Safe
Legitimate Piriform (CCleaner) self-extracting installer signed by trusted Gen Digital, with one low-trust generic detection and clean runtime behavior.
f865d2879b89045995…116115dd16The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file matches the signed commercial FP shape: verified signature from curated trusted publisher Gen Digital, minimal low-trust detections only, no tier-1 consensus, clean sandbox behavior, and no malicious children or hosts. Behavior aligns with installer activity, dropping icarus.exe and contacting Piriform/Avast CDNs for definitions. The direct-IP heuristic is outweighed by signer trust and URL evidence. Medium prevalence and tags like long-sleeps are consistent with legitimate software.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
Webroot (low_trust): Win.Trojan.Gen (1/72 malicious)
signing.trustedPublisher.matched=true ('Gen Digital')
behaviour.contactedUrls: 'honzik.avcdn.net/defs/piriform-ccl/release.xml.lzma'
signer='Gen Digital Inc.', verified=true, signerStats.safeRate=1
tier1FamilyConsensus.family=null, tier1Malicious=0
- Trusted publisher 'Gen Digital' match
- 17/17 tier-1 engines clean
- Piriform/Avast CDN contacts for legit defs
- No malicious sandbox or children
- 0 offensive MITRE techniques
- Single generic low-trust detection (Webroot)
- Direct IP contacts triggered heuristic (likely CDN resolution)
- Low signerStats samples (1 total)
This is a safe, legitimate installer from Piriform (CCleaner ecosystem). Run if needed for updates; otherwise, remove unnecessary executables.
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 34.117.223.223
- 23.221.220.52
- 34.160.176.28
- 23.221.220.70
- 8.8.8.8
- 23.53.11.141
- 208.89.75.147
- https://analytics.avcdn.net/v4/receive/json/25
- https://shepherd.avcdn.net/?p_age=0&p_bld=mmm_ccl_008_999_a10d_m&p_cpua=x64&p_icar=1&p_lng=en&p_midex=97B7721C4994E2556FF6A439510F665DC7076870BB538998334766988BDCE31D&p_olpeid=8cd9b1b1-452b-4a39-a058-2f0cc5ec240f&p_olpfp=FEC260E6F89774EF08792D2989D90C3B&p_ost=0&p_osv=10.0.19044&p_pro=111&p_prod=piriform-ccl&p_ram=16384&p_vbd=1275&p_vep=7&p_ves=6&p_vre=1607&repoid=release&
- analytics.avcdn.net/v4/receive/json/25
- honzik.avcdn.net/defs/piriform-ccl/release.xml.lzma
- honzik.avcdn.net/universe/094a/e716/bca9/094ae716bca95e01163dbd03b5f2877a646407a9c54c2e837a846e02174125e4.lzma
- honzik.avcdn.net/universe/0956/3e04/2918/09563e042918eb1c15647bb0ce66e952ade793781c054913d29c99fb61850334.lzma
- C:\ProgramData\Piriform\Icarus\Logs\sfx.log
- C:\ProgramData\Piriform\Icarus\Logs\sfx.log.tmp.4c87b095-2f54-41ae-b0d8-0f4cd90c108a
- C:\Users\<USER>\AppData\Local\Temp
- C:\Users\<USER>\AppData\Local\Temp\D566D7D7-DCD6-471C-8109-BE0AD33199E3
- C:\Users\<USER>\AppData\Local\Temp\6358C710-B89F-46B9-93F2-F6CAC44F5286
- C:\Users\<USER>\AppData\Local\Temp\CabAD0A.tmp
- C:\Users\<USER>\AppData\Local\Temp\TarAD0B.tmp
- Global\25f80c65fc4bf9f6eea20cdbc70dd4c2
- Global\348cf4229b5ea7fd858d4f580214c358
- Global\5c96c7b59b25aa8f1517387dceb71552
- Global\d28218099b482e81f10c092677dd3fe0
- Global\b989482194eb59dc47bab6088a305e8c
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 097709779bf6e7a3f93b…c44493Never scannednever seen before
- cacace6d2783540ddfae…0e6b6cNever scannednever seen before
- 8e511706c04e382e5815…2878b9Never scannednever seen before
- 094ae716bca95e01163d…4125e4Never scannednever seen before
- db86ebb3202f4e17bc89…586663Never scannednever seen before
- 09563e042918eb1c1564…850334Never scannednever seen before
- b639c62327c23f24310f…ed920cNever scannednever seen before
- dee6d211d1ee1a674ac9…aadcdcNever scannednever seen before
- 4d6acde9a68b34b03e63…f026bbNever scannednever seen before
- e722c3feca975ca8bd0b…93b41bNever scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 7 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence34.117.223.223 · 23.221.220.52 · 34.160.176.28Signed by "Gen Digital Inc." — short generic company CN. Paired with 1 engine hit(s); possible stolen, fraudulent, or reseller-purchased code-signing certificate.
EvidenceGen Digital Inc.
1 detection across 76 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- icarus_sfx.exe
- Size
- 1.67 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- f865d2879b890459952a1e6dd1d881e89d84325b3bf8035ba63ae3116115dd16
- MD5
- a89c041f764df30a9de18e012075bea6
- SHA-1
- 6516a34a0440a2cd112d1783009d77decca8e7ba
- PE imphash
- 4484535c3f28dccc63a294b328b4d09a
- First seen (VT)
- 4/2/2026, 9:29:53 PM
- Last analysis (VT)
- 4/22/2026, 9:40:27 AM
- First scan (MalwareTips)
- 4/22/2026, 5:58:32 AM
- Last scan (MalwareTips)
- 4/24/2026, 1:16:50 AM
- Code signer
- Gen Digital Inc.verified
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.