File name:

AutoHotkey_1.1.34.04_setup.exe

Full analysis: https://app.any.run/tasks/e1ea791b-f9a4-46f9-a649-b66340929f05
Verdict: Malicious activity
Analysis date: August 23, 2022, 14:31:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

AE9BFA10600EE7D3F253AA844A624B13

SHA1:

490532478297CDAA99C27DB0A5DADCFB651B3A6B

SHA256:

7350F50C3FC022D217821E6F416497820E6216A714C5EE859AF1F36BE9B740D7

SSDEEP:

49152:CFSNtBR9yymFQeRFrtJvBPXOxB4xa6dtM/U/+mWSjeCu+4whc3W4beqX+NWtUWu:CFSN7yqe9tJvBP8uYUnWSj+kHNQC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • AutoHotkey_1.1.34.04_setup.exe (PID: 1816)
      • setup.exe (PID: 2012)
    • Actions looks like stealing of personal data

      • AutoHotkey_1.1.34.04_setup.exe (PID: 1816)
    • Application was dropped or rewritten from another process

      • setup.exe (PID: 2012)
      • AutoHotkey.exe (PID: 3328)
      • AutoHotkey.exe (PID: 3472)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • AutoHotkey_1.1.34.04_setup.exe (PID: 1816)
      • setup.exe (PID: 2012)
    • Drops a file with a compile date too recent

      • AutoHotkey_1.1.34.04_setup.exe (PID: 1816)
      • setup.exe (PID: 2012)
    • Reads the computer name

      • setup.exe (PID: 2012)
      • AutoHotkey.exe (PID: 3328)
    • Checks supported languages

      • setup.exe (PID: 2012)
      • AutoHotkey.exe (PID: 3472)
      • AutoHotkey.exe (PID: 3328)
      • AutoHotkey_1.1.34.04_setup.exe (PID: 1816)
    • Reads Microsoft Outlook installation path

      • setup.exe (PID: 2012)
      • hh.exe (PID: 1228)
    • Reads internet explorer settings

      • setup.exe (PID: 2012)
      • hh.exe (PID: 1228)
    • Creates files in the program directory

      • setup.exe (PID: 2012)
    • Changes default file association

      • setup.exe (PID: 2012)
    • Creates a directory in Program Files

      • setup.exe (PID: 2012)
    • Creates a software uninstall entry

      • setup.exe (PID: 2012)
    • Application launched itself

      • AutoHotkey.exe (PID: 3328)
  • INFO

    • Manual execution by user

      • AutoHotkey.exe (PID: 3328)
    • Checks supported languages

      • hh.exe (PID: 1228)
    • Reads the computer name

      • hh.exe (PID: 1228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start autohotkey_1.1.34.04_setup.exe setup.exe autohotkey.exe no specs autohotkey.exe no specs hh.exe no specs autohotkey_1.1.34.04_setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1228"hh.exe" "ms-its:AutoHotkey.chm::/docs/Welcome.htm"C:\Windows\hh.exeAutoHotkey.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® HTML Help Executable
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\hh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\hhctrl.ocx
c:\windows\system32\user32.dll
1816"C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exe" C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Description:
AutoHotkey Setup
Exit code:
0
Version:
1.1.34.04
Modules
Images
c:\users\admin\appdata\local\temp\autohotkey_1.1.34.04_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2012C:\Users\admin\AppData\Local\Temp\7z34493718\setup.exe C:\Users\admin\AppData\Local\Temp\7z34493718\setup.exe
AutoHotkey_1.1.34.04_setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.1.34.04
Modules
Images
c:\users\admin\appdata\local\temp\7z34493718\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
3068"C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exe" C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
AutoHotkey Setup
Exit code:
3221226540
Version:
1.1.34.04
Modules
Images
c:\users\admin\appdata\local\temp\autohotkey_1.1.34.04_setup.exe
c:\windows\system32\ntdll.dll
3328"C:\Program Files\AutoHotkey\AutoHotkey.exe" "C:\Program Files\AutoHotkey\Installer.ahk" /exec runahkC:\Program Files\AutoHotkey\AutoHotkey.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.34.04
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\autohotkey\autohotkey.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
3472AutoHotkey.exeC:\Program Files\AutoHotkey\AutoHotkey.exeAutoHotkey.exe
User:
admin
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
2
Version:
1.1.34.04
Modules
Images
c:\program files\autohotkey\autohotkey.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
Total events
1 149
Read events
1 098
Write events
51
Delete events
0

Modification events

(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2012) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey
Operation:writeName:InstallDir
Value:
C:\Program Files\AutoHotkey
(PID) Process:(2012) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey
Operation:writeName:Version
Value:
1.1.34.04
(PID) Process:(2012) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey
Operation:writeName:StartMenuFolder
Value:
AutoHotkey
Executable files
17
Suspicious files
0
Text files
18
Unknown types
11

Dropped files

PID
Process
Filename
Type
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\AutoHotkeyU64.exeexecutable
MD5:835C24D817C673C7DAB0EEF9797E8C37
SHA256:7F36D9F4D60864266B5EFE83AC37BA23B464E4DC15FC82889C8EF90DBA418793
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\Compiler\ANSI 32-bit.binexecutable
MD5:EDE133190F07B58C7AA4E3E867BBB153
SHA256:F41E6CFEE66683C30006CBB1A7F33AEA1912FAEA5A28A2EBED42DFC450FE65E5
2012setup.exeC:\Program Files\AutoHotkey\AutoHotkeyU32.exeexecutable
MD5:03C469798BF1827D989F09F346CE95F7
SHA256:DE87C8713FAC002B0B0A0F9B02C4E3EBCCCF65282A22F5AB5912A9DA00F35C2A
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\Compiler\Ahk2Exe.exeexecutable
MD5:669B42CAB39D25552906127F534F45A6
SHA256:DE24A0364A8479A29BD350027FF5830B02216BD69FADED29816C7B3CF51F58C5
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\setup.exeexecutable
MD5:6D754A993E669C94E717093B470158D6
SHA256:9835380AD68B9B660552EDFEAF514CFA03D1A3676E30EC9C06516F2756BD62F3
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\Installer.ahktext
MD5:431996714A2B5AAC720AEE718D8313EA
SHA256:7218A733512E7A808B715B0CE9626361B5DC58AE73972D42A913F2738148464D
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\AutoHotkeyA32.exeexecutable
MD5:6F6BC3C733A886475FF6030AF1F2A2C7
SHA256:EECDB8568B4FCD8758F27468EFAEBA7700F8729DB0A06B8FDD2E20D01E0A3674
2012setup.exeC:\Program Files\AutoHotkey\WindowSpy.ahktext
MD5:32020E55548B1E9E7CE22899617D5CD2
SHA256:4688629BE394986C8DBE6517032429E6E8CDD9F5801DDB1AC1F53E6FE86EEE7B
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\WindowSpy.ahktext
MD5:32020E55548B1E9E7CE22899617D5CD2
SHA256:4688629BE394986C8DBE6517032429E6E8CDD9F5801DDB1AC1F53E6FE86EEE7B
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\Template.ahktext
MD5:A85EEB1DC6F9A33897C407B4240DC20F
SHA256:23E5115A25E2D539057443B0F0E9740B9AE85D7DE0DA204F1D739C9B2E206058
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info