Is patch.exe safe?
Thirty-nine of 74 engines flagged this unsigned executable, including nine tier-1 detections, while runtime evidence mapped activity to process injection technique T1055.
The evidence strongly indicates a Windows trojan associated most often with Pomal or Yogi labels. Microsoft and Ikarus identify Pomal, several other established engines identify Yogi, and the sandbox evidence maps activity to process injection and includes LSASS-related process activity.
a6b38c1ceab1dc64a7…4773c46604c144Recommended next actions
Before running
Do not run it. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already ran it
Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The evidence strongly indicates a Windows trojan associated most often with Pomal or Yogi labels. Microsoft and Ikarus identify Pomal, several other established engines identify Yogi, and the sandbox evidence maps activity to process injection and includes LSASS-related process activity.
The executable was detected by 39 of 74 engines, including nine tier-1 engines. Microsoft and Ikarus specifically identify Pomal, while BitDefender, Emsisoft, and GData identify the closely represented Yogi label. Runtime evidence maps activity to T1055 process injection and includes LSASS-related process activity, which materially reinforces the engine findings. The file is unsigned and has no established signer history to provide a credible benign explanation. Although no malicious sandbox verdict or network contacts were recorded, no complete contacted-host reputation result is available, and those limitations do not outweigh the detection volume and behavior.
What We Detected
Thirty-nine of 74 antivirus engines flagged this Win32 executable, including nine tier-1 detections. Microsoft and Ikarus identify the Pomal family, while BitDefender, Emsisoft, GData, ALYac, and VIPRE use the Yogi label. Other engines report generic trojan or agent classifications, supporting the broader malware finding even though family naming varies.
Threat Behavior
The completed sandbox run mapped activity to MITRE technique T1055, Process Injection. Saved evidence also includes LSASS-related process activity, a pattern associated with credential access, although the exact operation is not proven by the available record. No domains, IP addresses, or URLs were recorded during that run, and no complete contacted-host reputation cross-check is available.
What To Do Now
Do not execute the file. Keep endpoint protection enabled, quarantine or remove the sample, and run a full system scan if it was opened. If execution occurred, review the host for credential exposure and unauthorized process activity, then change affected credentials from a separate trusted device.
Where this verdict could be wrong4 caveats
- engines.tier1FamilyConsensus.strong=false, and only two tier-1 votes agree specifically on Pomal, so the exact family name is less certain than the malware finding.
- behaviour.hasMaliciousSandboxVerdict=false, and the completed sandbox recorded no contacted domains, IPs, or URLs.
- externalIntel.yaraify.ruleCount=0, externalIntel.circl.hit=false, and externalIntel.malwareBazaar.hit=false; these may reflect coverage gaps rather than exoneration.
- peAnalysis.highEntropyCode=false and peAnalysis.likelyPacked=false, providing no packing-based corroboration.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- behaviour.hasMaliciousSandboxVerdict=false
- No contacted domains, IPs, or URLs were recorded in the completed sandbox run
- No dropped file hashes were recorded
- peAnalysis.likelyPacked=false
- externalIntel.yaraify.ruleCount=0
- 39/74 antivirus detections
- Nine tier-1 engines flagged the sample
- Microsoft and Ikarus identify Pomal
- T1055 process-injection mapping
- LSASS-related process activity
- Unsigned Win32 executable
Quarantine or delete the file without running it, and keep endpoint protection enabled. If it already executed, isolate the system, perform a full scan, and investigate possible process injection and credential exposure.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete39 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 9MITRE ATT&CK techniques
- 9spawned processes
- 0network contacts
- 1filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Scans through your files and folders.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Reads your Windows user-account details.
Note: Collects details about your system.
Note: Loads extra code modules while running.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
patch.exe
a6b38c1ceab1dc64a71f2e1e1499ecad4a2da577cf0351e2394773c46604c144
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\software.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\services.exe
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Microsoft Compatibility Appraiser
C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
04Isolated runtime analysis
4 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 39 / 74engines flagged
- 321sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
39 of 74 antivirus engines flagged the file, including Alibaba and alibabacloud.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 410 times from 321 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: patch.exe — a6b38c1ceab1dc64a71f2e1e1499ecad4a2da577cf0351e2394773c46604c144
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\software.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\services.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Microsoft Compatibility Appraiser — C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: generic-trojan
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
39 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- patch.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 417.5 KB
- Last analyzed
- Sep 19, 2026, 6:45 AM UTC
a6b38c1ceab1dc64a71f2e1e1499ecad4a2da577cf0351e2394773c46604c144Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't run this file. Delete this file from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already ran it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the developer's official site or an official app store.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is patch.exe malware?
What is patch.exe?
How many antivirus engines detected patch.exe?
I already downloaded and ran patch.exe — what should I do?
How do I remove patch.exe?
What kind of malware is patch.exe?
What is the SHA-256 hash of patch.exe?
How up to date is this analysis of patch.exe?
Community
Member reviews and reports for this exact file hash.