File verdict·Decided by the MT AI Engine
Our call

Malicious

Four tier-1 antivirus engines converge on Win64 trojan family; explicit hacktool label for Windows Defender disabler; offensive MITRE techniques confirm malicious intent.

win64
Trust score8Critical
MT AI confidence · 92%
enable-defender.exe
286.5 KB
123866f5752a876a563357184224
Antivirus engines
13 of 74 flagged
Code signing
Unsigned
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

92%Confidence
Very high
Reasoning

The file exhibits a strong malicious profile: 4 tier-1 engines converge on the 'win64' family, with specific trojan names (Win64.Trojan.Disabler.K, Trojan.Win64.KILLAV, Program:Win32/Wacapew.C!ml). Alibabacloud explicitly identifies it as a hacktool for disabling Windows Defender. Static behaviour analysis reveals 7 offensive MITRE techniques including process injection (T1134), system-process modification (T1543.003), registry persistence (T1547.001), and tool disabling (T1562.001). The filename 'enable-defender.exe' is adversarial misdirection — the actual purpose is to disable security controls. No sandbox verdicts are available, but the convergence of tier-1 detections and explicit hacktool labeling is decisive.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. tier1Malicious=4 (GData, Microsoft, TrendMicro×2); tier1FamilyConsensus.strong=true, family='win64'

  2. Alibabacloud: 'Hacktool:Win/DisableWindowsDefender' with labelFlags.hacktool=true

  3. Offensive MITRE: T1134, T1543.003, T1546.012, T1547.001, T1562.001 — process injection, persistence, evasion

  4. Unsigned file; filename 'enable-defender.exe' mismatches actual trojan purpose (disables, not enables)

  5. Engine families: Win64.Trojan.Disabler.K (GData), Trojan.Win64.KILLAV (TrendMicro), Program:Win32/Wacapew.C!ml (Microsoft)

Points in its favour
  • No malicious sandbox verdicts (no runtime execution data available)
  • No contacted malicious hosts or dropped malicious children
  • No external YARA or CIRCL hits (limited external corroboration, but not exculpatory)
Points against
  • Tier-1 antivirus consensus on Win64 trojan family
  • Explicit hacktool label for Windows Defender disabler
  • Process injection and persistence techniques (T1134, T1543.003, T1547.001)
  • Tool disabling capability (T1562.001) — targets security software
  • Unsigned executable with adversarial filename misdirection
  • 7 offensive MITRE techniques indicating malware-grade evasion
What to do

Block and quarantine this file immediately. Do not execute under any circumstances. If this file was downloaded or executed, perform a full system scan with a clean antivirus tool and verify Windows Defender is enabled and functioning.

Threat family attribution

win64 corroborated by 1 source

  • MT AI Engine
    win64
No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

13 detections across 74 engines

13 malicious0 suspicious61 clean
Tier-117 engines
4flag
Top commercial AVs (low FP rate)
Tier-237 engines
2flag
Mainstream engines with mixed FP rates
Low-trust20 engines
7flag
Heuristic / generic-AI engines (high FP rate)
alibabacloud
malicious
Hacktool:Win/DisableWindowsDefender
APEX
malicious
Malicious
Bkav
malicious
W32.Malware.22284388
CrowdStrike
malicious
win/malicious_confidence_60% (D)
Elastic
malicious
malicious (moderate confidence)
GData
malicious
Win64.Trojan.Disabler.K
huorong
malicious
Trojan/KillAV.bk
McAfeeD
malicious
ti!123866F5752A
Microsoft
malicious
Program:Win32/Wacapew.C!ml
SentinelOne
malicious
Static AI - Suspicious PE
Trapmine
malicious
malicious.moderate.ml.score
TrendMicro
malicious
Trojan.Win64.KILLAV.SMYXCB2
TrendMicro-HouseCall
malicious
Trojan.Win64.KILLAV.SMYXCB2
Hash 123866f5752a… cross-referenced against 74 AV engines via our AV network.
File identity

Forensic fingerprint

File biography
First seen (VT)
First seen (MalwareBazaar)
Last analysis (VT)
6/24/2026, 12:26:07 PM
Scanned here
6/24/2026, 12:27:39 PM
File name
enable-defender.exe
Size
286.5 KB
MIME type
application/x-msdownload
Detected type
(unknown)
SHA-256
123866f5752a876a562fe8fca3b61846aecf3881477d31aedf735e3357184224
MD5
863303f5468199f1f5f6dddf3474fb04
SHA-1
9dae787d2df5248f12d70e89f6826bd160f12d2f
Last analysis (VT)
6/24/2026, 12:26:07 PM
First scan (MalwareTips)
6/24/2026, 12:27:39 PM
Last scan (MalwareTips)
6/24/2026, 12:27:39 PM
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Scanned by
harlan4096Staff
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.