| File name: | Natro_Macro_v0.9.9.2.zip |
| Full analysis: | https://app.any.run/tasks/cfaa4681-f5ed-4509-b027-aacbe085d07f |
| Verdict: | Malicious activity |
| Analysis date: | June 10, 2024, 21:00:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | 1F749671680CCF0E1287D96F9DE1E9A0 |
| SHA1: | 7D17D28C03EA90E6A33DA4E1C3E0800301CD7DC0 |
| SHA256: | 6ADA86DF844A75BA9869940AD74E33FE4CE4E2345338077DAE439952EE109446 |
| SSDEEP: | 98304:+yiMNaCFgdXy+rm7B2E+8J6zvLlLVLjEmjFsCaowQWbNX3cL08i18gYei2aU3EB1:rJFs4jep |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2024:01:22 00:46:32 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | Natro Macro v0.9.9.2/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 552 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\Natro Macro v0.9.9.2\START.bat" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 568 | "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /iLib nul /ErrorStdOut * | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe | — | AutoHotkeyU32.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey Unicode 32-bit Exit code: 0 Version: 1.1.37.01 Modules
| |||||||||||||||
| 588 | "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script "submacros\Heartbeat.ahk" | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe | — | AutoHotkeyU32.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey Unicode 32-bit Exit code: 0 Version: 1.1.37.01 Modules
| |||||||||||||||
| 692 | "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut * | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe | — | AutoHotkeyU32.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey Unicode 32-bit Exit code: 0 Version: 1.1.37.01 Modules
| |||||||||||||||
| 1072 | "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /r "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\natro_macro.ahk" | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe | AutoHotkeyU32.exe | ||||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey Unicode 32-bit Exit code: 0 Version: 1.1.37.01 Modules
| |||||||||||||||
| 1132 | "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /iLib nul /ErrorStdOut * | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe | — | AutoHotkeyU32.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey Unicode 32-bit Exit code: 0 Version: 1.1.37.01 Modules
| |||||||||||||||
| 1212 | "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script "submacros\Heartbeat.ahk" | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe | — | AutoHotkeyU32.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey Unicode 32-bit Exit code: 0 Version: 1.1.37.01 Modules
| |||||||||||||||
| 1284 | "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut * | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe | — | AutoHotkeyU32.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey Unicode 32-bit Exit code: 0 Version: 1.1.37.01 Modules
| |||||||||||||||
| 1368 | chcp 65001 | C:\Windows\System32\chcp.com | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Change CodePage Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1552 | "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut * | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe | — | AutoHotkeyU32.exe | |||||||||||
User: admin Company: AutoHotkey Foundation LLC Integrity Level: MEDIUM Description: AutoHotkey Unicode 32-bit Exit code: 0 Version: 1.1.37.01 Modules
| |||||||||||||||
| (PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\Natro_Macro_v0.9.9.2.zip | |||
| (PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (4004) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4004 | WinRAR.exe | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\Gdip_All.ahk | text | |
MD5:DE7A8C9B00225073F5AA6B64A271A47C | SHA256:A47005BE898FECC896E9A7049E9C9A2D994AB58B3C1F6F9E15F37F4D28B72066 | |||
| 4004 | WinRAR.exe | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\a bit of both.png | image | |
MD5:6839A3D9FB3A3B664A778DD6639DCC5E | SHA256:76F39CB1023EC4F6D52A898EEB277C288F892A03BFB6B67284F5548FFA57CC95 | |||
| 4004 | WinRAR.exe | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\aromatic pie.png | image | |
MD5:387F5BEFF1D2130447A882A07FBCA063 | SHA256:BB9562EFF9F7C9C2F17F8D140C85F00550BCE6AE9532A14009B1B4262ED7C4EE | |||
| 4004 | WinRAR.exe | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\any pollen.png | image | |
MD5:708DF32D7EB8AC41A80C09E7113797A5 | SHA256:7D84D787A6BA6EB380446FB161579391A4E41017DE59937B7E0D3B3A2F57E425 | |||
| 4004 | WinRAR.exe | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\abilities.png | image | |
MD5:0027C79985BFAE14612C922F63FFCCE0 | SHA256:BA536A4E376269C9055F571363C0370C3EAA5D3B2FA0BDAD18FD761A1E93CC65 | |||
| 4004 | WinRAR.exe | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\LICENSE.md | text | |
MD5:E62637EA8A114355B985FD86C9FFBD6E | SHA256:230184F60BAE2FEAF244F10A8BAC053C8FF33A183BCC365B4D8B876D2B7F4809 | |||
| 4004 | WinRAR.exe | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\bamboo.png | image | |
MD5:D6CFA28B03548D03D858B6F342214C0B | SHA256:2C30D62FC8F1C762E3302574A788BD60DCA0DB4B7B2555A9400FF3024F49DBF0 | |||
| 4004 | WinRAR.exe | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\3Planters.PNG | image | |
MD5:EF32FE4CC267AC9247834A8020A2174D | SHA256:0BE56F50839FD430A175C0F9CE91ED336DEF38021E6F21B6A1EFDAF4871FD501 | |||
| 4004 | WinRAR.exe | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\auryn.ico | image | |
MD5:D25B239F728617C3C6B41CEB0512AC8E | SHA256:B49C39DC0F040C1B8539DFF23B2A757103A8C723010348C69837052D2A41ED0E | |||
| 4004 | WinRAR.exe | C:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\enum\EnumInt.ahk | text | |
MD5:14C55D2755D309D7D56A10B645A69DA8 | SHA256:BEEC85031A74A5F63D5773483789CA74AC46DC05294F24ED02DEBF74E90F5D1B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1072 | AutoHotkeyU32.exe | GET | 304 | 23.50.131.205:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fe91146dead13689 | unknown | — | — | unknown |
1072 | AutoHotkeyU32.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D | unknown | — | — | unknown |
1072 | AutoHotkeyU32.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D | unknown | — | — | unknown |
1072 | AutoHotkeyU32.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd | unknown | — | — | unknown |
1088 | svchost.exe | GET | 304 | 23.50.131.200:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?cf3b3ae38045042c | unknown | — | — | unknown |
1072 | AutoHotkeyU32.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEQCL3A%2F%2FVHcvqtFzJz8jNiqv | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1072 | AutoHotkeyU32.exe | 140.82.121.5:443 | api.github.com | GITHUB | US | unknown |
1072 | AutoHotkeyU32.exe | 23.50.131.205:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
1072 | AutoHotkeyU32.exe | 185.199.109.133:443 | raw.githubusercontent.com | FASTLY | US | unknown |
1072 | AutoHotkeyU32.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
1072 | AutoHotkeyU32.exe | 172.64.149.23:80 | ocsp.comodoca.com | CLOUDFLARENET | US | unknown |
1072 | AutoHotkeyU32.exe | 104.18.38.233:80 | ocsp.comodoca.com | CLOUDFLARENET | — | shared |
1088 | svchost.exe | 23.50.131.200:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
api.github.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
raw.githubusercontent.com |
| shared |
ocsp.digicert.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |