| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2026-Apr-21 18:32:52 |
| Detected languages |
English - United States
|
| FileDescription | AutoHotkey 64-bit |
| FileVersion | 2.0 |
| CompanyName | AutoHotkey Foundation LLC |
| ProductName | AutoHotkey |
| ProductVersion | 2.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Suspicious | The PE is possibly packed. | Unusual section name found: .fptable |
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Suspicious | No VirusTotal score. | This file has never been scanned on VirusTotal. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x118 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 6 |
| TimeDateStamp | 2026-Apr-21 18:32:52 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_RELOCS_STRIPPED
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xca600 |
| SizeOfInitializedData | 0x53600 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000A6DAC (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x122000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
|
| SizeofStackReserve | 0x400000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| WSOCK32.dll |
WSAGetLastError
getservbyname htonl send recv inet_addr WSAAsyncSelect inet_ntoa gethostbyname WSASetLastError ioctlsocket htons gethostbyaddr getservbyport ntohs WSAStartup shutdown WSACleanup closesocket connect socket |
|---|---|
| WINMM.dll |
joyGetPosEx
mciSendStringW |
| COMCTL32.dll |
ImageList_GetIconSize
CreateStatusWindowW |
| PSAPI.DLL |
GetProcessImageFileNameW
|
| SHLWAPI.dll |
StrCmpLogicalW
|
| UxTheme.dll |
EnableThemeDialogTexture
SetWindowTheme IsAppThemed |
| dwmapi.dll |
DwmGetWindowAttribute
|
| KERNEL32.dll |
GlobalFree
GlobalUnlock WideCharToMultiByte GetCPInfo GetSystemDirectoryA LoadLibraryA GetProcAddress FreeLibrary GetCurrentThreadId GetEnvironmentVariableW IsValidCodePage LoadLibraryW GetLastError OutputDebugStringW lstrcmpiW GetStringTypeExW CreateThread SetThreadPriority GetExitCodeThread CloseHandle CreateMutexW VirtualProtect SetLastError GetModuleHandleW CreateFileW MultiByteToWideChar GetFullPathNameW GetFileAttributesW ReadFile LoadResource LockResource WriteFile SizeofResource SetCurrentDirectoryW CompareStringOrdinal FindFirstFileW FindNextFileW FindClose FileTimeToLocalFileTime GetSystemTimeAsFileTime GetFileSizeEx GetCurrentProcessId GlobalLock TerminateProcess GetProcessId QueryDosDeviceW EnterCriticalSection LeaveCriticalSection GetLocalTime GetDateFormatW GetTimeFormatW GetDateFormatEx GetTickCount64 GetSystemTime GetSystemDefaultUILanguage GetComputerNameW GetCurrentDirectoryW GetSystemWindowsDirectoryW GetTempPathW WaitForSingleObject GetExitCodeProcess GetVersionExW InitializeCriticalSection DeleteCriticalSection GetModuleFileNameW SetDllDirectoryW GetModuleHandleExW GetShortPathNameW CreateProcessW FormatMessageW GetCurrentProcess SetEndOfFile GetACP GetFileType GetStdHandle SetFilePointerEx SystemTimeToFileTime FileTimeToSystemTime GetFileSize EnumResourceNamesW LoadLibraryExW GlobalSize FindResourceW SetErrorMode Sleep GetTickCount MulDiv RaiseException EncodePointer InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree GetCommandLineA GetCommandLineW ExitProcess RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent QueryPerformanceCounter InitializeSListHead RtlUnwindEx HeapSize HeapReAlloc HeapQueryInformation HeapFree HeapAlloc GetProcessHeap FindFirstFileExW GetOEMCP GetEnvironmentStringsW FreeEnvironmentStringsW FlsAlloc FlsGetValue FlsSetValue FlsFree InitializeCriticalSectionEx LCMapStringW GlobalAlloc SetStdHandle GetStringTypeW FlushFileBuffers GetConsoleOutputCP GetConsoleMode WriteConsoleW OpenProcess RtlPcToFileHeader |
| USER32.dll |
IsZoomed
IsIconic DestroyWindow RegisterClassExW SystemParametersInfoW CreateWindowExW GetMenu EnableMenuItem LoadAcceleratorsW RemoveClipboardFormatListener LoadImageW PostQuitMessage CheckMenuItem RegisterWindowMessageW DefWindowProcW SetForegroundWindow GetMenuItemCount GetPropW GetClassLongW SetMenu SetPropW RemovePropW GetSysColor RedrawWindow DrawTextW SetParent GetClassInfoExW AdjustWindowRectEx GetAncestor UpdateWindow FlashWindow GetMessagePos GetSysColorBrush FillRect GetClassLongPtrW CallWindowProcW CheckRadioButton IntersectRect GetUpdateRect PtInRect CreateDialogIndirectParamW CreateAcceleratorTableW DestroyAcceleratorTable InsertMenuItemW RemoveMenu SetMenuItemInfoW GetMenuItemInfoW SetMenuDefaultItem CreateMenu CreatePopupMenu SetMenuInfo DestroyMenu TrackPopupMenuEx CopyImage CreateIconIndirect CreateIconFromResourceEx DrawIconEx EnumClipboardFormats GetWindow BringWindowToTop GetQueueStatus MapVirtualKeyW VkKeyScanExW EnumWindows GetKeyboardLayoutNameW ActivateKeyboardLayout GetGUIThreadInfo GetWindowTextW mouse_event WindowFromPoint keybd_event SetKeyboardState GetKeyboardState GetCursorPos GetAsyncKeyState AttachThreadInput SendInput UnregisterHotKey RegisterHotKey SendMessageTimeoutW CharUpperW UnhookWindowsHookEx SetWindowsHookExW PostThreadMessageW IsCharAlphaNumericW IsCharUpperW IsCharLowerW ToUnicodeEx CallNextHookEx CharLowerW ReleaseDC GetDC DialogBoxParamW ScrollWindow GetSystemMetrics GetWindowRect GetWindowLongPtrW SetFocus DefDlgProcW MoveWindow MapWindowPoints GetClientRect EnableWindow MapDialogRect GetDlgItem SetWindowLongPtrW SetWindowTextW MessageBoxW OpenClipboard GetClipboardData GetClipboardFormatNameW CloseClipboard SetClipboardData EmptyClipboard SetWindowPos IsChild IsWindowVisible EnumChildWindows GetLastInputInfo LoadCursorW GetCursorInfo ClientToScreen GetIconInfo GetWindowTextLengthW InvalidateRect PostMessageW FindWindowW EndDialog IsWindow DispatchMessageW TranslateMessage ShowWindow IsClipboardFormatAvailable CountClipboardFormats SetWindowLongW ScreenToClient DestroyIcon IsDialogMessageW SendMessageW IsWindowEnabled GetWindowLongW GetKeyState TranslateAcceleratorW KillTimer PeekMessageW GetFocus GetClassNameW GetWindowThreadProcessId GetForegroundWindow GetMessageW SetTimer GetParent GetDlgCtrlID IsCharAlphaW MapVirtualKeyExW GetKeyboardLayout |
| GDI32.dll |
GdiFlush
CreateDIBSection EnumFontFamiliesExW GetObjectW SetBrushOrgEx CreatePatternBrush GetClipBox SetBkMode SetBkColor GetDeviceCaps CreateCompatibleDC CreateFontIndirectW GetStockObject CreateSolidBrush GetCharABCWidthsW GetTextMetricsW GetDIBits SelectObject CreateFontW DeleteObject CreateCompatibleBitmap DeleteDC SetTextColor |
| ADVAPI32.dll |
UnlockServiceDatabase
RegDeleteKeyW RegSetValueExW RegCreateKeyExW RegQueryValueExW RegDeleteValueW GetUserNameW RegConnectRegistryW RegCloseKey RegOpenKeyExW RegQueryInfoKeyW RegEnumValueW RegEnumKeyExW CreateProcessWithLogonW OpenSCManagerW LockServiceDatabase CloseServiceHandle RegDeleteKeyExW |
| SHELL32.dll |
DragFinish
SHGetKnownFolderPath ExtractIconW DragQueryPoint DragQueryFileW ShellExecuteExW SHGetFolderPathW Shell_NotifyIconW |
| ole32.dll |
CoCreateInstance
CoTaskMemFree CLSIDFromString OleInitialize OleFlushClipboard OleUninitialize CLSIDFromProgID CoGetObject StringFromGUID2 CreateStreamOnHGlobal |
| OLEAUT32.dll |
SafeArrayDestroy
SysFreeString GetActiveObject SysStringLen SafeArrayCreate VariantClear VariantChangeType OleLoadPicture SafeArrayCopy SysAllocStringLen VariantCopyInd SafeArrayGetUBound SafeArrayGetLBound SafeArrayGetDim SafeArrayLock SysAllocString SafeArrayPtrOfIndex SafeArrayUnlock SafeArrayAccessData SafeArrayGetElemsize SafeArrayUnaccessData |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 2.0.0.0 |
| ProductVersion | 2.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileDescription | AutoHotkey 64-bit |
| FileVersion (#2) | 2.0 |
| CompanyName | AutoHotkey Foundation LLC |
| ProductName | AutoHotkey |
| ProductVersion (#2) | 2.0 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-21 18:32:52 |
| Version | 0.0 |
| SizeofData | 900 |
| AddressOfRawData | 0xf9a0c |
| PointerToRawData | 0xf840c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Apr-21 18:32:52 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x140106040 |
| XOR Key | 0x936bd1de |
|---|---|
| Unmarked objects | 0 |
| ASM objects (33145) | 23 |
| ASM objects (35207) | 9 |
| C objects (35207) | 19 |
| C++ objects (35207) | 46 |
| C objects (33145) | 35 |
| C++ objects (33145) | 159 |
| C objects (CVTCIL) (33145) | 1 |
| Imports (33145) | 33 |
| Total imports | 497 |
| ASM objects (35225) | 2 |
| C++ objects (LTCG) (35225) | 66 |
| Resource objects (35225) | 1 |
| Linker (35225) | 1 |
No comments yet.