Suspicious
This MD5_Hash_Changer.exe is flagged anomalous by one engine (Malwarebytes), but 15 tier-1 engines and most others see it clean—likely a false positive on a hash tool.
99cf802bec942be688…bcecd5b21eThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file is an unsigned Win32 EXE named MD5_Hash_Changer.exe, 142KB, first submitted about 700 days ago with neutral reputation (score 0). Out of 75 engines, only one—Malwarebytes (tier-2)—detects it as 'MachineLearning/Anomalous.95%', a heuristic signal, while 15 tier-1 engines (BitDefender, Kaspersky, ESET-NOD32, etc.) and 64 others say undetected or clean. No tier-1 malicious hits, no external intel from MalwareBazaar or others, and network tags like 'detect-debug-environment' suggest it might evade analysis but don't confirm threats. This single low-confidence flag pattern often means a false positive, especially on tools like hash changers. We rate it suspicious but lean safe—don't run it without verification.
- 15 tier-1 engines (BitDefender, Kaspersky, ESET-NOD32, etc.) report clean.
- 64 engines undetected, no other malicious hits.
- No hits in MalwareBazaar, YARAify, or CIRCL.
- Seen for 700 days without widespread flags.
- No popular threat label from our network.
- Flagged malicious by Malwarebytes as MachineLearning/Anomalous.95% (tier-2 heuristic).
- Unsigned executable with neutral reputation (0).
- Network tag 'detect-debug-environment' suggests anti-analysis tricks.
- File name MD5_Hash_Changer.exe implies hash manipulation, which can be misused.
- Only 75 engines scanned, 6 timeouts.
Quarantine or delete the file immediately. If it's a needed tool, verify from official source and rescan with multiple AVs before use.
1 detection across 75 engines
Forensic fingerprint
- File name
- MD5_Hash_Changer.exe
- Size
- 138.5 KB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 99cf802bec942be688352e3c0ccd1158250bd88cd38ea4cb6c5ef3bcecd5b21e
- MD5
- ea2d2d6003c858771eec344ac6aa494a
- SHA-1
- 227a3d41d9fa9f07682e22799366668c817a23be
- PE imphash
- f34d5f2d4577ed6d9ceec516c1f5a744
- First seen (VT)
- 5/20/2024, 12:46:01 PM
- Last analysis (VT)
- 4/1/2026, 12:49:39 AM
- First scan (MalwareTips)
- 4/20/2026, 4:00:54 PM
- Last scan (MalwareTips)
- 4/20/2026, 4:00:54 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.