File verdict·Decided by the MT AI Engine
Our call

Suspicious

This MD5_Hash_Changer.exe is flagged anomalous by one engine (Malwarebytes), but 15 tier-1 engines and most others see it clean—likely a false positive on a hash tool.

Trust score49Caution
MT AI confidence · 30%
MD5_Hash_Changer.exe
138.5 KB
99cf802bec942be688bcecd5b21e
Antivirus engines
1 of 75 flagged
Code signing
Unsigned
Age
First seen 2y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

30%Confidence
Exploratory
Reasoning

The file is an unsigned Win32 EXE named MD5_Hash_Changer.exe, 142KB, first submitted about 700 days ago with neutral reputation (score 0). Out of 75 engines, only one—Malwarebytes (tier-2)—detects it as 'MachineLearning/Anomalous.95%', a heuristic signal, while 15 tier-1 engines (BitDefender, Kaspersky, ESET-NOD32, etc.) and 64 others say undetected or clean. No tier-1 malicious hits, no external intel from MalwareBazaar or others, and network tags like 'detect-debug-environment' suggest it might evade analysis but don't confirm threats. This single low-confidence flag pattern often means a false positive, especially on tools like hash changers. We rate it suspicious but lean safe—don't run it without verification.

Points in its favour
  • 15 tier-1 engines (BitDefender, Kaspersky, ESET-NOD32, etc.) report clean.
  • 64 engines undetected, no other malicious hits.
  • No hits in MalwareBazaar, YARAify, or CIRCL.
  • Seen for 700 days without widespread flags.
  • No popular threat label from our network.
Points against
  • Flagged malicious by Malwarebytes as MachineLearning/Anomalous.95% (tier-2 heuristic).
  • Unsigned executable with neutral reputation (0).
  • Network tag 'detect-debug-environment' suggests anti-analysis tricks.
  • File name MD5_Hash_Changer.exe implies hash manipulation, which can be misused.
  • Only 75 engines scanned, 6 timeouts.
What to do

Quarantine or delete the file immediately. If it's a needed tool, verify from official source and rescan with multiple AVs before use.

No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

1 detection across 75 engines

1 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-237 engines
1flag
Mainstream engines with mixed FP rates
Low-trust21 engines
0flag
Heuristic / generic-AI engines (high FP rate)
Malwarebytes
malicious
MachineLearning/Anomalous.95%
Hash 99cf802bec94… cross-referenced against 75 AV engines via our AV network.
File identity

Forensic fingerprint

File biography
First seen (VT)
5/20/2024, 12:46:01 PM
First seen (MalwareBazaar)
Last analysis (VT)
4/1/2026, 12:49:39 AM
Scanned here
4/20/2026, 4:00:54 PM
File name
MD5_Hash_Changer.exe
Size
138.5 KB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
99cf802bec942be688352e3c0ccd1158250bd88cd38ea4cb6c5ef3bcecd5b21e
MD5
ea2d2d6003c858771eec344ac6aa494a
SHA-1
227a3d41d9fa9f07682e22799366668c817a23be
PE imphash
f34d5f2d4577ed6d9ceec516c1f5a744
First seen (VT)
5/20/2024, 12:46:01 PM
Last analysis (VT)
4/1/2026, 12:49:39 AM
First scan (MalwareTips)
4/20/2026, 4:00:54 PM
Last scan (MalwareTips)
4/20/2026, 4:00:54 PM
Behavior tags
detect-debug-environmentassemblypeexe
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Scanned by
harlan4096Staff
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.