Suspicious
Unsigned MSI with clean engine results but sandbox-detected process injection and LSASS access.
afe11244e96c0e3fa8…42836798e5The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Zero malicious detections across 61 reporting engines including all tier-1 vendors rules out widespread malware consensus. However the two offensive MITRE techniques and corresponding synthetic heuristics indicate suspicious runtime activity targeting LSASS and remote thread creation. Being unsigned and only 12 days old with minimal prevalence further reduces trust. The combination of clean static signals and concerning behavioural signals produces a borderline case best classified suspicious rather than safe or malicious.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0 malicious out of 75 (Microsoft, BitDefender, Kaspersky, ESET-NOD32 all undetected)
behaviour.offensiveTechniques: T1055, T1548 observed in sandbox
triggeredHeuristics[0]: MalwareTips.Synth.ProcessInjection fired (evidence: svchost.exe)
prevalence.classification: rare_new with 3 submitters
signing.verified: false (unsigned MSI)
- Zero detections from 75 engines
- No malicious dropped children
- No contacted malicious hosts
- Unsigned installer
- Sandbox observed LSASS access
- Process injection techniques recorded
- Rare new prevalence (3 submissions)
Treat as suspicious pending further behavioural analysis or a signed release from the vendor.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
- C:\Windows\Temp\~DF76BEA12B2B1B07C9.TMP
- C:\Windows\Temp\~DF761DEE14FD02EB44.TMP
- C:\Windows\Temp\~DFB1B372B70F233664.TMP
- C:\Windows\Temp\~DFD250934D3081A0A9.TMP
- C:\Config.Msi\CMPE1C4.tmp
- C:\Config.Msi
- C:\Windows\Installer\dc97.msi
- C:\Config.Msi\CMPE55E.tmp
- C:\Config.Msi\dc96.rbs
- Global\_MSIExecute
- \BaseNamedObjects\Local\SM0:6996:304:WilStaging_02
Files this sample writes at runtime
This file drops 8 children at runtime. None are currently flagged malicious in our cache.
- 8fdc8d3d12876b6c9dc8…9a3191Never scannednever seen before
- 24aa985d01d4123e0b3f…e17263Never scannednever seen before
- 01960077670b151ba514…ea9708Never scannednever seen before
- 31ef6d0daf229a90ed46…ceee49Never scannednever seen before
- ca286b2289d28013520c…8704bbNever scannednever seen before
- 325b0aa212d9245293f0…25922cNever scannednever seen before
- dd591596e8f8f1658e75…eea0d2Never scannednever seen before
- 1c119febd5f388f46b91…37a319Never scannednever seen before
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
0 detections across 75 engines
How often this file shows up in the wild
Barely seen in the wild and first surfaced recently. This is the footprint of targeted malware the AV industry hasn't signatured yet — extra scrutiny is warranted.
Forensic fingerprint
- File name
- HardwareVisualizer_1.8.1_x64_en-US.msi
- Size
- 6.16 MB
- MIME type
- (unknown)
- Detected type
- Windows Installer
- SHA-256
- afe11244e96c0e3fa8d60b1c58a587aa5cb063eac18a2d075d498842836798e5
- MD5
- c2e2b57ddcf92a2d9ad6bf9018ead90e
- SHA-1
- f0a687430a41b5f04bd26b39502b36e1d4ca1730
- First seen (VT)
- 5/11/2026, 4:41:38 AM
- Last analysis (VT)
- 5/12/2026, 6:34:40 AM
- First scan (MalwareTips)
- 5/23/2026, 7:26:28 AM
- Last scan (MalwareTips)
- 5/23/2026, 7:26:28 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.