File verdict·Decided by the MT AI Engine
Our call

Malicious

14 tier-1 engines converge on Malgent trojan/downloader; direct-IP C2 contact and sandbox evasion techniques confirm malware.

Malgent
Trust score8Critical
MT AI confidence · 96%
AorUi.exe
2.1 MB
a35c607f410213b4bde320fe5d81
Antivirus engines
44 of 74 flagged
Code signing
Unsigned
Age
First seen 4y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

96%Confidence
Very high
Reasoning

The evidence converges strongly on malware. Fourteen tier-1 engines (Microsoft, Fortinet, TrendMicro, Sophos, Symantec, BitDefender, Avast, Ikarus, and others) agree on the Malgent family or closely related trojan/downloader variants. The triggered heuristic 'DirectIpC2' identifies a hallmark malware evasion technique: contacting 18 external IPs without any DNS queries, which bypasses domain-based reputation blocklists. Sandbox analysis recorded six ambient MITRE techniques including code obfuscation (T1027.002), input capture (T1056), and sandbox evasion (T1497.001)—a profile consistent with trojan/downloader malware. The file is unsigned, has no legitimate signer history, and has been submitted 384 times since September 2022, indicating it is a known malware sample rather than a novel or misclassified file.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines.tier1Malicious=14/17 (82%); tier1FamilyConsensus.strong=true with 4 tier-1 engines agreeing on 'win32' family

  2. Microsoft, Fortinet, TrendMicro, Sophos, Symantec, BitDefender, Avast, Ikarus all flag 'Malgent', 'Dlder', 'Evo-gen', or 'W32/Mal_DLDER' — consistent named-family consensus

  3. triggeredHeuristics: 'MalwareTips.Synth.DirectIpC2' fired — 18 external IPs contacted, zero domains; direct-IP C2 is evasion technique bypassing DNS reputation systems

  4. behaviour.mitreTechniques includes T1027.002 (code obfuscation), T1056 (input capture), T1497.001 (sandbox evasion), T1574.002 (DLL side-loading) — trojan/downloader profile

  5. signing.verified=false, unsigned; prevalence.classification='common_old' (291 submitters, 384 submissions since 2022-09-03) — established malware with no legitimate signer backing

Points in its favour
  • No malicious sandbox verdict explicitly recorded (though sandbox evasion technique suggests evasion rather than benignity)
Points against
  • 14/17 tier-1 engines flag as Malgent trojan/downloader
  • Direct-IP C2 contact (18 IPs, zero DNS) — evasion technique
  • Code obfuscation and sandbox evasion techniques detected
  • Input capture capability (credential-theft risk)
  • Unsigned executable with no legitimate signer history
  • Spawns child processes (OneKey.exe, updater.exe) — typical downloader payload delivery
What to do

Block and remove this file immediately. It is a confirmed trojan/downloader with high-confidence detection across tier-1 antivirus engines and direct-IP C2 communication patterns. Do not attempt to execute or analyse it in an uncontrolled environment.

Threat family attribution

malgent corroborated by 2 sources

  • VT (74 engines)
    malgent
  • MT AI Engine
    Malgent
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
6

Adversary techniques mapped to the MITRE ATT&CK framework.

T1027.002T1056T1071T1082T1497.001T1574.002
Spawned processes
7
$(unnamed)
%SAMPLEPATH%\OneKey.exe
$(unnamed)
%SAMPLEPATH%\AorUi.exe
$(unnamed)
C:\Windows\System32\wuapihost.exe
$(unnamed)
%SAMPLEPATH%\a35c607f410213b4bd119c7faa88fd60717a97bd4c84da11ae515ee320fe5d81.exe
$(unnamed)
C:\Windows\System32\UI0Detect.exe
$(unnamed)
C:\Program Files\Google2412_2057586327\bin\updater.exe
$(unnamed)
"C:\Users\user\Desktop\AorUi.exe"
Network activity
20
IP addresses20
  • a83f:8110:0:0:100:0:1800:0
  • 20.62.24.77
  • 23.216.147.64
  • a83f:8110:a802:1300:100:0:0:0
  • 20.99.132.105
  • 20.99.133.109
  • 20.99.184.37
  • 192.229.211.108
  • 20.99.186.246
  • 23.59.198.43
+10 more
Filesystem & mutexes
15
Files deleted15
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER197E.tmp.WERInternalMetadata.xml
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER1980.tmp.csv
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER1991.tmp.txt
  • C:\Windows\System32\spp\store\2.0\cache\cache.dat
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER1279.tmp.WERInternalMetadata.xml
+10 more
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.

1 synthesis
MITRE ATT&CK profile
C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • DirectIpC2medium

    Sample contacted 18 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    a83f:8110:0:0:100:0:1800:0 · 20.62.24.77 · 23.216.147.64
Antivirus engine breakdown

44 detections across 74 engines

44 malicious0 suspicious30 clean
Tier-117 engines
14flag
Top commercial AVs (low FP rate)
Tier-237 engines
18flag
Mainstream engines with mixed FP rates
Low-trust20 engines
12flag
Heuristic / generic-AI engines (high FP rate)
AhnLab-V3
malicious
Trojan/Win.Dlder.C5233223
Alibaba
malicious
Trojan:Win32/Malgent.defbd67a
alibabacloud
malicious
Trojan:MSDOS/Malgent.Gen
ALYac
malicious
Trojan.GenericKD.61724715
Antiy-AVL
malicious
Trojan/Win32.Wacatac
Arcabit
malicious
Trojan.Generic.D3ADD82B
Avast
malicious
Win32:Evo-gen [Trj]
AVG
malicious
Win32:Evo-gen [Trj]
Avira
malicious
TR/W32.Evo
BitDefender
malicious
Trojan.GenericKD.61724715
CAT-QuickHeal
malicious
Trojan.Agent
CrowdStrike
malicious
win/malicious_confidence_100% (W)
CTX
malicious
exe.trojan.malgent
Cylance
malicious
Unsafe
Cynet
malicious
Malicious (score: 99)
DeepInstinct
malicious
MALICIOUS
Elastic
malicious
malicious (moderate confidence)
Emsisoft
malicious
Trojan.GenericKD.61724715 (B)
F-Secure
malicious
Trojan.TR/W32.Evo
Fortinet
malicious
W32/Mal_DLDER
GData
malicious
Trojan.GenericKD.61724715
Google
malicious
Detected
Ikarus
malicious
Trojan.Win32.Malgent
K7AntiVirus
malicious
Riskware ( 00584baa1 )
K7GW
malicious
Riskware ( 00584baa1 )
Lionic
malicious
Trojan.Win32.Generic.lNH1
Malwarebytes
malicious
Malware.AI.2252978712
MaxSecure
malicious
Trojan.Malware.187361165.susgen
McAfeeD
malicious
ti!A35C607F4102
Microsoft
malicious
Trojan:Win32/Malgent!MTB
MicroWorld-eScan
malicious
Trojan.GenericKD.61724715
Paloalto
malicious
generic.ml
Panda
malicious
Trj/Chgt.AD
Rising
malicious
Trojan.Bitrep!8.F596 (CLOUD)
Sangfor
malicious
Trojan.Win32.Evo.Vyk5
Sophos
malicious
Mal/Generic-S
Symantec
malicious
ML.Attribute.HighConfidence
TrellixENS
malicious
GenericRXAA-AA!B967A9514882
TrendMicro
malicious
Mal_DLDER
TrendMicro-HouseCall
malicious
Mal_DLDER
Varist
malicious
W32/ABTrojan.ZARV-3671
VIPRE
malicious
Trojan.GenericKD.61724715
VirIT
malicious
Trojan.Win32.Genus.YZV
ViRobot
malicious
Trojan.Win32.Z.Agent.2194944.D
Hash a35c607f4102… cross-referenced against 74 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

Unpacked
Section entropy3 sections
.MPRESS1
8.00
.MPRESS2
6.13
.rsrc
4.33
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.

Common & old
Unique uploaders
291
Hundreds of people have uploaded this — common.
Total submissions
384
Includes repeat uploads by the same source.
First seen by VT
4y ago
Sep 3, 2022
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
here
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
9/3/2022, 6:39:50 AM
First seen (MalwareBazaar)
Last analysis (VT)
6/24/2026, 1:47:26 PM
Scanned here
7/3/2026, 6:14:34 AM
File name
AorUi.exe
Size
2.09 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
a35c607f410213b4bd119c7faa88fd60717a97bd4c84da11ae515ee320fe5d81
MD5
b967a951488268dce91797d12ec4379a
SHA-1
ca38f04ab266dd756dee6a667e3bfc897d83d065
PE imphash
58c41d9c49c748c060398d3909617cc0
First seen (VT)
9/3/2022, 6:39:50 AM
Last analysis (VT)
6/24/2026, 1:47:26 PM
First scan (MalwareTips)
7/3/2026, 6:14:34 AM
Last scan (MalwareTips)
7/3/2026, 6:14:34 AM
Community reputation
+15trusted
Behavior tags
checks-user-inputpeexeidle
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.