Is Package_f905c5.exe safe?
Twenty-four of 75 engines flagged this unsigned executable, while runtime evidence showed injection, persistence, privilege manipulation, and defense-impairment techniques.
The evidence strongly supports a trojan assessment: 24 of 75 engines detected the file, including eight high-trust detections from Microsoft, TrendMicro, Fortinet, Sophos, and others. Runtime analysis also recorded five offensive techniques, while seven community YARA rules matched; the exact family remains uncertain.
8fa247609916e3d5fe…be72df6e5cc8bbRecommended next actions
Before running
Do not run it. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already ran it
Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The evidence strongly supports a trojan assessment: 24 of 75 engines detected the file, including eight high-trust detections from Microsoft, TrendMicro, Fortinet, Sophos, and others. Runtime analysis also recorded five offensive techniques, while seven community YARA rules matched; the exact family remains uncertain.
The detection volume is substantial, with 24 of 75 engines flagging the executable and eight independent high-trust votes. Microsoft names Wacatac, while TrendMicro associates it with USBLHA26; this disagreement limits family attribution but does not erase the broader trojan evidence. A completed sandbox run recorded T1055 process injection, T1134 token manipulation, T1543.003 service persistence, T1547.001 registry startup persistence, and T1562.001 defense impairment. Seven YARAify rules also matched, providing strong independent corroboration beyond engine labels. The executable is unsigned and has no established publisher history, leaving no meaningful trust signal to counterbalance these findings. No complete contacted-host reputation result is available, and all inspected child files remain unclassified rather than confirmed clean.
What We Detected
Twenty-four of 75 antivirus engines flagged the executable, including eight high-trust detections. Microsoft reported Wacatac, TrendMicro reported USBLHA26, and several other engines used generic trojan or high-confidence malware labels. The labels do not establish one definitive family, but their breadth strongly supports a generic-trojan assessment.
Threat Behavior
One completed sandbox run recorded five offensive MITRE techniques: T1055 process injection, T1134 access-token manipulation, T1543.003 service-based persistence, T1547.001 registry startup persistence, and T1562.001 defense impairment. Seven community YARA rules matched, including DebuggerCheck__API, DetectEncryptedVariants, pe_detect_tls_callbacks, and RANSOMWARE. No network contacts were recorded during that run, but no complete contacted-host reputation cross-check is available. Ten dropped files were inspected, yet all remain unclassified rather than confirmed benign.
What To Do Now
Do not run the file. Keep endpoint protection enabled, quarantine or remove the sample, and perform a full system scan if it was executed. If execution occurred, review startup entries, services, security-setting changes, and signs of process injection; consider isolating the affected device pending investigation.
Where this verdict could be wrong5 caveats
- engines.tier1FamilyConsensus has only two agreeing engines and strong=false, so the precise malware family is not established.
- behaviour.hasMaliciousSandboxVerdict=false, although the completed run still recorded five offensive techniques.
- droppedChildren inspected 10 files without a confirmed malicious child, but all 10 child verdicts remain unknown.
- BitDefender and DrWeb did not detect the sample, and 46/75 engines returned undetected.
- contactedHosts is null, so no complete host-reputation cross-check is available; the sandbox recorded no contacted domains, IPs, or URLs.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- No contacted domains, IP addresses, or URLs were recorded in the completed sandbox run
- No malicious sandbox verdict was recorded
- No inspected dropped child was confirmed malicious
- peAnalysis.highEntropyCode=false and peAnalysis.likelyPacked=false
- 24/75 antivirus detections
- Eight high-trust malicious engine votes
- Unsigned Win32 executable with no signer history
- T1055 process-injection evidence
- T1543.003 and T1547.001 persistence techniques
- T1562.001 defense-impairment behavior
Quarantine or delete the executable without launching it, and keep endpoint protection enabled. If it already ran, isolate the device and perform a full scan plus persistence and security-control checks.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete24 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete6 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 28MITRE ATT&CK techniques
- 5spawned processes
- 0network contacts
- 30filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Created or modified a system service, which can keep code running.
High concern: Changed an auto-start location that can make code run after sign-in or restart.
High concern: Attempted to impair or bypass security controls.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Runs hidden system commands (script or shell).
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Package_f905c5.exe
8fa247609916e3d5fe1831412c318c0e1f489399463021dc49be72df6e5cc8bb
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\software.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\{779324EA-317A-4831-B4F5-C699CDD6055B}\.cr\software.exe" -burn.clean.room="C:\Users\<USER>\Desktop\software.exe" -burn.filehandle.attached=672 -burn.filehandle.self=664
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
software.exe
C:\Users\<USER>\AppData\Local\Temp\{779324EA-317A-4831-B4F5-C699CDD6055B}\.cr\software.exe
04Isolated runtime analysis - Written fileObserved
mbahost.dll
C:\Users\<USER>\AppData\Local\Temp\{77E25A29-A243-4312-AC0B-50B9EBEFB2CA}\.ba\mbahost.dll
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\<USER>\AppData\Local\Temp\{779324EA-317A-4831-B4F5-C699CDD6055B}\.cr\software.exe
- C:\Users\<USER>\AppData\Local\Temp\{77E25A29-A243-4312-AC0B-50B9EBEFB2CA}\.ba\mbahost.dll
- C:\Users\<USER>\AppData\Local\Temp\{77E25A29-A243-4312-AC0B-50B9EBEFB2CA}\.ba\BootstrapperCore.dll
- C:\Users\<USER>\AppData\Local\Temp\{77E25A29-A243-4312-AC0B-50B9EBEFB2CA}\.ba\mbapreq.dll
- C:\Users\<USER>\AppData\Local\Temp\{77E25A29-A243-4312-AC0B-50B9EBEFB2CA}\.ba\mbapreq.thm
- C:\Users\<USER>\AppData\Local\Temp\{779324EA-317A-4831-B4F5-C699CDD6055B}\.cr\software.exe
- C:\Users\<USER>\AppData\Local\Temp\{779324EA-317A-4831-B4F5-C699CDD6055B}\.cr\
- C:\Users\<USER>\AppData\Local\Temp\{779324EA-317A-4831-B4F5-C699CDD6055B}\
- C:\Windows\Temp\{8862BBF2-9F21-4DE8-8DEB-FF969D99ECC7}\9BF3D5F06591BC0A4885771B8A85028B3BCBA732
- C:\Users\<USER>\AppData\Local\Package Cache\{a6d78ead-1f82-40ec-9681-a57e96c23b9a}\Package_f905c5.exe
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 886cb2a994461f091752…1880daNever scannednever seen before
- e2bfdb2cf3beae2e9888…63c385Never scannednever seen before
- 1b93556f07c35ac0564d…6fd04cNever scannednever seen before
- c91c9e87ab4a6db078f1…151c3bNever scannednever seen before
- d22f6ada97dbffc1e754…2cccbdNever scannednever seen before
- ecb5c22e6c2423caf07a…58ca15Never scannednever seen before
- f8c3a03f47f0b9b3c20f…8cbaeaNever scannednever seen before
- 6dd61cc6b87b53eaf284…c4fe7dNever scannednever seen before
- b8e90e20edf110aaaaea…3147b5Never scannednever seen before
- 06bfb6dfbc38105c699d…61487dNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 6rule hits recorded
- 24 / 75engines flagged
- 1sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
6 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
24 of 75 antivirus engines flagged the file, including alibabacloud and Avast.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
YARAify matched 7 researcher rules to this file.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Package_f905c5.exe — 8fa247609916e3d5fe1831412c318c0e1f489399463021dc49be72df6e5cc8bb
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\software.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\<USER>\AppData\Local\Temp\{779324EA-317A-4831-B4F5-C699CDD6055B}\.cr\software.exe" -burn.clean.room="C:\Users\<USER>\Desktop\software.exe" -burn.filehandle.attached=672 -burn.filehandle.self=664
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: software.exe — C:\Users\<USER>\AppData\Local\Temp\{779324EA-317A-4831-B4F5-C699CDD6055B}\.cr\software.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: mbahost.dll — C:\Users\<USER>\AppData\Local\Temp\{77E25A29-A243-4312-AC0B-50B9EBEFB2CA}\.ba\mbahost.dll
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: generic-trojan
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- DebuggerCheck__API
- DetectEncryptedVariants
- golang_bin_JCorn_CSC846
- pe_detect_tls_callbacks
- RANSOMWARE
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Users\<USER>\Desktop\software.exe"
24 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Package_f905c5.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 652.8 KB
- Last analyzed
- Sep 19, 2026, 9:17 PM UTC
8fa247609916e3d5fe1831412c318c0e1f489399463021dc49be72df6e5cc8bbSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't run this file. Delete this file from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already ran it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the developer's official site or an official app store.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Package_f905c5.exe malware?
What is Package_f905c5.exe?
How many antivirus engines detected Package_f905c5.exe?
I already downloaded and ran Package_f905c5.exe — what should I do?
How do I remove Package_f905c5.exe?
What kind of malware is Package_f905c5.exe?
What is the SHA-256 hash of Package_f905c5.exe?
How up to date is this analysis of Package_f905c5.exe?
Community
Member reviews and reports for this exact file hash.