Is Installer-1.1.0.exe safe?
Four tier-1 engines flagged this unsigned installer, while three researcher YARA rules identified anti-debugging and anti-virtualization characteristics consistent with evasive trojan activity.
The unsigned installer was flagged by 11 of 75 engines, including Microsoft, Fortinet, Symantec, and TrendMicro-HouseCall. Three researcher YARA rules also matched anti-debugging or anti-virtualization traits; although one sandbox produced no explicit malware verdict, the combined static evidence warrants blocking the file.
7d369ef21a49e0bcfd…88f40b3dc32249Recommended next actions
Before installing
Do not install it. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already installed it
Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The unsigned installer was flagged by 11 of 75 engines, including Microsoft, Fortinet, Symantec, and TrendMicro-HouseCall. Three researcher YARA rules also matched anti-debugging or anti-virtualization traits; although one sandbox produced no explicit malware verdict, the combined static evidence warrants blocking the file.
Eleven of 75 engines detected the sample, and four independent tier-1 votes make a routine low-quality false positive unlikely. Microsoft identified Malgent, while TrendMicro-HouseCall and Gridinsoft used Wacatac labels, supporting a generic trojan interpretation despite the lack of strong family consensus. Three researcher YARA rules matched, including rules for debugger checks and anti-virtualization behavior. One sandbox observed installer-like activity and no offensive-only techniques or explicit malware verdict, which lowers certainty but does not outweigh the engine and YARA evidence. The two contacted IP addresses were not covered by a completed host-reputation check, so their status remains unresolved. The executable is unsigned and has no established publisher history to provide a credible benign explanation.
What We Detected
Eleven of 75 antivirus engines flagged the installer. Four tier-1 engines contributed detections: Microsoft named Malgent, TrendMicro-HouseCall named Wacatac, Fortinet reported PossibleThreat, and Symantec produced a high-confidence machine-learning detection. The differing labels prevent firm attribution to one exact family, but they consistently indicate trojan-like risk.
Threat Behavior
Three researcher YARA rules matched, including DebuggerCheck__API and TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE. The completed sandbox observation recorded obfuscation and virtualization-evasion techniques, including T1027.002 and T1497.001, along with direct communication to two IP addresses. It did not issue an explicit malware verdict or observe offensive-only techniques. No complete host-reputation result is available for those IP addresses, and the ten inspected child files remain unclassified.
What To Do Now
Do not run the installer or grant it elevated privileges. Keep endpoint protection enabled, quarantine or delete the file, and obtain a replacement only from the software publisher's verified official channel. If it was already executed, isolate the system from sensitive accounts and networks, then run a full endpoint scan and review recent persistence, process, and credential-access activity.
Where this verdict could be wrong5 caveats
- engines.tier1FamilyConsensus.strong=false; the four tier-1 detections do not establish one strongly agreed malware family.
- behaviour.hasMaliciousSandboxVerdict=false and behaviour.offensiveCount=0 in the single completed sandbox observation.
- droppedChildren.inspected=10, but all ten child verdicts are unknown rather than confirmed benign or malicious.
- prevalence.uniqueSources=2956 and prevalence.timesSubmitted=4139 indicate broad circulation despite the file being recently observed.
- peAnalysis.highEntropyCode=false and peAnalysis.likelyPacked=false provide no static packing indication.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- The single sandbox observation produced no explicit malware verdict.
- No offensive-only MITRE techniques were observed.
- No inspected child was confirmed malicious, although all ten remain unclassified.
- peAnalysis.highEntropyCode=false and peAnalysis.likelyPacked=false.
- The file has 2,956 unique submitting sources and 4,139 submissions.
- 11 of 75 antivirus engines reported malicious detections.
- Four tier-1 engines flagged the sample.
- Microsoft identified Trojan:Win32/Malgent.
- Three researcher YARA rules matched the sample.
- Anti-debugging and anti-virtualization indicators were identified.
- The executable is unsigned and lacks publisher history.
Block and quarantine this installer, and obtain software only from a verified official source. If it has already run, keep security protection enabled and perform a full endpoint investigation.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete11 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial2 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete4 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 10MITRE ATT&CK techniques
- 4spawned processes
- 2network contacts
- 32filesystem & mutex artifacts
What this file does
Observed actions and their security significance
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Reads your Windows user-account details.
Note: Collects details about your system.
Note: Loads extra code modules while running.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Installer-1.1.0.exe
7d369ef21a49e0bcfd7875d2e000a5c6bb592e00f305e139a188f40b3dc32249
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\Installer-1.1.0.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\MadiumInstaller-54A5EBF2-02E6-44D5-9E66-3D7D8070B922\MadiumInstaller.exe" --from-sfx --first-install
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
payload.cab
C:\Users\<USER>\AppData\Local\Temp\MadiumInstaller-54A5EBF2-02E6-44D5-9E66-3D7D8070B922\payload.cab
04Isolated runtime analysis - Written fileObserved
app.so
C:\Users\<USER>\AppData\Local\Temp\MadiumInstaller-54A5EBF2-02E6-44D5-9E66-3D7D8070B922\data\app.so
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
172.67.130.103
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
162.159.36.2
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 172.67.130.103
- 162.159.36.2
- C:\Users\<USER>\AppData\Local\Temp\MadiumInstaller-54A5EBF2-02E6-44D5-9E66-3D7D8070B922\payload.cab
- C:\Users\<USER>\AppData\Local\Temp\MadiumInstaller-54A5EBF2-02E6-44D5-9E66-3D7D8070B922\data\app.so
- C:\Users\<USER>\AppData\Local\Temp\MadiumInstaller-54A5EBF2-02E6-44D5-9E66-3D7D8070B922\data\flutter_assets\AssetManifest.bin
- C:\Users\<USER>\AppData\Local\Temp\MadiumInstaller-54A5EBF2-02E6-44D5-9E66-3D7D8070B922\data\flutter_assets\FontManifest.json
- C:\Users\<USER>\AppData\Local\Temp\MadiumInstaller-54A5EBF2-02E6-44D5-9E66-3D7D8070B922\data\flutter_assets\fonts\MaterialIcons-Regular.otf
- C:\Users\<USER>\AppData\Local\Madium\Installer.new\data\5f15b8f7
- C:\Users\<USER>\AppData\Local\Madium\Installer.new\data\app.so.new
- C:\Users\<USER>\AppData\Local\Madium\Installer.new\data\flutter_assets\67363329
- C:\Users\<USER>\AppData\Local\Madium\Installer.new\data\flutter_assets\AssetManifest.bin.new
- C:\Users\<USER>\AppData\Local\Madium\Installer.new\data\flutter_assets\2a9d8a8
- Local\MadiumInstallerBootstrap-9D0FB8C3
- Local\MadiumInstaller-9D0FB8C3-1326-48C8
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 4ccd3c14651d1842b201…7cda4bNever scannednever seen before
- a0d636084c04969c1f0e…b518b4Never scannednever seen before
- 13837b89c714f22907b4…ab65e6Never scannednever seen before
- d40a6c1b6bb279aa9e9a…ef2f53Never scannednever seen before
- f566cc6fccc657365c01…4aa842Never scannednever seen before
- 28b1eb2b3d2e1ad60b8c…926e7dNever scannednever seen before
- d9865b671a09d683d13a…a62453Never scannednever seen before
- 9548a31e4a048135c1d9…7776cbNever scannednever seen before
- bdb492de2b031ec16101…52fccaNever scannednever seen before
- 1fe8436a743884cb6507…c604afNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 4rule hits recorded
- 11 / 75engines flagged
- 2,956sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
3 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceObservedSourceSignature and behavior rulesObserved at - 02
11 of 75 antivirus engines flagged the file, including APEX and CTX.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
YARAify matched 3 researcher rules to this file.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Installer-1.1.0.exe — 7d369ef21a49e0bcfd7875d2e000a5c6bb592e00f305e139a188f40b3dc32249
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\Installer-1.1.0.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\<USER>\AppData\Local\Temp\MadiumInstaller-54A5EBF2-02E6-44D5-9E66-3D7D8070B922\MadiumInstaller.exe" --from-sfx --first-install
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: payload.cab — C:\Users\<USER>\AppData\Local\Temp\MadiumInstaller-54A5EBF2-02E6-44D5-9E66-3D7D8070B922\payload.cab
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: app.so — C:\Users\<USER>\AppData\Local\Temp\MadiumInstaller-54A5EBF2-02E6-44D5-9E66-3D7D8070B922\data\app.so
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 172.67.130.103 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: generic-trojan
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- DebuggerCheck__API
- golang_bin_JCorn_CSC846
- TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence172.67.130.103 · 162.159.36.2
11 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.
Fingerprint and provenance
- File name
- Installer-1.1.0.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 9.8 MB
- Last analyzed
- Sep 13, 2026, 3:11 PM UTC
7d369ef21a49e0bcfd7875d2e000a5c6bb592e00f305e139a188f40b3dc32249Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't install this file. Delete this file from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already installed it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Download a fresh installer from the developer's official site or an official app store.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Installer-1.1.0.exe malware?
What is Installer-1.1.0.exe?
How many antivirus engines detected Installer-1.1.0.exe?
I already downloaded and installed Installer-1.1.0.exe — what should I do?
How do I remove Installer-1.1.0.exe?
What kind of malware is Installer-1.1.0.exe?
What is the SHA-256 hash of Installer-1.1.0.exe?
How up to date is this analysis of Installer-1.1.0.exe?
Community
Member reviews and reports for this exact file hash.