File verdict·Decided by the MT AI Engine
Our call

Malicious

WPD.exe matches three YARA rules for suspicious behavior including disabling Windows Defender, despite clean scans from 76 engines including all Tier-1.

INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender
Trust score88High trust
MT AI confidence · 90%
WPD.exe
576.5 KB
c21e9de5b28de8edfbeb5f0a09d7
Antivirus engines
0 of 76 flagged
Code signing
Unsigned
Age
First seen 5y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

90%Confidence
Very high
Reasoning

The file WPD.exe is an unsigned 590KB Win32 executable first seen in 2021 with a negative reputation score of -7 from community flags. Our antivirus network of 76 engines, including 17 Tier-1 scanners like Avast, BitDefender, ESET-NOD32, and Kaspersky, all report it undetected with zero malicious hits. However, it matches three community YARA rules: one for registry keys that disable Windows Defender, plus two imphash indicators tied to malware. Network tags reveal anti-analysis tricks like detecting debug environments and checking network adapters, plus WMI calls and direct CPU access. These YARA hits override the clean scans, indicating hacktool behavior that could weaken your defenses if run. With the file's age and tags, it's likely offensive tooling—do not run it.

Points in its favour
  • Zero malicious detections across 76 engines, including all Tier-1 like BitDefender, Kaspersky, ESET-NOD32.
  • 17 Tier-1 engines explicitly clean.
  • Old file age of 1646 days since first seen in 2021, with consistent clean scans over time.
Points against
  • Matches YARA rule INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefender, indicating attempts to turn off Windows Defender.
  • Two additional YARA imphash matches linked to malware by independent researchers.
  • Network tags show anti-analysis behavior like detect-debug-environment and direct-cpu-clock-access.
  • Calls WMI and checks network adapters, common in tools that prepare for deeper infection.
  • Negative reputation of -7 from community reports.
  • Unsigned executable with PE imphash f34d5f2d4577ed6d9ceec516c1f5a744 shared by suspicious samples.
What to do

Quarantine or delete WPD.exe immediately. Run a full antivirus scan on your system and enable real-time protection if it was disabled.

Threat family attribution

INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender corroborated by 2 sources

  • 3 YARA rules
    INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefender, pe_imphash, Skystars_Malware_Imphash
  • MT AI Engine
    DefenderDisabler
External threat intelligence

1 corroborating signal from researcher-curated sources

YARAify HIT·3 community rules matchedView on YARAify
  • INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefenderby ditekSHen
    Detects executables embedding registry key / value combination indicative of disabling Windows Defedner features
  • pe_imphash
  • Skystars_Malware_Imphashby Skystars LightDefender
    imphash
Cross-referenced against MalwareBazaar (abuse.ch), YARAify, and the CIRCL hashlookup reference DB.
Antivirus engine breakdown

0 detections across 76 engines

0 malicious0 suspicious76 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust21 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 76 engines report this file as clean.
Hash c21e9de5b28d… cross-referenced against 76 AV engines via our AV network.
File identity

Forensic fingerprint

File biography
First seen (VT)
10/17/2021, 5:24:41 PM
First seen (MalwareBazaar)
Last analysis (VT)
4/20/2026, 2:10:47 AM
Scanned here
4/20/2026, 3:33:08 PM
File name
WPD.exe
Size
576.5 KB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
c21e9de5b28de8edfb6b2264b33846e842f7954ad70fa07b3c652feb5f0a09d7
MD5
65325f636ac238568a21f389387f0299
SHA-1
acf8022648f3eab3b6da50e0f90301eefe64a3f7
PE imphash
f34d5f2d4577ed6d9ceec516c1f5a744
First seen (VT)
10/17/2021, 5:24:41 PM
Last analysis (VT)
4/20/2026, 2:10:47 AM
First scan (MalwareTips)
4/20/2026, 3:33:08 PM
Last scan (MalwareTips)
4/20/2026, 3:33:08 PM
Community reputation
-7flagged
Behavior tags
assemblychecks-network-adaptersruntime-modulescalls-wmidirect-cpu-clock-accesspeexedetect-debug-environment
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Scanned by
harlan4096Staff
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.