| File name: | AutoHotkey_2.0.13_setup.exe |
| Full analysis: | https://app.any.run/tasks/219aabb6-836c-4fb6-9aa6-cd6a0ab53211 |
| Verdict: | Malicious activity |
| Analysis date: | April 22, 2024, 18:00:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | E882AA0FEE14AB1EF25B169E91430ED4 |
| SHA1: | 7E50BB20C434F3D94EEBE71E9F55D002328F6D92 |
| SHA256: | D7646CA3A26760FE5633288D79D7B6A44CFC19A85C5315F94E0861963F1C601E |
| SSDEEP: | 98304:M59ljV4ykxLK3oqIuaCwoVZNKJWb/PiGpT2pmrx9tFY+7MdKRfFAOSNf/s72PVLd:Vrok4tk |
| .exe | | | UPX compressed Win32 Executable (64.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.6) |
| .exe | | | Win32 Executable (generic) (10.6) |
| .exe | | | Generic Win/DOS Executable (4.7) |
| .exe | | | DOS Executable Generic (4.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:04:20 11:25:49+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.39 |
| CodeSize: | 2969600 |
| InitializedDataSize: | 40960 |
| UninitializedDataSize: | 2514944 |
| EntryPoint: | 0x53af00 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.13.0 |
| ProductVersionNumber: | 2.0.13.0 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileDescription: | AutoHotkey installer |
| FileVersion: | 2.0.13 |
| ProductName: | AutoHotkey Setup |
| ProductVersion: | 2.0.13 |
| InternalName: | AutoHotkey Setup |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 452 | "C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" "C:\Program Files\AutoHotkey\UX\reset-assoc.ahk" /check | C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe | — | AutoHotkey_2.0.13_setup.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: HIGH Description: AutoHotkey 32-bit Exit code: 0 Version: 2.0.13 Modules
| |||||||||||||||
| 668 | "C:\Users\admin\AppData\Local\Temp\AutoHotkey_2.0.13_setup.exe" | C:\Users\admin\AppData\Local\Temp\AutoHotkey_2.0.13_setup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: AutoHotkey installer Exit code: 0 Version: 2.0.13 Modules
| |||||||||||||||
| 796 | "C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" /script WindowSpy.ahk | C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe | — | AutoHotkeyUX.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey 32-bit Exit code: 0 Version: 2.0.13 Modules
| |||||||||||||||
| 1028 | "C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" UX\ui-dash.ahk | C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe | — | explorer.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey 32-bit Version: 2.0.13 Modules
| |||||||||||||||
| 1336 | "C:\Program Files\AutoHotkey\Compiler\Ahk2Exe.exe" | C:\Program Files\AutoHotkey\Compiler\Ahk2Exe.exe | — | explorer.exe | |||||||||||
User: admin Company: AutoHotkey Integrity Level: MEDIUM Description: AutoHotkey Script Compiler Version: 1.1.37.01c1 Modules
| |||||||||||||||
| 1604 | "C:\Users\admin\AppData\Local\Temp\AutoHotkey_2.0.13_setup.exe" /to "C:\Program Files\AutoHotkey" | C:\Users\admin\AppData\Local\Temp\AutoHotkey_2.0.13_setup.exe | AutoHotkey_2.0.13_setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: AutoHotkey installer Exit code: 0 Version: 2.0.13 Modules
| |||||||||||||||
| 2148 | "C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" /script "C:\Program Files\AutoHotkey\UX\install-ahk2exe.ahk" | C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe | — | AutoHotkeyUX.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey 32-bit Exit code: 0 Version: 2.0.13 Modules
| |||||||||||||||
| 3564 | "C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" "C:\Program Files\AutoHotkey\UX\ui-editor.ahk" "C:\Users\admin\Documents\AutoHotkey\Untitled.ahk" | C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe | — | AutoHotkeyUX.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey 32-bit Exit code: 0 Version: 2.0.13 Modules
| |||||||||||||||
| 3916 | "C:\Windows\system32\cmd.exe" /c echo 1 | C:\Windows\System32\cmd.exe | — | Ahk2Exe.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3992 | "C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" /restart /script "C:\Program Files\AutoHotkey\UX\install-ahk2exe.ahk" /Y | C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe | AutoHotkeyUX.exe | ||||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: HIGH Description: AutoHotkey 32-bit Exit code: 0 Version: 2.0.13 Modules
| |||||||||||||||
| (PID) Process: | (668) AutoHotkey_2.0.13_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (668) AutoHotkey_2.0.13_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (668) AutoHotkey_2.0.13_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (668) AutoHotkey_2.0.13_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1604) AutoHotkey_2.0.13_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey |
| Operation: | write | Name: | DisplayName |
Value: AutoHotkey | |||
| (PID) Process: | (1604) AutoHotkey_2.0.13_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey |
| Operation: | write | Name: | UninstallString |
Value: "C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" "C:\Program Files\AutoHotkey\UX\ui-uninstall.ahk" | |||
| (PID) Process: | (1604) AutoHotkey_2.0.13_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey |
| Operation: | write | Name: | QuietUninstallString |
Value: "C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" "C:\Program Files\AutoHotkey\UX\install.ahk" /uninstall /silent | |||
| (PID) Process: | (1604) AutoHotkey_2.0.13_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (1604) AutoHotkey_2.0.13_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe | |||
| (PID) Process: | (1604) AutoHotkey_2.0.13_setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey |
| Operation: | write | Name: | DisplayVersion |
Value: 2.0.13 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1604 | AutoHotkey_2.0.13_setup.exe | C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\license.txt | text | |
MD5:E3F2AD7733F3166FE770E4DC00AF6C45 | SHA256:B27C1A7C92686E47F8740850AD24877A50BE23FD3DBD44EDEE50AC1223135E38 | |||
| 1604 | AutoHotkey_2.0.13_setup.exe | C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\WindowSpy.ahk | text | |
MD5:1B081984B7C90528E03E67096F001E5F | SHA256:83E60BA7D330D4FAA32576C0AB223A2440EF92972D3D32DEE46D117E8A446CE9 | |||
| 1604 | AutoHotkey_2.0.13_setup.exe | C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\AutoHotkey32.exe | executable | |
MD5:BC75CAA2EFEE658B95842F8C87D27B33 | SHA256:26B3AF11F7B62CBC9C272771369438B3AA342D1B0D89BBFFAF51FA04F3B1908A | |||
| 1604 | AutoHotkey_2.0.13_setup.exe | C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\AutoHotkey64.exe | executable | |
MD5:DC0831F83B56454C47CB8EF2C819C3D8 | SHA256:8A81FD3F6973F18B04E902D3EDA0B99B398813799311347498D52FE52317B85A | |||
| 1604 | AutoHotkey_2.0.13_setup.exe | C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\ui-uninstall.ahk | text | |
MD5:0FE4932669E99A498A7BC76975919000 | SHA256:1E09FC4AF5DC3E673D4FACFE4FA849C6BDD0B29C67B0EFD7F96AAF387FCEF698 | |||
| 1604 | AutoHotkey_2.0.13_setup.exe | C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\ui-launcherconfig.ahk | text | |
MD5:852BF007A6DDD80A2E5C9D82D874CF45 | SHA256:C91E18A25069E7B501D2D0E1C8FC23B78CB962D93469CD0B2EA7E24CDF181DC1 | |||
| 1604 | AutoHotkey_2.0.13_setup.exe | C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\ui-dash.ahk | text | |
MD5:669BD791C5AAFB60EE0885EF064D3622 | SHA256:E8C0B4E149AD58C57E77AAC12041F1FA8BC9F25C6D642D12837EFC5FD97B8D21 | |||
| 1604 | AutoHotkey_2.0.13_setup.exe | C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\reset-assoc.ahk | text | |
MD5:0299132478B49E3EB706C214BF32E62F | SHA256:D26CAEF44190E0B612C3E4309FF6689DC2953C72CB3DE1C94D002250B089F16B | |||
| 1604 | AutoHotkey_2.0.13_setup.exe | C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\ui-setup.ahk | text | |
MD5:DD3F9C2F9115689F4350896752F15926 | SHA256:68B114A2EA4AF9DF54709A78EC5991A1F271097B29CB93757403FDB158746BC7 | |||
| 1604 | AutoHotkey_2.0.13_setup.exe | C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\ui-editor.ahk | text | |
MD5:82EB574294FF4E2E7461B95F5BAD0A87 | SHA256:7263286EB3A42ECCF5EDC39B43C74A8BF7C82F2671204D1AE654236C1DE3F05D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3992 | AutoHotkeyUX.exe | GET | 304 | 199.232.214.172:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c4fe3068aac1251e | unknown | — | — | unknown |
3992 | AutoHotkeyUX.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd | unknown | — | — | unknown |
3992 | AutoHotkeyUX.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D | unknown | — | — | unknown |
3992 | AutoHotkeyUX.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEQCL3A%2F%2FVHcvqtFzJz8jNiqv | unknown | — | — | unknown |
3992 | AutoHotkeyUX.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEE4o94a2bBo7lCzSxA63QqU%3D | unknown | — | — | unknown |
3992 | AutoHotkeyUX.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D | unknown | — | — | unknown |
1080 | svchost.exe | GET | 200 | 199.232.210.172:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?aab46216fbac899d | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3992 | AutoHotkeyUX.exe | 140.82.121.5:443 | api.github.com | GITHUB | US | unknown |
3992 | AutoHotkeyUX.exe | 199.232.214.172:80 | ctldl.windowsupdate.com | FASTLY | US | unknown |
3992 | AutoHotkeyUX.exe | 172.64.149.23:80 | ocsp.comodoca.com | CLOUDFLARENET | US | unknown |
3992 | AutoHotkeyUX.exe | 140.82.121.3:443 | github.com | GITHUB | US | unknown |
3992 | AutoHotkeyUX.exe | 185.199.109.133:443 | objects.githubusercontent.com | FASTLY | US | unknown |
3992 | AutoHotkeyUX.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
api.github.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
github.com |
| shared |
objects.githubusercontent.com |
| shared |
ocsp.digicert.com |
| whitelisted |