Is STRUCKTOR_UK_ST8960047-2026_07_13.com safe?
Unsigned NSIS executable flagged by Kaspersky and Rising as GuLoader/NSIS downloader with token-manipulation behaviour.
Eight engines detected the sample, including one tier-1 engine naming NSIS.Agent and another explicitly calling GuLoader/NSIS. The file is unsigned, brand new, and drops multiple files under AppData while using T1134 token manipulation.
64e87caa73abf5463f…a4da94b21571c1Recommended next actions
Before running
Do not run it. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already ran it
Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Eight engines detected the sample, including one tier-1 engine naming NSIS.Agent and another explicitly calling GuLoader/NSIS. The file is unsigned, brand new, and drops multiple files under AppData while using T1134 token manipulation.
The combination of a tier-1 detection on a known NSIS downloader family, explicit GuLoader label from Rising, and offensive MITRE technique T1134 outweighs the limited tier-1 consensus. Zero signer history and rare_new prevalence further reduce the chance of a benign installer. Sandbox and child-file signals are absent, but the engine labels and dropped-file pattern are consistent with GuLoader loaders.
What We Detected
8 of 74 engines flagged the 687 kB Win32 EXE. Kaspersky (tier-1) reported VHO:Trojan.NSIS.Agent.gen; Rising labelled it Downloader.GuLoader/NSIS. Four tier-2 engines also returned malicious verdicts. The sample is unsigned and first seen today.
Threat Behavior
Behaviour analysis recorded T1134 (Access Token Manipulation) plus 13 ambient techniques. Eight files were written under AppData\Roaming\Microsoft\Windows\Templates\glutamine, a pattern typical of NSIS-based loaders. No C2 domains or malicious child hashes were observed in the current run.
What To Do Now
Do not execute the file. Quarantine or delete it. If the file arrived via email or download link, scan the source and monitor for follow-on payloads.
Where this verdict could be wrong3 caveats
- Only 1 tier-1 engine flagged; 10 tier-1 engines reported clean and 51 undetected — coverage is moderate but consensus is weak.
- No sandbox verdicts, no malicious dropped children, no contacted malicious hosts — runtime behaviour lacks direct C2 or payload execution confirmation.
- No YARAify or CIRCL hits; similarHashes empty — external researcher corroboration is absent.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- No malicious sandbox verdict
- No malicious dropped children
- No contacted malicious hosts
- Unsigned executable
- Rare new prevalence
- T1134 token manipulation
- GuLoader/NSIS engine labels
Block the hash and avoid execution; treat as a GuLoader downloader until further sandbox confirmation.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete8 of 74 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Threat context
How downloaders work
This file is a delivery vehicle. On its own it can look small and harmless, but its job is to quietly pull down and install the REAL payload — often a stealer, ransomware, or bot — from a server the attacker controls.
Bottom line:Because the dangerous part arrives later, early scans can look cleaner than the threat really is.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
STRUCKTOR_UK_ST8960047-2026_07_13.com
64e87caa73abf5463fccec3a7adc55ec1395fffb315e0380f6a4da94b21571c1
01Uploaded file
Files
Created or changed
- Written fileObserved
Cnidarian
C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Templates\glutamine\konsummlks\Cnidarian
02Isolated runtime analysis - Written fileObserved
Encyclicals.voa
C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Templates\glutamine\konsummlks\Encyclicals.voa
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
3 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Files this sample writes at runtime
This file drops 8 children at runtime. None are currently flagged malicious in our cache.
- 7755d98c6798e92d5a4c…806344Never scannednever seen before
- 475001c1457f149f3dac…ceece0Never scannednever seen before
- 76bd5c4a138361ac9a5d…de6917Never scannednever seen before
- 795ce9b5df889047897e…ef2f2dNever scannednever seen before
- 439ebd6843acf2406429…9104c9Never scannednever seen before
- 85fb6d6a7ff0219723be…f8c1bdNever scannednever seen before
- e0b217e3dbdc10de2642…3c6cb7Never scannednever seen before
- 7a9ddee34562cd3703f1…6cb2a5Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 8 / 74engines flagged
- 1sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
8 of 74 antivirus engines flagged the file, including APEX and CrowdStrike.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: STRUCKTOR_UK_ST8960047-2026_07_13.com — 64e87caa73abf5463fccec3a7adc55ec1395fffb315e0380f6a4da94b21571c1
ProvenanceObservedSourceUploaded fileObserved at - 04
File written: Cnidarian — C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Templates\glutamine\konsummlks\Cnidarian
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
File written: Encyclicals.voa — C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Templates\glutamine\konsummlks\Encyclicals.voa
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: downloader
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
8 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 8 antivirus detections make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- STRUCKTOR_UK_ST8960047-2026_07_13.com
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 671.0 KB
- Last analyzed
- Jul 13, 2026, 1:05 PM UTC
64e87caa73abf5463fccec3a7adc55ec1395fffb315e0380f6a4da94b21571c1Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't run this file. Delete this file from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already ran it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the developer's official site or an official app store.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is STRUCKTOR_UK_ST8960047-2026_07_13.com malware?
What is STRUCKTOR_UK_ST8960047-2026_07_13.com?
How many antivirus engines detected STRUCKTOR_UK_ST8960047-2026_07_13.com?
I already downloaded and ran STRUCKTOR_UK_ST8960047-2026_07_13.com — what should I do?
How do I remove STRUCKTOR_UK_ST8960047-2026_07_13.com?
What kind of malware is STRUCKTOR_UK_ST8960047-2026_07_13.com?
What is the SHA-256 hash of STRUCKTOR_UK_ST8960047-2026_07_13.com?
How up to date is this analysis of STRUCKTOR_UK_ST8960047-2026_07_13.com?
Community
Member reviews and reports for this exact file hash.