File name:

qDu.u.exe

Full analysis: https://app.any.run/tasks/a838e540-1886-4d2f-8cca-a12dfda4d9fd
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 25, 2025, 22:37:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
ahk
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

03C469798BF1827D989F09F346CE95F7

SHA1:

05E491BC1B8FBFBFDCA24B565F2464137F30691E

SHA256:

DE87C8713FAC002B0B0A0F9B02C4E3EBCCCF65282A22F5AB5912A9DA00F35C2A

SSDEEP:

24576:mjSsPIqS9jL0rJ3n770E9d8qTtE4n4CucuHA:GzyH0ZOqTGQ4CDug

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • AHK has been detected (YARA)

      • qDu.u.exe (PID: 2060)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • qDu.u.exe (PID: 2060)
  • INFO

    • The sample compiled with english language support

      • qDu.u.exe (PID: 2060)
    • Detects AutoHotkey samples (YARA)

      • qDu.u.exe (PID: 2060)
    • Checks supported languages

      • qDu.u.exe (PID: 2060)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (35.8)
.exe | Win64 Executable (generic) (31.7)
.scr | Windows screen saver (15)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:08:23 07:49:30+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 701440
InitializedDataSize: 231936
UninitializedDataSize: -
EntryPoint: 0x9c940
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.1.34.4
ProductVersionNumber: 1.1.34.4
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: AutoHotkey Unicode 32-bit
FileVersion: 1.1.34.04
InternalName: AutoHotkey
LegalCopyright: Copyright (C) 2003-2013
OriginalFileName: AutoHotkey.exe
ProductName: AutoHotkey
ProductVersion: 1.1.34.04
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
33
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #AHK qdu.u.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2060"C:\Users\admin\AppData\Local\Temp\qDu.u.exe" C:\Users\admin\AppData\Local\Temp\qDu.u.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
AutoHotkey Unicode 32-bit
Version:
1.1.34.04
Modules
Images
c:\users\admin\appdata\local\temp\qdu.u.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winmm.dll
Total events
73
Read events
73
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted

Threats

No threats detected
No debug info