File verdict·Decided by the MT AI Engine
Our call

Suspicious

Unsigned tool exhibiting process injection and direct-IP contact; no tier-1 consensus or malicious hosts detected, but heuristic signals warrant caution.

Trust score52Caution
MT AI confidence · 62%
ZEN Scripter
8.7 MB
0e01904957d0d45f3abacc366a11
Antivirus engines
0 of 66 flagged
Code signing
Unsigned
Age
First seen 4y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

62%Confidence
Moderate
Reasoning

This unsigned executable exhibits suspicious heuristic patterns — process injection and direct-IP contact — that typically indicate evasive malware. However, the complete absence of detections from tier-1 engines (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, F-Secure, Ikarus, GData, Emsisoft, DrWeb, Avira) and zero malicious host cache hits argue against active malware. The 21 ambient MITRE techniques (system discovery, registry access, file enumeration) are consistent with legitimate system-monitoring or scripting tools. The file's 1284-day submission history and medium prevalence (47 submitters) suggest an established tool rather than a zero-day. The heuristic rules are evidence of suspicious behaviour, not verdicts; they require corroboration from detections or sandbox consensus, which is absent here.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. tier1Malicious=0 across 14 tier-1 engines (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, F-Secure, Ikarus, GData, Emsisoft, DrWeb, Avira all undetected)

  2. triggeredHeuristics: MalwareTips.Synth.ProcessInjection (T1055) and MalwareTips.Synth.DirectIpC2 fired, but no tier-1 consensus on family and no malicious host cache hits for 11 contacted IPs

  3. behaviour: 1 offensive technique (T1055) + 21 ambient techniques (T1082, T1083, T1087, T1112, T1113, T1115, T1129, T1497, T1564.003, T1614, T1071, T1056.001, T1059, T1027.002, T1027.005, T1010, T1012, T1027, T1033, T1115, T1497.001) — mixed profile inconsistent with pure malware

  4. prevalence: medium (47 submitters, 51 submissions since Dec 2022); no external-intel hits (CIRCL, MalwareBazaar, YARA)

  5. unsigned, no signer history, no brand mismatch; filename 'ZEN Scripter' does not trigger security-software or research-tool classifiers

Points in its favour
  • Zero tier-1 engine detections across 14 high-trust vendors (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, F-Secure, Ikarus, GData, Emsisoft, DrWeb, Avira)
  • No malicious host cache hits for 11 contacted IPs; several are known CDN/cloud ranges
  • 1284-day submission history with medium prevalence (47 submitters, 51 submissions) — established tool, not zero-day
  • No malicious sandbox verdict, no dropped children, no persistence indicators
  • 21 ambient MITRE techniques consistent with legitimate system-monitoring or scripting tools
Points against
  • Process injection (T1055) observed — payload smuggled into legitimate process
  • Direct-IP C2 contact pattern — 11 external IPs contacted, zero DNS domains
  • Unsigned executable — no publisher identity or code-signing certificate
  • Heuristic rule triggers — MalwareTips.Synth.ProcessInjection and MalwareTips.Synth.DirectIpC2
What to do

Treat as suspicious pending manual review. The heuristic signals (process injection, direct-IP contact) are legitimate malware indicators, but the complete absence of tier-1 consensus and malicious host hits suggest a false positive or legitimate tool with unusual behaviour. If the source is trusted, execution in an isolated environment is acceptable; otherwise, isolate and monitor.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
22

Adversary techniques mapped to the MITRE ATT&CK framework.

T1010T1012T1027T1027.002T1027.005T1033T1055T1056.001T1059T1071T1082T1083T1087T1112T1113T1115T1129T1497T1497.001T1564.003T1614T1614.001
Spawned processes
5
$(unnamed)
"C:\Users\<USER>\Desktop\file.exe"
$(unnamed)
%SAMPLEPATH%\0e01904957d0d45f3a548085d7e6ae97d036c931e4447ad3c3e3c3bacc366a11.exe
$(unnamed)
C:\Windows\System32\wuapihost.exe
$(unnamed)
C:\Windows\System32\UI0Detect.exe
$(unnamed)
C:\Program Files\Google3804_1544199537\bin\updater.exe
Network activity
13
IP addresses13
  • 23.216.147.76
  • 20.99.184.37
  • 23.40.197.184
  • a83f:8110:5013:4d00:100:0:100:0
  • 192.168.0.42
  • 23.213.37.172
  • 192.168.0.49
  • 151.101.22.172
  • 20.69.140.28
  • 23.196.145.221
+3 more
Filesystem & mutexes
17
Files written2
  • C:\Windows\System32\Tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector
  • C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
Files deleted15
  • C:\Windows\System32\spp\store\2.0\cache\cache.dat
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER342A.tmp.WERInternalMetadata.xml
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER34D6.tmp.csv
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER3506.tmp.txt
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER3A07.tmp.WERInternalMetadata.xml
+10 more
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

2 synthesis
MITRE ATT&CK profile
Defense evasion× 1C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    "C:\Users\<USER>\Desktop\file.exe"
  • DirectIpC2medium

    Sample contacted 11 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    23.216.147.76 · 20.99.184.37 · 23.40.197.184
Antivirus engine breakdown

0 detections across 66 engines

0 malicious0 suspicious66 clean
Tier-114 engines
0flag
Top commercial AVs (low FP rate)
Tier-233 engines
0flag
Mainstream engines with mixed FP rates
Low-trust19 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 66 engines report this file as clean.
Hash 0e01904957d0… cross-referenced against 66 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

Unpacked
Section entropy8 sections
CODE
6.56
DATA
4.59
BSS
0.00
.idata
4.93
.tls
0.00
.rdata
0.21
.reloc
6.72
.rsrc
7.92
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
47
Moderate upload volume.
Total submissions
51
Includes repeat uploads by the same source.
First seen by VT
4y ago
Dec 15, 2022
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
12/15/2022, 4:46:04 PM
First seen (MalwareBazaar)
Last analysis (VT)
4/21/2026, 1:08:12 AM
Scanned here
6/22/2026, 5:13:18 AM
File name
ZEN Scripter
Size
8.66 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
0e01904957d0d45f3a548085d7e6ae97d036c931e4447ad3c3e3c3bacc366a11
MD5
9ede236cbd864af39bff861b57368554
SHA-1
bef048d54c2b4d714af51c966b828af64c883342
PE imphash
65ce057600e3d9ea4ed37f5f68912c21
First seen (VT)
12/15/2022, 4:46:04 PM
Last analysis (VT)
4/21/2026, 1:08:12 AM
First scan (MalwareTips)
6/22/2026, 5:13:18 AM
Last scan (MalwareTips)
6/22/2026, 5:13:18 AM
Behavior tags
runtime-modulespeexeidledirect-cpu-clock-accessbobsoft
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.