Malicious
WPD.exe matches three YARA rules for suspicious behavior including disabling Windows Defender, despite clean scans from 76 engines including all Tier-1.
c21e9de5b28de8edfb…eb5f0a09d7The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file WPD.exe is an unsigned 590KB Win32 executable first seen in 2021 with a negative reputation score of -7 from community flags. Our antivirus network of 76 engines, including 17 Tier-1 scanners like Avast, BitDefender, ESET-NOD32, and Kaspersky, all report it undetected with zero malicious hits. However, it matches three community YARA rules: one for registry keys that disable Windows Defender, plus two imphash indicators tied to malware. Network tags reveal anti-analysis tricks like detecting debug environments and checking network adapters, plus WMI calls and direct CPU access. These YARA hits override the clean scans, indicating hacktool behavior that could weaken your defenses if run. With the file's age and tags, it's likely offensive tooling—do not run it.
- Zero malicious detections across 76 engines, including all Tier-1 like BitDefender, Kaspersky, ESET-NOD32.
- 17 Tier-1 engines explicitly clean.
- Old file age of 1646 days since first seen in 2021, with consistent clean scans over time.
- Matches YARA rule INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefender, indicating attempts to turn off Windows Defender.
- Two additional YARA imphash matches linked to malware by independent researchers.
- Network tags show anti-analysis behavior like detect-debug-environment and direct-cpu-clock-access.
- Calls WMI and checks network adapters, common in tools that prepare for deeper infection.
- Negative reputation of -7 from community reports.
- Unsigned executable with PE imphash f34d5f2d4577ed6d9ceec516c1f5a744 shared by suspicious samples.
Quarantine or delete WPD.exe immediately. Run a full antivirus scan on your system and enable real-time protection if it was disabled.
INDICATOR SUSPICIOUS EXE RegKeyComb DisableWinDefender corroborated by 2 sources
- 3 YARA rulesINDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefender, pe_imphash, Skystars_Malware_Imphash
- MT AI EngineDefenderDisabler
1 corroborating signal from researcher-curated sources
- INDICATOR_SUSPICIOUS_EXE_RegKeyComb_DisableWinDefenderby ditekSHenDetects executables embedding registry key / value combination indicative of disabling Windows Defedner features
- pe_imphash
- Skystars_Malware_Imphashby Skystars LightDefenderimphash
0 detections across 76 engines
Forensic fingerprint
- File name
- WPD.exe
- Size
- 576.5 KB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- c21e9de5b28de8edfb6b2264b33846e842f7954ad70fa07b3c652feb5f0a09d7
- MD5
- 65325f636ac238568a21f389387f0299
- SHA-1
- acf8022648f3eab3b6da50e0f90301eefe64a3f7
- PE imphash
- f34d5f2d4577ed6d9ceec516c1f5a744
- First seen (VT)
- 10/17/2021, 5:24:41 PM
- Last analysis (VT)
- 4/20/2026, 2:10:47 AM
- First scan (MalwareTips)
- 4/20/2026, 3:33:08 PM
- Last scan (MalwareTips)
- 4/20/2026, 3:33:08 PM
- Community reputation
- -7flagged
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.