Unknown
Our AI analyst is temporarily unavailable, so we've applied a conservative fallback: all 71 antivirus engines that scanned this file report it as clean.
3182b6025c5a211c5a…dc177596f0The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Our AI analyst is temporarily unavailable, so we've applied a conservative fallback: all 71 antivirus engines that scanned this file report it as clean. With that much coverage, the file looks safe — but re-scan in a few minutes to get the full AI assessment.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
AI arbiter unavailable (reason: arbiter_exception:OpenRouter HTTP 402 for anthropic/claude-haiku-4.5: Insufficient credits. Add more using https://openrouter.ai/settings/credits)
engines.tier1Malicious=0
engines.reporting=71
- 71 antivirus engines all report this file as clean.
The file appears safe based on antivirus coverage. Re-scan for the full AI assessment.
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- \Sessions\1\BaseNamedObjects\TSInstance
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
Evidence"C:\Users\user\Desktop\touchskins.exe"
0 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- touchskins.exe
- Size
- 5.31 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 3182b6025c5a211c5ac51475e4e7e84b951bd04515c8b22eb34bc9dc177596f0
- MD5
- 1695b48facf51d0d1f3df1f5cc0f18db
- SHA-1
- 2c827beb9bab9d5d460920fa1a54ce68164e9c69
- PE imphash
- bdeb01affe6d82c8d1d6089ce319907a
- First seen (VT)
- 6/13/2026, 12:11:13 PM
- Last analysis (VT)
- 6/13/2026, 12:11:13 PM
- First scan (MalwareTips)
- 6/14/2026, 12:12:33 AM
- Last scan (MalwareTips)
- 6/14/2026, 12:12:33 AM
- Code signer
- IP Davydov Egor Denisovichverified
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.