File verdict·Decided by the MT AI Engine
Our call

Safe

Legitimately signed Microsoft Sysinternals autoruns.exe; 0/70 engines flag it; tier-1 consensus clean; expected behaviour for autorun enumeration tool.

Verified · Microsoft Corporation
Trust score88High trust
MT AI confidence · 92%
autoruns.exe
1.7 MB
38519c3ae945f67826e1151ff157
Antivirus engines
0 of 74 flagged
Code signing
Signed by Microsoft Corporation
Age
First seen 1 day ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

92%Confidence
Very high
Reasoning

The file exhibits a clean-engine consensus: 0 malicious detections across 70 reporting engines, with 17 tier-1 engines (Avast, BitDefender, Kaspersky, ESET, Fortinet, DrWeb, Ikarus, and others) all reporting clean. It is legitimately signed by Microsoft Corporation with a verified certificate, and our signer history shows 4/4 prior Microsoft-signed samples safe. The RAG system returned 3 prior verdicts on Microsoft-signed files, all 'safe' with reason ai:benign_signed_installer. The triggered heuristics (ProcessInjection, CredentialDumper) are expected for a tool designed to inspect autorun mechanisms and process startup hooks. No malicious sandbox verdict, no contacted malicious hosts, and no dropped malicious children support the benign classification.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. signing.verified=true, signer='Microsoft Corporation', trustedPublisher.matched=true — legitimately signed by Microsoft

  2. engines: 0/70 malicious; tier1Malicious=0; tier1ReportedClean=17 (Avast, BitDefender, Kaspersky, ESET, Fortinet, DrWeb, Ikarus all clean)

  3. similarHashes: 3/3 prior verdicts 'safe' (matchKind=signer, reason=ai:benign_signed_installer) — consistent signer history

  4. triggeredHeuristics: ProcessInjection (T1055) and CredentialDumper (LSASS) are expected autoruns.exe behaviour, not malware indicators

  5. behaviour: 5 offensive + 25 ambient MITRE techniques; no malicious sandbox verdict, no malicious hosts contacted, no malicious children dropped

Points in its favour
  • Signed by Microsoft Corporation with verified Authenticode certificate
  • 0/70 antivirus engines report malicious; 17 tier-1 engines all clean
  • 3/3 similar Microsoft-signed files previously verdicted safe
  • No malicious sandbox verdict, no malicious host contact, no dropped malicious children
  • Triggered heuristics (process injection, LSASS access) are expected autoruns.exe functionality
What to do

This file is safe. It is the legitimate Microsoft Sysinternals autoruns.exe utility. No remediation is needed.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
30

Adversary techniques mapped to the MITRE ATT&CK framework.

T1007T1010T1012T1027T1027.005T1033T1047T1053.005T1055T1056.001T1057T1059T1071T1082T1083T1112T1115T1129T1134T1222T1489T1497T1497.002T1543.003+6 more
Spawned processes
10
$(unnamed)
"C:\Users\<USER>\Desktop\autoruns.exe"
$(unnamed)
C:\Windows\system32\services.exe
$(unnamed)
C:\Windows\System32\svchost.exe -k NetworkService -p
$(unnamed)
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
$(unnamed)
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
$(unnamed)
C:\Windows\system32\svchost.exe -k LocalService -s W32Time
$(unnamed)
C:\Windows\system32\lsass.exe
$(unnamed)
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s WdiSystemHost
+2 more processes captured.
Filesystem & mutexes
14
Files written4
  • C:\Windows\System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
  • C:\Users\user\AppData\Local\Microsoft\Windows\Explorer
  • C:\Windows\system32\catroot
  • C:\Windows\system32\catroot2
Mutexes created10
  • Global\OneSettingQueryMutex+compat+encapsulation
  • \Sessions\1\BaseNamedObjects\Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:iconcache_idx.db!rwWriterMutex
  • \Sessions\1\BaseNamedObjects\Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:iconcache_16.db!dfMaintainer
  • \Sessions\1\BaseNamedObjects\Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:iconcache_32.db!dfMaintainer
  • \Sessions\1\BaseNamedObjects\Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:iconcache_48.db!dfMaintainer
+5 more
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

2 synthesis
MITRE ATT&CK profile
Defense evasion× 1Cred access× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    C:\Windows\System32\svchost.exe -k NetworkService -p
  • CredentialDumpermedium

    Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.

    Evidence
    C:\Windows\system32\lsass.exe
Antivirus engine breakdown

0 detections across 74 engines

0 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-237 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 74 engines report this file as clean.
Hash 38519c3ae945… cross-referenced against 74 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 7.52Unpacked
Section entropy5 sections
.text
6.47
.rdata
4.74
.data
4.96
.rsrc
4.54
.reloc
6.67
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
14
Moderate upload volume.
Total submissions
15
Includes repeat uploads by the same source.
First seen by VT
1d ago
Jun 17, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
6/17/2026, 6:27:09 PM
First seen (MalwareBazaar)
Last analysis (VT)
6/18/2026, 9:48:27 AM
Scanned here
6/18/2026, 4:12:59 PM
File name
autoruns.exe
Size
1.73 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
38519c3ae945f678261327d05efe8fb0be44afb91236bd71199e20e1151ff157
MD5
71f811047b7a455117a8fdd0e136ccfc
SHA-1
0beb22b80aa17e98fba6bba3a311027abb8d596e
PE imphash
2418ca697ff3a1e12dac4a0b4a01b85e
First seen (VT)
6/17/2026, 6:27:09 PM
Last analysis (VT)
6/18/2026, 9:48:27 AM
First scan (MalwareTips)
6/18/2026, 4:12:59 PM
Last scan (MalwareTips)
6/18/2026, 4:12:59 PM
Code signer
Microsoft Corporationverified
Behavior tags
signedcalls-wmioverlaypeexedetect-debug-environment
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Scanned by
Gandalf_The_Grey
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.