Our call: Is AutoHotkey_2.0.26.zip safe?Safe
This file is a legitimate AutoHotkey distribution, and the single heuristic detection is a known false positive common to automation tools that hook system processes.
- 1 high-confidence signature or behavior rule matched this file.Derived · Signature and behavior rules
- 1 of 74 antivirus engines flagged the file, including Zillya.Observed · Antivirus analysis
- The hash has been submitted 788 times from 717 sources.Derived · Saved report facts
43522aa3122a57784a…55f9e926aeRecommended next actions
Before opening or extracting
Open or extract it only when its sender or download source has been independently verified.
If you already opened or extracted it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete3 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
AutoHotkey_2.0.26.zip
43522aa3122a57784ac5db30abf85c2244475c36acd7796e2c993355f9e926ae
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\AutoHotkey32.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\AutoHotkey64.exe"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
AutoHotkey32.exe
C:\Program Files\AutoHotkey\v2\AutoHotkey32.exe
04Isolated runtime analysis - Written fileObserved
AutoHotkey64.exe
C:\Program Files\AutoHotkey\v2\AutoHotkey64.exe
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
162.159.36.2
Contact observed during runtime.
06Isolated runtime analysis
6 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
1 of 74 antivirus engines flagged the file, including Zillya.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 788 times from 717 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: AutoHotkey_2.0.26.zip — 43522aa3122a57784ac5db30abf85c2244475c36acd7796e2c993355f9e926ae
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\AutoHotkey32.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\<USER>\AppData\Local\Temp\AutoHotkey64.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: AutoHotkey32.exe — C:\Program Files\AutoHotkey\v2\AutoHotkey32.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: AutoHotkey64.exe — C:\Program Files\AutoHotkey\v2\AutoHotkey64.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Our analysis indicates this file is a legitimate AutoHotkey utility. The single detection is a generic heuristic flag, and the observed sandbox behaviors are consistent with the tool's intended automation functionality rather than malicious activity.
The file is a standard distribution of AutoHotkey, a widely used automation tool. While one engine flagged it as a trojan, 17 high-trust engines reported it as clean, and there is no consensus among security vendors. The sandbox behaviors, including process injection and credential access, are well-documented false-positive triggers for this software because it uses system hooks to perform its automation tasks. Given the prevalence and the lack of corroborating malicious signals, we conclude this is a false positive.
What We Detected
The file 'AutoHotkey_2.0.26.zip' is a legitimate software package. Our analysis shows that 73 out of 74 engines found no issues, with only one tier-2 engine providing a generic heuristic detection. This pattern is typical for automation tools that are frequently misidentified by heuristic scanners.
Threat Behavior
The sandbox observed behaviors such as process injection and interaction with system processes. While these techniques are often used by malware, they are also core components of AutoHotkey's functionality, which requires hooking into the operating system to automate keyboard and mouse inputs. These behaviors are expected for this type of software and do not indicate malicious intent in this context.
What To Do Now
This file is safe to use. If your security software continues to flag it, you may need to add an exclusion for the AutoHotkey installation directory. Always ensure you download such tools from the official project website to maintain integrity.
Where this verdict could be wrong2 caveats
- The 'Trojan.GenKryptik' label from Zillya is a generic heuristic detection that can trigger on legitimate packed binaries.
- Sandbox heuristics flagged LSASS access and process injection, which are common false-positive triggers for automation tools that hook system processes.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 17/17 tier-1 engines reported clean
- Medium prevalence (788 submissions)
- No malicious external intelligence hits
The file is safe to use. No action is required.
Behavior
Plain-English impact first, then the observed runtime evidence.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Program Files\AutoHotkey\v2\AutoHotkey32.exe
- C:\Program Files\AutoHotkey\v2\AutoHotkey64.exe
- C:\Program Files\AutoHotkey\v2\AutoHotkey.chm
- C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe
- C:\Program Files\AutoHotkey\UX\install-ahk2exe.ahk
- C:\Program Files\AutoHotkey\v2\AutoHotkey32.exe:Zone.Identifier
- C:\Program Files\AutoHotkey\v2\AutoHotkey64.exe:Zone.Identifier
- C:\Program Files\AutoHotkey\v2\AutoHotkey.chm:Zone.Identifier
- C:\Program Files\AutoHotkey\UX\AutoHotkeyUX.exe:Zone.Identifier
- C:\Program Files\AutoHotkey\UX\install-ahk2exe.ahk:Zone.Identifier
- cversions.3.m
- Global\OneSettingQueryMutex+compat+encapsulation
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- e19e68f3904e1e5d3eee…2e53c3Never scannednever seen before
- af304c425b28d247f771…0fff39Never scannednever seen before
- c2563ab626df89239808…fad854Never scannednever seen before
- 5f0208e050c64b5b8c77…1ed651Never scannednever seen before
- 179fc8b7ec8ed9c3240b…ed11f2Never scannednever seen before
- b29f7037876d82deaaf2…299967Never scannednever seen before
- 9b75c7f804d1d5580745…53b982Never scannednever seen before
- cfa4775b267c527a2ea1…e8a0f2Never scannednever seen before
- 48a3f822a720b8e9b411…cf0f1bNever scannednever seen before
- c7e976240a067afdf6f8…d74bc5Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeThe sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence162.159.36.2
1 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- AutoHotkey_2.0.26.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 3.0 MB
- Last analyzed
- Jul 29, 2026, 9:43 PM UTC
43522aa3122a57784ac5db30abf85c2244475c36acd7796e2c993355f9e926aeSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
Open or extract it only when its sender or download source has been independently verified.
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
Keep your antivirus and Windows updates switched on so you stay protected.