Unknown
Single low-trust detection with zero tier-1 consensus and benign sandbox behaviour; likely false positive.
0603b790d8c8db731b…9f68fce09cThe reasoning behind this verdict
The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.
This file exhibits a classic low-trust-only detection pattern: 1 of 71 engines flagged it, that engine is low-trust tier, and the label is generic ('suspicious.low.ml.score'). All major tier-1 antivirus engines (BitDefender, Kaspersky, ESET, Fortinet, Avast, etc.) reported clean. The triggered heuristic (DirectIpC2) identified a single IP contact without DNS, which is a legitimate malware evasion indicator, but the absence of malicious sandbox verdicts, offensive MITRE techniques, and any malicious host cache match suggests the IP is likely a legitimate service endpoint (CDN, update server, or analytics). The file is unsigned and makes no false publisher claims. Prevalence is medium (4 submitters, 5 submissions) with no external intelligence corroboration.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 1/71 malicious (Trapmine, low-trust); tier1Malicious=0; onlyLowTrustFlagging=true
signing.verified=null (unsigned); no signer history; no brand mismatch
behaviour.hasMaliciousSandboxVerdict=false; offensiveCount=0; no malicious dropped children
triggeredHeuristics: MalwareTips.Synth.DirectIpC2 fired (medium) on contactedIps=['162.159.36.2'], but no corroborating malicious sandbox or host-cache hits
prevalence.classification='medium' (4 submitters, 5 submissions); no similar-hash RAG; no external intel (CIRCL/YARAify/MalwareBazaar) hits
- All 16 tier-1 antivirus engines reported clean
- Sandbox analysis: zero offensive MITRE techniques, no malicious dropped files, no persistence indicators
- No malicious host cache match for contacted IP
- No external intelligence corroboration (CIRCL, YARAify, MalwareBazaar all negative)
- Direct IP contact without DNS resolution (162.159.36.2) — flagged as potential C2 evasion, but no malicious host match
- Unsigned executable — no publisher verification available
- Low-trust engine detection — generic ML score, not a named malware family
This file is likely safe. The single low-trust detection is a false positive, contradicted by universal tier-1 engine silence and benign sandbox behaviour. If you obtained it from a trusted source, proceed with confidence; if uncertain, verify the source or run it in an isolated environment first.
What to do now
There isn't enough information to give this file a clear rating.
Be cautious — an unknown rating is not the same as a clean bill of health.
Only run it if it came directly from the official maker of the software.
When in doubt, don't open it — or scan it again later once it's more widely seen.
2 contradictions resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
YARA & heuristic rule matches
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2
1 detection across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- CaseCracker3.exe
- Size
- 651.0 KB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 0603b790d8c8db731b6169a053f36c1f0c7be5d97c97245ed540239f68fce09c
- MD5
- a8c35ffaf42e8d555f678525ceba9a86
- SHA-1
- 078cdf3e582917dde6145c89144278f7ab7945fc
- PE imphash
- ce1183cc150987a99aef5749f22af81e
- First seen (VT)
- 5/14/2026, 12:00:05 PM
- Last analysis (VT)
- 6/27/2026, 1:42:31 AM
- First scan (MalwareTips)
- 6/27/2026, 3:36:50 PM
- Last scan (MalwareTips)
- 6/27/2026, 3:36:50 PM
Safety FAQ
Common questions about CaseCracker3.exe, answered from the scan data above.
- We can't give CaseCracker3.exe a confident verdict yet — too few engines have an opinion on this exact file. Uncommon or brand-new files often show little coverage before vendors catch up, so treat it as untrusted: don't run it unless you're certain of the source.
- CaseCracker3.exe is a Windows executable program, about 651 KB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
- 1 of 75 antivirus engines flagged CaseCracker3.exe, 1 of them as outright malicious. A small number of detections can include false positives, so we weigh which engines flagged it and what else the file does, not just the raw count.
- The SHA-256 hash of CaseCracker3.exe is 0603b790d8c8db731b6169a053f36c1f0c7be5d97c97245ed540239f68fce09c, and its MD5 is a8c35ffaf42e8d555f678525ceba9a86. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on June 27, 2026. Because a file's hash never changes, the identity of CaseCracker3.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.