Suspicious
Unsigned new executable with heuristic AV detections and direct IP connection (Cloudflare) triggers suspicion despite no tier-1 flags or offensive behavior.
fcb3b8e9782eef8a99…f105c38717The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file lacks code signing and has zero reputation as a brand-new submission, amplifying risks from its rare prevalence. Heuristic detections are present but confined to tier2/low-trust engines without tier1 backing or family consensus, suggesting possible overreach. The direct IP contact to a Cloudflare address fires a medium-severity C2 evasion rule, yet no further malicious runtime (e.g., sandbox verdicts, offensive MITRE) supports escalation. Overall, signals mix weakly toward threat without decisive proof.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
Gridinsoft (tier2): Trojan.Heur!.0205202F
triggeredHeuristics[0]: MalwareTips.Synth.DirectIpC2 fired on 162.159.36.2
engines.tier1Malicious=0 / tier1ReportedClean=17
prevalence.classification: rare_new
signing.signed=false
- No tier-1 malicious detections (17 clean)
- No offensive MITRE techniques
- No malicious sandbox verdict
- No contacted malicious hosts
- Direct IP C2 heuristic (MalwareTips.Synth.DirectIpC2)
- Unsigned executable
- Zero-day age (firstSubmissionDate 2026-05-15)
- Rare new prevalence (2 submissions)
- Heuristic Trojan detection (Gridinsoft)
- Overlay and checks-user-input tags
Quarantine the file immediately and avoid execution. Monitor for related activity and resubmit after more scans for confirmation.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2
2 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Barely seen in the wild and first surfaced recently. This is the footprint of targeted malware the AV industry hasn't signatured yet — extra scrutiny is warranted.
Forensic fingerprint
- File name
- citron.exe
- Size
- 61.85 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- fcb3b8e9782eef8a992e989becfdebf879de7c0c1996e8e2c2d9b1f105c38717
- MD5
- f32908fe21e824071c126f03bc079bc9
- SHA-1
- 0799f37a02589d070e752ec9444748a660a9bcd1
- PE imphash
- 88523bdfa23813abc1972f29e1d967d7
- First seen (VT)
- 5/15/2026, 11:28:07 AM
- Last analysis (VT)
- 5/15/2026, 11:28:07 AM
- First scan (MalwareTips)
- 5/15/2026, 3:28:44 PM
- Last scan (MalwareTips)
- 5/15/2026, 3:28:44 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.