| File name: | AutoHotkey_1.1.34.04_setup.exe |
| Full analysis: | https://app.any.run/tasks/e1ea791b-f9a4-46f9-a649-b66340929f05 |
| Verdict: | Malicious activity |
| Analysis date: | August 23, 2022, 14:31:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | AE9BFA10600EE7D3F253AA844A624B13 |
| SHA1: | 490532478297CDAA99C27DB0A5DADCFB651B3A6B |
| SHA256: | 7350F50C3FC022D217821E6F416497820E6216A714C5EE859AF1F36BE9B740D7 |
| SSDEEP: | 49152:CFSNtBR9yymFQeRFrtJvBPXOxB4xa6dtM/U/+mWSjeCu+4whc3W4beqX+NWtUWu:CFSN7yqe9tJvBP8uYUnWSj+kHNQC |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1228 | "hh.exe" "ms-its:AutoHotkey.chm::/docs/Welcome.htm" | C:\Windows\hh.exe | — | AutoHotkey.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® HTML Help Executable Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1816 | "C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exe" | C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: HIGH Description: AutoHotkey Setup Exit code: 0 Version: 1.1.34.04 Modules
| |||||||||||||||
| 2012 | C:\Users\admin\AppData\Local\Temp\7z34493718\setup.exe | C:\Users\admin\AppData\Local\Temp\7z34493718\setup.exe | AutoHotkey_1.1.34.04_setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.1.34.04 Modules
| |||||||||||||||
| 3068 | "C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exe" | C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: AutoHotkey Setup Exit code: 3221226540 Version: 1.1.34.04 Modules
| |||||||||||||||
| 3328 | "C:\Program Files\AutoHotkey\AutoHotkey.exe" "C:\Program Files\AutoHotkey\Installer.ahk" /exec runahk | C:\Program Files\AutoHotkey\AutoHotkey.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Description: AutoHotkey Unicode 32-bit Exit code: 0 Version: 1.1.34.04 Modules
| |||||||||||||||
| 3472 | AutoHotkey.exe | C:\Program Files\AutoHotkey\AutoHotkey.exe | — | AutoHotkey.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: AutoHotkey Unicode 32-bit Exit code: 2 Version: 1.1.34.04 Modules
| |||||||||||||||
| (PID) Process: | (2012) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2012) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2012) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2012) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2012) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2012) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2012) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2012) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey |
| Operation: | write | Name: | InstallDir |
Value: C:\Program Files\AutoHotkey | |||
| (PID) Process: | (2012) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey |
| Operation: | write | Name: | Version |
Value: 1.1.34.04 | |||
| (PID) Process: | (2012) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey |
| Operation: | write | Name: | StartMenuFolder |
Value: AutoHotkey | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1816 | AutoHotkey_1.1.34.04_setup.exe | C:\Users\admin\AppData\Local\Temp\7z34493718\AutoHotkeyU64.exe | executable | |
MD5:835C24D817C673C7DAB0EEF9797E8C37 | SHA256:7F36D9F4D60864266B5EFE83AC37BA23B464E4DC15FC82889C8EF90DBA418793 | |||
| 1816 | AutoHotkey_1.1.34.04_setup.exe | C:\Users\admin\AppData\Local\Temp\7z34493718\AutoHotkeyA32.exe | executable | |
MD5:6F6BC3C733A886475FF6030AF1F2A2C7 | SHA256:EECDB8568B4FCD8758F27468EFAEBA7700F8729DB0A06B8FDD2E20D01E0A3674 | |||
| 1816 | AutoHotkey_1.1.34.04_setup.exe | C:\Users\admin\AppData\Local\Temp\7z34493718\license.txt | text | |
MD5:E3F2AD7733F3166FE770E4DC00AF6C45 | SHA256:B27C1A7C92686E47F8740850AD24877A50BE23FD3DBD44EDEE50AC1223135E38 | |||
| 1816 | AutoHotkey_1.1.34.04_setup.exe | C:\Users\admin\AppData\Local\Temp\7z34493718\AutoHotkey.chm | chm | |
MD5:D57EEB3B1B1DC23C25FC89A4E2FF6444 | SHA256:982DA174108F5F1D9C1200879CEB3EA0D6F081BE77A2EE687B9B87B418D0D750 | |||
| 1816 | AutoHotkey_1.1.34.04_setup.exe | C:\Users\admin\AppData\Local\Temp\7z34493718\Compiler\ANSI 32-bit.bin | executable | |
MD5:EDE133190F07B58C7AA4E3E867BBB153 | SHA256:F41E6CFEE66683C30006CBB1A7F33AEA1912FAEA5A28A2EBED42DFC450FE65E5 | |||
| 2012 | setup.exe | C:\Program Files\AutoHotkey\AutoHotkeyU32.exe | executable | |
MD5:03C469798BF1827D989F09F346CE95F7 | SHA256:DE87C8713FAC002B0B0A0F9B02C4E3EBCCCF65282A22F5AB5912A9DA00F35C2A | |||
| 1816 | AutoHotkey_1.1.34.04_setup.exe | C:\Users\admin\AppData\Local\Temp\7z34493718\AutoHotkeyU32.exe | executable | |
MD5:03C469798BF1827D989F09F346CE95F7 | SHA256:DE87C8713FAC002B0B0A0F9B02C4E3EBCCCF65282A22F5AB5912A9DA00F35C2A | |||
| 1816 | AutoHotkey_1.1.34.04_setup.exe | C:\Users\admin\AppData\Local\Temp\7z34493718\setup.exe | executable | |
MD5:6D754A993E669C94E717093B470158D6 | SHA256:9835380AD68B9B660552EDFEAF514CFA03D1A3676E30EC9C06516F2756BD62F3 | |||
| 1816 | AutoHotkey_1.1.34.04_setup.exe | C:\Users\admin\AppData\Local\Temp\7z34493718\Installer.ahk | text | |
MD5:431996714A2B5AAC720AEE718D8313EA | SHA256:7218A733512E7A808B715B0CE9626361B5DC58AE73972D42A913F2738148464D | |||
| 1816 | AutoHotkey_1.1.34.04_setup.exe | C:\Users\admin\AppData\Local\Temp\7z34493718\Compiler\Unicode 32-bit.bin | executable | |
MD5:96C54C207DFD4D94A07EF2209D9B38CD | SHA256:E6BC4E7BD473494EA8803EE2FF32E8CDB35229F6F3A888E940A3ADA81829CE9E | |||