File verdict·Decided by the MT AI Engine
Our call

Suspicious

Single tier-2 generic detection plus direct-IP contact without domains creates moderate suspicion for this unsigned rare executable.

Trust score50Caution
Tracking.exe
11.0 MB
b3b424ab934451178e5be8095e2a
Antivirus engines
1 of 79 flagged
Code signing
Unsigned
Age
First seen 2y ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

65%Confidence
High
Reasoning

Our analysis weighs the single tehtris Generic.Malware flag against the complete absence of tier-1 detections and the clean sandbox outcome. The direct-IP C2 heuristic is a legitimate red flag because benign software almost always resolves domains, yet it remains a single medium-severity rule without supporting malicious behaviour or dropped payloads. Unsigned status and rare_old prevalence add uncertainty but do not rise to malicious on their own. Similar-hash RAG returned no prior verdicts, leaving the mixed signals unresolved.

Key signals · 4

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines.topDetections[0]: tehtris tier2 Generic.Malware

  2. triggeredHeuristics[0]: MalwareTips.Synth.DirectIpC2 fired true with evidence 23.216.81.152 · 52.154.209.174

  3. behaviour.contactedIps: 2 external IPs and 0 domains

  4. signing.signed: false; prevalence.classification: rare_old

Points in its favour
  • Zero tier-1 malicious detections
  • Clean sandbox verdicts
  • No malicious dropped children
  • No external intelligence hits
Points against
  • Direct external IP contact without domains
  • Single AV detection (tehtris Generic.Malware)
  • Unsigned executable
  • Rare_old prevalence (3 submitters)
Recommended action

Exercise caution and avoid execution on production systems; re-evaluate with additional context or updated scans.

What this file does

What it attempted when executed in an isolated sandbox

  • High concern: Talks to a remote server to take commands or send out your data.

  • High concern: Hijacks how Windows loads programs so it runs automatically.

  • Moderate concern: Obfuscates or packs its code to avoid detection.

  • Moderate concern: Runs hidden system commands (script or shell).

  • Moderate concern: Checks whether it's being watched in a sandbox before acting.

  • Moderate concern: Checks which security software you have installed.

  • Note: Collects details about your system.

Translated from the file's technical behaviour during analysis. It never ran on your device.

What to do now

We couldn't fully clear this file. Treat it with caution.

  1. Don't run it unless you're certain it came from a source you trust.

  2. Check where you got it — an email attachment or a random download link is a red flag.

  3. If you're unsure, delete it. You can always re-download a clean copy from the official source.

  4. If you're still unsure, scan it again in a day or two — detections often catch up on newer files.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
10

Adversary techniques mapped to the MITRE ATT&CK framework.

T1027· Obfuscated codeT1027.002· Obfuscated codeT1036T1059· Runs commandsT1071· Remote server (C2)T1082· System reconT1129· Loads modulesT1497.001· Sandbox evasionT1518.001· Checks your AVT1574.002· Execution hijack
Spawned processes
10
$(unnamed)
"C:\Users\<USER>\Desktop\Tracking.exe"
$(unnamed)
%SAMPLEPATH%\Tracking.exe
$(unnamed)
%SAMPLEPATH%\b3b424ab934451178eb5343cb4a9131a848f71badca5d8a1b5579d5be8095e2a.exe
$(unnamed)
"C:\Users\user\Desktop\file.exe" -install
$(unnamed)
C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
$(unnamed)
"C:\Users\user\Desktop\file.exe" /install
$(unnamed)
"C:\Users\user\Desktop\file.exe" /load
$(unnamed)
"C:\Users\user\Desktop\Tracking.exe" -install
+2 more processes captured.
Network activity
3
IP addresses3
  • 192.168.0.17
  • 23.216.81.152
  • 52.154.209.174
Filesystem & mutexes
9
Files written9
  • C:\Users\<USER>\Desktop\log.txt
  • C:\Users\<USER>\Desktop\config.cfg
  • ./log.txt
  • ./config.cfg
  • C:\Users\<USER>\Downloads\log.txt
+4 more
Dropped payload

Files this sample writes at runtime

This file drops 3 children at runtime. None are currently flagged malicious in our cache.

3 unseen
  • e3b0c44298fc1c149afb52b855Never scanned
    never seen before
  • 802449f39a2b6f5720048c195aNever scanned
    never seen before
  • dfd4e8d7e69a3bbbd651ca6bdbNever scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA & heuristic rule matches

One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.

1 synthesis
MITRE ATT&CK profile
C2× 1
MalwareTips synthesis rules
Our own detection rules, applied to the scan data and sandbox behaviour
  • DirectIpC2medium

    Sample contacted 2 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    23.216.81.152 · 52.154.209.174
Antivirus engine breakdown

1 detection across 79 engines

1 malicious0 suspicious78 clean
Tier-118 engines
0flag
Top commercial AVs (low FP rate)
Tier-243 engines
1flag
Mainstream engines with mixed FP rates
Low-trust18 engines
0flag
Heuristic / generic-AI engines (high FP rate)
tehtris
malicious
Generic.Malware
Hash b3b424ab9344… cross-referenced against 79 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

Unpacked
Section entropy10 sections
.text
5.84
.rdata
5.38
.data
5.56
/4
4.83
/19
8.00
/32
7.94
/46
7.97
/63
7.99
/80
0.77
/99
8.00
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Rarely uploaded, but has been around for a while. Often niche legitimate software or old internal tooling; not a strong malware signal on its own.

Rare & old
Unique uploaders
3
Very few people have ever uploaded this — rare.
Total submissions
4
Includes repeat uploads by the same source.
First seen
2y ago
Aug 6, 2024
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
here
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
8/6/2024, 5:55:09 AM
First seen (MalwareBazaar)
Last analysis (VT)
8/6/2024, 5:56:02 AM
Scanned here
6/6/2026, 10:04:52 PM
File name
Tracking.exe
Size
11.03 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
b3b424ab934451178eb5343cb4a9131a848f71badca5d8a1b5579d5be8095e2a
MD5
d468098873adb090ea6252b3aabd9456
SHA-1
415fa88e99366972fe44d773b820a1e1eb61dcdb
PE imphash
91802a615b3a5c4bcc05bc5f66a5b219
First seen (VT)
8/6/2024, 5:55:09 AM
Last analysis (VT)
8/6/2024, 5:56:02 AM
First scan (MalwareTips)
6/6/2026, 10:04:52 PM
Last scan (MalwareTips)
6/6/2026, 10:04:52 PM
Behavior tags
peexe64bits
Frequently asked

Safety FAQ

Common questions about Tracking.exe, answered from the scan data above.

  • Tracking.exe is suspicious — treat it as unsafe until you're sure. 1 of 79 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't run it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
  • Tracking.exe is a Windows executable program, about 11 MB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
  • 1 of 79 antivirus engines flagged Tracking.exe, 1 of them as outright malicious. A small number of detections can include false positives, so we weigh which engines flagged it and what else the file does, not just the raw count.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove Tracking.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original Tracking.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • The SHA-256 hash of Tracking.exe is b3b424ab934451178eb5343cb4a9131a848f71badca5d8a1b5579d5be8095e2a, and its MD5 is d468098873adb090ea6252b3aabd9456. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on June 6, 2026. Because a file's hash never changes, the identity of Tracking.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.