Safe
Single low-trust engine flag on an unsigned 8-year-old file with medium prevalence and clean sandbox results.
23411007ac7b7d324b…a8668e2f05The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The engine distribution matches the low-trust-only false-positive archetype exactly. Medium prevalence and multi-year age argue against a novel threat. Sandbox and dropped-file results are clean. The two synthesis heuristics are legitimate signals but insufficient to override the dominant safe indicators when tier-1 coverage is unanimous clean.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines.onlyLowTrustFlagging=true with tier1Malicious=0 (Jiangmin sole flag)
prevalence.classification=medium (98 uniqueSources since 2018-01-11)
behaviour.hasMaliciousSandboxVerdict=false and droppedChildren.hasMaliciousChild=false
externalIntel.yaraify.ruleCount=0 and circl.knownMalicious=null
- Zero tier-1 malicious detections
- Medium prevalence over 8 years
- No malicious sandbox verdict or children
- Process injection technique observed (T1055)
- Direct-IP network contact without DNS
Treat as safe; the single low-trust flag is a classic false positive on an established file.
stealer corroborated by 1 source
- VT (75 engines)stealer
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- a83f:8110:0:0:1400:0:0:0
- 23.216.147.76
- a83f:8110:cce1:d301:10:0:0:0
- 20.99.132.105
- 23.216.147.62
- 20.80.129.13
- 20.99.184.37
- 20.99.133.109
- 20.99.186.246
- 192.229.211.108
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_admin\580
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8023.timestamp
- C:\ProgramData\Oracle\Java\.oracle_jre_usage
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8080.timestamp
- C:\Users\user\AppData\Local\Temp\hsperfdata_user
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c7c05.timestamp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER124A.tmp.WERInternalMetadata.xml
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER12E7.tmp.csv
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1336.tmp.txt
- C:\Windows\System32\spp\store\2.0\cache\cache.dat
- CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.TMD.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
Files this sample writes at runtime
This file drops 9 children at runtime. None are currently flagged malicious in our cache.
- 13f8be4dafd0a0d261d4…8b96f1Never scannednever seen before
- 63b84513f63e7911a977…58c2f6Never scannednever seen before
- 363d6bdbcec8fd9c84e1…22be11Never scannednever seen before
- c21c6b13afec132f2bbf…e4350aNever scannednever seen before
- d019edfbf6d2b12bf41c…e958f4Never scannednever seen before
- 445ce1f1164d368b3d44…75eab9Never scannednever seen before
- 6eccf3ce31c9423f2b62…19fab8Never scannednever seen before
- 4ff4b0d96b3817686146…bf9292Never scannednever seen before
- b6555a95843fb699aef1…f6f555Never scannednever seen before
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe" -nohome"Sample contacted 18 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidencea83f:8110:0:0:1400:0:0:0 · 23.216.147.76 · a83f:8110:cce1:d301:10:0:0:0
1 detection across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- FTLProfileEditor.exe
- Size
- 23.5 KB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 23411007ac7b7d324bb457fe3a4a4155c6bdc0bb2cd82722cd518da8668e2f05
- MD5
- d5dca14f14b18296aece3a85f8d44e57
- SHA-1
- 8727414fef9880de0db6b33fb8dd020b7c714acf
- PE imphash
- 84b3221283aac2bcdcfe1b1a69fd01d7
- First seen (VT)
- 1/11/2018, 5:50:45 PM
- Last analysis (VT)
- 5/29/2026, 9:21:36 AM
- First scan (MalwareTips)
- 5/29/2026, 9:27:46 AM
- Last scan (MalwareTips)
- 5/29/2026, 9:27:46 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.