Safe
Unsigned media player exe flagged only by low-trust engines; all tier-1 engines clean, behaviour shows benign CDN contacts and no offensive actions.
62917efbf880f3b23a…dd71a5f9d7The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Dominant signal is low-trust-only flagging with full tier-1 consensus on clean. Unsigned status and rarity add caution, but zero offensive MITRE techniques, no malicious sandbox verdict, and CDN IP contacts outweigh the direct-IP heuristic. Dropped children unknown but not malicious. Overall FP shape prevails.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
3/72 engines malicious, tier1Malicious=0, onlyLowTrustFlagging=true
contactedIps includes CDN IPs (20.69.140.28 Azure, 23.196.193.245 Fastly) via behaviour.contactedIps
triggeredHeuristics 'MalwareTips.Synth.DirectIpC2' fired but no offensiveTechniques
tier1FamilyConsensus.family=null, agreeingEngines=0
- tier1Malicious=0, 17 tier1 clean
- offensiveCount=0, no malicious sandbox
- no malicious contacted hosts or children
- no externalIntel or YARAify hits
- unsigned executable
- rare_old prevalence (3 submissions)
- direct IP contacts (6 IPs, no DNS)
- generic filename 'Player (1).exe'
- reputation score 0
- dropped children unknown
This file is safe based on our analysis. Run it if trusted source, but scan with updated security software and observe network activity.
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 192.168.0.15
- 20.69.140.28
- 23.196.193.245
- 20.99.133.109
- 184.27.218.92
- 23.46.216.136
- 23.48.99.4
- C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView\Crashpad
- C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView\Crashpad\attachments
- C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView\Crashpad\reports
- C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView\Default\Local Storage\leveldb\LOG
- C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy\LocalState\EBWebView\Default\Network\Cookies
- \Sessions\1\BaseNamedObjects\Local\SessionImmersiveColorMutex
- \Sessions\1\BaseNamedObjects\mfx_d3d_mutex
Files this sample writes at runtime
This file drops 2 children at runtime. None are currently flagged malicious in our cache.
- 4f53cda18c2baa0c0354…02b945Never scannednever seen before
- 96ea12b4d524e56dd2a3…3f595eNever scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 6 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence20.69.140.28 · 23.196.193.245 · 20.99.133.109
3 detections across 76 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Rarely uploaded, but has been around for a while. Often niche legitimate software or old internal tooling; not a strong malware signal on its own.
Forensic fingerprint
- File name
- Player (1).exe
- Size
- 153.5 KB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 62917efbf880f3b23a563ee2445fc6334b73265f00d0e651d6b239dd71a5f9d7
- MD5
- 3c81c3788e4b403b706ddb0a4dfbde95
- SHA-1
- debabe600b93d3f9a3970f240136dbca648870b5
- PE imphash
- f89c2f3bdca8cfb6a2e03d3121b871bc
- First seen (VT)
- 5/20/2025, 10:18:52 PM
- Last analysis (VT)
- 6/26/2025, 12:04:13 AM
- First scan (MalwareTips)
- 5/9/2026, 11:50:27 PM
- Last scan (MalwareTips)
- 5/9/2026, 11:50:27 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.