File name:

Natro_Macro_v0.9.9.2.zip

Full analysis: https://app.any.run/tasks/cfaa4681-f5ed-4509-b027-aacbe085d07f
Verdict: Malicious activity
Analysis date: June 10, 2024, 21:00:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

1F749671680CCF0E1287D96F9DE1E9A0

SHA1:

7D17D28C03EA90E6A33DA4E1C3E0800301CD7DC0

SHA256:

6ADA86DF844A75BA9869940AD74E33FE4CE4E2345338077DAE439952EE109446

SSDEEP:

98304:+yiMNaCFgdXy+rm7B2E+8J6zvLlLVLjEmjFsCaowQWbNX3cL08i18gYei2aU3EB1:rJFs4jep

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts application with an unusual extension

      • cmd.exe (PID: 552)
    • Application launched itself

      • AutoHotkeyU32.exe (PID: 1856)
      • AutoHotkeyU32.exe (PID: 692)
      • AutoHotkeyU32.exe (PID: 1588)
      • AutoHotkeyU32.exe (PID: 1284)
      • AutoHotkeyU32.exe (PID: 2060)
      • AutoHotkeyU32.exe (PID: 1812)
      • AutoHotkeyU32.exe (PID: 1552)
      • AutoHotkeyU32.exe (PID: 2232)
      • AutoHotkeyU32.exe (PID: 2240)
      • AutoHotkeyU32.exe (PID: 2256)
      • AutoHotkeyU32.exe (PID: 1800)
      • AutoHotkeyU32.exe (PID: 2196)
      • AutoHotkeyU32.exe (PID: 1072)
    • Reads the Internet Settings

      • AutoHotkeyU32.exe (PID: 1072)
    • Reads security settings of Internet Explorer

      • AutoHotkeyU32.exe (PID: 1072)
    • Reads settings of System Certificates

      • AutoHotkeyU32.exe (PID: 1072)
    • Checks Windows Trust Settings

      • AutoHotkeyU32.exe (PID: 1072)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 4004)
    • Checks supported languages

      • chcp.com (PID: 1368)
      • AutoHotkeyU32.exe (PID: 1856)
      • AutoHotkeyU32.exe (PID: 588)
      • AutoHotkeyU32.exe (PID: 692)
      • AutoHotkeyU32.exe (PID: 1660)
      • AutoHotkeyU32.exe (PID: 1588)
      • AutoHotkeyU32.exe (PID: 1284)
      • AutoHotkeyU32.exe (PID: 2012)
      • AutoHotkeyU32.exe (PID: 2060)
      • AutoHotkeyU32.exe (PID: 2008)
      • AutoHotkeyU32.exe (PID: 1132)
      • AutoHotkeyU32.exe (PID: 1800)
      • AutoHotkeyU32.exe (PID: 1640)
      • AutoHotkeyU32.exe (PID: 1816)
      • AutoHotkeyU32.exe (PID: 1812)
      • AutoHotkeyU32.exe (PID: 1824)
      • AutoHotkeyU32.exe (PID: 1552)
      • AutoHotkeyU32.exe (PID: 2240)
      • AutoHotkeyU32.exe (PID: 2280)
      • AutoHotkeyU32.exe (PID: 2232)
      • AutoHotkeyU32.exe (PID: 2368)
      • AutoHotkeyU32.exe (PID: 1820)
      • AutoHotkeyU32.exe (PID: 568)
      • AutoHotkeyU32.exe (PID: 1072)
      • AutoHotkeyU32.exe (PID: 1212)
      • AutoHotkeyU32.exe (PID: 2256)
      • AutoHotkeyU32.exe (PID: 1596)
      • AutoHotkeyU32.exe (PID: 2196)
      • wmpnscfg.exe (PID: 1612)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4004)
    • Manual execution by a user

      • notepad.exe (PID: 2316)
      • cmd.exe (PID: 552)
      • taskmgr.exe (PID: 1964)
      • wmpnscfg.exe (PID: 1612)
    • Reads the computer name

      • AutoHotkeyU32.exe (PID: 1072)
      • wmpnscfg.exe (PID: 1612)
    • Reads the machine GUID from the registry

      • AutoHotkeyU32.exe (PID: 1072)
    • Checks proxy server information

      • AutoHotkeyU32.exe (PID: 1072)
    • Reads the software policy settings

      • AutoHotkeyU32.exe (PID: 1072)
    • Creates files or folders in the user directory

      • AutoHotkeyU32.exe (PID: 1072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:01:22 00:46:32
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Natro Macro v0.9.9.2/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
33
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe notepad.exe no specs cmd.exe no specs chcp.com no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe autohotkeyu32.exe no specs autohotkeyu32.exe no specs wmpnscfg.exe no specs taskmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
552C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\Natro Macro v0.9.9.2\START.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
568"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /iLib nul /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
588"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script "submacros\Heartbeat.ahk"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
692"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1072"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /r "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\natro_macro.ahk" C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe
AutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1132"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /iLib nul /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1212"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script "submacros\Heartbeat.ahk"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1284"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1368chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1552"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
Total events
9 400
Read events
9 321
Write events
70
Delete events
9

Modification events

(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4004) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Natro_Macro_v0.9.9.2.zip
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
28
Suspicious files
10
Text files
448
Unknown types
1

Dropped files

PID
Process
Filename
Type
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\Gdip_All.ahktext
MD5:DE7A8C9B00225073F5AA6B64A271A47C
SHA256:A47005BE898FECC896E9A7049E9C9A2D994AB58B3C1F6F9E15F37F4D28B72066
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\nm_InventorySearch.ahktext
MD5:E928F930BB62589F53B6D577D1E01446
SHA256:147B79A283DDC943DAA298F1A039F20E77F927FEA42E81985244EA3F5C26581C
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\GetRobloxHWND.ahktext
MD5:55B09DABFF1ADD633BD4AA14DE5C90CB
SHA256:BACA8E5595CC34B6A8DB514D8E8EFB7AC75F0A3828B7BB5EAD48613FAB081DC6
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\WinGetClientPos.ahktext
MD5:F09DE6E9CDC38868E283B7017FA0549B
SHA256:34146230F92526BF000F76E91EFC23A38BC66E5B8F05A6D0FC081FD0F9A4FA99
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\LICENSE.mdtext
MD5:E62637EA8A114355B985FD86C9FFBD6E
SHA256:230184F60BAE2FEAF244F10A8BAC053C8FF33A183BCC365B4D8B876D2B7F4809
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\HyperSleep.ahktext
MD5:7F119F281F4D0915ECAE0DD4B92DF746
SHA256:2D6776C4AF23D10C14A8CDE2D02260C2B05B6C366221C5724DB65116A37611E6
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\Walk.ahktext
MD5:DC190A84180336DA91959CBD7511881B
SHA256:75AD4AD1FC125139CBDB817E8D7EC512F2CE341F19495A769A893D372740E02D
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\any pollen.pngimage
MD5:708DF32D7EB8AC41A80C09E7113797A5
SHA256:7D84D787A6BA6EB380446FB161579391A4E41017DE59937B7E0D3B3A2F57E425
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\auryn.icoimage
MD5:D25B239F728617C3C6B41CEB0512AC8E
SHA256:B49C39DC0F040C1B8539DFF23B2A757103A8C723010348C69837052D2A41ED0E
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\3Planters.PNGimage
MD5:EF32FE4CC267AC9247834A8020A2174D
SHA256:0BE56F50839FD430A175C0F9CE91ED336DEF38021E6F21B6A1EFDAF4871FD501
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
12
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1072
AutoHotkeyU32.exe
GET
304
23.50.131.205:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fe91146dead13689
unknown
unknown
1072
AutoHotkeyU32.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D
unknown
unknown
1072
AutoHotkeyU32.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd
unknown
unknown
1072
AutoHotkeyU32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
unknown
1088
svchost.exe
GET
304
23.50.131.200:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?cf3b3ae38045042c
unknown
unknown
1072
AutoHotkeyU32.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEQCL3A%2F%2FVHcvqtFzJz8jNiqv
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
1072
AutoHotkeyU32.exe
140.82.121.5:443
api.github.com
GITHUB
US
unknown
1072
AutoHotkeyU32.exe
23.50.131.205:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1072
AutoHotkeyU32.exe
185.199.109.133:443
raw.githubusercontent.com
FASTLY
US
unknown
1072
AutoHotkeyU32.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1072
AutoHotkeyU32.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
1072
AutoHotkeyU32.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
1088
svchost.exe
23.50.131.200:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
api.github.com
  • 140.82.121.5
whitelisted
ctldl.windowsupdate.com
  • 23.50.131.205
  • 23.50.131.221
  • 23.50.131.222
  • 23.50.131.199
  • 23.50.131.208
  • 23.50.131.210
  • 23.50.131.200
  • 23.50.131.207
  • 23.50.131.223
  • 23.50.131.211
  • 23.50.131.203
  • 23.50.131.216
whitelisted
raw.githubusercontent.com
  • 185.199.109.133
  • 185.199.111.133
  • 185.199.108.133
  • 185.199.110.133
shared
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.sectigo.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted

Threats

No threats detected
No debug info