File verdict·Decided by the MT AI Engine
Our call

Suspicious

Unsigned launcher with direct-IP contact and low-trust detection; benign widget-related file writes suggest possible false positive.

Trust score52Caution
MT AI confidence · 58%
Launcher.exe
50.5 KB
cfae4f94b83db7c50bb6e0c79c33
Antivirus engines
1 of 75 flagged
Code signing
Unsigned
Age
First seen 3mo ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

58%Confidence
Moderate
Reasoning

The evidence presents a mixed picture. On one hand, the direct-IP contact without domain resolution is a known evasion technique used by malware to bypass reputation systems. On the other hand, the single malicious detection comes from a low-trust engine with a generic label, while 17 tier-1 engines remain silent. The file's behaviour — writing to Windows widget feed directories and invoking WidgetService.exe — aligns with legitimate Windows system components. The absence of offensive MITRE techniques, malicious sandbox verdicts, dropped children, or external-intelligence hits further suggests this may be a benign utility or system tool flagged by heuristic false positives. The unsigned status and lack of signer history prevent publisher-based trust anchoring, but do not confirm malice.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines: 1/71 malicious (Bkav, low-trust tier); tier1Malicious=0; onlyLowTrustFlagging=true

  2. signing.verified=false, unsigned, no signer history

  3. triggeredHeuristics: MalwareTips.Synth.DirectIpC2 (medium) — contacted 162.159.36.2 with zero domains

  4. behaviour: 0 offensive MITRE techniques, 6 ambient (T1036, T1070, T1071, T1129, T1614); file writes to Windows widget feed paths

  5. prevalence=medium; no external-intel hits; no malicious sandbox verdict; no dropped children

Points in its favour
  • 17 tier-1 antivirus engines reported clean
  • 0 offensive MITRE techniques detected
  • File writes align with legitimate Windows widget feed functionality
  • No malicious sandbox verdict, no dropped children, no external-intelligence hits
Points against
  • Direct IP contact without DNS resolution (162.159.36.2) — potential C2 evasion
  • Unsigned executable with no publisher history
  • Generic malware label from low-trust engine (Bkav) — no family consensus
What to do

Exercise caution with this file due to the direct-IP contact pattern. If you recognize it as a legitimate utility, it is likely safe; if not, isolate it and verify its source before execution. Monitor network activity if you choose to run it.

Sources disagree

1 contradiction resolved by the scoring engine

Only low-trust / heuristic engines flagged this file
1 engine from the heuristic / generic-AI set flagged it. No tier-1 engine agreed.
Detection weight reduced in scoring.
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
6

Adversary techniques mapped to the MITRE ATT&CK framework.

T1036T1070T1070.006T1071T1129T1614
Spawned processes
3
$(unnamed)
"C:\Users\<USER>\Desktop\Launcher.exe"
$(unnamed)
"C:\Users\user\Desktop\Launcher.exe"
$(unnamed)
"C:\Program Files\WindowsApps\Microsoft.WidgetsPlatformRuntime_1.6.2.0_x64__8wekyb3d8bbwe\WidgetService\WidgetService.exe" -RegisterProcessAsComServer -Embedding
Network activity
1
IP addresses1
  • 162.159.36.2
Filesystem & mutexes
9
Files written5
  • C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed
  • C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat
  • C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat.~tmp
  • C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat~RF3ce3e4.TMP
  • C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat~RF3ce720.TMP
Files deleted4
  • C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed
  • C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat
  • C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat~RF3ce3e4.TMP
  • C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat~RF3ce720.TMP
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.

1 synthesis
MITRE ATT&CK profile
C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • DirectIpC2medium

    Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    162.159.36.2
Antivirus engine breakdown

1 detection across 75 engines

1 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
1flag
Heuristic / generic-AI engines (high FP rate)
Bkav
malicious
W32.Malware.34D540C8
Hash cfae4f94b83d… cross-referenced against 75 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

Unpacked
Section entropy5 sections
.text
6.37
.rdata
4.40
.data
4.01
.rsrc
6.46
.reloc
5.78
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
5
Moderate upload volume.
Total submissions
5
Includes repeat uploads by the same source.
First seen by VT
3mo ago
Mar 14, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
3/14/2026, 9:58:51 PM
First seen (MalwareBazaar)
Last analysis (VT)
5/27/2026, 9:29:19 AM
Scanned here
6/13/2026, 11:24:34 AM
File name
Launcher.exe
Size
50.5 KB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
cfae4f94b83db7c50b20914692e30586b43a650bdafabaf957e01cb6e0c79c33
MD5
581916a5a6aaf99bca315b78088a3b96
SHA-1
446e25031712b706f7257564f60958b152660f07
PE imphash
bbd0e91d0b2ac32a74852d828a0cee5a
First seen (VT)
3/14/2026, 9:58:51 PM
Last analysis (VT)
5/27/2026, 9:29:19 AM
First scan (MalwareTips)
6/13/2026, 11:24:34 AM
Last scan (MalwareTips)
6/13/2026, 11:24:34 AM
Behavior tags
peexe
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.