Malicious
Unsigned executable flagged by 19 engines including two tier-1 as abltrojan with data-destruction behavior.
9f4a974810932b8dfc…370bfd2733The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Nineteen engines report malicious, two of which are tier-1, with labels converging on abltrojan variants. The presence of T1485 in offensive techniques indicates destructive capability typical of trojans. The binary is unsigned and carries a medium-prevalence threat label that matches the engine families. Absence of sandbox malice and low tier-1 agreement are noted but insufficient to override the volume and tier of detections.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines.tier1Malicious=2 with Fortinet and TrendMicro-HouseCall detections
behaviour.offensiveTechniques=["T1485"]
file.popularThreatLabel=abltrojan and popularThreatName=abltrojan
engines.malicious=19 out of 71 reporting
- No malicious dropped children
- No contacted malicious hosts
- Medium prevalence with 29 submitters
- Unsigned PE with 19 malicious detections
- Offensive MITRE T1485 present
- Consistent abltrojan family labels across engines
Treat as malicious; remove the file and scan the system for related artifacts.
abltrojan corroborated by 2 sources
- VT (75 engines)abltrojan
- MT AI Engineabltrojan
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\<USER>\AppData\Local\Temp\_MEI58562\VCRUNTIME140.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI58562\_bz2.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI58562\_ctypes.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI58562\_decimal.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI58562\_hashlib.pyd
- C:\Users\<USER>\AppData\Local\Temp\_MEI58562\api-ms-win-core-console-l1-1-0.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI58562\api-ms-win-core-datetime-l1-1-0.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI58562\api-ms-win-core-debug-l1-1-0.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI58562\api-ms-win-core-errorhandling-l1-1-0.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI58562\api-ms-win-core-file-l1-1-0.dll
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- d045a72c3e4d21165e93…a310e8Never scannednever seen before
- eb8fe2778c54213aa2cc…588e74Never scannednever seen before
- 6f50b4dc2129ff8e2280…5de06cNever scannednever seen before
- 8eccaba9321df69182ee…7395aeNever scannednever seen before
- 5783c5c5a3ffce181691…7cfcc5Never scannednever seen before
- 39e363c47d4d45beda15…76453cNever scannednever seen before
- 91d7a4c39baac78c595f…dcd42cNever scannednever seen before
- 6e6bfdc656f0cf22fabb…e57ab2Never scannednever seen before
- b545db2339ae74c52336…619b68Never scannednever seen before
- b9ae70e8f74615ea2dc6…3424f2Never scannednever seen before
19 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- info.exe
- Size
- 6.05 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 9f4a974810932b8dfc8a80417b3323054cbe4e90cc6885715b2467370bfd2733
- MD5
- b049a74577d29889cd1db21c80da6761
- SHA-1
- 09d45b4e9be02dfa05dfc60b919f290e88898723
- PE imphash
- 1af6c885af093afc55142c2f1761dbe8
- First seen (VT)
- 4/19/2025, 5:45:20 PM
- Last analysis (VT)
- 5/29/2026, 8:21:29 AM
- First scan (MalwareTips)
- 5/30/2026, 2:52:18 PM
- Last scan (MalwareTips)
- 5/30/2026, 2:52:18 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.