Safe
Clean scans across 72 engines including top tier1 vendors, behaviour consistent with portable web-based app using Microsoft Edge WebView2, medium prevalence supports benign commodity software.
6f8d7de09986672827…05a0df392fThe reasoning behind this verdict
The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.
Unanimous clean results from 72 engines, including 17 tier1 like BitDefender and Kaspersky, indicate no malicious signatures or heuristics fired. Behaviour shows standard WebView2 spawning for a portable app, with files dropped in expected user data paths. One offensive MITRE technique (T1562.001) and debug detection tag raise minor flags, but absence of sandbox alerts, malicious children, or external intel confirms safety. Medium prevalence across 17 sources aligns with legitimate software distribution.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
0/72 engines.malicious, 17 tier1ReportedClean (e.g., BitDefender, ESET-NOD32, Kaspersky undetected)
behaviour.offensiveTechniques=['T1562.001'] but ambientCount=7, processes spawn msedgewebview2.exe legitimately
prevalence.classification='medium', 17 uniqueSources
droppedChildren.hasMaliciousChild=false (8 inspected, all unknown)
filenameAnalysis.looksLikePortable=true
- 0/72 engines.malicious, tier1ReportedClean=17
- Legitimate Microsoft Edge WebView2 processes
- Medium prevalence (17 unique sources)
- No malicious dropped children or sandbox verdicts
- No external intel or heuristic triggers
- Unsigned executable (no Authenticode verification)
- behaviour.offensiveTechniques includes T1562.001 (potential tool disablement)
- tags['detect-debug-environment'] suggests anti-analysis
- Recent file (ageDays=8), reputation=0
This appears to be a safe portable application, likely a web-scripting tool using Edge WebView2. Run in a sandbox if wary of the debug detection tag.
What to do now
This file looks safe based on everything we checked.
This file is safe to use.
Good habit: only download files from the official website or an app store.
Keep your antivirus and Windows updates switched on so you stay protected.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\user\AppData\Local\flick.winscript.dev
- C:\Users\user\AppData\Local\flick.winscript.dev\EBWebView
- C:\Users\user\AppData\Local\flick.winscript.dev\EBWebView\8729a88b-289f-404b-9a78-4ccf0794f34b.tmp
- C:\Users\user\AppData\Local\flick.winscript.dev\EBWebView\BrowserMetrics
- C:\Users\user\AppData\Local\flick.winscript.dev\EBWebView\BrowserMetrics\BrowserMetrics-69E511F3-1444.pma
- \Sessions\1\BaseNamedObjects\DBWinMutex
- \Sessions\1\BaseNamedObjects\Local\ChromeProcessSingletonStartup!
- \Sessions\1\BaseNamedObjects\__OMADM_NAMED_MUTEX__
Files this sample writes at runtime
This file drops 8 children at runtime. None are currently flagged malicious in our cache.
- 4f4b15a44590d478a981…40ebbcNever scannednever seen before
- 41c91a9c93d76295746a…1cc304Never scannednever seen before
- 903fe65cb6fb5b3c5d83…8fad6eNever scannednever seen before
- a0c9abae18599f0a65fc…e38e87Never scannednever seen before
- 36010d34116fd0146839…68e8f4Never scannednever seen before
- e54e9d1652848051e07a…4c8461Never scannednever seen before
- f7b24f2eb3d5eb055052…8b5fedNever scannednever seen before
- 4bd19a12e59964e2d028…a0d9ffNever scannednever seen before
0 detections across 76 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- winscript-portable.exe
- Size
- 10.27 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 6f8d7de09986672827739e88e7bd62149560f87114177c3d7b9ead05a0df392f
- MD5
- 563a1e38b112f0c84595040ac38fe829
- SHA-1
- e1319ed657e59c66dc42597e0c75b70873e09935
- PE imphash
- 8e3963a8d933e246b6f4e8616fc79b24
- First seen (VT)
- 4/19/2026, 11:48:30 AM
- Last analysis (VT)
- 4/21/2026, 3:59:31 AM
- First scan (MalwareTips)
- 4/20/2026, 3:19:31 PM
- Last scan (MalwareTips)
- 4/27/2026, 5:20:21 AM
Safety FAQ
Common questions about winscript-portable.exe, answered from the scan data above.
- winscript-portable.exe appears safe. 76 of 76 antivirus engines report it clean. As a habit, only run files you downloaded from the official source, since attackers sometimes distribute trojanised copies of legitimate software under the same name.
- winscript-portable.exe is a Windows executable program, about 10.3 MB. Our analysis found no threat indicators for it. A file's name can be reused by different files, so we identify it by its cryptographic hash (below).
- None — all 76 antivirus engines we queried report winscript-portable.exe as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
- The SHA-256 hash of winscript-portable.exe is 6f8d7de09986672827739e88e7bd62149560f87114177c3d7b9ead05a0df392f, and its MD5 is 563a1e38b112f0c84595040ac38fe829. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- Based on this scan, yes — winscript-portable.exe shows no threat indicators. The important caveat is source: make sure you downloaded it from the official website or a trusted store, because attackers sometimes distribute malware-laced copies under a legitimate file's name. If your own antivirus flags it while we report it clean, that is most often a false positive, but verify the source before overriding your antivirus.
- This report reflects the scan run on April 20, 2026. Because a file's hash never changes, the identity of winscript-portable.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.