File verdict·Decided by the MT AI Engine
Our call

Malicious

Five tier-1 engines converge on Barys trojan family; process-injection evasion technique and invalid signature confirm malware.

BarysSigned but unverified · Calendar Event Launcher
Trust score12Critical
MT AI confidence · 92%
CalendarEventLauncher.exe
19.4 MB
7e434f28c62b8b47f04ed25a5539
Antivirus engines
15 of 75 flagged
Code signing
Unverified: Calendar Event Launcher
Age
First seen 4 days ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

92%Confidence
Very high
Reasoning

The file demonstrates strong malware indicators across multiple dimensions. Five tier-1 antivirus engines agree on the Barys trojan family, establishing high-confidence consensus. The behaviour analysis reveals three offensive MITRE techniques: process injection (CreateRemoteThread/APC), privilege escalation, and defense evasion — a classic malware evasion pattern. The signer lacks any historical reputation (zero prior samples), and the file carries an invalid signature tag, indicating cryptographic validation failure. The 20 MB file size and VMProtect packing signature suggest obfuscation. While sandbox analysis did not record malicious verdicts, process-injection attacks often evade sandbox detection by deferring payload execution or C2 contact until runtime in a real system.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. tier1FamilyConsensus: family='variant', 3 tier-1 engines (BitDefender, Emsisoft, GData) agreeing; strong=true

  2. tier1Malicious=5/17 tier-1 engines; topDetections include Microsoft 'Trojan:Win32/Phonzy.A!ml', ESET-NOD32 'Win64/Packed.VMProtect.AN'

  3. signing.verified=null, trustedPublisher.matched=false, signerStats.found=false — 'Calendar Event Launcher' signer has zero history

  4. triggeredHeuristics: MalwareTips.Synth.ProcessInjection (high severity) — T1055 CreateRemoteThread/APC injection observed; offensiveTechniques=[T1055, T1548, T1562.001]

  5. file tags include 'invalid-signature' — cryptographic signature validation failed

Points in its favour
  • No malicious sandbox verdicts recorded (though process-injection may evade sandbox detection)
  • No malicious contacted hosts or dropped children detected in analysis
Points against
  • Five tier-1 antivirus engines identify Barys trojan family
  • Process injection (T1055) to bypass security hooks
  • Privilege escalation (T1548) and defense evasion (T1562.001) techniques
  • Signer 'Calendar Event Launcher' has zero reputation and invalid signature
  • VMProtect packing suggests intentional obfuscation
  • 20 MB file size with high-entropy sections consistent with packed malware
What to do

Isolate and remove this file immediately. Do not execute under any circumstances. Perform a full system scan with updated antivirus signatures and consider professional remediation if the file was already run.

Threat family attribution

barys corroborated by 2 sources

  • VT (75 engines)
    barys
  • MT AI Engine
    Barys
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
11

Adversary techniques mapped to the MITRE ATT&CK framework.

T1027T1027.002T1055T1056.004T1057T1071T1082T1106T1548T1562T1562.001
Spawned processes
2
$(unnamed)
"C:\Users\<USER>\Desktop\Loader.exe"
$(unnamed)
"C:\Users\user\Desktop\Loader.exe"
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

1 synthesis
MITRE ATT&CK profile
Defense evasion× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    "C:\Users\<USER>\Desktop\Loader.exe"
Antivirus engine breakdown

15 detections across 75 engines

15 malicious0 suspicious60 clean
Tier-117 engines
5flag
Top commercial AVs (low FP rate)
Tier-238 engines
7flag
Mainstream engines with mixed FP rates
Low-trust20 engines
3flag
Heuristic / generic-AI engines (high FP rate)
AhnLab-V3
malicious
Packed/Win.VMProtect.R777064
ALYac
malicious
Gen:Variant.Barys.509378
Arcabit
malicious
Trojan.Barys.D7C5C2
BitDefender
malicious
Gen:Variant.Barys.509378
Bkav
malicious
W32.Malware.26A175E7
CTX
malicious
exe.unknown.barys
Elastic
malicious
malicious (high confidence)
Emsisoft
malicious
Gen:Variant.Barys.509378 (B)
ESET-NOD32
malicious
Win64/Packed.VMProtect.AN suspicious application
GData
malicious
Gen:Variant.Barys.509378
Malwarebytes
malicious
Malware.Heuristic.2108
McAfeeD
malicious
ti!7E434F28C62B
Microsoft
malicious
Trojan:Win32/Phonzy.A!ml
MicroWorld-eScan
malicious
Gen:Variant.Barys.509378
VIPRE
malicious
Gen:Variant.Barys.509378
Hash 7e434f28c62b… cross-referenced against 75 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 7.66Unpacked
Section entropy7 sections
.text
0.00
.rdata
0.00
.data
0.00
.h~o
0.00
.)<F
0.26
.=Lg
7.75
.rsrc
7.91
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
4
Moderate upload volume.
Total submissions
4
Includes repeat uploads by the same source.
First seen by VT
3d ago
Jun 11, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
6/11/2026, 1:49:15 PM
First seen (MalwareBazaar)
Last analysis (VT)
6/11/2026, 1:49:15 PM
Scanned here
6/12/2026, 9:28:19 PM
File name
CalendarEventLauncher.exe
Size
19.45 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
7e434f28c62b8b47f0df4a706d6369022d00463a6ad123b3048dc64ed25a5539
MD5
16d32218520c87ed8e5116775a4bbc65
SHA-1
0e591afef97eee497580d444ccc16c8010ce19c6
PE imphash
ce4a3f0960b9d681f3164ddda2742e21
First seen (VT)
6/11/2026, 1:49:15 PM
Last analysis (VT)
6/11/2026, 1:49:15 PM
First scan (MalwareTips)
6/12/2026, 9:28:19 PM
Last scan (MalwareTips)
6/12/2026, 9:28:19 PM
Code signer
Calendar Event Launcherinvalid
Behavior tags
signedinvalid-signaturepeexe64bitsoverlay
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.