Malicious
This file is confirmed confirmed malware — abuse.ch researchers uploaded this exact sample to MalwareBazaar as known malware. Delete it and scan your system.
888bfc44c03e97875f…480313f0dcThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
This file is confirmed confirmed malware — abuse.ch researchers uploaded this exact sample to MalwareBazaar as known malware. Delete it and scan your system. MalwareBazaar is a researcher-curated malware repository; hits there are ground-truth positives.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
MalwareBazaar: confirmed malware
(no named signature)
First catalogued: 2026-04-18 01:26:35
- MalwareBazaar confirmed family: confirmed malware
- Researcher-uploaded malware sample
Delete this file and run a full-system antivirus scan.
offercore corroborated by 3 sources
- 5 YARA rulesBorland, HUNTING_SUSP_TLS_SECTION, pe_detect_tls_callbacks
- VT (75 engines)offercore
- MT AI Engineconfirmed malware
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 108.138.176.178
- 20.99.186.246
- 192.229.211.108
- 23.216.147.76
- 20.99.133.109
- 20.99.185.48
- 23.53.122.135
- 20.99.184.37
- 23.216.147.67
- 2.23.84.59
- http://sslcom.repository.certum.pl/ctnca.cer
- http://d3st27td9yruau.cloudfront.net:443
- C:\Users\<USER>\AppData\Local\Temp\is-7JSV3.tmp\Tag After School_qa-ors1.tmp
- C:\Users\user\AppData\Local\Temp\is-A4AR0.tmp\a07f51d11acb0a2c06c24afc5d8c0bce.tmp
- C:\Users\user\AppData\Local\Temp\is-MJNDR.tmp\_isetup\_setup64.tmp
- \Device\KsecDD
- C:\Users\user\AppData\Local\Temp\is-MJNDR.tmp\botva2.dll
- C:\Users\<USER>\AppData\Local\Temp\is-65ILB.tmp\program.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-65ILB.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-DM9AJ.tmp\botva2.dll
- C:\Users\<USER>\AppData\Local\Temp\is-DM9AJ.tmp\zbShieldUtils.dll
- C:\Users\<USER>\AppData\Local\Temp\is-DM9AJ.tmp\_isetup\_setup64.tmp
- Local\SM0:1180:168:WilStaging_02
- Local\SM0:3364:168:WilStaging_02
- Local\RstrMgr3887CAB8-533F-4C85-B0DC-3E5639F8D511
- Local\RstrMgr-3887CAB8-533F-4C85-B0DC-3E5639F8D511-Session0000
- {6F44C754-77E7-4687-80D4-B48E574DF023}Installer
Files this sample writes at runtime
This file drops 5 children at runtime. None are currently flagged malicious in our cache.
- eaa483432e2cae37fcf1…8d5d07Never scannednever seen before
- 450b9b0ba25bf068afbc…fd0105Never scannednever seen before
- 7d09715c4e0735a0832b…c450a5Never scannednever seen before
- 388a796580234efc95f3…136f95Never scannednever seen before
- 33ba8221ff3f5211b6b0…17d7a0Never scannednever seen before
2 corroborating signals from researcher-curated sources
- Borlandby malware-lu
- HUNTING_SUSP_TLS_SECTIONby chaosphereDetect PE files with .tls section that can be used for anti-debugging
- pe_detect_tls_callbacks
- PE_Digital_Certificateby albertzsigovits
- shellcodeby nexMatched shellcode byte patterns
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
- Borland
- HUNTING_SUSP_TLS_SECTION
- pe_detect_tls_callbacks
- PE_Digital_Certificate
- shellcode
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
Evidence"C:\Users\<USER>\AppData\Local\Temp\program.exe"Sample contacted 12 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence108.138.176.178 · 20.99.186.246 · 192.229.211.108
41 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- Milfy City Final Edition_n-iyDQ5.exe
- Size
- 13.83 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 888bfc44c03e97875fd1e88f56c8c052c94af130803a096114a76e480313f0dc
- MD5
- 73ba3a923298bec113961f4fc107d3ce
- SHA-1
- bf29783bb2daa9d8a8f1306153072375d2f5eae7
- PE imphash
- 5a594319a0d69dbc452e748bcf05892e
- First seen (VT)
- 2/14/2024, 7:53:00 AM
- Last analysis (VT)
- 6/29/2026, 12:52:09 AM
- First scan (MalwareTips)
- 6/29/2026, 5:12:28 PM
- Last scan (MalwareTips)
- 6/29/2026, 5:12:28 PM
- Code signer
- Axium Auditverified
- Community reputation
- -19flagged
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.