Suspicious
Signed SSD utility shows heavy obfuscation, suspicious sandbox behaviour (LSASS targeting, direct IP contact), but clean across 72 engines.
291e282a1574dda5ca…2c4362d15eThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Zero detections from 72 engines including top tier-1 vendors provide a strong clean signal, but high-entropy packing, .NET Reactor obfuscation, and offensive MITRE techniques (T1562.001 via fsutil, T1620 timestomp) raise red flags. Heuristics highlight credential dumping shape and dropper profile, though the file is signed and has medium prevalence. No malicious runtime outcomes or external intel hits, but behaviour doesn't align with typical benign optimizers. Overall mixed signals warrant caution.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
0/72 engines malicious (17 tier1 clean: Avast, AVG, BitDefender, DrWeb, Emsisoft, ESET, F-Secure, Fortinet, GData, Ikarus, Kaspersky)
triggeredHeuristics 'MalwareTips.Synth.CredentialDumper' fired (evidence: lsass.exe)
behaviour.offensiveCount=3 (T1560, T1562.001, T1620); contactedIps[0]='162.159.36.2'
peAnalysis.likelyPacked=true; communityComments THOR 'SUSP_OBF_NET_Reactor_JIT_Encryption'
prevalence.classification='medium' (34 uniqueSources, 40 submissions)
- 0 malicious engines (17 tier1 clean: BitDefender, ESET, Kaspersky, etc.)
- Medium prevalence (40 submissions, 34 sources)
- No malicious sandbox verdict
- No dropped children or malicious hosts
- Signed executable
- High-entropy code and likely packing
- .NET Reactor obfuscation (cracked versions malware-linked)
- Offensive MITRE: T1562.001 (anti-forensic check), T1560, T1620
- LSASS targeting (Mimikatz-like)
- Direct IP C2 profile (162.159.36.2)
- Unknown signer 'Omid Soroori' (no history)
Treat as suspicious: do not execute unless verified from official source. Use sandbox or static analysis tools for confirmation; delete if unnecessary.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
- \Sessions\1\BaseNamedObjects
- \Device\KsecDD
- \\?\PIPE\lsarpc
- \\?\PIPE\NETLOGON
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeSample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2Unsigned, packed PE with sandbox-observed network activity. The packing step hides the payload until execution; the network call fetches / reports for the next stage. Classic dropper / stager behaviour.
Evidence162.159.36.2
0 detections across 76 engines
Section entropy & packers
Executable sections have high entropy (7.2+) — the code is compressed or encrypted and only decrypted at runtime. Classic packing behaviour.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- SSDBooster.exe
- Size
- 3.38 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 291e282a1574dda5ca191a456d0c01f0defb69b2a4b18e2b4bbbdf2c4362d15e
- MD5
- 49f22135e2aa4a6abebc8cad0bc2ce07
- SHA-1
- 74f790636a883b9f7075a4988d9ee298c9da2852
- PE imphash
- f34d5f2d4577ed6d9ceec516c1f5a744
- First seen (VT)
- 1/27/2026, 3:09:17 PM
- Last analysis (VT)
- 2/11/2026, 1:14:56 AM
- First scan (MalwareTips)
- 4/21/2026, 2:13:31 PM
- Last scan (MalwareTips)
- 4/24/2026, 2:18:12 AM
- Code signer
- Omid Sorooriinvalid
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.