File name:

AutoHotkey_1.1.34.04_setup.exe

Full analysis: https://app.any.run/tasks/e1ea791b-f9a4-46f9-a649-b66340929f05
Verdict: Malicious activity
Analysis date: August 23, 2022, 14:31:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

AE9BFA10600EE7D3F253AA844A624B13

SHA1:

490532478297CDAA99C27DB0A5DADCFB651B3A6B

SHA256:

7350F50C3FC022D217821E6F416497820E6216A714C5EE859AF1F36BE9B740D7

SSDEEP:

49152:CFSNtBR9yymFQeRFrtJvBPXOxB4xa6dtM/U/+mWSjeCu+4whc3W4beqX+NWtUWu:CFSN7yqe9tJvBP8uYUnWSj+kHNQC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • AutoHotkey_1.1.34.04_setup.exe (PID: 1816)
    • Drops executable file immediately after starts

      • AutoHotkey_1.1.34.04_setup.exe (PID: 1816)
      • setup.exe (PID: 2012)
    • Application was dropped or rewritten from another process

      • AutoHotkey.exe (PID: 3328)
      • AutoHotkey.exe (PID: 3472)
      • setup.exe (PID: 2012)
  • SUSPICIOUS

    • Checks supported languages

      • setup.exe (PID: 2012)
      • AutoHotkey_1.1.34.04_setup.exe (PID: 1816)
      • AutoHotkey.exe (PID: 3328)
      • AutoHotkey.exe (PID: 3472)
    • Drops a file with a compile date too recent

      • AutoHotkey_1.1.34.04_setup.exe (PID: 1816)
      • setup.exe (PID: 2012)
    • Executable content was dropped or overwritten

      • AutoHotkey_1.1.34.04_setup.exe (PID: 1816)
      • setup.exe (PID: 2012)
    • Changes default file association

      • setup.exe (PID: 2012)
    • Reads internet explorer settings

      • setup.exe (PID: 2012)
      • hh.exe (PID: 1228)
    • Creates a software uninstall entry

      • setup.exe (PID: 2012)
    • Application launched itself

      • AutoHotkey.exe (PID: 3328)
    • Reads the computer name

      • AutoHotkey.exe (PID: 3328)
      • setup.exe (PID: 2012)
    • Reads Microsoft Outlook installation path

      • hh.exe (PID: 1228)
      • setup.exe (PID: 2012)
    • Creates files in the program directory

      • setup.exe (PID: 2012)
    • Creates a directory in Program Files

      • setup.exe (PID: 2012)
  • INFO

    • Manual execution by user

      • AutoHotkey.exe (PID: 3328)
    • Reads the computer name

      • hh.exe (PID: 1228)
    • Checks supported languages

      • hh.exe (PID: 1228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start start autohotkey_1.1.34.04_setup.exe setup.exe autohotkey.exe no specs autohotkey.exe no specs hh.exe no specs autohotkey_1.1.34.04_setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1228"hh.exe" "ms-its:AutoHotkey.chm::/docs/Welcome.htm"C:\Windows\hh.exeAutoHotkey.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® HTML Help Executable
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\hh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\hhctrl.ocx
c:\windows\system32\user32.dll
1816"C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exe" C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Description:
AutoHotkey Setup
Exit code:
0
Version:
1.1.34.04
Modules
Images
c:\users\admin\appdata\local\temp\autohotkey_1.1.34.04_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
2012C:\Users\admin\AppData\Local\Temp\7z34493718\setup.exe C:\Users\admin\AppData\Local\Temp\7z34493718\setup.exe
AutoHotkey_1.1.34.04_setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.1.34.04
Modules
Images
c:\users\admin\appdata\local\temp\7z34493718\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\user32.dll
3068"C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exe" C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.34.04_setup.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
AutoHotkey Setup
Exit code:
3221226540
Version:
1.1.34.04
Modules
Images
c:\users\admin\appdata\local\temp\autohotkey_1.1.34.04_setup.exe
c:\windows\system32\ntdll.dll
3328"C:\Program Files\AutoHotkey\AutoHotkey.exe" "C:\Program Files\AutoHotkey\Installer.ahk" /exec runahkC:\Program Files\AutoHotkey\AutoHotkey.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.34.04
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\autohotkey\autohotkey.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
3472AutoHotkey.exeC:\Program Files\AutoHotkey\AutoHotkey.exeAutoHotkey.exe
User:
admin
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
2
Version:
1.1.34.04
Modules
Images
c:\program files\autohotkey\autohotkey.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
Total events
1 149
Read events
1 098
Write events
51
Delete events
0

Modification events

(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2012) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2012) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey
Operation:writeName:InstallDir
Value:
C:\Program Files\AutoHotkey
(PID) Process:(2012) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey
Operation:writeName:Version
Value:
1.1.34.04
(PID) Process:(2012) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey
Operation:writeName:StartMenuFolder
Value:
AutoHotkey
Executable files
17
Suspicious files
0
Text files
18
Unknown types
11

Dropped files

PID
Process
Filename
Type
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\AutoHotkeyU64.exeexecutable
MD5:835C24D817C673C7DAB0EEF9797E8C37
SHA256:7F36D9F4D60864266B5EFE83AC37BA23B464E4DC15FC82889C8EF90DBA418793
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\AutoHotkeyA32.exeexecutable
MD5:6F6BC3C733A886475FF6030AF1F2A2C7
SHA256:EECDB8568B4FCD8758F27468EFAEBA7700F8729DB0A06B8FDD2E20D01E0A3674
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\license.txttext
MD5:E3F2AD7733F3166FE770E4DC00AF6C45
SHA256:B27C1A7C92686E47F8740850AD24877A50BE23FD3DBD44EDEE50AC1223135E38
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\AutoHotkey.chmchm
MD5:D57EEB3B1B1DC23C25FC89A4E2FF6444
SHA256:982DA174108F5F1D9C1200879CEB3EA0D6F081BE77A2EE687B9B87B418D0D750
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\Compiler\ANSI 32-bit.binexecutable
MD5:EDE133190F07B58C7AA4E3E867BBB153
SHA256:F41E6CFEE66683C30006CBB1A7F33AEA1912FAEA5A28A2EBED42DFC450FE65E5
2012setup.exeC:\Program Files\AutoHotkey\AutoHotkeyU32.exeexecutable
MD5:03C469798BF1827D989F09F346CE95F7
SHA256:DE87C8713FAC002B0B0A0F9B02C4E3EBCCCF65282A22F5AB5912A9DA00F35C2A
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\AutoHotkeyU32.exeexecutable
MD5:03C469798BF1827D989F09F346CE95F7
SHA256:DE87C8713FAC002B0B0A0F9B02C4E3EBCCCF65282A22F5AB5912A9DA00F35C2A
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\setup.exeexecutable
MD5:6D754A993E669C94E717093B470158D6
SHA256:9835380AD68B9B660552EDFEAF514CFA03D1A3676E30EC9C06516F2756BD62F3
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\Installer.ahktext
MD5:431996714A2B5AAC720AEE718D8313EA
SHA256:7218A733512E7A808B715B0CE9626361B5DC58AE73972D42A913F2738148464D
1816AutoHotkey_1.1.34.04_setup.exeC:\Users\admin\AppData\Local\Temp\7z34493718\Compiler\Unicode 32-bit.binexecutable
MD5:96C54C207DFD4D94A07EF2209D9B38CD
SHA256:E6BC4E7BD473494EA8803EE2FF32E8CDB35229F6F3A888E940A3ADA81829CE9E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info