Unknown
Our AI analyst is temporarily unavailable.
c2d5d156ef4e5e09ed…4a292ac6c5The reasoning behind this verdict
The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.
Our AI analyst is temporarily unavailable. Based on the raw antivirus data we have (2 malicious of 71 reporting engines), we can't commit to a verdict confidently — re-scan in a few minutes for the full AI assessment.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
AI arbiter unavailable (reason: grok_exception:This operation was aborted)
engines.tier1Malicious=0
engines.reporting=71
Wait a few minutes and re-scan for the full AI assessment before deciding.
What to do now
There isn't enough information to give this file a clear rating.
Be cautious — an unknown rating is not the same as a clean bill of health.
Only run it if it came directly from the official maker of the software.
When in doubt, don't open it — or scan it again later once it's more widely seen.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 74.125.132.94
- a83f:8110:c85f:700:8875:700:c077:700
- 192.168.0.134
- a83f:8110:106:0:0:5:5000:0
- a83f:8110:0:0:cc00:0:0:0
- 23.40.197.184
- 20.62.24.77
- 23.216.147.76
- a83f:8110:ae01:0:d8ef:fcfe:ae01:0
- 20.99.132.105
- C:\Users\<USER>\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\file.exe.log
- C:\Users\user\AppData\Roaming
- C:\Users\<USER>\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.1460.32552359
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERFEA3.tmp.WERInternalMetadata.xml
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERFFAD.tmp.csv
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERFFEC.tmp.txt
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERAAA.tmp.WERInternalMetadata.xml
- CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
- CTF.TMD.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
Files this sample writes at runtime
This file drops 1 child at runtime. None are currently flagged malicious in our cache.
- 9d7a8c7c5f3278daf8fb…37a6b5Never scannednever seen before
YARA & heuristic rule matches
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
Evidence"C:\Users\<USER>\Desktop\file.exe"Sample contacted 18 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence74.125.132.94 · a83f:8110:c85f:700:8875:700:c077:700 · a83f:8110:106:0:0:5:5000:0
2 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- WindowTitleChanger.exe
- Size
- 13.0 KB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- c2d5d156ef4e5e09ed8811655df989d757b3e1ddd3c68d98ff66d24a292ac6c5
- MD5
- 42257edf7d67f3dc5fc4b98b3f274da9
- SHA-1
- 731997a449d530ab5208ebb048def355c9bb0eba
- PE imphash
- f34d5f2d4577ed6d9ceec516c1f5a744
- First seen (VT)
- 4/30/2013, 3:47:16 AM
- Last analysis (VT)
- 5/8/2026, 4:56:24 PM
- First scan (MalwareTips)
- 5/11/2026, 3:35:46 AM
- Last scan (MalwareTips)
- 5/11/2026, 3:35:46 AM
- Community reputation
- +39trusted
Safety FAQ
Common questions about WindowTitleChanger.exe, answered from the scan data above.
- We can't give WindowTitleChanger.exe a confident verdict yet — too few engines have an opinion on this exact file. Uncommon or brand-new files often show little coverage before vendors catch up, so treat it as untrusted: don't run it unless you're certain of the source.
- WindowTitleChanger.exe is a Windows executable program, about 13 KB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
- 2 of 75 antivirus engines flagged WindowTitleChanger.exe, 2 of them as outright malicious. A small number of detections can include false positives, so we weigh which engines flagged it and what else the file does, not just the raw count.
- The SHA-256 hash of WindowTitleChanger.exe is c2d5d156ef4e5e09ed8811655df989d757b3e1ddd3c68d98ff66d24a292ac6c5, and its MD5 is 42257edf7d67f3dc5fc4b98b3f274da9. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on May 11, 2026. Because a file's hash never changes, the identity of WindowTitleChanger.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.