Safe
Clean across 71 engines including all tier-1 scanners; behaviour matches WebView2 portable app with minor heuristic flags explained by CDN usage.
217663b0928af6be64…ec47434707The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
With perfect engine results (0 malicious from 71 reporters, 17 tier-1 clean), this file lacks any detection consensus. Behaviour reveals a standard WebView2 app from flick.winscript.dev, writing expected app data and launching edgewebview2.exe. The direct IP to Cloudflare (162.159.36.2) triggered a heuristic but aligns with CDN asset loading in portable web apps. Unsigned status and newness raise caution, but medium prevalence and no malicious runtime evidence support safety. Anti-debug tags are common in apps.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/71 malicious (17 tier1 clean)
contactedIps: [162.159.36.2] (Cloudflare)
triggeredHeuristics[0].rule: MalwareTips.Synth.DirectIpC2 (fired=true, medium)
prevalence.classification: medium
behaviour.offensiveCount=1 (T1562.001)
- 0 malicious detections (71 engines, 17 tier1 clean)
- Medium prevalence (18 sources)
- No malicious sandbox verdict
- No malicious dropped children
- Behaviour consistent with WebView2 app
- Direct IP connection (162.159.36.2) without DNS
- Unsigned executable
- Recent first submission (1 day old)
- Offensive MITRE T1562.001 detected
- detect-debug-environment tag
This file is safe based on our analysis. Verify the download source and run in a sandbox if handling sensitive data, given its unsigned and recent status.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Users\user\AppData\Local\flick.winscript.dev
- C:\Users\user\AppData\Local\flick.winscript.dev\EBWebView
- C:\Users\user\AppData\Local\flick.winscript.dev\EBWebView\BrowserMetrics
- C:\Users\user\AppData\Local\flick.winscript.dev\EBWebView\BrowserMetrics\BrowserMetrics-69ED4E5D-7DC.pma
- C:\Users\user\AppData\Local\flick.winscript.dev\EBWebView\Crashpad
- \Sessions\1\BaseNamedObjects\DBWinMutex
- \Sessions\1\BaseNamedObjects\Local\ChromeProcessSingletonStartup!
- \Sessions\1\BaseNamedObjects\__OMADM_NAMED_MUTEX__
Files this sample writes at runtime
This file drops 2 children at runtime. None are currently flagged malicious in our cache.
- 41c91a9c93d76295746a…1cc304Never scannednever seen before
- f7b24f2eb3d5eb055052…8b5fedNever scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2
0 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- winscript-portable.exe
- Size
- 10.66 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 217663b0928af6be647766aa9d81e028802e7b957258e821f0c48fec47434707
- MD5
- df2b7aa621032f7d173d1568c5f9ea80
- SHA-1
- 6f6e6d3b35619aabbd6da3846517dc5072177719
- PE imphash
- c9b35c76dbec5f8bb5efd850a3c8022f
- First seen (VT)
- 4/25/2026, 6:19:47 PM
- Last analysis (VT)
- 4/26/2026, 7:02:48 AM
- First scan (MalwareTips)
- 4/27/2026, 5:43:47 AM
- Last scan (MalwareTips)
- 4/27/2026, 5:43:47 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.