Malicious
GData tier-1 detection of PSEB family, corroborated by RAG consensus, process injection, direct-IP C2, and YARA hits.
16c82723b441f048a7…ab90b343daThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The sample shows convergent malicious signals: GData tier-1 engine names PSEB family; RAG shows 2/3 prior imphash-matched samples verdicted malicious with the same family; behaviour analysis flags T1055 process injection and direct-IP C2 (15 IPs, no DNS) as high-severity indicators; yaraify matched 3 community YARA rules; contacted hosts include fitgirl-repacks.site (suspicious, warez distribution); reputation is negative; file is unsigned with no signer history. While only one tier-1 engine flagged it, the structural match (imphash), family consensus across RAG, and offensive behaviour patterns (injection + C2) establish malware classification.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
GData (tier-1) flags 'Generic.Trojan.PSEB.X0G340' — named PSEB family
similarHashes: 2/3 prior imphash-matched verdicts 'malicious' with reason='ai:tier1_consensus_pseb'
triggeredHeuristics: T1055 Process Injection (high severity) + direct-IP C2 to 15 external IPs, zero domains
yaraify: 3 community YARA rules matched (Borland, pe_detect_tls_callbacks, shellcode)
contactedHosts: 'fitgirl-repacks.site' (suspicious, score=40) — known warez distribution; reputation=-9; unsigned, no signer history
- No malicious dropped children (10 inspected, 0 malicious)
- No malicious sandbox verdict recorded (though process chain is suspicious)
- Process injection (T1055) to bypass security hooks
- Direct-IP C2 communication (15 external IPs, no DNS)
- Contact with known warez distribution site (fitgirl-repacks.site)
- Unsigned executable with negative reputation
- PSEB malware family identified by tier-1 engine
- Community YARA rules converged on malicious patterns
Block and quarantine this file immediately. The convergence of tier-1 detection, RAG consensus, process injection, C2 communication, and warez-site contact establishes malware classification. Do not execute or allow execution on any system.
crack corroborated by 3 sources
- 3 YARA rulesBorland, pe_detect_tls_callbacks, shellcode
- VT (74 engines)crack
- MT AI Enginepseb
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 23.216.147.76
- 192.229.211.108
- 20.99.185.48
- 20.99.133.109
- 20.99.184.37
- 23.216.147.64
- 20.99.186.246
- a83f:8110:900:3000:3000:3000:6100:3000
- a83f:8110:201:3ff:202:2ff:202:2ff
- 184.25.191.235
- http://bit.ly/fitgirl-repacks-site
- http://fitgirl-repacks.site/
- http://r3.i.lencr.org/
- C:\Users\<USER>\AppData\Local\Temp\is-A3ASQ.tmp\executable.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-AH377.tmp\_isetup\_setup64.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-AH377.tmp\_isetup\_shfoldr.dll
- C:\Users\<USER>\AppData\Local\Temp\is-AH377.tmp\idp.dll
- C:\Users\<USER>\AppData\Local\Temp\is-AH377.tmp\innocallback.dll
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERFB19.tmp.WERInternalMetadata.xml
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERFBF4.tmp.csv
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERFC23.tmp.txt
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER170D.tmp.WERInternalMetadata.xml
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER174E.tmp.csv
- Local\DirectSound DllMain mutex (0x00001A10)
- Local\RstrMgr3887CAB8-533F-4C85-B0DC-3E5639F8D511
- Local\RstrMgr-3887CAB8-533F-4C85-B0DC-3E5639F8D511-Session0000
- \Sessions\1\BaseNamedObjects\Local\RstrMgr3887CAB8-533F-4C85-B0DC-3E5639F8D511
- \Sessions\1\BaseNamedObjects\Local\RstrMgr-3887CAB8-533F-4C85-B0DC-3E5639F8D511-Session0000
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 09af8004b85478e1eca0…47b449Never scannednever seen before
- d92f7c60256509f74e36…62ea29Never scannednever seen before
- 58045dfbe8eb137de53d…94d65dNever scannednever seen before
- 450b9b0ba25bf068afbc…fd0105Never scannednever seen before
- f84677643d9977aa1e8a…61f824Never scannednever seen before
- 19a5466ab1834f953662…6072f5Never scannednever seen before
- ed8a485b9984997306ea…c78ee9Never scannednever seen before
- 9884e9d1b4f8a873ccbd…360d87Never scannednever seen before
- b5918c0eac32ea3fcb3a…3b1c7aNever scannednever seen before
- fbbf18f351711497ef2c…43fa39Never scannednever seen before
Who this file talks to on the internet
This sample contacts 1 host we've verdicted suspicious in our own URL scanner.
1 corroborating signal from researcher-curated sources
- Borlandby malware-lu
- pe_detect_tls_callbacks
- shellcodeby nexMatched shellcode byte patterns
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
- Borland
- pe_detect_tls_callbacks
- shellcode
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
Evidence"C:\Users\<USER>\Desktop\executable.exe"Sample contacted 15 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence23.216.147.76 · 192.229.211.108 · 20.99.185.48
3 detections across 74 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- setup.exe
- Size
- 4.32 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 16c82723b441f048a70938670cbd7b8e59429e3c62066db7788954ab90b343da
- MD5
- 6edbcf7f16d1f06b165297ae77166fff
- SHA-1
- 1a6dfe4fca3421df0c6bac0f9b4d5980665c8480
- PE imphash
- 483f0c4259a9148c34961abbda6146c1
- First seen (VT)
- 9/13/2023, 10:49:52 AM
- Last analysis (VT)
- 6/23/2026, 10:55:02 PM
- First scan (MalwareTips)
- 6/25/2026, 10:41:54 AM
- Last scan (MalwareTips)
- 6/25/2026, 10:41:54 AM
- Community reputation
- -9flagged
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.