Is AutoHotkey Setup safe?
Generic detections and UPX packing warrant caution, although tier-1 engines, network reputation checks, dropped-file inspection, and sandbox verdicts provide substantial counter-evidence.
Only 4 of 75 engines flagged this unsigned, UPX-packed installer, and none was tier-1 or identified a consistent family. A sandbox mapped activity to T1055, but issued no malicious verdict; complete domain checks found no bad hosts, while all five community rules merely detected UPX packing.
aca3f50a66ac4c6fce…9a26ea1e087dc3Recommended next actions
Before opening
Do not open it until the source can be verified independently.
If you already opened it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Only 4 of 75 engines flagged this unsigned, UPX-packed installer, and none was tier-1 or identified a consistent family. A sandbox mapped activity to T1055, but issued no malicious verdict; complete domain checks found no bad hosts, while all five community rules merely detected UPX packing.
The scan produced four generic detections among 75 engines, with no tier-1 detection or family consensus. The executable is unsigned and UPX-packed, which reduces transparency and makes the weak detections more relevant. One sandbox mapped activity to T1055 and exposed an LSASS process, but the supplied evidence does not establish actual credential access or a malicious sandbox conclusion. Its network activity went to GitHub and certificate-revocation infrastructure, with all five distinct domains covered by the host check and none listed as malicious or suspicious. The five community rules strengthen the packing finding, but all are UPX-oriented rather than malware-family signatures. These competing signals justify isolation and source verification rather than either immediate trust or a definitive malware-family attribution.
What We Detected
Four of 75 antivirus engines flagged the executable. SentinelOne reported a suspicious PE, while APEX, MaxSecure, and Trapmine used generic malicious or machine-learning labels; no tier-1 engine detected it and no family consensus formed. The file is unsigned, and peAnalysis.likelyPacked=true with an entropy value of 8 in the UPX1 section.
Threat Behavior
One sandbox mapped observed activity to MITRE T1055 and recorded an LSASS process, but it produced no malicious sandbox verdict and the evidence does not prove memory access or credential theft. Network activity involved GitHub download infrastructure and certificate-revocation services. The host-reputation check covered all five distinct contacted domains and found no malicious or suspicious entries. Ten dropped files were inspected without a malicious child, although all ten remained unclassified.
Additional Context
Five community YARA rules matched, but every listed rule concerns UPX packing. That confirms obfuscating compression rather than a particular malware family. Broad prevalence across 1,912 sources and silence from 17 tier-1 engines are meaningful counter-signals.
What To Do Now
Do not run this copy until its SHA-256 is compared with a hash published by the official AutoHotkey distribution channel. If verification is unavailable, delete it and obtain a fresh installer directly from the official source while keeping endpoint protection enabled.
Where this verdict could be wrong4 caveats
- All 17 reporting tier-1 engines, including BitDefender, Kaspersky, ESET-NOD32, and Fortinet, left the sample undetected.
- The five YARAify matches identify UPX packing; none names a malware family, so their convergence is less decisive than five behavior- or family-specific rules.
- The sample contacted GitHub infrastructure and certificate-revocation hosts, and complete domain coverage found no cached malicious or suspicious host.
- All 10 dropped children remain unclassified rather than positively clean, so dropped-file analysis supplies no malicious corroboration but also limited reassurance.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- All 17 reporting tier-1 engines were undetected.
- No malicious sandbox verdict was recorded.
- Complete domain-reputation coverage found no malicious or suspicious contacted host.
- No malicious child was found among 10 inspected dropped files.
- The file was submitted by 1,912 distinct sources.
- The executable is unsigned despite code signing being applicable.
- peAnalysis.likelyPacked=true with a high-entropy UPX1 section.
- MITRE T1055 was mapped during one sandbox run.
- Four generic detections were recorded among 75 engines.
- Five UPX-oriented community YARA rules matched.
Quarantine this copy and verify its SHA-256 against the official publisher's release before use. If it cannot be verified, download a fresh installer from the official channel and keep endpoint protection enabled.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete4 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial5 of 10 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete9 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 8MITRE ATT&CK techniques
- 10spawned processes
- 15network contacts
- 15filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Note: Reads your Windows user-account details.
Note: Listed running processes; both legitimate software and malware may do this.
Note: Collects details about your system.
Note: Connected to 10 servers during sandbox analysis.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
AutoHotkey Setup
aca3f50a66ac4c6fcee5bd168c90929c70f3ea9e12fc62b6699a26ea1e087dc3
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\AutoHotkey_2.0.28_setup.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\services.exe
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Download-1.tmp
C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
04Isolated runtime analysis - Written fileObserved
AutoHotkey
C:\Program Files\AutoHotkey
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
api.github.com
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostDerived
github.com
Saved reputation verdict: safe.
07Contacted-host cross-check - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- api.github.com
- github.com
- release-assets.githubusercontent.com
- yr.c.lencr.org
- yr1.c.lencr.org
- 140.82.116.5
- 140.82.116.3
- 185.199.110.133
- 23.213.34.89
- 104.18.20.213
- http://yr.c.lencr.org/
- http://yr1.c.lencr.org/127.crl
- https://api.github.com/repos/AutoHotkey/Ahk2Exe/releases/latest
- https://github.com/AutoHotkey/Ahk2Exe/releases/download/Ahk2Exe1.1.37.02a2/Ahk2Exe1.1.37.02a2.zip
- https://release-assets.githubusercontent.com/github-production-release-asset/2136168/ab0329ed-f82d-4d48-8dd8-954bcdda9dc5?sp=r&sv=2018-11-09&sr=b&spr=https&se=2026-09-12T06%3A02%3A36Z&rscd=attachment%3B+filename%3DAhk2Exe1.1.37.02a2.zip&rsct=application%2Foctet-stream&skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0&sktid=398a6654-997b-47e9-b12b-9515b896b4de&skt=2026-09-12T05%3A02%3A23Z&ske=2026-09-12T06%3A02%3A36Z&sks=b&skv=2018-11-09&sig=J4mFcT9Kbii%2FRzbHv4i2vVjntFyGo3Dth%2BgySN%2BasPo%3D&jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmVsZWFzZS1hc3NldHMuZ2l0aHVidXNlcmNvbnRlbnQuY29tIiwia2V5Ijoia2V5MSIsImV4cCI6MTc4OTE5MTI1NiwibmJmIjoxNzg5MTkwOTU2LCJwYXRoIjoicmVsZWFzZWFzc2V0cHJvZHVjdGlvbi5ibG9iLmNvcmUud2luZG93cy5uZXQifQ.a7jUTVyUn1tn0pG9OBG9hTtojMKHbWX8GZ-LZrkAe0E&response-content-disposition=attachment%3B%20filename%3DAhk2Exe1.1.37.02a2.zip&response-content-type=application%2Foctet-stream
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
- C:\Program Files\AutoHotkey
- C:\Program Files\AutoHotkey\.staging
- C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.28_setup.exe
- C:\Program Files\AutoHotkey\.staging\AutoHotkey_2.0.28_setup.exe\AutoHotkey.chm
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 3b7d1809c49b9932304f…1bb326Never scannednever seen before
- 461ab9fc31d12658e50c…d88568Never scannednever seen before
- 373181727d1ae858564d…b05e98Never scannednever seen before
- db2578b4ee5617f45acf…a015e7Never scannednever seen before
- 7f618d3ca343a0739a52…ec12d3Never scannednever seen before
- b29f7037876d82deaaf2…299967Never scannednever seen before
- a6c51e2188e31e351057…a859eeNever scannednever seen before
- 40a6f0cda5fd1dff324c…f33935Never scannednever seen before
- a9a824a763195e5810bf…9d69b9Never scannednever seen before
- 48a3f822a720b8e9b411…cf0f1bNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 9rule hits recorded
- 4 / 75engines flagged
- 1,912sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
7 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
4 of 75 antivirus engines flagged the file, including APEX and MaxSecure.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
YARAify matched 5 researcher rules to this file.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: AutoHotkey Setup — aca3f50a66ac4c6fcee5bd168c90929c70f3ea9e12fc62b6699a26ea1e087dc3
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\AutoHotkey_2.0.28_setup.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\services.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Download-1.tmp — C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: AutoHotkey — C:\Program Files\AutoHotkey
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: api.github.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: github.com — Saved reputation verdict: safe.
ProvenanceDerivedSourceContacted-host cross-checkObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- UPX
- upx_largefile
- UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
- UPXv20MarkusLaszloReiser
- win_upx_packed
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s WdiSystemHostPE is packed (high-entropy code or known packer) AND unsigned AND at least one engine flagged it. Packing alone is common in legit software; packing + unsigned + signal is the malware-dropper pattern.
Evidencehigh-entropy code sectionSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeUnsigned, packed PE with sandbox-observed network activity. The packing step hides the payload until execution; the network call fetches / reports for the next stage. Classic dropper / stager behaviour.
Evidenceapi.github.com
4 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
Executable sections have high entropy (7.2+) — the code is compressed or encrypted and only decrypted at runtime. Classic packing behaviour.
How widely this file has been seen
Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.
Fingerprint and provenance
- File name
- AutoHotkey Setup
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 2.9 MB
- Last analyzed
- Sep 24, 2026, 9:54 AM UTC
aca3f50a66ac4c6fcee5bd168c90929c70f3ea9e12fc62b6699a26ea1e087dc3Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is AutoHotkey Setup safe, or is it malware?
What is AutoHotkey Setup?
How many antivirus engines detected AutoHotkey Setup?
I already downloaded and opened AutoHotkey Setup — what should I do?
How do I remove AutoHotkey Setup?
What is the SHA-256 hash of AutoHotkey Setup?
How up to date is this analysis of AutoHotkey Setup?
Community
Member reviews and reports for this exact file hash.