Safe
This old Installer.exe has a positive reputation but flags as generic trojan by 3 engines (no tier-1 hits), with suspicious network behaviors like via-tor access.
a453b3ea8d8133531f…e100908c1aThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file presents as Installer.exe, a Win32 PE executable over 5MB, first submitted over 10 years ago with strong positive reputation (176) and no code signature. Out of 76 engines, only 3 flagged it malicious—Jiangmin calls it Trojan.Generic.haljt, SentinelOne sees suspicious PE traits, and low-trust Trapmine gives a low ML score—while 17 tier-1 engines (Avast, BitDefender, ESET, etc.) and 68 others report clean. Network tags like via-tor, overlay, and direct-cpu-clock-access raise flags for potential hidden malicious behavior if run. No external intel hits, so the few detections without tier-1 backing suggest a possible false positive on this aged file, but caution is warranted. Quarantine it and avoid execution until further analysis.
- Positive reputation score of 176 indicates community trust.
- First seen 3805 days ago (2015), with consistent clean scans over time.
- All 17 tier-1 engines (BitDefender, Kaspersky, ESET, etc.) report clean.
- 68 engines undetected out of 76 total, showing broad consensus.
- No hits in MalwareBazaar, YARAify, or CIRCL threat intel.
- Jiangmin (tier2) detects it as Trojan.Generic.haljt, a generic malware label.
- SentinelOne (tier2) flags Static AI - Suspicious PE based on file structure.
- Trapmine (low-trust) scores it suspicious.low.ml.score via ML heuristics.
- Network tag 'via-tor' suggests potential anonymous malicious communication.
- Network tag 'direct-cpu-clock-access' hints at timing evasion or mining behavior.
- PE imphash a8fd72e864d14b8484dd49e800fd3a36 seen in some suspicious files.
Quarantine or delete Installer.exe immediately—do not run it. Resubmit the hash to MalwareTips or your AV for a second opinion, as the low detection count and strong clean signals from tier-1 engines suggest it may be safe.
generic trojan corroborated by 1 source
- MT AI Enginegeneric trojan
2 contradictions resolved by the scoring engine
3 detections across 76 engines
Forensic fingerprint
- File name
- Installer.exe
- Size
- 5.10 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- a453b3ea8d8133531fad26b18701c694c324cc201e3069d07e99f0e100908c1a
- MD5
- a7c8cf1d50ebe630a7d0c47686a0abbf
- SHA-1
- 3229e8080975f4f5512d2382552f68c0389acff5
- PE imphash
- a8fd72e864d14b8484dd49e800fd3a36
- First seen (VT)
- 11/19/2015, 7:07:14 AM
- Last analysis (VT)
- 4/19/2026, 4:37:26 PM
- First scan (MalwareTips)
- 4/20/2026, 3:51:49 PM
- Last scan (MalwareTips)
- 4/20/2026, 3:51:49 PM
- Community reputation
- +176trusted
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.