Suspicious
Low-trust detections only on a common_old unsigned Delphi EXE with mixed installer-like and direct-IP behaviour.
a90c7a464e2865290c…b836697088The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The payload shows classic low-trust-only flagging with zero tier-1 malicious detections and a prior safe verdict on the same imphash. Prevalence as common_old over 1169 days plus clean dropped children and sandbox results weigh against active malware. However, the DirectIpC2 heuristic and single offensive MITRE technique prevent a clean safe verdict, producing mixed signals best captured as suspicious.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines.onlyLowTrustFlagging=true with tier1Malicious=0 and 2 low-trust detections (CrowdStrike, MaxSecure)
similarHashes[0].verdict=safe (ai:av_on_av_fp_pattern, matchKind=imphash)
triggeredHeuristics.security_tool_classifier + MalwareTips.Synth.DirectIpC2 (direct-IP contacts: 204.79.197.203 etc.)
prevalence.classification=common_old (250 submitters) + behaviour.hasMaliciousSandboxVerdict=false
- Zero tier-1 malicious detections
- Prior safe verdict on identical imphash
- Common_old prevalence with 250 submitters
- No malicious dropped children or sandbox verdicts
- Direct IP contacts bypassing DNS reputation (DirectIpC2 heuristic)
- T1134 offensive technique present
- Unsigned binary
Treat as suspicious pending additional context; do not execute without isolation or further analysis.
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 204.79.197.203
- 192.229.211.108
- 20.99.184.37
- 23.216.147.76
- 20.22.113.133
- a83f:8110:0:0:2000:0:0:0
- 20.99.186.246
- a83f:8110:4000:0:0:0:0:0
- 20.99.185.48
- 23.216.147.64
- C:\Users\<USER>\AppData\Local\Temp\is-9H72R.tmp\Delphi 2021.10b Cars & Trucks.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-MAQLH.tmp\_isetup\_setup64.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-MAQLH.tmp\_isetup\_isdecmp.dll
- C:\Users\user\AppData\Local\Programs
- C:\Users\user\AppData\Local\Programs\Common
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1911.tmp.WERInternalMetadata.xml
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER19CC.tmp.csv
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER1A0C.tmp.txt
- C:\Windows\System32\spp\store\2.0\cache\cache.dat
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER31D8.tmp.WERInternalMetadata.xml
- Local\RstrMgr3887CAB8-533F-4C85-B0DC-3E5639F8D511
- Local\RstrMgr-3887CAB8-533F-4C85-B0DC-3E5639F8D511-Session0000
- \Sessions\1\BaseNamedObjects\Local\RstrMgr3887CAB8-533F-4C85-B0DC-3E5639F8D511
- \Sessions\1\BaseNamedObjects\Local\RstrMgr-3887CAB8-533F-4C85-B0DC-3E5639F8D511-Session0000
Files this sample writes at runtime
This file drops 3 children at runtime. None are currently flagged malicious in our cache.
- e34fc85e9ed99fac2619…c5d2bcNever scannednever seen before
- 388a796580234efc95f3…136f95Never scannednever seen before
- 8287d0e287a66ee78537…a57e64Never scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 18 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence204.79.197.203 · 192.229.211.108 · 20.99.184.37
2 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- Delphi 2021.10b Cars & Trucks.exe
- Size
- 1.86 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- a90c7a464e2865290c7212360fbac6ad976109c2da8c9c77f6e641b836697088
- MD5
- d39311a01ac2cecf3e45bad448342ce1
- SHA-1
- b44eb8652b3503adc8bda6acc6b923554966d268
- PE imphash
- 5a594319a0d69dbc452e748bcf05892e
- First seen (VT)
- 3/10/2023, 12:13:33 PM
- Last analysis (VT)
- 5/14/2026, 2:30:30 PM
- First scan (MalwareTips)
- 5/22/2026, 1:21:09 PM
- Last scan (MalwareTips)
- 5/22/2026, 1:21:09 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.