Is Blurred Installer.exe safe?
Multiple high-trust engines corroborate Defender Control tooling, while runtime evidence records security impairment, possible process injection, and installation of dControl.exe.
The file is flagged by 41 of 75 engines, including 10 high-trust detections, with several independently naming DControl or DefenderControl. Runtime evidence records dControl.exe, possible process injection, and activity intended to impair security controls, so it should not be executed.
7bf0ac86481ec8da00…3c9369eef63819Recommended next actions
Before installing
Do not install it. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already installed it
Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The file is flagged by 41 of 75 engines, including 10 high-trust detections, with several independently naming DControl or DefenderControl. Runtime evidence records dControl.exe, possible process injection, and activity intended to impair security controls, so it should not be executed.
Forty-one of 75 engines detected the sample, and 10 high-trust engines contributed flags. BitDefender, Emsisoft, GData, and Ikarus specifically identify DControl or DefenderControl, satisfying the corroboration requirement for offensive tooling. The completed runtime observation recorded T1055 and T1562.001 and showed dControl.exe being written, supporting the engine labels. The executable is unsigned and has no established publisher history. One sandbox supplied a clean label, but that conflicts with its saved offensive activity and the broad independent engine evidence. The lone prior safe similarity is only an imphash match to a differently signed installer and carries little weight.
What We Detected
Our antivirus network recorded 41 detections among 75 engines, including 10 high-trust detections. BitDefender, Emsisoft, GData, and Ikarus identify DControl or DefenderControl, while other engines use Agentb, Ravartar, or generic trojan labels. The offensive-tool identification is corroborated, and the executable has no digital signature or established publisher history.
Threat Behavior
The completed runtime observation recorded T1055, associated with process injection, and T1562.001, associated with impairing security tools. It also showed the installer writing dControl.exe and interacting with processes that included LSASS. These observations support the DControl labels, although the available data does not prove a specific credential-extraction method. Host-reputation coverage was incomplete because only one of four listed domain or IP contacts was inspected.
What To Do Now
Do not run the installer, and keep antivirus and endpoint protection enabled. Quarantine or remove the file; if it already ran, perform a full endpoint scan, review security-control settings for unauthorized changes, and investigate affected credentials and active processes.
Where this verdict could be wrong5 caveats
- behaviour.hasMaliciousSandboxVerdict=false in the single completed sandbox run, although the saved activity still includes T1055, T1562.001, and dControl.exe.
- contactedHosts inspected only 1 host while behaviour lists 4 distinct domain/IP contacts, so no complete host-reputation result is available.
- droppedChildren inspected 8 files without a malicious child verdict, but all 8 child verdicts remain unknown.
- externalIntel.yaraify.ruleCount=0 and externalIntel.circl.hit=false provide no researcher corroboration, though absence of a hit does not negate the engine and runtime evidence.
- similarHashes shows 1/1 prior verdict 'safe' for matchKind=imphash, but signerCoMatch=false and the matched file was a differently signed installer.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- The single sandbox verdict was clean
- No inspected child received a malicious verdict, although all eight remained unknown
- No high-entropy code or likely packing was identified
- no complete contacted-host reputation result was available appeared in the limited one-host reputation check
- CIRCL and YARAify returned no matching intelligence
- 41/75 engine detections
- 10 high-trust engine detections
- Corroborated DControl or DefenderControl hacktool labels
- T1562.001 security-control impairment activity
- T1055 process-injection activity
- dControl.exe written during execution
Quarantine or delete the installer and keep all endpoint protection enabled. If it was executed, run a full scan and investigate security-setting changes, LSASS access, and unexpected processes.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete41 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 of 4 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete3 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 14MITRE ATT&CK techniques
- 14spawned processes
- 4network contacts
- 25filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Attempted to impair or bypass security controls.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Removed execution artefacts or logs, which can conceal activity.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Reads your Windows user-account details.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How hacktools are abused
This is a hacking or cracking tool — the kind used to bypass software licences, generate fake keys, or attack other systems. Even when the tool 'works', these downloads very often carry hidden malware.
Bottom line:Running one means trusting an anonymous author with full access to your PC — rarely worth the risk.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Blurred Installer.exe
7bf0ac86481ec8da00e9bc764afee313092c5fa7a52d7769453c9369eef63819
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\Blurred Installer.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\is-C9D3L.tmp\Blurred Installer.tmp" /SL5="$30196,35583683,982016,C:\Users\<USER>\Desktop\Blurred Installer.exe"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Blurred Installer.tmp
C:\Users\<USER>\AppData\Local\Temp\is-C9D3L.tmp\Blurred Installer.tmp
04Isolated runtime analysis - Written fileObserved
_setup64.tmp
C:\Users\<USER>\AppData\Local\Temp\is-SNLRO.tmp\_isetup\_setup64.tmp
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
loader.blurred.gg
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
104.26.15.175
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- loader.blurred.gg
- 104.26.15.175
- 35.190.80.1
- 150.171.28.11
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000\RegFiles0000
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000\RegFilesHash
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Blurred.gg Loader_is1\Inno Setup: Setup Version
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Blurred.gg Loader_is1\Inno Setup: App Path
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Blurred.gg Loader_is1\InstallLocation
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Blurred.gg Loader_is1\Inno Setup: Icon Group
- C:\Users\<USER>\AppData\Local\Temp\is-C9D3L.tmp\Blurred Installer.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-SNLRO.tmp\_isetup\_setup64.tmp
- C:\Users\<USER>\Desktop\BlurredGG\Blurred.exe
- C:\Users\<USER>\AppData\Local\Temp\is-SNLRO.tmp\dControl.exe
- C:\Users\<USER>\AppData\Local\Temp\is-SNLRO.tmp\MicrosoftEdgeWebview2Setup.exe
- C:\Program Files (x86)\Blurred\is-J4IG7.tmp
- C:\Users\<USER>\Desktop\BlurredGG\is-KJAKO.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-SNLRO.tmp\VC_redist.x64.exe
- C:\Users\<USER>\AppData\Local\Temp\is-SNLRO.tmp\MicrosoftEdgeWebview2Setup.exe
- C:\Users\<USER>\AppData\Local\Temp\is-SNLRO.tmp\dControl.exe
- Local\Blurred.gg Loader
- Global\OneSettingQueryMutex+compat+encapsulation
- \Sessions\1\BaseNamedObjects\Local\RstrMgr3887CAB8-533F-4C85-B0DC-3E5639F8D511
- \Sessions\1\BaseNamedObjects\Local\RstrMgr-3887CAB8-533F-4C85-B0DC-3E5639F8D511-Session0000
Files this sample writes at runtime
This file drops 8 children at runtime. None are currently flagged malicious in our cache.
- e83998a5867cdb585796…16bbb4Never scannednever seen before
- 1ef6c1a4dfdc39b63bfe…559326Never scannednever seen before
- 1ab08ff8c01bb18a95e8…acf321Never scannednever seen before
- 388a796580234efc95f3…136f95Never scannednever seen before
- 48c60e32d609e979f745…650868Never scannednever seen before
- 1cb7b2d181ab57ee25ab…e81185Never scannednever seen before
- 580258b37a95b339e3a4…e984dcNever scannednever seen before
- cc0ff0eb1dc3f5188ae6…6b713bNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 3rule hits recorded
- 41 / 75engines flagged
- 18sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
2 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
41 of 75 antivirus engines flagged the file, including AhnLab-V3 and Alibaba.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 22 times from 18 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Blurred Installer.exe — 7bf0ac86481ec8da00e9bc764afee313092c5fa7a52d7769453c9369eef63819
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\Blurred Installer.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\<USER>\AppData\Local\Temp\is-C9D3L.tmp\Blurred Installer.tmp" /SL5="$30196,35583683,982016,C:\Users\<USER>\Desktop\Blurred Installer.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Blurred Installer.tmp — C:\Users\<USER>\AppData\Local\Temp\is-C9D3L.tmp\Blurred Installer.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: _setup64.tmp — C:\Users\<USER>\AppData\Local\Temp\is-SNLRO.tmp\_isetup\_setup64.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: loader.blurred.gg — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 104.26.15.175 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: hacktool
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pAt least one AV engine labelled this sample as anti-VM / anti-debug / sandbox-evading. These techniques are specifically designed to bail out when the sample notices it's being analysed.
EvidenceTrojan.AntiVM!1.CC71 (CLOUD)Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceSangfor: Hacktool.Win32.Agentb.Vyjv
41 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Blurred Installer.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 34.9 MB
- Last analyzed
- Oct 3, 2026, 12:58 AM UTC
7bf0ac86481ec8da00e9bc764afee313092c5fa7a52d7769453c9369eef63819Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't install this file. Delete this file from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already installed it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Download a fresh installer from the developer's official site or an official app store.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Blurred Installer.exe a virus?
What is Blurred Installer.exe?
How many antivirus engines detected Blurred Installer.exe?
What should I do if I already installed Blurred Installer.exe?
How do I remove Blurred Installer.exe?
What kind of malware is Blurred Installer.exe?
What is the SHA-256 hash of Blurred Installer.exe?
How up to date is this analysis of Blurred Installer.exe?
Community
Member reviews and reports for this exact file hash.