Safe
Legitimate Malwarebytes installer signed by official publisher with clean scans across our antivirus network and typical security software behavior.
0b9465643cd2609856…430c97bf41The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file matches all criteria for a signed commercial installer: verified signature from curated trusted publisher 'Malwarebytes', zero malicious detections even from tier-1 engines, no malicious runtime signals. Heuristics firing on process injection (T1055) and LSASS access are standard for AV installers to hook processes and scan system credentials. YARA rules are generic anti-VM/detection evasions common in protected software. Community notes confirm official download source, outweighing outlier malware tags.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
signing.trustedPublisher.matched=true ('Malwarebytes')
engines.tier1Malicious=0 / 17 tier1 clean (Avast, BitDefender, Kaspersky)
prevalence.uniqueSources=2946 / timesSubmitted=3904
file.fileName='MBSetup.exe' + signing.signer='Malwarebytes Inc'
communityComments[0]: downloaded from official malwarebytes.com
- Trusted Malwarebytes signature
- 17 tier-1 engines clean
- Common prevalence (2946 sources)
- Official download confirmed in comments
- No malicious sandbox verdict
- Heuristic process injection (T1055) into svchost.exe
- LSASS memory access pattern
- YARAify 14 rules (generic anti-analysis)
- Direct IP contact (16.145.101.152)
This is safe and legitimate Malwarebytes software. Run it to install if needed, or ignore/delete if not sourced from official site.
Sandworm ArguePatch Apr 2022 1 corroborated by 1 source
- 14 YARA rulesAPT_Sandworm_ArguePatch_Apr_2022_1, Check_VBox_Description, DebuggerCheck__API
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 16.145.101.152
- https://api2.amplitude.com/batch
- C:\Users\<USER>\AppData\Local\Temp\mbsetup.log
- C:\ProgramData\mbamtestfile.dat
- C:\Program Files (x86)\mbamtestfile.dat
- C:\Windows\System32\drivers\mbamtestfile.dat
- C:\Windows\System32\wbem\repository\WRITABLE.TST
- C__Users_Bruno_Desktop_MbamSetup.exe
- Global\OneSettingQueryMutex+compat+encapsulation
- C__Users_azure_Downloads_MbamSetup.exe
- \Sessions\1\BaseNamedObjects\C__Users_user_Desktop_MbamSetup.exe
Files this sample writes at runtime
This file drops 2 children at runtime. None are currently flagged malicious in our cache.
- ede1645ea6d74ba2267a…6cea2aNever scannednever seen before
- 3c3b166e33d1fdf710f0…51d9d8Never scannednever seen before
1 corroborating signal from researcher-curated sources
- APT_Sandworm_ArguePatch_Apr_2022_1by Arkbird_SOLGDetect ArguePatch loader used by Sandworm group for load CaddyWiper
- Check_VBox_Description
- DebuggerCheck__API
- DetectEncryptedVariantsby ZinythDetects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
- FreddyBearDropperby Dwarozh HoshiarFreddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
- APT_Sandworm_ArguePatch_Apr_2022_1
- Check_VBox_Description
- DebuggerCheck__API
- DetectEncryptedVariants
- FreddyBearDropper
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeSample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence16.145.101.152
0 detections across 76 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.
Forensic fingerprint
- File name
- MBSetup.exe
- Size
- 2.72 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 0b9465643cd2609856e7ebdebc34296670a2b388c2bcf6e5ee0b59430c97bf41
- MD5
- c12892ce63fe1ece5eb0b551019f0b9a
- SHA-1
- 1c8e0ef2c2af8a6cc7763e87a3db307cf231df6d
- PE imphash
- 8c1be39b6ace6c7da85b7edd83bef6f8
- First seen (VT)
- 4/7/2026, 7:05:07 PM
- Last analysis (VT)
- 4/23/2026, 11:15:55 PM
- First scan (MalwareTips)
- 4/24/2026, 1:17:49 AM
- Last scan (MalwareTips)
- 4/24/2026, 1:17:49 AM
- Code signer
- Malwarebytes Incverified
- Community reputation
- -8flagged
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.