Suspicious
Unsigned launcher with direct-IP contact and low-trust detection; benign widget-related file writes suggest possible false positive.
cfae4f94b83db7c50b…b6e0c79c33The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The evidence presents a mixed picture. On one hand, the direct-IP contact without domain resolution is a known evasion technique used by malware to bypass reputation systems. On the other hand, the single malicious detection comes from a low-trust engine with a generic label, while 17 tier-1 engines remain silent. The file's behaviour — writing to Windows widget feed directories and invoking WidgetService.exe — aligns with legitimate Windows system components. The absence of offensive MITRE techniques, malicious sandbox verdicts, dropped children, or external-intelligence hits further suggests this may be a benign utility or system tool flagged by heuristic false positives. The unsigned status and lack of signer history prevent publisher-based trust anchoring, but do not confirm malice.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 1/71 malicious (Bkav, low-trust tier); tier1Malicious=0; onlyLowTrustFlagging=true
signing.verified=false, unsigned, no signer history
triggeredHeuristics: MalwareTips.Synth.DirectIpC2 (medium) — contacted 162.159.36.2 with zero domains
behaviour: 0 offensive MITRE techniques, 6 ambient (T1036, T1070, T1071, T1129, T1614); file writes to Windows widget feed paths
prevalence=medium; no external-intel hits; no malicious sandbox verdict; no dropped children
- 17 tier-1 antivirus engines reported clean
- 0 offensive MITRE techniques detected
- File writes align with legitimate Windows widget feed functionality
- No malicious sandbox verdict, no dropped children, no external-intelligence hits
- Direct IP contact without DNS resolution (162.159.36.2) — potential C2 evasion
- Unsigned executable with no publisher history
- Generic malware label from low-trust engine (Bkav) — no family consensus
Exercise caution with this file due to the direct-IP contact pattern. If you recognize it as a legitimate utility, it is likely safe; if not, isolate it and verify its source before execution. Monitor network activity if you choose to run it.
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat.~tmp
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat~RF3ce3e4.TMP
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat~RF3ce720.TMP
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat~RF3ce3e4.TMP
- C:\Users\user\AppData\Local\Packages\Microsoft.WidgetsPlatformRuntime_8wekyb3d8bbwe\LocalState\FeedSessions\MicrosoftWindows.Client.WebExperience_cw5n1h2txyewy!Widgets!!com.msn.desktopfeed\a0a175a8-ffcb-4b46-919d-b3107ac1c378.dat~RF3ce720.TMP
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2
1 detection across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- Launcher.exe
- Size
- 50.5 KB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- cfae4f94b83db7c50b20914692e30586b43a650bdafabaf957e01cb6e0c79c33
- MD5
- 581916a5a6aaf99bca315b78088a3b96
- SHA-1
- 446e25031712b706f7257564f60958b152660f07
- PE imphash
- bbd0e91d0b2ac32a74852d828a0cee5a
- First seen (VT)
- 3/14/2026, 9:58:51 PM
- Last analysis (VT)
- 5/27/2026, 9:29:19 AM
- First scan (MalwareTips)
- 6/13/2026, 11:24:34 AM
- Last scan (MalwareTips)
- 6/13/2026, 11:24:34 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.