File name:

AutoHotkey_2.0.13_setup.exe

Full analysis: https://app.any.run/tasks/219aabb6-836c-4fb6-9aa6-cd6a0ab53211
Verdict: Malicious activity
Analysis date: April 22, 2024, 18:00:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

E882AA0FEE14AB1EF25B169E91430ED4

SHA1:

7E50BB20C434F3D94EEBE71E9F55D002328F6D92

SHA256:

D7646CA3A26760FE5633288D79D7B6A44CFC19A85C5315F94E0861963F1C601E

SSDEEP:

98304:M59ljV4ykxLK3oqIuaCwoVZNKJWb/PiGpT2pmrx9tFY+7MdKRfFAOSNf/s72PVLd:Vrok4tk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AutoHotkey_2.0.13_setup.exe (PID: 668)
      • AutoHotkey_2.0.13_setup.exe (PID: 1604)
      • AutoHotkeyUX.exe (PID: 3992)
  • SUSPICIOUS

    • Reads the Internet Settings

      • AutoHotkey_2.0.13_setup.exe (PID: 668)
      • AutoHotkeyUX.exe (PID: 2148)
      • AutoHotkeyUX.exe (PID: 3992)
    • Reads security settings of Internet Explorer

      • AutoHotkey_2.0.13_setup.exe (PID: 668)
      • AutoHotkeyUX.exe (PID: 2148)
      • AutoHotkeyUX.exe (PID: 3992)
    • Application launched itself

      • AutoHotkey_2.0.13_setup.exe (PID: 668)
      • AutoHotkeyUX.exe (PID: 1028)
      • AutoHotkeyUX.exe (PID: 2148)
    • Executable content was dropped or overwritten

      • AutoHotkey_2.0.13_setup.exe (PID: 1604)
      • AutoHotkeyUX.exe (PID: 3992)
    • Creates a software uninstall entry

      • AutoHotkey_2.0.13_setup.exe (PID: 1604)
    • Adds/modifies Windows certificates

      • AutoHotkey_2.0.13_setup.exe (PID: 1604)
      • AutoHotkeyUX.exe (PID: 3992)
    • Reads settings of System Certificates

      • AutoHotkey_2.0.13_setup.exe (PID: 1604)
      • AutoHotkeyUX.exe (PID: 3992)
    • Checks Windows Trust Settings

      • AutoHotkeyUX.exe (PID: 3992)
    • Reads Internet Explorer settings

      • AutoHotkeyUX.exe (PID: 3992)
    • Starts CMD.EXE for commands execution

      • Ahk2Exe.exe (PID: 1336)
    • Reads Microsoft Outlook installation path

      • AutoHotkeyUX.exe (PID: 3992)
  • INFO

    • Checks supported languages

      • AutoHotkey_2.0.13_setup.exe (PID: 668)
      • AutoHotkey_2.0.13_setup.exe (PID: 1604)
      • AutoHotkeyUX.exe (PID: 452)
      • AutoHotkeyUX.exe (PID: 1028)
      • AutoHotkeyUX.exe (PID: 3564)
      • AutoHotkeyUX.exe (PID: 2148)
      • AutoHotkeyUX.exe (PID: 796)
      • AutoHotkeyUX.exe (PID: 3992)
      • Ahk2Exe.exe (PID: 1336)
    • Reads the computer name

      • AutoHotkey_2.0.13_setup.exe (PID: 668)
      • AutoHotkey_2.0.13_setup.exe (PID: 1604)
      • AutoHotkeyUX.exe (PID: 1028)
      • AutoHotkeyUX.exe (PID: 2148)
      • AutoHotkeyUX.exe (PID: 3992)
    • Creates files in the program directory

      • AutoHotkey_2.0.13_setup.exe (PID: 1604)
      • AutoHotkeyUX.exe (PID: 3992)
    • Reads the machine GUID from the registry

      • AutoHotkey_2.0.13_setup.exe (PID: 1604)
      • AutoHotkeyUX.exe (PID: 3992)
    • Creates files or folders in the user directory

      • AutoHotkey_2.0.13_setup.exe (PID: 1604)
      • AutoHotkeyUX.exe (PID: 3992)
    • Reads the software policy settings

      • AutoHotkey_2.0.13_setup.exe (PID: 1604)
      • AutoHotkeyUX.exe (PID: 3992)
    • Manual execution by a user

      • AutoHotkeyUX.exe (PID: 1028)
      • Ahk2Exe.exe (PID: 1336)
    • Checks proxy server information

      • AutoHotkeyUX.exe (PID: 3992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (64.2)
.dll | Win32 Dynamic Link Library (generic) (15.6)
.exe | Win32 Executable (generic) (10.6)
.exe | Generic Win/DOS Executable (4.7)
.exe | DOS Executable Generic (4.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:20 11:25:49+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.39
CodeSize: 2969600
InitializedDataSize: 40960
UninitializedDataSize: 2514944
EntryPoint: 0x53af00
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.13.0
ProductVersionNumber: 2.0.13.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: AutoHotkey installer
FileVersion: 2.0.13
ProductName: AutoHotkey Setup
ProductVersion: 2.0.13
InternalName: AutoHotkey Setup
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
10
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start autohotkey_2.0.13_setup.exe no specs autohotkey_2.0.13_setup.exe autohotkeyux.exe no specs autohotkeyux.exe no specs autohotkeyux.exe no specs autohotkeyux.exe no specs autohotkeyux.exe no specs autohotkeyux.exe ahk2exe.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
452"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" "C:\Program Files\AutoHotkey\UX\reset-assoc.ahk" /checkC:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exeAutoHotkey_2.0.13_setup.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
HIGH
Description:
AutoHotkey 32-bit
Exit code:
0
Version:
2.0.13
Modules
Images
c:\program files\autohotkey\ux\autohotkeyux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
668"C:\Users\admin\AppData\Local\Temp\AutoHotkey_2.0.13_setup.exe" C:\Users\admin\AppData\Local\Temp\AutoHotkey_2.0.13_setup.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
AutoHotkey installer
Exit code:
0
Version:
2.0.13
Modules
Images
c:\users\admin\appdata\local\temp\autohotkey_2.0.13_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
796"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" /script WindowSpy.ahkC:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exeAutoHotkeyUX.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey 32-bit
Exit code:
0
Version:
2.0.13
Modules
Images
c:\program files\autohotkey\ux\autohotkeyux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1028"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" UX\ui-dash.ahkC:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exeexplorer.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey 32-bit
Version:
2.0.13
Modules
Images
c:\program files\autohotkey\ux\autohotkeyux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1336"C:\Program Files\AutoHotkey\Compiler\Ahk2Exe.exe" C:\Program Files\AutoHotkey\Compiler\Ahk2Exe.exeexplorer.exe
User:
admin
Company:
AutoHotkey
Integrity Level:
MEDIUM
Description:
AutoHotkey Script Compiler
Version:
1.1.37.01c1
Modules
Images
c:\program files\autohotkey\compiler\ahk2exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
1604"C:\Users\admin\AppData\Local\Temp\AutoHotkey_2.0.13_setup.exe" /to "C:\Program Files\AutoHotkey"C:\Users\admin\AppData\Local\Temp\AutoHotkey_2.0.13_setup.exe
AutoHotkey_2.0.13_setup.exe
User:
admin
Integrity Level:
HIGH
Description:
AutoHotkey installer
Exit code:
0
Version:
2.0.13
Modules
Images
c:\users\admin\appdata\local\temp\autohotkey_2.0.13_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2148"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" /script "C:\Program Files\AutoHotkey\UX\install-ahk2exe.ahk"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exeAutoHotkeyUX.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey 32-bit
Exit code:
0
Version:
2.0.13
Modules
Images
c:\program files\autohotkey\ux\autohotkeyux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
3564"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" "C:\Program Files\AutoHotkey\UX\ui-editor.ahk" "C:\Users\admin\Documents\AutoHotkey\Untitled.ahk"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exeAutoHotkeyUX.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
MEDIUM
Description:
AutoHotkey 32-bit
Exit code:
0
Version:
2.0.13
Modules
Images
c:\program files\autohotkey\ux\autohotkeyux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
3916"C:\Windows\system32\cmd.exe" /c echo 1C:\Windows\System32\cmd.exeAhk2Exe.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3992"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" /restart /script "C:\Program Files\AutoHotkey\UX\install-ahk2exe.ahk" /YC:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe
AutoHotkeyUX.exe
User:
admin
Company:
AutoHotkey Foundation LLC
Integrity Level:
HIGH
Description:
AutoHotkey 32-bit
Exit code:
0
Version:
2.0.13
Modules
Images
c:\program files\autohotkey\ux\autohotkeyux.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
Total events
21 044
Read events
20 922
Write events
102
Delete events
20

Modification events

(PID) Process:(668) AutoHotkey_2.0.13_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(668) AutoHotkey_2.0.13_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(668) AutoHotkey_2.0.13_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(668) AutoHotkey_2.0.13_setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1604) AutoHotkey_2.0.13_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey
Operation:writeName:DisplayName
Value:
AutoHotkey
(PID) Process:(1604) AutoHotkey_2.0.13_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey
Operation:writeName:UninstallString
Value:
"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" "C:\Program Files\AutoHotkey\UX\ui-uninstall.ahk"
(PID) Process:(1604) AutoHotkey_2.0.13_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe" "C:\Program Files\AutoHotkey\UX\install.ahk" /uninstall /silent
(PID) Process:(1604) AutoHotkey_2.0.13_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey
Operation:writeName:NoModify
Value:
1
(PID) Process:(1604) AutoHotkey_2.0.13_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey
Operation:writeName:DisplayIcon
Value:
C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe
(PID) Process:(1604) AutoHotkey_2.0.13_setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoHotkey
Operation:writeName:DisplayVersion
Value:
2.0.13
Executable files
13
Suspicious files
19
Text files
65
Unknown types
0

Dropped files

PID
Process
Filename
Type
1604AutoHotkey_2.0.13_setup.exeC:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\license.txttext
MD5:E3F2AD7733F3166FE770E4DC00AF6C45
SHA256:B27C1A7C92686E47F8740850AD24877A50BE23FD3DBD44EDEE50AC1223135E38
1604AutoHotkey_2.0.13_setup.exeC:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\WindowSpy.ahktext
MD5:1B081984B7C90528E03E67096F001E5F
SHA256:83E60BA7D330D4FAA32576C0AB223A2440EF92972D3D32DEE46D117E8A446CE9
1604AutoHotkey_2.0.13_setup.exeC:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\AutoHotkey32.exeexecutable
MD5:BC75CAA2EFEE658B95842F8C87D27B33
SHA256:26B3AF11F7B62CBC9C272771369438B3AA342D1B0D89BBFFAF51FA04F3B1908A
1604AutoHotkey_2.0.13_setup.exeC:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\AutoHotkey64.exeexecutable
MD5:DC0831F83B56454C47CB8EF2C819C3D8
SHA256:8A81FD3F6973F18B04E902D3EDA0B99B398813799311347498D52FE52317B85A
1604AutoHotkey_2.0.13_setup.exeC:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\ui-uninstall.ahktext
MD5:0FE4932669E99A498A7BC76975919000
SHA256:1E09FC4AF5DC3E673D4FACFE4FA849C6BDD0B29C67B0EFD7F96AAF387FCEF698
1604AutoHotkey_2.0.13_setup.exeC:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\ui-launcherconfig.ahktext
MD5:852BF007A6DDD80A2E5C9D82D874CF45
SHA256:C91E18A25069E7B501D2D0E1C8FC23B78CB962D93469CD0B2EA7E24CDF181DC1
1604AutoHotkey_2.0.13_setup.exeC:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\ui-dash.ahktext
MD5:669BD791C5AAFB60EE0885EF064D3622
SHA256:E8C0B4E149AD58C57E77AAC12041F1FA8BC9F25C6D642D12837EFC5FD97B8D21
1604AutoHotkey_2.0.13_setup.exeC:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\reset-assoc.ahktext
MD5:0299132478B49E3EB706C214BF32E62F
SHA256:D26CAEF44190E0B612C3E4309FF6689DC2953C72CB3DE1C94D002250B089F16B
1604AutoHotkey_2.0.13_setup.exeC:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\ui-setup.ahktext
MD5:DD3F9C2F9115689F4350896752F15926
SHA256:68B114A2EA4AF9DF54709A78EC5991A1F271097B29CB93757403FDB158746BC7
1604AutoHotkey_2.0.13_setup.exeC:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.13_setup.exe\UX\ui-editor.ahktext
MD5:82EB574294FF4E2E7461B95F5BAD0A87
SHA256:7263286EB3A42ECCF5EDC39B43C74A8BF7C82F2671204D1AE654236C1DE3F05D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
13
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3992
AutoHotkeyUX.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c4fe3068aac1251e
unknown
unknown
3992
AutoHotkeyUX.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd
unknown
unknown
3992
AutoHotkeyUX.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D
unknown
unknown
3992
AutoHotkeyUX.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEQCL3A%2F%2FVHcvqtFzJz8jNiqv
unknown
unknown
3992
AutoHotkeyUX.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEE4o94a2bBo7lCzSxA63QqU%3D
unknown
unknown
3992
AutoHotkeyUX.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
unknown
unknown
1080
svchost.exe
GET
200
199.232.210.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?aab46216fbac899d
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3992
AutoHotkeyUX.exe
140.82.121.5:443
api.github.com
GITHUB
US
unknown
3992
AutoHotkeyUX.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
3992
AutoHotkeyUX.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
3992
AutoHotkeyUX.exe
140.82.121.3:443
github.com
GITHUB
US
unknown
3992
AutoHotkeyUX.exe
185.199.109.133:443
objects.githubusercontent.com
FASTLY
US
unknown
3992
AutoHotkeyUX.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
api.github.com
  • 140.82.121.5
whitelisted
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
ocsp.comodoca.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
ocsp.sectigo.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
github.com
  • 140.82.121.3
shared
objects.githubusercontent.com
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.111.133
  • 185.199.108.133
shared
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info