File verdict·Decided by the MT AI Engine
Our call

Safe

17 tier-1 engines report clean; zero malicious detections across 71 engines; old installer-like utility with benign file-drop pattern.

Trust score82Moderate trust
MT AI confidence · 78%
ckrn_108.exe
601.5 KB
f2466c19e3d0d5cacd065e9839af
Antivirus engines
0 of 75 flagged
Code signing
Unsigned
Age
First seen 18y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

78%Confidence
High
Reasoning

The evidence strongly supports a benign classification. Seventeen tier-1 antivirus engines—including industry leaders BitDefender, Kaspersky, ESET-NOD32, Fortinet, and Avast—all report the file as undetected. Zero of 71 reporting engines flagged it as malicious or suspicious. The file's age (first submitted in 2008) and medium prevalence (65 unique submitters) indicate it is a known-benign or legacy utility. Behavioural analysis shows zero offensive MITRE techniques and installer-consistent file drops (CKRename.exe, uninstal.exe). A single heuristic rule (MalwareTips.Synth.DirectIpC2) fired on direct-IP contact, but this is isolated evidence without malware family naming, tier-1 consensus, or malicious sandbox verdict. The filename pattern and file-drop behaviour are consistent with a legitimate rename utility installer, not malware.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. tier1Malicious=0; tier1ReportedClean=17 (Avast, BitDefender, Kaspersky, ESET-NOD32, Fortinet, GData, Ikarus, F-Secure, Emsisoft, DrWeb, Avira, AVG, and others all undetected)

  2. engines.malicious=0/71; no malware family consensus; no tier-1 agreement on any threat

  3. behaviour: 0 offensive MITRE techniques; 9 ambient techniques consistent with installer; no malicious sandbox verdict; droppedChildren.hasMaliciousChild=false

  4. triggeredHeuristics: MalwareTips.Synth.DirectIpC2 fired (medium severity) on single IPv6 contact, but isolated against clean consensus — insufficient to override

  5. prevalence.classification=medium (65 submitters, 76 submissions since 2008); file age 6506 days; filename pattern consistent with CKRename utility installer

Points in its favour
  • 17 tier-1 antivirus engines (Avast, BitDefender, Kaspersky, ESET-NOD32, Fortinet, GData, Ikarus, F-Secure, Emsisoft, DrWeb, Avira, AVG, and others) all report undetected
  • Zero malicious detections across 71 reporting engines
  • File age 6,506 days (first submitted 2008) with medium prevalence (65 unique submitters, 76 submissions)
  • Zero offensive MITRE techniques; 9 ambient techniques consistent with installer software
  • File-drop pattern (CKRename.exe, uninstal.exe, uninstal.log) consistent with legitimate rename utility installer
Points against
  • MalwareTips.Synth.DirectIpC2 heuristic fired on direct-IP contact (IPv6 a83f:8110:6700:7500:6c00:6100:7400:6f00) with zero domain contact
  • Joe Sandbox community analysis reported borderline-suspicious verdict (score 22/100)
  • Unsigned executable with no publisher verification
What to do

This file is classified as benign based on consensus from 17 tier-1 antivirus engines and 18 years of prevalence data. No action is required. If you have specific concerns about the DirectIpC2 heuristic or wish to verify the file's legitimacy, consult the official CKRename utility publisher or your security team.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
9

Adversary techniques mapped to the MITRE ATT&CK framework.

T1010T1027.002T1036T1071T1082T1083T1129T1564.003T1574
Spawned processes
2
$(unnamed)
"C:\Users\<USER>\Desktop\software.exe"
$(unnamed)
%SAMPLEPATH%\f2466c19e3d0d5cacd26f034dfd36561c39297d19a2936ac31a828065e9839af.exe
Network activity
1
IP addresses1
  • a83f:8110:6700:7500:6c00:6100:7400:6f00
Filesystem & mutexes
24
Files written13
  • C:\Users\<USER>\AppData\Local\Temp\instcrin.dll
  • C:\Program Files (x86)\CKRename\uninstal.log
  • C:\Program Files (x86)\CKRename\Uninstal.exe
  • C:\Documents and Settings\Administrator\Local Settings\Temp\instcrin.dll
  • C:\Program Files\CKRename\uninstal.log
+8 more
Files deleted3
  • C:\Users\<USER>\AppData\Local\Temp\instcrin.dll
  • C:\Documents and Settings\Administrator\Local Settings\Temp\instcrin.dll
  • C:\Users\user\AppData\Local\Temp\instcrin.dll
Mutexes created8
  • CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
  • CTF.Compart.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
  • CTF.Asm.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
  • CTF.Layouts.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
  • CTF.TMD.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
+3 more
Dropped payload

Files this sample writes at runtime

This file drops 5 children at runtime. None are currently flagged malicious in our cache.

5 unseen
  • 4d82c0a5ca87ad225fa8e2c191Never scanned
    never seen before
  • cf87c2a055733ba6021564a7bbNever scanned
    never seen before
  • 216d8c03fc834a2703a94c8d25Never scanned
    never seen before
  • cfd0d3cd954fab163d26d936f4Never scanned
    never seen before
  • abb20c12b8cad6f55883e6bb08Never scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.

1 synthesis
MITRE ATT&CK profile
C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • DirectIpC2medium

    Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    a83f:8110:6700:7500:6c00:6100:7400:6f00
Antivirus engine breakdown

0 detections across 75 engines

0 malicious0 suspicious75 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 75 engines report this file as clean.
Hash f2466c19e3d0… cross-referenced against 75 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 7.98Unpacked
Section entropy7 sections
.text
5.51
.rdata
0.09
.data
2.19
.idata
4.14
.Shared
0.07
.rsrc
3.18
.reloc
3.14
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
65
Moderate upload volume.
Total submissions
76
Includes repeat uploads by the same source.
First seen by VT
18y ago
Sep 5, 2008
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
9/5/2008, 5:01:46 AM
First seen (MalwareBazaar)
Last analysis (VT)
6/26/2026, 1:19:41 PM
Scanned here
6/28/2026, 5:54:07 PM
File name
ckrn_108.exe
Size
601.5 KB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
f2466c19e3d0d5cacd26f034dfd36561c39297d19a2936ac31a828065e9839af
MD5
8ff088fa78f39a41315179be3002545d
SHA-1
50c4ecbf3731ea9f96b6d7be2738e7fc97b58bd1
PE imphash
547c94826e733fab0c2f59262339e0b1
First seen (VT)
9/5/2008, 5:01:46 AM
Last analysis (VT)
6/26/2026, 1:19:41 PM
First scan (MalwareTips)
6/28/2026, 5:54:07 PM
Last scan (MalwareTips)
6/28/2026, 5:54:07 PM
Community reputation
-2flagged
Behavior tags
direct-cpu-clock-accessoverlaycreateinstallpeexeruntime-modules
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.