Suspicious
Signed taskbar utility with clean engine scans but high-entropy packing, minor offensive behaviour, and similar files previously flagged suspicious.
71b99bdf4511eaafe0…8fd6986e30The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file scans completely clean, which is a strong safe signal, but technical anomalies like high entropy and likely packing raise concerns typical of obfuscated software. One offensive behaviour technique (T1620: victim identity gathering) appears alongside common ambient actions, hinting at potential monitoring capabilities. Similar files by import hash were previously deemed suspicious for analogous reasons, and the extreme rarity (first submission today) limits confidence in its legitimacy despite valid signing.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
0/71 engines.malicious (17 tier1ReportedClean)
signer='VoodooSoft' verified, signerStats.safeCount=1/1
behaviour.offensiveTechniques T1620, peAnalysis.likelyPacked=true
similarHashes[0].verdict='suspicious' (imphash match to Screenpresso.exe)
prevalence.classification='rare_new' (1 submission)
- engines 0/71 malicious, 17 tier1ReportedClean
- signing.verified=true
- signerStats safeRate=1.0
- no malicious sandbox/contactedHosts/droppedChildren
- peAnalysis.likelyPacked=true, highEntropyCode=true
- behaviour.offensiveTechniques T1620
- similarHashes 2/2 'suspicious' (imphash)
- prevalence 'rare_new', ageDays=0
- signerStats totalSamples=1 (not autoTrusted)
Quarantine and verify the download source (e.g., official VoodooSoft site). Avoid execution until more community scans or publisher history accumulates; rescan in 24-48 hours.
0 detections across 75 engines
Section entropy & packers
Executable sections have high entropy (7.2+) — the code is compressed or encrypted and only decrypted at runtime. Classic packing behaviour.
How often this file shows up in the wild
Barely seen in the wild and first surfaced recently. This is the footprint of targeted malware the AV industry hasn't signatured yet — extra scrutiny is warranted.
Forensic fingerprint
- File name
- TaskbarPlus60.exe
- Size
- 775.1 KB
- MIME type
- application/octet-stream
- Detected type
- Win32 EXE
- SHA-256
- 71b99bdf4511eaafe0ca800eab85f5b60f53ca5498358ac3eb36b28fd6986e30
- MD5
- 134b4140cce3c55f8ba42943f0225ff4
- SHA-1
- 3fd49d8b176bdcafa6f343e2ac2cb64e378b2b98
- PE imphash
- f34d5f2d4577ed6d9ceec516c1f5a744
- First seen (VT)
- 4/26/2026, 1:49:16 PM
- Last analysis (VT)
- 4/26/2026, 1:49:16 PM
- First scan (MalwareTips)
- 4/26/2026, 1:49:53 PM
- Last scan (MalwareTips)
- 4/26/2026, 1:49:53 PM
- Code signer
- VoodooSoftverified
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.