File name:

Natro_Macro_v0.9.9.2.zip

Full analysis: https://app.any.run/tasks/cfaa4681-f5ed-4509-b027-aacbe085d07f
Verdict: Malicious activity
Analysis date: June 10, 2024, 21:00:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

1F749671680CCF0E1287D96F9DE1E9A0

SHA1:

7D17D28C03EA90E6A33DA4E1C3E0800301CD7DC0

SHA256:

6ADA86DF844A75BA9869940AD74E33FE4CE4E2345338077DAE439952EE109446

SSDEEP:

98304:+yiMNaCFgdXy+rm7B2E+8J6zvLlLVLjEmjFsCaowQWbNX3cL08i18gYei2aU3EB1:rJFs4jep

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts application with an unusual extension

      • cmd.exe (PID: 552)
    • Application launched itself

      • AutoHotkeyU32.exe (PID: 1856)
      • AutoHotkeyU32.exe (PID: 692)
      • AutoHotkeyU32.exe (PID: 1588)
      • AutoHotkeyU32.exe (PID: 1284)
      • AutoHotkeyU32.exe (PID: 2060)
      • AutoHotkeyU32.exe (PID: 1812)
      • AutoHotkeyU32.exe (PID: 1800)
      • AutoHotkeyU32.exe (PID: 1552)
      • AutoHotkeyU32.exe (PID: 2240)
      • AutoHotkeyU32.exe (PID: 2232)
      • AutoHotkeyU32.exe (PID: 2256)
      • AutoHotkeyU32.exe (PID: 2196)
      • AutoHotkeyU32.exe (PID: 1072)
    • Checks Windows Trust Settings

      • AutoHotkeyU32.exe (PID: 1072)
    • Reads security settings of Internet Explorer

      • AutoHotkeyU32.exe (PID: 1072)
    • Reads settings of System Certificates

      • AutoHotkeyU32.exe (PID: 1072)
    • Reads the Internet Settings

      • AutoHotkeyU32.exe (PID: 1072)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4004)
    • Manual execution by a user

      • cmd.exe (PID: 552)
      • notepad.exe (PID: 2316)
      • wmpnscfg.exe (PID: 1612)
      • taskmgr.exe (PID: 1964)
    • Checks supported languages

      • chcp.com (PID: 1368)
      • AutoHotkeyU32.exe (PID: 1856)
      • AutoHotkeyU32.exe (PID: 588)
      • AutoHotkeyU32.exe (PID: 692)
      • AutoHotkeyU32.exe (PID: 1660)
      • AutoHotkeyU32.exe (PID: 1588)
      • AutoHotkeyU32.exe (PID: 2012)
      • AutoHotkeyU32.exe (PID: 1284)
      • AutoHotkeyU32.exe (PID: 2008)
      • AutoHotkeyU32.exe (PID: 2060)
      • AutoHotkeyU32.exe (PID: 1132)
      • AutoHotkeyU32.exe (PID: 1816)
      • AutoHotkeyU32.exe (PID: 1812)
      • AutoHotkeyU32.exe (PID: 1824)
      • AutoHotkeyU32.exe (PID: 1800)
      • AutoHotkeyU32.exe (PID: 1552)
      • AutoHotkeyU32.exe (PID: 568)
      • AutoHotkeyU32.exe (PID: 1640)
      • AutoHotkeyU32.exe (PID: 2240)
      • AutoHotkeyU32.exe (PID: 2280)
      • AutoHotkeyU32.exe (PID: 2232)
      • AutoHotkeyU32.exe (PID: 2368)
      • AutoHotkeyU32.exe (PID: 2256)
      • AutoHotkeyU32.exe (PID: 1596)
      • AutoHotkeyU32.exe (PID: 2196)
      • wmpnscfg.exe (PID: 1612)
      • AutoHotkeyU32.exe (PID: 1212)
      • AutoHotkeyU32.exe (PID: 1072)
      • AutoHotkeyU32.exe (PID: 1820)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 4004)
    • Checks proxy server information

      • AutoHotkeyU32.exe (PID: 1072)
    • Reads the machine GUID from the registry

      • AutoHotkeyU32.exe (PID: 1072)
    • Reads the software policy settings

      • AutoHotkeyU32.exe (PID: 1072)
    • Creates files or folders in the user directory

      • AutoHotkeyU32.exe (PID: 1072)
    • Reads the computer name

      • wmpnscfg.exe (PID: 1612)
      • AutoHotkeyU32.exe (PID: 1072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2024:01:22 00:46:32
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Natro Macro v0.9.9.2/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
71
Monitored processes
33
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe notepad.exe no specs cmd.exe no specs chcp.com no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe no specs autohotkeyu32.exe autohotkeyu32.exe no specs autohotkeyu32.exe no specs wmpnscfg.exe no specs taskmgr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
552C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\Natro Macro v0.9.9.2\START.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
568"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /iLib nul /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
588"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script "submacros\Heartbeat.ahk"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
692"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1072"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /r "C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\natro_macro.ahk" C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe
AutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1132"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /iLib nul /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1212"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script "submacros\Heartbeat.ahk"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1284"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1368chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1552"C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exe" /script /ErrorStdOut *C:\Users\admin\Desktop\Natro Macro v0.9.9.2\submacros\AutoHotkeyU32.exeAutoHotkeyU32.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Exit code:
0
Version:
1.1.37.01
Modules
Images
c:\users\admin\desktop\natro macro v0.9.9.2\submacros\autohotkeyu32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
Total events
9 400
Read events
9 321
Write events
70
Delete events
9

Modification events

(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(4004) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Natro_Macro_v0.9.9.2.zip
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4004) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
28
Suspicious files
10
Text files
448
Unknown types
1

Dropped files

PID
Process
Filename
Type
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\Gdip_All.ahktext
MD5:DE7A8C9B00225073F5AA6B64A271A47C
SHA256:A47005BE898FECC896E9A7049E9C9A2D994AB58B3C1F6F9E15F37F4D28B72066
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\a bit of both.pngimage
MD5:6839A3D9FB3A3B664A778DD6639DCC5E
SHA256:76F39CB1023EC4F6D52A898EEB277C288F892A03BFB6B67284F5548FFA57CC95
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\aromatic pie.pngimage
MD5:387F5BEFF1D2130447A882A07FBCA063
SHA256:BB9562EFF9F7C9C2F17F8D140C85F00550BCE6AE9532A14009B1B4262ED7C4EE
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\any pollen.pngimage
MD5:708DF32D7EB8AC41A80C09E7113797A5
SHA256:7D84D787A6BA6EB380446FB161579391A4E41017DE59937B7E0D3B3A2F57E425
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\abilities.pngimage
MD5:0027C79985BFAE14612C922F63FFCCE0
SHA256:BA536A4E376269C9055F571363C0370C3EAA5D3B2FA0BDAD18FD761A1E93CC65
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\LICENSE.mdtext
MD5:E62637EA8A114355B985FD86C9FFBD6E
SHA256:230184F60BAE2FEAF244F10A8BAC053C8FF33A183BCC365B4D8B876D2B7F4809
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\bamboo.pngimage
MD5:D6CFA28B03548D03D858B6F342214C0B
SHA256:2C30D62FC8F1C762E3302574A788BD60DCA0DB4B7B2555A9400FF3024F49DBF0
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\3Planters.PNGimage
MD5:EF32FE4CC267AC9247834A8020A2174D
SHA256:0BE56F50839FD430A175C0F9CE91ED336DEF38021E6F21B6A1EFDAF4871FD501
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\nm_image_assets\auryn.icoimage
MD5:D25B239F728617C3C6B41CEB0512AC8E
SHA256:B49C39DC0F040C1B8539DFF23B2A757103A8C723010348C69837052D2A41ED0E
4004WinRAR.exeC:\Users\admin\Desktop\Natro Macro v0.9.9.2\lib\enum\EnumInt.ahktext
MD5:14C55D2755D309D7D56A10B645A69DA8
SHA256:BEEC85031A74A5F63D5773483789CA74AC46DC05294F24ED02DEBF74E90F5D1B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
12
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1072
AutoHotkeyU32.exe
GET
304
23.50.131.205:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fe91146dead13689
unknown
unknown
1072
AutoHotkeyU32.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
unknown
1072
AutoHotkeyU32.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D
unknown
unknown
1072
AutoHotkeyU32.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd
unknown
unknown
1088
svchost.exe
GET
304
23.50.131.200:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?cf3b3ae38045042c
unknown
unknown
1072
AutoHotkeyU32.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEQCL3A%2F%2FVHcvqtFzJz8jNiqv
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
1072
AutoHotkeyU32.exe
140.82.121.5:443
api.github.com
GITHUB
US
unknown
1072
AutoHotkeyU32.exe
23.50.131.205:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1072
AutoHotkeyU32.exe
185.199.109.133:443
raw.githubusercontent.com
FASTLY
US
unknown
1072
AutoHotkeyU32.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1072
AutoHotkeyU32.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
1072
AutoHotkeyU32.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
1088
svchost.exe
23.50.131.200:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
api.github.com
  • 140.82.121.5
whitelisted
ctldl.windowsupdate.com
  • 23.50.131.205
  • 23.50.131.221
  • 23.50.131.222
  • 23.50.131.199
  • 23.50.131.208
  • 23.50.131.210
  • 23.50.131.200
  • 23.50.131.207
  • 23.50.131.223
  • 23.50.131.211
  • 23.50.131.203
  • 23.50.131.216
whitelisted
raw.githubusercontent.com
  • 185.199.109.133
  • 185.199.111.133
  • 185.199.108.133
  • 185.199.110.133
shared
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.sectigo.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted

Threats

No threats detected
No debug info