Safe
18 tier-1 engines report clean; no malicious sandbox verdict or offensive behaviour despite direct-IP contact heuristic.
679d6a6715f5bbf999…972f8c47ffThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
This file presents a mixed-signal case dominated by clean verdicts. Zero malicious detections across 72 engines, with 18 tier-1 vendors all silent, strongly indicates the sample is benign or at least not recognized as malware by our antivirus network. The triggered heuristic 'DirectIpC2' cites direct-IP contact, which is typically associated with C2 beacons; however, this pattern alone does not establish malicious intent when paired with zero offensive MITRE techniques, no malicious sandbox verdict, and no malicious host contacts in our cache. The file's age (2037 days), medium prevalence (11 submitters), and idle tag suggest a known commodity or research tool rather than a novel threat. The unsigned status and lack of signer history are neutral in this context given the overwhelming engine consensus.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
tier1Malicious=0; tier1ReportedClean=18 (Avast, BitDefender, Kaspersky, ESET, Fortinet, GData, Ikarus, F-Secure, DrWeb, Emsisoft, Avira, AVG all undetected)
engines.malicious=0/72 reporting; no tier-1 family consensus; no named malware family in any detection
behaviour.offensiveCount=0 (no MITRE offensive techniques); behaviour.hasMaliciousSandboxVerdict=false; contactedHosts.maliciousHosts=0
triggeredHeuristics: MalwareTips.Synth.DirectIpC2 fired (medium) citing 3 external IPs, but no sandbox malice verdict or dropped malicious children corroborate C2 intent
File age 2037 days; medium prevalence (11 submitters, 12 submissions); idle tag; no recent feedback or community annotations
- 18 tier-1 antivirus engines report undetected (Kaspersky, BitDefender, ESET, Fortinet, Avast, AVG, Avira, DrWeb, Emsisoft, F-Secure, GData, Ikarus, and others)
- Zero malicious detections across 72 engines
- No malicious sandbox verdict; no offensive MITRE techniques
- 5+ year submission history (first seen 2020-11-28); medium prevalence (11 submitters, 12 submissions)
- No malicious dropped children; no malicious contacted hosts in our cache
- Direct-IP contact without DNS queries (3 external IPs: 23.55.140.42, 184.27.218.92, 151.101.22.172)
- Unsigned executable with no signer history
- Ambient MITRE techniques observed (T1071, T1082, T1129, T1574.002)
This file is assessed as safe based on consensus from tier-1 antivirus engines and the absence of malicious runtime behaviour. The direct-IP contact heuristic is noted but does not override the clean verdict without corroborating malice signals. Standard security practices (keep software updated, monitor network activity) apply.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 192.168.0.57
- 23.55.140.42
- 184.27.218.92
- 151.101.22.172
- C:\Windows\System32\wbem\Performance\WmiApRpl.h
- C:\Windows\System32\wbem\Performance\WmiApRpl.ini
- C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_cbbb49d6-b7ff-44ca-aba5-8a5e250d4d42
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 3 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence23.55.140.42 · 184.27.218.92 · 151.101.22.172
0 detections across 76 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- Field Hospital.exe
- Size
- 635.5 KB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 679d6a6715f5bbf99932379ef7b5adea81f927a417db14d02c3b1d972f8c47ff
- MD5
- 68119f2adfdf0d9db459f9eb4b229663
- SHA-1
- 3ed63aeb66e62fe4c61d82a8b4bea982cf81798c
- PE imphash
- fd60dddc87379c239e8ac49516966c3e
- First seen (VT)
- 11/28/2020, 11:09:34 AM
- Last analysis (VT)
- 3/10/2025, 6:49:29 PM
- First scan (MalwareTips)
- 6/27/2026, 3:39:31 PM
- Last scan (MalwareTips)
- 6/27/2026, 3:39:31 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.