File verdict·Decided by the MT AI Engine
Our call

Malicious

This file is confirmed confirmed malware — abuse.ch researchers uploaded this exact sample to MalwareBazaar as known malware. Delete it and scan your system.

confirmed malwareVerified · Axium Audit
Trust score3Critical
MT AI confidence · 99%
Milfy City Final Edition_n-iyDQ5.exe
13.8 MB
888bfc44c03e97875f480313f0dc
Antivirus engines
41 of 75 flagged
Code signing
Signed by Axium Audit
Age
First seen 2y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

99%Confidence
Very high
Reasoning

This file is confirmed confirmed malware — abuse.ch researchers uploaded this exact sample to MalwareBazaar as known malware. Delete it and scan your system. MalwareBazaar is a researcher-curated malware repository; hits there are ground-truth positives.

Key signals · 3

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. MalwareBazaar: confirmed malware

  2. (no named signature)

  3. First catalogued: 2026-04-18 01:26:35

Points against
  • MalwareBazaar confirmed family: confirmed malware
  • Researcher-uploaded malware sample
What to do

Delete this file and run a full-system antivirus scan.

Threat family attribution

offercore corroborated by 3 sources

  • 5 YARA rules
    Borland, HUNTING_SUSP_TLS_SECTION, pe_detect_tls_callbacks
  • VT (75 engines)
    offercore
  • MT AI Engine
    confirmed malware
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
25

Adversary techniques mapped to the MITRE ATT&CK framework.

T1012T1018T1027T1027.009T1033T1036T1045T1055T1059T1063T1070T1071T1082T1083T1095T1129T1134T1140T1198T1497T1518.001T1529T1573T1614+1 more
Spawned processes
14
$(unnamed)
"C:\Users\<USER>\AppData\Local\Temp\program.exe"
$(unnamed)
"C:\Users\<USER>\AppData\Local\Temp\is-65ILB.tmp\program.tmp" /SL5="$201A6,13603942,780800,C:\Users\<USER>\AppData\Local\Temp\program.exe"
$(unnamed)
%SAMPLEPATH%\Tag After School_qa-ors1.exe
$(unnamed)
%USERPROFILE%\AppData\Local\Temp\is-K9CIB.tmp\Tag After School_qa-ors1.tmp
$(unnamed)
%SAMPLEPATH%\888bfc44c03e97875fd1e88f56c8c052c94af130803a096114a76e480313f0dc.exe
$(unnamed)
%USERPROFILE%\AppData\Local\Temp\is-IP7KF.tmp\888bfc44c03e97875fd1e88f56c8c052c94af130803a096114a76e480313f0dc.tmp
$(unnamed)
%USERPROFILE%\AppData\Local\Temp\is-FD3A5.tmp\888bfc44c03e97875fd1e88f56c8c052c94af130803a096114a76e480313f0dc.tmp
$(unnamed)
C:\Windows\System32\wuapihost.exe
+6 more processes captured.
Network activity
14
IP addresses12
  • 108.138.176.178
  • 20.99.186.246
  • 192.229.211.108
  • 23.216.147.76
  • 20.99.133.109
  • 20.99.185.48
  • 23.53.122.135
  • 20.99.184.37
  • 23.216.147.67
  • 2.23.84.59
+2 more
URLs2
  • http://sslcom.repository.certum.pl/ctnca.cer
  • http://d3st27td9yruau.cloudfront.net:443
Filesystem & mutexes
40
Files written15
  • C:\Users\<USER>\AppData\Local\Temp\is-7JSV3.tmp\Tag After School_qa-ors1.tmp
  • C:\Users\user\AppData\Local\Temp\is-A4AR0.tmp\a07f51d11acb0a2c06c24afc5d8c0bce.tmp
  • C:\Users\user\AppData\Local\Temp\is-MJNDR.tmp\_isetup\_setup64.tmp
  • \Device\KsecDD
  • C:\Users\user\AppData\Local\Temp\is-MJNDR.tmp\botva2.dll
+10 more
Files deleted15
  • C:\Users\<USER>\AppData\Local\Temp\is-65ILB.tmp\program.tmp
  • C:\Users\<USER>\AppData\Local\Temp\is-65ILB.tmp
  • C:\Users\<USER>\AppData\Local\Temp\is-DM9AJ.tmp\botva2.dll
  • C:\Users\<USER>\AppData\Local\Temp\is-DM9AJ.tmp\zbShieldUtils.dll
  • C:\Users\<USER>\AppData\Local\Temp\is-DM9AJ.tmp\_isetup\_setup64.tmp
+10 more
Mutexes created10
  • Local\SM0:1180:168:WilStaging_02
  • Local\SM0:3364:168:WilStaging_02
  • Local\RstrMgr3887CAB8-533F-4C85-B0DC-3E5639F8D511
  • Local\RstrMgr-3887CAB8-533F-4C85-B0DC-3E5639F8D511-Session0000
  • {6F44C754-77E7-4687-80D4-B48E574DF023}Installer
+5 more
Dropped payload

Files this sample writes at runtime

This file drops 5 children at runtime. None are currently flagged malicious in our cache.

5 unseen
  • eaa483432e2cae37fcf18d5d07Never scanned
    never seen before
  • 450b9b0ba25bf068afbcfd0105Never scanned
    never seen before
  • 7d09715c4e0735a0832bc450a5Never scanned
    never seen before
  • 388a796580234efc95f3136f95Never scanned
    never seen before
  • 33ba8221ff3f5211b6b017d7a0Never scanned
    never seen before
External threat intelligence

2 corroborating signals from researcher-curated sources

MalwareBazaar HIT·abuse.ch confirmed sampleView on MalwareBazaar
· exe· first seen 4/18/2026, 1:26:35 AM
exesigned
YARAify HIT·5 community rules matchedView on YARAify
  • Borlandby malware-lu
  • HUNTING_SUSP_TLS_SECTIONby chaosphere
    Detect PE files with .tls section that can be used for anti-debugging
  • pe_detect_tls_callbacks
  • PE_Digital_Certificateby albertzsigovits
  • shellcodeby nex
    Matched shellcode byte patterns
Cross-referenced against MalwareBazaar (abuse.ch), YARAify, and the CIRCL hashlookup reference DB.
Signature matches

YARA + heuristic rules that fired

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

5 YARAify2 synthesis
MITRE ATT&CK profile
Defense evasion× 1C2× 1
YARAify (community)
Researcher-authored rules via abuse.ch
  • Borland
  • HUNTING_SUSP_TLS_SECTION
  • pe_detect_tls_callbacks
  • PE_Digital_Certificate
  • shellcode
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    "C:\Users\<USER>\AppData\Local\Temp\program.exe"
  • DirectIpC2medium

    Sample contacted 12 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    108.138.176.178 · 20.99.186.246 · 192.229.211.108
Antivirus engine breakdown

41 detections across 75 engines

41 malicious0 suspicious34 clean
Tier-117 engines
12flag
Top commercial AVs (low FP rate)
Tier-238 engines
20flag
Mainstream engines with mixed FP rates
Low-trust20 engines
9flag
Heuristic / generic-AI engines (high FP rate)
alibabacloud
malicious
Trojan[downloader]:Win/OfferCore.C
ALYac
malicious
Adware.GenericKD.61134485
Arcabit
malicious
Adware.Generic.D3A4D695
Avast
malicious
FileRepPup [PUP]
AVG
malicious
FileRepPup [PUP]
BitDefender
malicious
Adware.GenericKD.61134485
CAT-QuickHeal
malicious
Botnet.StormCiR
ClamAV
malicious
Win.Dropper.Bundler-9917193-0
CrowdStrike
malicious
win/grayware_confidence_100% (W)
CTX
malicious
exe.adware.offercore
Cylance
malicious
Unsafe
DeepInstinct
malicious
MALICIOUS
DrWeb
malicious
Adware.Downware.20329
Elastic
malicious
malicious (high confidence)
Emsisoft
malicious
Application.Generic (A)
ESET-NOD32
malicious
Win32/OfferCore.C potentially unwanted application
Fortinet
malicious
Riskware/OfferCore
GData
malicious
Adware.GenericKD.61134485
Google
malicious
Detected
Gridinsoft
malicious
PUP.Win32.OfferCore.dd!c
K7AntiVirus
malicious
Adware ( 005a23da1 )
K7GW
malicious
Adware ( 005a23da1 )
Kaspersky
malicious
not-a-virus:Downloader.Win32.Bundler.gen
Lionic
malicious
Riskware.Win32.OfferCore.1!c
Malwarebytes
malicious
PUP.Optional.BundleInstaller.DDS
MaxSecure
malicious
Trojan.Malware.121086327.susgen
Microsoft
malicious
PUADlManager:Win32/OfferCore
MicroWorld-eScan
malicious
Adware.GenericKD.61134485
Paloalto
malicious
generic.ml
Rising
malicious
Adware.OfferCore!1.DF4C (CLASSIC)
Skyhigh
malicious
BehavesLike.Win32.Dropper.tc
Sophos
malicious
Generic Reputation PUA (PUA)
Symantec
malicious
PUA.Gen.2
TrellixENS
malicious
Artemis!73BA3A923298
Varist
malicious
W32/ABApplication.CAXN-3768
VBA32
malicious
Downloader.Bundler
VIPRE
malicious
Adware.GenericKD.61134485
VirIT
malicious
PUP.Win32.DelphGen.JMW
Webroot
malicious
W32.Malware.Gen
Xcitium
malicious
ApplicUnwnt@#3u6rs81yge0id
Yandex
malicious
PUA.Downloader!1HSQBwPDTj4
Hash 888bfc44c03e… cross-referenced against 75 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 8.00Unpacked
Section entropy10 sections
.text
6.36
.itext
5.97
.data
5.04
.bss
0.00
.idata
4.90
.didata
2.76
.edata
1.87
.tls
0.00
.rdata
1.38
.rsrc
4.59
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.

Common & old
Unique uploaders
3,606
Hundreds of people have uploaded this — common.
Total submissions
7,825
Includes repeat uploads by the same source.
First seen by VT
2y ago
Feb 14, 2024
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
here
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
2/14/2024, 7:53:00 AM
First seen (MalwareBazaar)
4/18/2026, 1:26:35 AM
Last analysis (VT)
6/29/2026, 12:52:09 AM
Scanned here
6/29/2026, 5:12:28 PM
File name
Milfy City Final Edition_n-iyDQ5.exe
Size
13.83 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
888bfc44c03e97875fd1e88f56c8c052c94af130803a096114a76e480313f0dc
MD5
73ba3a923298bec113961f4fc107d3ce
SHA-1
bf29783bb2daa9d8a8f1306153072375d2f5eae7
PE imphash
5a594319a0d69dbc452e748bcf05892e
First seen (VT)
2/14/2024, 7:53:00 AM
Last analysis (VT)
6/29/2026, 12:52:09 AM
First scan (MalwareTips)
6/29/2026, 5:12:28 PM
Last scan (MalwareTips)
6/29/2026, 5:12:28 PM
Code signer
Axium Auditverified
Community reputation
-19flagged
Behavior tags
invalid-signaturedetect-debug-environmentoverlaylong-sleepssignedpeexe
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.