File name:

Natro_Macro_v0.9.9.2.zip

Full analysis: https://app.any.run/tasks/ce712754-47ff-4186-8c2a-c2ae3487cea0
Verdict: Malicious activity
Analysis date: February 03, 2024, 15:59:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

1F749671680CCF0E1287D96F9DE1E9A0

SHA1:

7D17D28C03EA90E6A33DA4E1C3E0800301CD7DC0

SHA256:

6ADA86DF844A75BA9869940AD74E33FE4CE4E2345338077DAE439952EE109446

SSDEEP:

98304:+yiMNaCFgdXy+rm7B2E+8J6zvLlLVLjEmjFsCaowQWbNX3cL08i18gYei2aU3EB1:rJFs4jep

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Application launched itself

      • AutoHotkeyU32.exe (PID: 3012)
      • AutoHotkeyU32.exe (PID: 1376)
      • AutoHotkeyU32.exe (PID: 1408)
      • AutoHotkeyU32.exe (PID: 2556)
      • AutoHotkeyU32.exe (PID: 2824)
      • AutoHotkeyU32.exe (PID: 908)
      • AutoHotkeyU32.exe (PID: 3412)
      • AutoHotkeyU32.exe (PID: 3584)
      • AutoHotkeyU32.exe (PID: 3588)
      • AutoHotkeyU32.exe (PID: 3560)
      • AutoHotkeyU32.exe (PID: 3644)
      • AutoHotkeyU32.exe (PID: 3624)
      • AutoHotkeyU32.exe (PID: 3672)
      • AutoHotkeyU32.exe (PID: 2792)
      • AutoHotkeyU32.exe (PID: 2944)
    • Starts application with an unusual extension

      • cmd.exe (PID: 2628)
      • cmd.exe (PID: 2420)
    • Checks Windows Trust Settings

      • AutoHotkeyU32.exe (PID: 3624)
      • AutoHotkeyU32.exe (PID: 3672)
      • AutoHotkeyU32.exe (PID: 2792)
    • Reads settings of System Certificates

      • AutoHotkeyU32.exe (PID: 3624)
      • AutoHotkeyU32.exe (PID: 3672)
      • AutoHotkeyU32.exe (PID: 2792)
    • Reads security settings of Internet Explorer

      • AutoHotkeyU32.exe (PID: 3624)
      • AutoHotkeyU32.exe (PID: 3672)
      • AutoHotkeyU32.exe (PID: 2792)
    • Reads the Internet Settings

      • AutoHotkeyU32.exe (PID: 3672)
      • AutoHotkeyU32.exe (PID: 3624)
      • AutoHotkeyU32.exe (PID: 2792)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1632)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1632)
    • Checks supported languages

      • AutoHotkeyU32.exe (PID: 3016)
      • chcp.com (PID: 324)
      • AutoHotkeyU32.exe (PID: 1408)
      • AutoHotkeyU32.exe (PID: 3332)
      • AutoHotkeyU32.exe (PID: 1376)
      • AutoHotkeyU32.exe (PID: 3244)
      • AutoHotkeyU32.exe (PID: 2556)
      • AutoHotkeyU32.exe (PID: 2508)
      • AutoHotkeyU32.exe (PID: 3024)
      • AutoHotkeyU32.exe (PID: 2824)
      • AutoHotkeyU32.exe (PID: 3584)
      • AutoHotkeyU32.exe (PID: 3524)
      • AutoHotkeyU32.exe (PID: 908)
      • AutoHotkeyU32.exe (PID: 3396)
      • AutoHotkeyU32.exe (PID: 3412)
      • AutoHotkeyU32.exe (PID: 3588)
      • AutoHotkeyU32.exe (PID: 3596)
      • AutoHotkeyU32.exe (PID: 3568)
      • AutoHotkeyU32.exe (PID: 3056)
      • AutoHotkeyU32.exe (PID: 3644)
      • AutoHotkeyU32.exe (PID: 3624)
      • AutoHotkeyU32.exe (PID: 3420)
      • AutoHotkeyU32.exe (PID: 3728)
      • AutoHotkeyU32.exe (PID: 3884)
      • AutoHotkeyU32.exe (PID: 3560)
      • AutoHotkeyU32.exe (PID: 3672)
      • AutoHotkeyU32.exe (PID: 3652)
      • AutoHotkeyU32.exe (PID: 3916)
      • chcp.com (PID: 956)
      • AutoHotkeyU32.exe (PID: 2792)
      • AutoHotkeyU32.exe (PID: 2688)
      • AutoHotkeyU32.exe (PID: 2256)
      • AutoHotkeyU32.exe (PID: 3012)
      • AutoHotkeyU32.exe (PID: 2944)
      • AutoHotkeyU32.exe (PID: 3084)
    • Manual execution by a user

      • cmd.exe (PID: 2628)
      • cmd.exe (PID: 2420)
    • Reads the computer name

      • AutoHotkeyU32.exe (PID: 3624)
      • AutoHotkeyU32.exe (PID: 3672)
      • AutoHotkeyU32.exe (PID: 2792)
    • Creates files or folders in the user directory

      • AutoHotkeyU32.exe (PID: 3624)
      • AutoHotkeyU32.exe (PID: 3672)
    • Reads the machine GUID from the registry

      • AutoHotkeyU32.exe (PID: 3672)
      • AutoHotkeyU32.exe (PID: 3624)
      • AutoHotkeyU32.exe (PID: 2792)
    • Checks proxy server information

      • AutoHotkeyU32.exe (PID: 3624)
      • AutoHotkeyU32.exe (PID: 3672)
      • AutoHotkeyU32.exe (PID: 2792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:01:22 00:46:32
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Natro Macro v0.9.9.2/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
83
Monitored processes
38
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe cmd.exe no specs chcp.com no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe autohotkeyu32.exe no specs autohotkeyu32.exe no specs cmd.exe no specs chcp.com no specs autohotkeyu32.exe autohotkeyu32.exe no specs autohotkeyu32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
324chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
908"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
956chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1376"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1408"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\natro_macro.ahk" C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.execmd.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1632"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Natro_Macro_v0.9.9.2.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2256"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script "submacros\Heartbeat.ahk"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
2420C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\Natro Macro v0.9.9.2\START.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2508"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /iLib nul /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
2556"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
Total events
11 060
Read events
10 935
Write events
125
Delete events
0

Modification events

(PID) Process:(1632) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1632) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
36
Suspicious files
11
Text files
446
Unknown types
0

Dropped files

PID
Process
Filename
Type
1632WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\Gdip_All.ahktext
MD5:DE7A8C9B00225073F5AA6B64A271A47C
SHA256:A47005BE898FECC896E9A7049E9C9A2D994AB58B3C1F6F9E15F37F4D28B72066
1632WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\enum\EnumStr.ahktext
MD5:01EED943EE4A0F92490133B76EED7922
SHA256:C8F0F0F0C3C077013FD62E16B12FFA84734A5CCFCED82B0A214EF52542E67D84
1632WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\GetYOffset.ahktext
MD5:FC55A57751001C33C0E081F6A94CDC74
SHA256:E4C145031E827FDBD2173E3580B6FD2BA131CA509A21E79580BDFF650C71E063
1632WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\enum\EnumInt.ahktext
MD5:14C55D2755D309D7D56A10B645A69DA8
SHA256:BEEC85031A74A5F63D5773483789CA74AC46DC05294F24ED02DEBF74E90F5D1B
1632WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\GetRobloxHWND.ahktext
MD5:55B09DABFF1ADD633BD4AA14DE5C90CB
SHA256:BACA8E5595CC34B6A8DB514D8E8EFB7AC75F0A3828B7BB5EAD48613FAB081DC6
1632WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\nm_InventorySearch.ahktext
MD5:E928F930BB62589F53B6D577D1E01446
SHA256:147B79A283DDC943DAA298F1A039F20E77F927FEA42E81985244EA3F5C26581C
1632WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\nm_OpenMenu.ahktext
MD5:3DC7DEB50C67B706ADF3B7FA85311683
SHA256:AB52D4A704DD0331D418EDBB41220CE9CAB70370E1752F15B0B4625C30D86F0A
1632WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\Walk.ahktext
MD5:DC190A84180336DA91959CBD7511881B
SHA256:75AD4AD1FC125139CBDB817E8D7EC512F2CE341F19495A769A893D372740E02D
1632WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\JSON.ahktext
MD5:6095BDD16FCFD4632B52097A931F1A25
SHA256:B15B407854B2704514ABDD4D31DCDB147CA0860023DBD84FCD184F660E16C5AD
1632WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\Gdip_ImageSearch.ahkbinary
MD5:D526571C7F58C984C3FF70D81E08E183
SHA256:AB019DBE5A85A8F81A5AF63895E7D238A966C0B29FD72E04593DC23CAC04EA88
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
16
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3624
AutoHotkeyU32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
binary
471 b
unknown
3624
AutoHotkeyU32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQrHR6YzPN2BNbByL0VoiTIBBMAOAQUCrwIKReMpTlteg7OM8cus%2B37w3oCEAuJBTcSX0UQ1jcqECipKaU%3D
unknown
binary
313 b
unknown
1080
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?89bca2e7018c82c0
unknown
compressed
65.2 Kb
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c503292d7802e201
unknown
compressed
65.2 Kb
unknown
3624
AutoHotkeyU32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAfy81yHqHeveu%2FpR5k1Jb0%3D
unknown
binary
471 b
unknown
3624
AutoHotkeyU32.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8bbac7a3b9c97ce5
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3624
AutoHotkeyU32.exe
140.82.121.5:443
api.github.com
GITHUB
US
unknown
3624
AutoHotkeyU32.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
3624
AutoHotkeyU32.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3624
AutoHotkeyU32.exe
185.199.110.133:443
raw.githubusercontent.com
FASTLY
US
unknown
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
3672
AutoHotkeyU32.exe
140.82.121.6:443
api.github.com
GITHUB
US
unknown
3672
AutoHotkeyU32.exe
185.199.110.133:443
raw.githubusercontent.com
FASTLY
US
unknown

DNS requests

Domain
IP
Reputation
api.github.com
  • 140.82.121.5
  • 140.82.121.6
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
raw.githubusercontent.com
  • 185.199.110.133
  • 185.199.111.133
  • 185.199.108.133
  • 185.199.109.133
shared

Threats

No threats detected
No debug info