File name:

PUBG AUTO HOTKEY SCRIPTS_[unknowncheats.me]_.rar

Full analysis: https://app.any.run/tasks/a1da83a2-f6f0-4a81-81d1-3ae0415efc6b
Verdict: Malicious activity
Analysis date: August 25, 2020, 18:11:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

37FBBFAD28AE62C6DCB96B470AC055BA

SHA1:

273041EAC0EF1F2B55FC0FD62A8B1C2615BEF55C

SHA256:

74A86AE9823F396E3C4E34F88C4DDB58F29485B26FA0A3B00B6F071BCBDFDCB3

SSDEEP:

49152:XzuwQGGDfpcLOaLv4ta9tFQ1wXHBGy0Tc2SK+ICbIbSAnS1eQ91Nl68rXDL24YmA:XSkGDDHmFQ1wsyws7ImAS1eT8rTL245A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • AutoHotkey_1.1.26.01_setup.exe (PID: 3616)
      • AutoHotkey_1.1.26.01_setup.exe (PID: 404)
      • setup.exe (PID: 2668)
      • AutoHotkey_1.1.26.01_setup.exe (PID: 908)
      • setup.exe (PID: 3980)
      • AutoHotkey.exe (PID: 2076)
      • AutoHotkey_1.1.26.01_setup.exe (PID: 3248)
      • AutoHotkey_1.1.26.01_setup.exe (PID: 3012)
      • AutoHotkey_1.1.26.01_setup.exe (PID: 3988)
      • setup.exe (PID: 2600)
    • Actions looks like stealing of personal data

      • AutoHotkey_1.1.26.01_setup.exe (PID: 404)
      • AutoHotkey_1.1.26.01_setup.exe (PID: 3248)
      • AutoHotkey_1.1.26.01_setup.exe (PID: 3988)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • AutoHotkey_1.1.26.01_setup.exe (PID: 404)
      • setup.exe (PID: 2668)
      • WinRAR.exe (PID: 2796)
      • AutoHotkey_1.1.26.01_setup.exe (PID: 3248)
      • AutoHotkey_1.1.26.01_setup.exe (PID: 3988)
    • Reads internet explorer settings

      • setup.exe (PID: 2668)
      • hh.exe (PID: 2800)
      • setup.exe (PID: 2600)
      • setup.exe (PID: 3980)
    • Creates files in the program directory

      • setup.exe (PID: 2668)
    • Creates files in the Windows directory

      • setup.exe (PID: 2668)
    • Modifies the open verb of a shell class

      • setup.exe (PID: 2668)
    • Creates a software uninstall entry

      • setup.exe (PID: 2668)
    • Searches for installed software

      • setup.exe (PID: 3980)
    • Removes files from Windows directory

      • setup.exe (PID: 3980)
  • INFO

    • Manual execution by user

      • hh.exe (PID: 2800)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 355
UncompressedSize: 442
OperatingSystem: Win32
ModifyDate: 2017:11:08 22:54:07
PackingMethod: Normal
ArchivedFileName: PUBG AUTO HOTKEY SCRIPTS\AK NO RECOIL.ahk
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
12
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start drop and start drop and start start drop and start drop and start drop and start winrar.exe autohotkey_1.1.26.01_setup.exe no specs autohotkey_1.1.26.01_setup.exe setup.exe hh.exe no specs autohotkey_1.1.26.01_setup.exe no specs autohotkey_1.1.26.01_setup.exe setup.exe no specs autohotkey.exe no specs autohotkey_1.1.26.01_setup.exe no specs autohotkey_1.1.26.01_setup.exe setup.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
404"C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.45759\PUBG AUTO HOTKEY SCRIPTS\AutoHotkey_1.1.26.01_setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.45759\PUBG AUTO HOTKEY SCRIPTS\AutoHotkey_1.1.26.01_setup.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
AutoHotkey Setup
Exit code:
0
Version:
1.1.26.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2796.45759\pubg auto hotkey scripts\autohotkey_1.1.26.01_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
908"C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.48240\PUBG AUTO HOTKEY SCRIPTS\AutoHotkey_1.1.26.01_setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.48240\PUBG AUTO HOTKEY SCRIPTS\AutoHotkey_1.1.26.01_setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
AutoHotkey Setup
Exit code:
3221226540
Version:
1.1.26.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2796.48240\pubg auto hotkey scripts\autohotkey_1.1.26.01_setup.exe
c:\systemroot\system32\ntdll.dll
2076"C:\Program Files\AutoHotkey\AutoHotkey.exe" "C:\Users\admin\AppData\Local\Temp\VersionTest.ahk"C:\Program Files\AutoHotkey\AutoHotkey.exesetup.exe
User:
admin
Integrity Level:
HIGH
Description:
AutoHotkey Unicode 32-bit
Exit code:
256
Version:
1.1.26.01
Modules
Images
c:\program files\autohotkey\autohotkey.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
2600C:\Users\admin\AppData\Local\Temp\7z59575F94\setup.exe C:\Users\admin\AppData\Local\Temp\7z59575F94\setup.exeAutoHotkey_1.1.26.01_setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.1.26.01
Modules
Images
c:\users\admin\appdata\local\temp\7z59575f94\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
2668C:\Users\admin\AppData\Local\Temp\7z53450194\setup.exe C:\Users\admin\AppData\Local\Temp\7z53450194\setup.exe
AutoHotkey_1.1.26.01_setup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
1.1.26.01
Modules
Images
c:\users\admin\appdata\local\temp\7z53450194\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
2796"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\PUBG AUTO HOTKEY SCRIPTS_[unknowncheats.me]_.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
2800"C:\Windows\hh.exe" mk:@MSITStore:C:\Users\admin\AppData\Local\Temp\7z53450194\AutoHotkey.chm::/docs/AHKL_ChangeLog.htmC:\Windows\hh.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® HTML Help Executable
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\hh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\hhctrl.ocx
c:\windows\system32\user32.dll
3012"C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.49811\PUBG AUTO HOTKEY SCRIPTS\AutoHotkey_1.1.26.01_setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.49811\PUBG AUTO HOTKEY SCRIPTS\AutoHotkey_1.1.26.01_setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
AutoHotkey Setup
Exit code:
3221226540
Version:
1.1.26.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2796.49811\pubg auto hotkey scripts\autohotkey_1.1.26.01_setup.exe
c:\systemroot\system32\ntdll.dll
3248"C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.48240\PUBG AUTO HOTKEY SCRIPTS\AutoHotkey_1.1.26.01_setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.48240\PUBG AUTO HOTKEY SCRIPTS\AutoHotkey_1.1.26.01_setup.exe
WinRAR.exe
User:
admin
Integrity Level:
HIGH
Description:
AutoHotkey Setup
Exit code:
0
Version:
1.1.26.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2796.48240\pubg auto hotkey scripts\autohotkey_1.1.26.01_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3616"C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.45759\PUBG AUTO HOTKEY SCRIPTS\AutoHotkey_1.1.26.01_setup.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2796.45759\PUBG AUTO HOTKEY SCRIPTS\AutoHotkey_1.1.26.01_setup.exeWinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Description:
AutoHotkey Setup
Exit code:
3221226540
Version:
1.1.26.01
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2796.45759\pubg auto hotkey scripts\autohotkey_1.1.26.01_setup.exe
c:\systemroot\system32\ntdll.dll
Total events
1 010
Read events
924
Write events
67
Delete events
19

Modification events

(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2796) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2796) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\137\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\PUBG AUTO HOTKEY SCRIPTS_[unknowncheats.me]_.rar
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2796) WinRAR.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
39
Suspicious files
0
Text files
37
Unknown types
12

Dropped files

PID
Process
Filename
Type
2796WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2796.45759\PUBG AUTO HOTKEY SCRIPTS\AutoHotkey_1.1.26.01_setup.exeexecutable
MD5:CBA6D31679870ADD7166EA8628FB081B
SHA256:64D391B2E42B022D5ADC1BB5B342F5B631E347CCE1BBE027945A6F0A6A664AF2
404AutoHotkey_1.1.26.01_setup.exeC:\Users\admin\AppData\Local\Temp\7z53450194\Compiler\Unicode 32-bit.binexecutable
MD5:EBAF02A89A7E88FEF30E961B3EA2DAB1
SHA256:032F9C39B5D4CC22E9EF7B0FD1092887112C118EDC11855664F51BB800C44E99
404AutoHotkey_1.1.26.01_setup.exeC:\Users\admin\AppData\Local\Temp\7z53450194\license.txttext
MD5:E3F2AD7733F3166FE770E4DC00AF6C45
SHA256:B27C1A7C92686E47F8740850AD24877A50BE23FD3DBD44EDEE50AC1223135E38
404AutoHotkey_1.1.26.01_setup.exeC:\Users\admin\AppData\Local\Temp\7z53450194\AU3_Spy.exeexecutable
MD5:980BFE20AD22A850A39DDB1C4EF39F47
SHA256:5637038C2E6343EC9EC533B1048E58023AED15E4BE87D31C24D0EF5B17F4A3AB
404AutoHotkey_1.1.26.01_setup.exeC:\Users\admin\AppData\Local\Temp\7z53450194\Compiler\Ahk2Exe.exeexecutable
MD5:F5C83F2CB1B26DEFF26953C6A17D116B
SHA256:29023A9F35ADB27997C6B4961B34EEA1F56D4F72339B8C4B78F8CA6143A13081
404AutoHotkey_1.1.26.01_setup.exeC:\Users\admin\AppData\Local\Temp\7z53450194\Compiler\readme.txttext
MD5:7DC396DF6D33B515684FC351F3D84410
SHA256:EA06BAFAE404A13B5F4AE9AB7901D0865FAACC1E252306AC52051E6AF5CD80A7
404AutoHotkey_1.1.26.01_setup.exeC:\Users\admin\AppData\Local\Temp\7z53450194\AutoHotkeyU32.exeexecutable
MD5:FA7C080F02B8A18F3C151DEB812CA35B
SHA256:1B5E7860C517AD4C70EB750E0F0EECD43A1CF90DF3ADC4B5195242EF8944E9E1
404AutoHotkey_1.1.26.01_setup.exeC:\Users\admin\AppData\Local\Temp\7z53450194\Compiler\Unicode 64-bit.binexecutable
MD5:6823C30D573D47945A6159E0B2122DE0
SHA256:BA4D0284E83C0883E180E0A8603C51321E7A8677F310A87007BCE814CA58ABF6
404AutoHotkey_1.1.26.01_setup.exeC:\Users\admin\AppData\Local\Temp\7z53450194\setup.exeexecutable
MD5:B9CDED1124C0C0A34792083FA99C6A45
SHA256:7B9F3B32199EFBF5E31A409224F011A363F28B030716665FB6E86C38467BE1EF
404AutoHotkey_1.1.26.01_setup.exeC:\Users\admin\AppData\Local\Temp\7z53450194\AutoHotkeyU64.exeexecutable
MD5:5A5E15CEEF9AD54B309A917A45897D2D
SHA256:BC5EAF53C7C136C517672A655BD81D751DC39B9E1CFFA46E25E7F874EE5D5DA9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info