Is mm.exe safe?
Only 2 of 74 engines flagged this old, prevalent executable, but packing, absent signing, process-injection evidence, and unchecked IP contacts warrant caution.
Most antivirus engines, including all 17 reporting tier-1 engines, did not flag the file, and no named malware family is corroborated. However, the unsigned packed executable showed possible process injection and direct-IP traffic, so it should not be run on a production system without publisher verification.
ca55c9ae1dbee55efd…71f97444d2ed5eRecommended next actions
Before running
Do not run it until the source and publisher can be verified independently.
If you already ran it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the developer's official site or an official app store.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Most antivirus engines, including all 17 reporting tier-1 engines, did not flag the file, and no named malware family is corroborated. However, the unsigned packed executable showed possible process injection and direct-IP traffic, so it should not be run on a production system without publisher verification.
Two of 74 engines produced generic detections, while all 17 reporting tier-1 engines remained silent and no family consensus exists. The sample has circulated since 2020 across 456 sources, and researcher-curated intelligence produced no matching malware rules or known-family record. Countering those reassuring indicators, the executable is unsigned, likely packed, and one sandbox mapped its activity to T1055 process injection. It also contacted multiple IP addresses directly, but no complete host-reputation result is available because that cross-check was not saved. The dropped files were not identified as malicious, although both remain unclassified, leaving enough uncertainty to require isolation and further verification.
What We Detected
Two of 74 antivirus engines flagged the executable: Cylance used a generic unsafe label and Kingsoft used a generic malware label. None of the 17 reporting tier-1 engines detected it, no malware family consensus formed, and curated intelligence returned no known-family or matching-rule hit.
Threat Behavior
One completed sandbox mapped activity to MITRE T1055, indicating possible process injection. The unsigned executable is likely packed and contacted several IP addresses without recorded application domains. Because the contacted-host reputation check was not completed or saved, those connections cannot be characterized as benign or malicious. Two dropped files were inspected but remain unclassified rather than confirmed clean.
What To Do Now
Keep endpoint protection enabled and do not run the file on a production computer. Verify its origin and expected publisher, then test it only in an isolated environment or submit it for deeper manual analysis if it is operationally necessary.
Where this verdict could be wrong3 caveats
- Cylance labeled the sample "Unsafe" and Kingsoft reported "malware.kb.a.891," although neither supplies a corroborated family and no tier-1 engine flagged it.
- Runtime evidence maps activity to T1055 and records direct-IP connections, but behaviour.hasMaliciousSandboxVerdict=false and the host-reputation cross-check was not saved.
- The executable is unsigned and likely packed, which can conceal code even though the sample is old and widely submitted.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 2 of 74 engines detected the sample
- All 17 reporting tier-1 engines were undetected
- No tier-1 malware-family consensus
- Observed since 2020 across 456 unique sources
- No MalwareBazaar, CIRCL, or YARAify corroboration
- Unsigned Win32 executable with no established signer history
- Likely packed code with high-entropy .text section
- Sandbox evidence mapped to MITRE T1055 process injection
- Direct-IP network activity without complete host-reputation coverage
- Two dropped files remain unclassified
Quarantine the file pending source and publisher verification, and keep endpoint protection enabled. If it must be evaluated, use an isolated sandbox and investigate the observed IP contacts and dropped-file hashes.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete2 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial20 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete3 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 13MITRE ATT&CK techniques
- 6spawned processes
- 20network contacts
- 22filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Used an input-capture technique that can record credentials or keystrokes.
High concern: Used removable-media replication behaviour that can spread files between devices.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Checked the environment for virtualisation or analysis tools.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
mm.exe
ca55c9ae1dbee55efd2733b28824a4ee08999979881e8fe0fc71f97444d2ed5e
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\program.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
%SAMPLEPATH%\ca55c9ae1dbee55efd2733b28824a4ee08999979881e8fe0fc71f97444d2ed5e.exe
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
system32CmdLineExt.dll
C:\WINDOWS\system32CmdLineExt.dll
04Isolated runtime analysis - Written fileObserved
d3d9caps.dat
C:\WINDOWS\system32\d3d9caps.dat
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
a83f:8110:0:40:d01:1b0:7818:100
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
192.168.0.32
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- a83f:8110:0:40:d01:1b0:7818:100
- 192.168.0.32
- 209.197.3.8
- 20.99.133.109
- 192.168.0.77
- 23.216.81.152
- 192.168.0.42
- a83f:8110:0:0:678c:21:0:0
- a83f:8110:400:0:e902:0:1100:0
- 192.168.0.14
- C:\WINDOWS\system32CmdLineExt.dll
- C:\WINDOWS\system32\d3d9caps.dat
- C:\WINDOWS\system32\d3d9caps.tmp
- C:\DOCUME~1\<USER>~1\LOCALS~1\Temp\drm_dialogs.dll
- C:\Windows\system32CmdLineExt.dll
- C:\Windows\System32\spp\store\2.0\cache\cache.dat
- C:\Windows\System32\wbem\Performance\WmiApRpl.h
- C:\Windows\System32\wbem\Performance\WmiApRpl.ini
- C:\WINDOWS\system32\d3d9caps.dat
- C:\WINDOWS\system32\d3d9caps.tmp
- CMS32_MUTEX
- DDrawWindowListMutex
- __DDrawExclMode__
- __DDrawCheckExclMode__
- CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
Files this sample writes at runtime
This file drops 2 children at runtime. None are currently flagged malicious in our cache.
- 90cd3aa951d71cf8d479…7412c8Never scannednever seen before
- 168d9b0118438e96cf21…25cda2Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 3rule hits recorded
- 2 / 74engines flagged
- 456sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
2 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
2 of 74 antivirus engines flagged the file, including Cylance and Kingsoft.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has a long, established submission history across 456 sources.
ProvenanceDerivedSourceSubmission historyObserved at - 04
Scanned file: mm.exe — ca55c9ae1dbee55efd2733b28824a4ee08999979881e8fe0fc71f97444d2ed5e
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\program.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — %SAMPLEPATH%\ca55c9ae1dbee55efd2733b28824a4ee08999979881e8fe0fc71f97444d2ed5e.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: system32CmdLineExt.dll — C:\WINDOWS\system32CmdLineExt.dll
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: d3d9caps.dat — C:\WINDOWS\system32\d3d9caps.dat
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: a83f:8110:0:40:d01:1b0:7818:100 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 192.168.0.32 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Users\<USER>\AppData\Local\Temp\program.exe"The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidencea83f:8110:0:40:d01:1b0:7818:100 · 209.197.3.8 · 20.99.133.109Unsigned, packed PE with sandbox-observed network activity. The packing step hides the payload until execution; the network call fetches / reports for the next stage. Classic dropper / stager behaviour.
Evidencea83f:8110:0:40:d01:1b0:7818:100
2 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
Executable sections have high entropy (7.2+) — the code is compressed or encrypted and only decrypted at runtime. Classic packing behaviour.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- mm.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 3.6 MB
- Last analyzed
- Sep 20, 2026, 5:16 PM UTC
ca55c9ae1dbee55efd2733b28824a4ee08999979881e8fe0fc71f97444d2ed5eSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't run it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Get a fresh copy from the developer's official site or an official app store.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is mm.exe safe, or is it malware?
What is mm.exe?
How many antivirus engines detected mm.exe?
I already downloaded and ran mm.exe — what should I do?
How do I remove mm.exe?
What is the SHA-256 hash of mm.exe?
How up to date is this analysis of mm.exe?
Community
Member reviews and reports for this exact file hash.