putty.exe
Summary
PuTTY SSH/Telnet client. Popular open-source terminal emulator for remote access. Also used for SSH tunneling, serial console access, and secure file transfer. Occasionally trojanized and distributed in supply chain attacks.
putty.exe is the 1593rd most commonly executed Windows program in EchoTrail's dataset, observed 585 times across enterprise environments. It typically runs from C:\Program Files\PuTTY and it is most often launched by explorer.exe.
Behavior
Top Paths
- C:\Program Files\PuTTY62.22%
- C:\Program Files (x86)\PuTTY20.17%
- C:\Users\...14.53%
- C:\...3.08%
Top Hashes (SHA256)
- 7afb56dd48565c3c9804f683c80ef47e5333f847f2d3211ec11ed13ad36061e143.14%
- 567efd7abb99428737d22bf3f8cee9d23a540b4e1565938b557eec54078b8a3112%
- 9f9e74241d59eccfe7040bfdcbbceacb374eda397cc53a4197b59e4f6f380a9111.91%
- 8aafc0858cb440910b9b7f237124f373389591a488a77d3d367da56bbf4626787.12%
- 35c9df3a348ae805902a95ab8ad32a6d61ef85ca8249ae78f1077edd2429fe6b4.95%
- d4ffa4559a1e22167933772d82cf714cd4bb7a0e79511c2424e18bdb619d63a44.88%
- 81de431987304676134138705fc1c21188ad7f27edf6b77a6551aa693194485e3.11%
- f3a88083d28dcd6fa129e8912a8770e5e9987c69ca7b332672bccfbf4ab1ff212.91%
- abcc2a2d828b1624459cf8c4d2ccdfdcde62c8d1ab51e438db200ab3c5c8cd172.88%
- 12e2bea20981e4c31e8009be676ae25595a7877d03755126df060ae6336148862.1%
Process Ancestry
Top Grandparents
- userinit.exe78.02%
- explorer.exe10.09%
- putty.exe6.57%
- svchost.exe1.54%
- MitelAdminDiag.exe0.67%
- WerFault.exe0.64%
- winlogon.exe0.64%
- googledrivesync.exe0.41%
- RuntimeBroker.exe0.29%
Top Parents
- explorer.exe81.69%
- putty.exe13.82%
- RuntimeBroker.exe1.36%
- MitelAdminDiag.exe0.53%
- javaw.exe0.42%
- cmd.exe0.29%
- chrome.exe0.11%
- powershell.exe0.02%
Top Children
- putty.exe100%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does putty.exe normally do?
Runs from wherever installed (typically Program Files or user download location). Interactive GUI application for SSH/Telnet connections. Used by IT admins and developers for remote system management.
When is putty.exe suspicious?
PuTTY connecting to unusual external IPs. Running from temp directories or unusual paths. Port forwarding enabled. Running as a background process without UI. Trojanized versions — verify hash against official releases.
How do attackers abuse putty.exe?
1. TUNNELING: Same SSH tunneling capabilities as ssh.exe for C2 and data exfiltration. 2. TROJANIZED DISTRIBUTION: North Korean threat actors (Lazarus) have distributed trojanized PuTTY installers as part of Operation Dream Job, targeting security researchers and developers. 3. CREDENTIAL HARVESTING: PuTTY stores session configurations in the registry (HKCU\Software\SimonTatham\PuTTY) including saved sessions with hostnames — useful for attackers mapping infrastructure.
Detection guidance
MEDIUM-CONFIDENCE: - PuTTY with port forwarding configurations - PuTTY connecting to external IPs outside normal admin patterns - PuTTY hash not matching official release hashes (trojanized) - PuTTY running from temp/download directories DATA SOURCES: Process creation (Sysmon 1), network connections (Sysmon 3), registry access for saved sessions
False positive notes
Extremely common among IT administrators and developers. Many organizations standardize on PuTTY for SSH access to Linux systems.
Related Processes
Ask Rocky about putty.exe
Rocky answers questions about putty.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.