File verdict·Decided by the MT AI Engine
Our call

Safe

18 tier-1 engines report clean; no malicious sandbox verdict or offensive behaviour despite direct-IP contact heuristic.

Trust score82Moderate trust
MT AI confidence · 78%
Field Hospital.exe
635.5 KB
679d6a6715f5bbf999972f8c47ff
Antivirus engines
0 of 76 flagged
Code signing
Unsigned
Age
First seen 6y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

78%Confidence
High
Reasoning

This file presents a mixed-signal case dominated by clean verdicts. Zero malicious detections across 72 engines, with 18 tier-1 vendors all silent, strongly indicates the sample is benign or at least not recognized as malware by our antivirus network. The triggered heuristic 'DirectIpC2' cites direct-IP contact, which is typically associated with C2 beacons; however, this pattern alone does not establish malicious intent when paired with zero offensive MITRE techniques, no malicious sandbox verdict, and no malicious host contacts in our cache. The file's age (2037 days), medium prevalence (11 submitters), and idle tag suggest a known commodity or research tool rather than a novel threat. The unsigned status and lack of signer history are neutral in this context given the overwhelming engine consensus.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. tier1Malicious=0; tier1ReportedClean=18 (Avast, BitDefender, Kaspersky, ESET, Fortinet, GData, Ikarus, F-Secure, DrWeb, Emsisoft, Avira, AVG all undetected)

  2. engines.malicious=0/72 reporting; no tier-1 family consensus; no named malware family in any detection

  3. behaviour.offensiveCount=0 (no MITRE offensive techniques); behaviour.hasMaliciousSandboxVerdict=false; contactedHosts.maliciousHosts=0

  4. triggeredHeuristics: MalwareTips.Synth.DirectIpC2 fired (medium) citing 3 external IPs, but no sandbox malice verdict or dropped malicious children corroborate C2 intent

  5. File age 2037 days; medium prevalence (11 submitters, 12 submissions); idle tag; no recent feedback or community annotations

Points in its favour
  • 18 tier-1 antivirus engines report undetected (Kaspersky, BitDefender, ESET, Fortinet, Avast, AVG, Avira, DrWeb, Emsisoft, F-Secure, GData, Ikarus, and others)
  • Zero malicious detections across 72 engines
  • No malicious sandbox verdict; no offensive MITRE techniques
  • 5+ year submission history (first seen 2020-11-28); medium prevalence (11 submitters, 12 submissions)
  • No malicious dropped children; no malicious contacted hosts in our cache
Points against
  • Direct-IP contact without DNS queries (3 external IPs: 23.55.140.42, 184.27.218.92, 151.101.22.172)
  • Unsigned executable with no signer history
  • Ambient MITRE techniques observed (T1071, T1082, T1129, T1574.002)
What to do

This file is assessed as safe based on consensus from tier-1 antivirus engines and the absence of malicious runtime behaviour. The direct-IP contact heuristic is noted but does not override the clean verdict without corroborating malice signals. Standard security practices (keep software updated, monitor network activity) apply.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
4

Adversary techniques mapped to the MITRE ATT&CK framework.

T1071T1082T1129T1574.002
Spawned processes
2
$(unnamed)
%SAMPLEPATH%\679d6a6715f5bbf99932379ef7b5adea81f927a417db14d02c3b1d972f8c47ff.exe
$(unnamed)
"C:\Users\user\Desktop\software.exe"
Network activity
4
IP addresses4
  • 192.168.0.57
  • 23.55.140.42
  • 184.27.218.92
  • 151.101.22.172
Filesystem & mutexes
3
Files deleted3
  • C:\Windows\System32\wbem\Performance\WmiApRpl.h
  • C:\Windows\System32\wbem\Performance\WmiApRpl.ini
  • C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_cbbb49d6-b7ff-44ca-aba5-8a5e250d4d42
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.

1 synthesis
MITRE ATT&CK profile
C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • DirectIpC2medium

    Sample contacted 3 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    23.55.140.42 · 184.27.218.92 · 151.101.22.172
Antivirus engine breakdown

0 detections across 76 engines

0 malicious0 suspicious76 clean
Tier-118 engines
0flag
Top commercial AVs (low FP rate)
Tier-237 engines
0flag
Mainstream engines with mixed FP rates
Low-trust21 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 76 engines report this file as clean.
Hash 679d6a6715f5… cross-referenced against 76 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

Unpacked
Section entropy6 sections
.text
6.40
.rdata
4.73
.data
1.81
.pdata
4.31
.rsrc
5.98
.reloc
4.76
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
11
Moderate upload volume.
Total submissions
12
Includes repeat uploads by the same source.
First seen by VT
6y ago
Nov 28, 2020
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
11/28/2020, 11:09:34 AM
First seen (MalwareBazaar)
Last analysis (VT)
3/10/2025, 6:49:29 PM
Scanned here
6/27/2026, 3:39:31 PM
File name
Field Hospital.exe
Size
635.5 KB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
679d6a6715f5bbf99932379ef7b5adea81f927a417db14d02c3b1d972f8c47ff
MD5
68119f2adfdf0d9db459f9eb4b229663
SHA-1
3ed63aeb66e62fe4c61d82a8b4bea982cf81798c
PE imphash
fd60dddc87379c239e8ac49516966c3e
First seen (VT)
11/28/2020, 11:09:34 AM
Last analysis (VT)
3/10/2025, 6:49:29 PM
First scan (MalwareTips)
6/27/2026, 3:39:31 PM
Last scan (MalwareTips)
6/27/2026, 3:39:31 PM
Behavior tags
idle64bitsassemblypeexedetect-debug-environment
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.