Is backgroundTaskHost.exe safe?
The verified Microsoft signature, zero detections across 75 engines, broad prevalence, and consistent signer history strongly outweigh the sandbox’s unconfirmed behavioral heuristics.
No antivirus engine flagged this verified Microsoft-signed executable, including all 17 tier-1 engines. Although one sandbox mapped activity to process injection and noted LSASS in its process context, it produced no malicious runtime verdict, and the broader evidence strongly supports an authentic Windows component.
b7d2c17e0038945aa4…b7b67de43c2530Recommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
No antivirus engine flagged this verified Microsoft-signed executable, including all 17 tier-1 engines. Although one sandbox mapped activity to process injection and noted LSASS in its process context, it produced no malicious runtime verdict, and the broader evidence strongly supports an authentic Windows component.
The sample has a valid signature from Microsoft Windows, and the publisher matches the curated Microsoft identity. None of 75 antivirus engines detected it, with all 17 tier-1 engines reporting no detection. It is also broadly established, having appeared in 6,140 submissions from 3,192 sources, while four signer-matched historical samples received clean assessments. One completed sandbox run produced no malicious verdict, although its T1055 mapping and LSASS-related heuristic warrant acknowledgment. Those heuristic findings do not establish process injection or credential access and are outweighed by the signature, prevalence, engine results, and signer history. The network reputation check covered only part of the observed contacts, so it is not used as comprehensive exonerating evidence.
What We Detected
The file is a verified executable signed by Microsoft Windows, with a trusted-publisher match for Microsoft. None of 75 antivirus engines flagged it, and all 17 tier-1 engines reported no detection. The sample is well established, with 6,140 submissions from 3,192 sources, and four recent signer-matched files also received clean assessments.
Threat Behavior
One completed sandbox run returned no malicious verdict. It mapped activity to T1055 and generated a credential-dumping heuristic because lsass.exe appeared in the process context, but the saved evidence does not prove memory access, credential extraction, or a specific injection method. No malicious child was recorded, and the executable does not appear packed or unusually high-entropy. Host-reputation coverage was incomplete because only three observed hosts were inspected, so no comprehensive network conclusion is drawn.
What To Do Now
The file is consistent with an authentic Windows component when located in its expected Windows system path. Keep endpoint protection enabled and verify the signature and location before restoring or running any copy obtained from an unusual source.
Where this verdict could be wrong2 caveats
- behaviour.offensiveTechniques includes T1055, and MalwareTips.Synth.CredentialDumper references interaction involving lsass.exe; the recorded process list alone does not establish memory access or credential theft.
- contactedHosts.inspected=3 covers only part of the domains and IPs listed by behaviour, so the host-reputation check is incomplete.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 antivirus engines detected the file.
- Verified signature from Microsoft Windows with signing.trustedPublisher.matched=true.
- All 17 tier-1 engines reported no detection.
- Established prevalence: 3,192 sources and 6,140 submissions.
- Four of four signer-matched historical samples received clean assessments.
- Sandbox evidence mapped activity to MITRE T1055.
- A heuristic associated process context involving lsass.exe with possible credential-dumping behavior.
- Host-reputation inspection did not cover every observed domain and IP.
Allow the file only when its Microsoft signature remains valid and it resides in the expected Windows system location. Keep endpoint protection enabled and quarantine copies found in unusual directories or obtained from untrusted downloads.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial3 of 23 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 7MITRE ATT&CK techniques
- 15spawned processes
- 23network contacts
- 4filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- www.microsoft.com
- res.public.onecdn.static.microsoft
- bg.microsoft.map.fastly.net
- 192.168.0.9
- 23.216.81.152
- 192.168.0.35
- 20.99.133.109
- a83f:8110:bf18:9536:bb2a:494e:a412:84d6
- 192.168.0.21
- 23.213.37.172
- 151.101.22.172
- 192.168.0.6
- 20.99.186.246
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications\Data\418A073AA3BC1C75
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
- C:\Windows\System32\wbem\Performance\WmiApRpl.h
- C:\Windows\System32\wbem\Performance\WmiApRpl.ini
- %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCache\IE\KLT1I0ZU\update50[1].xml
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 0 / 75engines flagged
- 3,192sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 3,192 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The file has a valid code signature from Microsoft Windows.
ProvenanceObservedSourceCode-signing metadataObserved at - 04
Scanned file: backgroundTaskHost.exe — b7d2c17e0038945aa4b72ae7a89e54d29b04ccc0feb62df5c9b7b67de43c2530
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\software.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\services.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Download-1.tmp — C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: www.microsoft.com — Saved reputation verdict: safe.
ProvenanceDerivedSourceContacted-host cross-checkObserved at - 09
Contacted host: res.public.onecdn.static.microsoft — Saved reputation verdict: safe.
ProvenanceDerivedSourceContacted-host cross-checkObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
0 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- backgroundTaskHost.exe
- Format
- Win32 EXE
- Code signing
- Signature valid: Microsoft Windows
- Size
- 49.3 KB
- Last analyzed
- Oct 4, 2026, 5:04 PM UTC
b7d2c17e0038945aa4b72ae7a89e54d29b04ccc0feb62df5c9b7b67de43c2530Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is backgroundTaskHost.exe safe?
What is backgroundTaskHost.exe?
How many antivirus engines detected backgroundTaskHost.exe?
Is backgroundTaskHost.exe digitally signed?
What is the SHA-256 hash of backgroundTaskHost.exe?
Is it safe to run backgroundTaskHost.exe?
How up to date is this analysis of backgroundTaskHost.exe?
Community
Member reviews and reports for this exact file hash.