File name: | AutoHotkey_1.1.30.03_setup.exe |
Full analysis: | https://app.any.run/tasks/23a29fce-036c-4ee0-91ed-b556ac9ca706 |
Verdict: | Malicious activity |
Analysis date: | May 30, 2020, 18:24:29 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | FA2625BE0F5255AC3731215008447FA2 |
SHA1: | BF884FB93D67D105576331E786BAA745C24BAE34 |
SHA256: | 9C044862A4CD488B3B69B77AB775ADB43643B686B2AF367A9667E936322A63A4 |
SSDEEP: | 98304:K8ujRtOHxXVYwrpXn9uchZprcCWDzHMsqHFoPt7G2:K8u6Rlv13JZprQD7o2 |
.dll | | | Win32 Dynamic Link Library (generic) (43.5) |
---|---|---|
.exe | | | Win32 Executable (generic) (29.8) |
.exe | | | Generic Win/DOS Executable (13.2) |
.exe | | | DOS Executable Generic (13.2) |
ProductVersion: | 1.1.30.03 |
---|---|
ProductName: | AutoHotkey |
FileVersion: | 1.1.30.03 |
FileDescription: | AutoHotkey Setup |
CharacterSet: | Unicode |
LanguageCode: | English (U.S.) |
FileSubtype: | - |
ObjectFileType: | Executable application |
FileOS: | Windows NT 32-bit |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 1.1.30.3 |
FileVersionNumber: | 1.1.30.3 |
Subsystem: | Windows GUI |
SubsystemVersion: | 4 |
ImageVersion: | - |
OSVersion: | 4 |
EntryPoint: | 0x643f |
UninitializedDataSize: | - |
InitializedDataSize: | 33792 |
CodeSize: | 22016 |
LinkerVersion: | 6 |
PEType: | PE32 |
TimeStamp: | 2010:11:18 19:41:55+01:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 18-Nov-2010 18:41:55 |
Detected languages: |
|
FileDescription: | AutoHotkey Setup |
FileVersion: | 1.1.30.03 |
ProductName: | AutoHotkey |
ProductVersion: | 1.1.30.03 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x000000D8 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 4 |
Time date stamp: | 18-Nov-2010 18:41:55 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000055CC | 0x00005600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.59892 |
.rdata | 0x00007000 | 0x00000548 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.38017 |
.data | 0x00008000 | 0x0000220C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.32755 |
.rsrc | 0x0000B000 | 0x000058DF | 0x00005A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.37766 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.31459 | 727 | UNKNOWN | UNKNOWN | RT_MANIFEST |
2 | 3.18403 | 296 | UNKNOWN | English - United States | RT_ICON |
3 | 3.1643 | 744 | UNKNOWN | UNKNOWN | RT_ICON |
4 | 3.5146 | 296 | UNKNOWN | UNKNOWN | RT_ICON |
5 | 5.93897 | 2216 | UNKNOWN | UNKNOWN | RT_ICON |
6 | 3.37592 | 1384 | UNKNOWN | UNKNOWN | RT_ICON |
7 | 5.199 | 9640 | UNKNOWN | UNKNOWN | RT_ICON |
8 | 5.44465 | 4264 | UNKNOWN | UNKNOWN | RT_ICON |
9 | 4.85349 | 1128 | UNKNOWN | UNKNOWN | RT_ICON |
KERNEL32.dll |
MSVCRT.dll |
SHELL32.dll |
USER32.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2664 | "C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.30.03_setup.exe" | C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.30.03_setup.exe | — | explorer.exe |
User: admin Integrity Level: MEDIUM Description: AutoHotkey Setup Exit code: 3221226540 Version: 1.1.30.03 | ||||
2508 | "C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.30.03_setup.exe" | C:\Users\admin\AppData\Local\Temp\AutoHotkey_1.1.30.03_setup.exe | explorer.exe | |
User: admin Integrity Level: HIGH Description: AutoHotkey Setup Exit code: 0 Version: 1.1.30.03 | ||||
3472 | C:\Users\admin\AppData\Local\Temp\7z0ED849CC\setup.exe | C:\Users\admin\AppData\Local\Temp\7z0ED849CC\setup.exe | AutoHotkey_1.1.30.03_setup.exe | |
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.1.30.03 | ||||
2344 | "C:\Windows\hh.exe" mk:@MSITStore:C:\Users\admin\AppData\Local\Temp\7z0ED849CC\AutoHotkey.chm::/docs/AHKL_ChangeLog.htm | C:\Windows\hh.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® HTML Help Executable Exit code: 3221225547 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
(PID) Process: | (3472) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (3472) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (3472) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (3472) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (3472) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (3472) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey |
Operation: | write | Name: | InstallDir |
Value: C:\Program Files\AutoHotkey | |||
(PID) Process: | (3472) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey |
Operation: | write | Name: | Version |
Value: 1.1.30.03 | |||
(PID) Process: | (3472) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\AutoHotkey |
Operation: | write | Name: | StartMenuFolder |
Value: AutoHotkey | |||
(PID) Process: | (3472) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ahk |
Operation: | write | Name: | |
Value: AutoHotkeyScript | |||
(PID) Process: | (3472) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ahk\ShellNew |
Operation: | write | Name: | FileName |
Value: Template.ahk |
PID | Process | Filename | Type | |
---|---|---|---|---|
2508 | AutoHotkey_1.1.30.03_setup.exe | C:\Users\admin\AppData\Local\Temp\7z0ED849CC\AutoHotkey.chm | chm | |
MD5:8FEBCA19D269FA7F6DA04DB3E4A8D1B2 | SHA256:CD2A5F24243AE18D20FCE17707924FC3404993D20C65456C7F50200C1D72D3B8 | |||
3472 | setup.exe | C:\Program Files\AutoHotkey\Installer.ahk | text | |
MD5:822BE09B42717A81C8042BCFAD09F504 | SHA256:BF2DB211C8FC56797F7668E22FA7C123022C8DA1F0D45AD59CFB7BF1CD1518B0 | |||
2508 | AutoHotkey_1.1.30.03_setup.exe | C:\Users\admin\AppData\Local\Temp\7z0ED849CC\AutoHotkeyU32.exe | executable | |
MD5:3B02391B4546307DCAE5A57B0BBD7041 | SHA256:0DAD23C0E6C295C32E90479116DC58663CC8818735E8B8E2193E85BD9A68B428 | |||
2508 | AutoHotkey_1.1.30.03_setup.exe | C:\Users\admin\AppData\Local\Temp\7z0ED849CC\setup.exe | executable | |
MD5:680CA8A1C751942113D62A481D1AED06 | SHA256:6A2E4B72B15DB3DD6C25530FC39C5B0C030B29F3D273C56534121728E6D615B5 | |||
2508 | AutoHotkey_1.1.30.03_setup.exe | C:\Users\admin\AppData\Local\Temp\7z0ED849CC\Compiler\Ahk2Exe.exe | executable | |
MD5:EBC1E8C709D5F1A4C1B41EAEE5BCF8CF | SHA256:3EF18E351A8C9BC9ED13D78CC5540657C08DFA8B0554EFC9BD2F266A02428038 | |||
3472 | setup.exe | C:\Program Files\AutoHotkey\AutoHotkeyU32.exe | executable | |
MD5:3B02391B4546307DCAE5A57B0BBD7041 | SHA256:0DAD23C0E6C295C32E90479116DC58663CC8818735E8B8E2193E85BD9A68B428 | |||
2508 | AutoHotkey_1.1.30.03_setup.exe | C:\Users\admin\AppData\Local\Temp\7z0ED849CC\Compiler\Unicode 64-bit.bin | executable | |
MD5:BCB9DC9DEC30DB9FDA021243EB6A27AA | SHA256:AD450FC11E28E967730A97F2EA72F438CA9FE4161D1D28744FDC6CDEB8780DAC | |||
2508 | AutoHotkey_1.1.30.03_setup.exe | C:\Users\admin\AppData\Local\Temp\7z0ED849CC\Compiler\Unicode 32-bit.bin | executable | |
MD5:A39D5DB2DD76A3229267B2E9C529BB24 | SHA256:F75A39E7CB26AAFCA0E4C54D1E342DD83BEAB1C41613B8157B5523668D0BE22C | |||
3472 | setup.exe | C:\Program Files\AutoHotkey\AutoHotkey.chm | chm | |
MD5:8FEBCA19D269FA7F6DA04DB3E4A8D1B2 | SHA256:CD2A5F24243AE18D20FCE17707924FC3404993D20C65456C7F50200C1D72D3B8 | |||
2508 | AutoHotkey_1.1.30.03_setup.exe | C:\Users\admin\AppData\Local\Temp\7z0ED849CC\Installer.ahk | text | |
MD5:822BE09B42717A81C8042BCFAD09F504 | SHA256:BF2DB211C8FC56797F7668E22FA7C123022C8DA1F0D45AD59CFB7BF1CD1518B0 |