File verdict·Decided by the MT AI Engine
Our call

Suspicious

Installer exhibits offensive MITRE techniques (process injection, LSASS access, direct-IP C2) but lacks tier-1 family consensus; signer unverified.

Signed but unverified · EbonholdLauncher
Trust score58Caution
MT AI confidence · 62%
ebonhold_1.0.5_x64-setup.exe
10.2 MB
8680fac1ecd0b0ce58206f7a7e26
Antivirus engines
1 of 75 flagged
Code signing
Unverified: EbonholdLauncher
Age
First seen 6 days ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

62%Confidence
Moderate
Reasoning

The evidence presents a mixed picture. On one hand, Sophos (tier-1) flagged the sample as 'Generic ML PUA', and the sandbox observed offensive behaviour: process injection (T1055), process hollowing (T1134), data destruction (T1485), LSASS access (credential-dumper pattern), and direct-IP C2 contact (162.159.36.2) with no DNS fallback. These are coherent malware indicators. On the other hand, the signer 'EbonholdLauncher' has no historical track record, the Sophos label is a machine-learning heuristic rather than a named family, and 16 other tier-1 engines are silent. The file is an NSIS installer with rapid distribution (common_new, 122 submitters), consistent with either legitimate software or an active campaign. The dropped children (10 inspected) have not yet been verdicted, so we cannot confirm whether they are malicious. The direct-IP C2 contact is suspicious but not yet confirmed as malicious in our URL cache.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. Sophos (tier1) flagged 'Generic ML PUA (PUA)' — 1/71 engines malicious; tier1FamilyConsensus.strong=false (no family agreement among tier-1 engines)

  2. behaviour.offensiveTechniques: T1055 (process injection), T1134 (process hollowing), T1485 (data destruction) — three offensive MITRE techniques observed in sandbox

  3. triggeredHeuristics: MalwareTips.Synth.CredentialDumper (medium severity) — LSASS access observed; MalwareTips.Synth.DirectIpC2 (medium severity) — contacted 162.159.36.2 with zero DNS queries

  4. yaraify.ruleCount=2 — community YARA rules matched (Detect_NSIS_Nullsoft_Installer, PE_Digital_Certificate); external researcher interest in the sample

  5. signing.signerStats.found=false — signer 'EbonholdLauncher' has no historical track record; trustedPublisher.matched=false

Points in its favour
  • 16 tier-1 antivirus engines reported the sample clean
  • No malicious dropped children confirmed (10 inspected, 0 verdicted malicious)
  • No malicious contacted hosts in our URL cache
  • High prevalence (122 submitters, 125 submissions) suggests legitimate software or active campaign, not targeted malware
  • NSIS installer format is common for legitimate software distribution
Points against
  • Process injection (T1055) observed in sandbox — payload smuggled into legitimate process to bypass AV hooks
  • LSASS access (credential-dumper pattern) — legitimate software has no business reading Windows credential store
  • Direct-IP C2 contact (162.159.36.2) without DNS queries — bypasses reputation-based domain blocklists
  • Signer 'EbonholdLauncher' unverified with no historical track record
  • Data destruction technique (T1485) observed — consistent with ransomware or wiper malware
  • Community YARA rules matched (2 rules) — external researchers flagged the sample
What to do

Do not execute this file on production systems. Isolate and monitor any system that has run it. Await further analysis of the dropped children and IP reputation confirmation before making a final security decision. If you are the publisher, verify the signer certificate and consider re-signing with a trusted publisher identity.

Threat family attribution

NSIS Nullsoft Installer corroborated by 1 source

  • 2 YARA rules
    Detect_NSIS_Nullsoft_Installer, PE_Digital_Certificate
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
21

Adversary techniques mapped to the MITRE ATT&CK framework.

T1010T1012T1027T1033T1055T1057T1059T1071T1082T1083T1112T1115T1125T1129T1134T1222T1485T1518T1529T1547.009T1574
Spawned processes
11
$(unnamed)
"C:\Users\<USER>\Desktop\ebonhold_1.0.5_x64-setup.exe"
$(unnamed)
C:\Windows\Explorer.EXE
$(unnamed)
C:\Windows\system32\services.exe
$(unnamed)
C:\Windows\System32\svchost.exe -k NetworkService -p
$(unnamed)
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
$(unnamed)
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
$(unnamed)
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s WdiSystemHost
$(unnamed)
C:\Windows\system32\lsass.exe
+3 more processes captured.
Network activity
1
IP addresses1
  • 162.159.36.2
Filesystem & mutexes
23
Files written15
  • C:\Users\<USER>\AppData\Local\Temp\nssC66D.tmp
  • C:\Users\<USER>\AppData\Local\Temp\nssC66E.tmp\System.dll
  • C:\Users\<USER>\AppData\Local\Temp\nssC66E.tmp\modern-wizard.bmp
  • C:\Users\<USER>\AppData\Local\Temp\nssC66E.tmp\nsDialogs.dll
  • C:\Users\<USER>\AppData\Local\Temp\nssC66E.tmp\nsis_tauri_utils.dll
+10 more
Files deleted6
  • C:\Users\<USER>\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\KnownGameList.bin
  • C:\Users\<USER>\AppData\Local\Microsoft\GameDVR\KnownGameList.update
  • C:\Users\<USER>\AppData\Local\Temp\nsqD284.tmp
  • C:\Users\<USER>\AppData\Local\Temp\nsvD2F3.tmp
  • C:\Users\user\AppData\Local\Temp\nsn4DDF.tmp
+1 more
Mutexes created2
  • cversions.3.m
  • Global\OneSettingQueryMutex+compat+encapsulation
Dropped payload

Files this sample writes at runtime

This file drops 10 children at runtime. None are currently flagged malicious in our cache.

10 unseen
  • e153bf80f73051aae8f0f78258Never scanned
    never seen before
  • 6a32397b51babc7673c3bfe955Never scanned
    never seen before
  • f942c40a34155aa4ead36bc2c5Never scanned
    never seen before
  • aade2b63fc1e6cccdf2f15cd88Never scanned
    never seen before
  • b1350f487692057c8ffd551fc0Never scanned
    never seen before
  • 3860bb6d19ed159f91e07ec35aNever scanned
    never seen before
  • 9baee42d66f715bba878b40256Never scanned
    never seen before
  • 807590c24c354a943b8b1eca52Never scanned
    never seen before
  • 8fc936ee48511dc4170d1516e2Never scanned
    never seen before
  • 8b4c47c4cf5e76ec57dd90d37cNever scanned
    never seen before
External threat intelligence

1 corroborating signal from researcher-curated sources

YARAify HIT·2 community rules matchedView on YARAify
  • Detect_NSIS_Nullsoft_Installerby Obscurity Labs LLC
    Detects NSIS installers by .ndata section + NSIS header string
  • PE_Digital_Certificateby albertzsigovits
Cross-referenced against MalwareBazaar (abuse.ch), YARAify, and the CIRCL hashlookup reference DB.
Signature matches

YARA + heuristic rules that fired

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

2 YARAify3 synthesis
MITRE ATT&CK profile
Defense evasion× 1Cred access× 1C2× 1
YARAify (community)
Researcher-authored rules via abuse.ch
  • Detect_NSIS_Nullsoft_Installer
  • PE_Digital_Certificate
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    C:\Windows\Explorer.EXE
  • CredentialDumpermedium

    Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.

    Evidence
    C:\Windows\system32\lsass.exe
  • DirectIpC2medium

    Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    162.159.36.2
Antivirus engine breakdown

1 detection across 75 engines

1 malicious0 suspicious74 clean
Tier-117 engines
1flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
0flag
Heuristic / generic-AI engines (high FP rate)
Sophos
malicious
Generic ML PUA (PUA)
Hash 8680fac1ecd0… cross-referenced against 75 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 8.00Unpacked
Section entropy5 sections
.text
6.45
.rdata
5.10
.data
4.12
.ndata
0.00
.rsrc
5.88
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.

Common & new
Unique uploaders
122
Hundreds of people have uploaded this — common.
Total submissions
125
Includes repeat uploads by the same source.
First seen by VT
6d ago
Jun 19, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
6/19/2026, 12:33:25 PM
First seen (MalwareBazaar)
Last analysis (VT)
6/25/2026, 2:53:34 PM
Scanned here
6/25/2026, 3:55:08 PM
File name
ebonhold_1.0.5_x64-setup.exe
Size
10.22 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
8680fac1ecd0b0ce58e99dcbe5c9764c8842bf69af75cfb9699399206f7a7e26
MD5
26687c80e4da79b8b83d596ebbe19a20
SHA-1
6a908e0f26bb15e54907eb161efa0c5b1c1d8533
PE imphash
46ce5c12b293febbeb513b196aa7f843
First seen (VT)
6/19/2026, 12:33:25 PM
Last analysis (VT)
6/25/2026, 2:53:34 PM
First scan (MalwareTips)
6/25/2026, 3:55:08 PM
Last scan (MalwareTips)
6/25/2026, 3:55:08 PM
Code signer
EbonholdLauncherinvalid
Behavior tags
invalid-signaturepeexesignedoverlay
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.