Safe
Old signed Macroplant installer with zero engine detections and clean child/host signals despite synthesis heuristics.
89efa9f4fea8d38780…f33314f828The reasoning behind this verdict
The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.
The file shows classic benign-signed-installer shape: verified signature, long prevalence history, and zero malicious engine detections. The synthesis heuristics that fired are known to trigger on legitimate installers that extract bundled runtimes and contact CDNs. The single RAG hit is an imphash-only collision with no signer match. No malicious children, hosts, or external-intel hits exist.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/74 malicious (tier1Malicious=0) across 70 reporting engines
signing.verified=true, signer='Macroplant LLC'
prevalence.classification='common_old' (733 sources, 930 submissions since 2015-08-29)
similarHashes[0].matchKind='imphash' with signerCoMatch=false — framework collision only
triggeredHeuristics: MalwareTips.Synth.ProcessInjection, MalwareTips.Synth.CredentialDumper, MalwareTips.Synth.DirectIpC2
- 0/74 engines malicious
- Verified signature by Macroplant LLC
- Common_old prevalence (930 submissions since 2015)
- No malicious dropped children or contacted hosts
- Synthesis heuristics flagged process injection and LSASS access
- Direct-IP contacts without domain resolution
Treat as clean; obtain a current copy from the vendor if installation is required.
What to do now
This file looks safe based on everything we checked.
This file is safe to use.
Good habit: only download files from the official website or an app store.
Keep your antivirus and Windows updates switched on so you stay protected.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 172.67.170.89
- 64.50.236.52
- 104.21.47.35
- 23.216.147.64
- 20.99.132.105
- 131.253.33.203
- 23.216.147.76
- a83f:8110:2800:1800:4000:1800:1800:100
- 20.62.24.77
- 20.99.184.37
- http://cdn.macroplant.com/dependencies/adapter/ffmpeg-pc.zip
- http://ftp.osuosl.org/pub/videolan/vlc/2.1.0/win32/vlc-2.1.0-win32.exe
- C:\Users\<USER>\AppData\Local\Adapter\ffmpeg\ffmpeg.exe
- C:\Program Files (x86)\VideoLAN\VLC\plugins\plugins.dat.4276
- C:\Users\<USER>\AppData\Local\Temp\is-7R3I3.tmp\program.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-U3DNS.tmp\_isetup\_setup64.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-U3DNS.tmp\_isetup\_shfoldr.dll
- C:\Program Files (x86)\Adapter\is-J42TK.tmp
- C:\Program Files (x86)\Adapter\is-O1HRJ.tmp
- C:\Program Files (x86)\Adapter\is-M0TNM.tmp
- C:\Program Files (x86)\Adapter\is-I873C.tmp
- C:\Program Files (x86)\Adapter\is-083Q0.tmp
- Global\OneSettingQueryMutex+compat+encapsulation
- Local\InternetShortcutMutex
- cversions.3.m
- CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- cffbe6fbb9f403bdcbaf…84e9d8Never scannednever seen before
- 659931b0a68cc61acb90…c29714Never scannednever seen before
- 8ac5b633d7808b2b654e…73a3dfNever scannednever seen before
- 709909ecf38eb203b0fd…9af4adNever scannednever seen before
- 93b47c72be20af618a38…2f02f2Never scannednever seen before
- 30b4788a7ca06bf9f98e…20b561Never scannednever seen before
- aa8eae5950edcab4409c…b4f6f2Never scannednever seen before
- 4e70ba36cc70ba00ba7b…48d32fNever scannednever seen before
- 203d7b61eac96de865ab…6fd006Never scannednever seen before
- 606d458c049203e542c3…ac4f7fNever scannednever seen before
YARA & heuristic rule matches
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeSample contacted 20 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence172.67.170.89 · 64.50.236.52 · 104.21.47.35
0 detections across 74 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- Adapter_Setup_2120.exe
- Size
- 3.34 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 89efa9f4fea8d38780531a4904fc2d500835f952a827412cb81713f33314f828
- MD5
- 8c8a4f4607fff51bbeb9f6e85ee5d635
- SHA-1
- 6cd747a3c0d490c88ad7e01adc78a9d6c19f77c2
- PE imphash
- 884310b1928934402ea6fec1dbd3cf5e
- First seen (VT)
- 8/29/2015, 2:08:31 AM
- Last analysis (VT)
- 7/19/2026, 8:51:38 AM
- First scan (MalwareTips)
- 7/19/2026, 8:53:07 AM
- Last scan (MalwareTips)
- 7/19/2026, 8:53:07 AM
- Code signer
- Macroplant LLCverified
- Community reputation
- +33trusted
Safety FAQ
Common questions about Adapter_Setup_2120.exe, answered from the scan data above.
- Adapter_Setup_2120.exe appears safe. 74 of 74 antivirus engines report it clean. It carries a verified digital signature from Macroplant LLC. As a habit, only run files you downloaded from the official source, since attackers sometimes distribute trojanised copies of legitimate software under the same name.
- Adapter_Setup_2120.exe is a Windows executable program, about 3.3 MB. Our analysis found no threat indicators for it. It carries a verified digital signature from Macroplant LLC. A file's name can be reused by different files, so we identify it by its cryptographic hash (below).
- None — all 74 antivirus engines we queried report Adapter_Setup_2120.exe as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
- Yes — Adapter_Setup_2120.exe carries a valid digital signature from Macroplant LLC, which confirms the file hasn't been tampered with since that publisher signed it. A valid signature is a positive signal, but note that malware is occasionally signed with stolen or abused certificates, so it isn't proof of safety on its own.
- The SHA-256 hash of Adapter_Setup_2120.exe is 89efa9f4fea8d38780531a4904fc2d500835f952a827412cb81713f33314f828, and its MD5 is 8c8a4f4607fff51bbeb9f6e85ee5d635. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- Based on this scan, yes — Adapter_Setup_2120.exe shows no threat indicators and is properly signed. The important caveat is source: make sure you downloaded it from the official website or a trusted store, because attackers sometimes distribute malware-laced copies under a legitimate file's name. If your own antivirus flags it while we report it clean, that is most often a false positive, but verify the source before overriding your antivirus.
- This report reflects the scan run on July 19, 2026. Because a file's hash never changes, the identity of Adapter_Setup_2120.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.