Unknown
Our AI analyst is temporarily unavailable, so we've applied a conservative fallback: all 67 antivirus engines that scanned this file report it as clean.
3b36284f28824b8b87…13e9abbb31The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Our AI analyst is temporarily unavailable, so we've applied a conservative fallback: all 67 antivirus engines that scanned this file report it as clean. With that much coverage, the file looks safe — but re-scan in a few minutes to get the full AI assessment.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
AI arbiter unavailable (reason: grok_exception:This operation was aborted)
engines.tier1Malicious=0
engines.reporting=67
- 67 antivirus engines all report this file as clean.
The file appears safe based on antivirus coverage. Re-scan for the full AI assessment.
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\<USER>\AppData\Local\Temp\is-DSDCM.tmp\Unison Chord Genie - 1.0.37-3b36284f.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-824DR.tmp\_isetup\_setup64.tmp
- C:\Program Files\Steinberg\VSTPlugins\Unison\Unison Chord Genie.dll
- C:\Program Files (x86)\Unison\Unison Chord Genie\unins000.dat
- C:\Program Files (x86)\Unison\Unison Chord Genie\is-614GN.tmp
- C:\Program Files (x86)\Unison\Unison Chord Genie\is-614GN.tmp
- C:\Program Files\Steinberg\VSTPlugins\Unison\is-5HIL8.tmp
- C:\Program Files\Common Files\VST3\Unison\Unison Chord Genie.vst3\Contents\x86_64-win\is-RD5R6.tmp
- C:\Program Files\Common Files\Avid\Audio\Plug-Ins\Unison Chord Genie.aaxplugin\Contents\x64\is-HTC55.tmp
- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unison\Uninstall Unison Chord Genie.lnk
- cversions.3.m
- \Sessions\1\BaseNamedObjects\Local\RstrMgr3887CAB8-533F-4C85-B0DC-3E5639F8D511
- \Sessions\1\BaseNamedObjects\Local\RstrMgr-3887CAB8-533F-4C85-B0DC-3E5639F8D511-Session0000
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- a8a2ae67a11ce0544723…7dce50Never scannednever seen before
- 355a946bb8164a71feff…94ee41Never scannednever seen before
- 388a796580234efc95f3…136f95Never scannednever seen before
- 0285cefdc97eb3cf947b…1ba648Never scannednever seen before
- 8490373134e8a4279ac0…e5d2b3Never scannednever seen before
- e0a5114172276a53cb31…ff79e8Never scannednever seen before
- be0294393ccebf054ae2…f955a7Never scannednever seen before
- 84c9cd7391c06b41dfbb…0357a9Never scannednever seen before
- 5ed0233c0922e9f20307…313b66Never scannednever seen before
- 40a3d73c95b8f33fa270…ef3854Never scannednever seen before
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\Explorer.EXE
0 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- Unison Chord Genie - 1.0.37-3b36284f.exe
- Size
- 89.07 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 3b36284f28824b8b8777bec4faecf2facd0ed87328942791fcd2b013e9abbb31
- MD5
- cc8119d48d2c06f0b7bb40e55ccd9964
- SHA-1
- 4058f057af5667fc7f4f1f94ab9e9b0f4fe7d9c4
- PE imphash
- 40ab50289f7ef5fae60801f88d4541fc
- First seen (VT)
- 10/29/2025, 2:50:08 PM
- Last analysis (VT)
- 4/26/2026, 12:49:19 AM
- First scan (MalwareTips)
- 5/15/2026, 9:33:25 PM
- Last scan (MalwareTips)
- 5/15/2026, 9:33:25 PM
- Code signer
- Unison Audio Incverified
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.