F322C2BF49506EF03424517310080BE1B
7580Win64OpenSSL_Light-3_3_1.tmpC:\Program Files\OpenSSL-Win64\bin\PEM\is-K8COV.tmptext
MD5:377334238578965DE872E01690988532
SHA256:A4C9B015F67947C38833FA9B2C0A07D4EE4136955FFA3A28A1E34BE048F9B957
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
13
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4032
svchost.exe
239.255.255.250:1900
whitelisted
4716
svchost.exe
40.126.32.72:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1796
backgroundTaskHost.exe
20.74.47.205:443
MICROSOFT-CORP-MSN-AS-BLOCK
FR
unknown
2760
svchost.exe
40.113.103.199:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7856
svchost.exe
4.209.32.198:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1796
backgroundTaskHost.exe
20.223.36.55:443
fd.api.iris.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3552
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4716
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
login.live.com
  • 40.126.32.72
  • 40.126.32.133
  • 40.126.32.138
  • 20.190.160.17
  • 40.126.32.134
  • 40.126.32.140
  • 20.190.160.20
  • 40.126.32.136
whitelisted
google.com
  • 142.250.184.206
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
www.bing.com
  • 92.123.104.15
  • 92.123.104.22
  • 92.123.104.17
  • 92.123.104.16
  • 92.123.104.13
  • 92.123.104.20
  • 92.123.104.21
  • 92.123.104.14
  • 92.123.104.18
whitelisted

Threats

No threats detected
No debug info