Malicious
Unsigned installer flagged as EDRSilencer hacktool by Kaspersky and others, with process injection (T1055), LSASS access, and a malicious dropped child.
d6ba6bf6cff69a19d8…c8f82fb371The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Tier-1 engines including Kaspersky explicitly name it EDRSilencer hacktool, corroborated by tier2/low-trust detections and high-severity heuristics for process injection and credential dumping. A dropped child was previously verdicted malicious, strengthening the case. Unsigned status and debug-environment tag align with offensive tooling. While many tier-1 engines are clean, hacktool principles mandate malicious verdict on confirmed labels regardless of intent.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
Kaspersky (tier1): HackTool.Win64.EDRSilencer.ar (hacktool=true)
Alibaba / Antiy-AVL / CTX: EDRSilencer hacktool detections
droppedChildren d6a0a37ba8d07bbca3606c1ef06dea7f7b49b88c51f46bccfd7d33f3295f916b (malicious verdict)
triggeredHeuristics Synth.ProcessInjection (T1055, CreateRemoteThread into Explorer.EXE)
behaviour.offensiveTechniques: T1055
- 15 tier1 engines clean (e.g. BitDefender, ESET)
- No malicious sandbox consensus
- Medium prevalence, no community comments
- EDRSilencer hacktool (Kaspersky, multiple engines)
- Process injection (T1055 into Explorer.exe)
- LSASS targeting (credential dump shape)
- Malicious dropped child file
- Direct IP contact (162.159.36.2, no DNS)
- Unsigned executable
Treat as confirmed hacktool: quarantine the file, full system scan, and monitor for related processes or mutexes. Do not execute HeliosSetup.exe.
edrsilencer corroborated by 2 sources
- VT (76 engines)edrsilencer
- MT AI EngineEDRSilencer
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Users\<USER>\AppData\Local\Temp\HeliosSetup_62375\GUIInstaller.exe
- C:\Users\<USER>\AppData\Local\Temp\HeliosSetup_62375\HeliosWebMarshall.exe
- C:\Users\<USER>\AppData\Local\Temp\HeliosSetup_62375\HeliosWebMarshallCommunicator.exe
- C:\Users\<USER>\AppData\Local\Temp\HeliosSetup_62375\helios_notify.exe
- C:\Users\<USER>\AppData\Local\Temp\HeliosSetup_62375\bloom_filter.hebf
- C:\Users\<USER>\AppData\Local\Temp\HeliosSetup_62375
- C:\Users\<USER>\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\KnownGameList.bin
- C:\Users\<USER>\AppData\Local\Microsoft\GameDVR\KnownGameList.update
- Global\SyncRootManager
- Local\Mutexf01b4d95cf55d32a.automaticDestinations-ms
- Local\Mutex5f7b5f1e01b83767.automaticDestinations-ms
- Global\OneSettingQueryMutex+compat+encapsulation
Files this sample writes at runtime
The sandbox saw this file drop 10 children. 1 of them is already known-malicious in our database — this file is a dropper.
- ea34b21ea7e43554fe8d…4d7273Never scannednever seen before
- f4992c7a55221726ebed…61e9a7Never scannednever seen before
- d54ec6ee82db68f3f023…1fee80Never scannednever seen before
- 58e0bdbd8cdacd40135d…b0283aNever scannednever seen before
- 25063a008668a6db2571…2a33a0Never scannednever seen before
- 15cad5c2b5586e055c16…19b2a3Never scannednever seen before
- f7b0421daf8b64147086…aa07ffNever scannednever seen before
- c19b18a6b71e50997d7f…7439a0Never scannednever seen before
- d6a0a37ba8d07bbca360…5f916bMalicious6/76 enginesrisk 84from our cache
- ae69309c5e356350ea28…19cc08Never scannednever seen before
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceKaspersky: HackTool.Win64.EDRSilencer.arSample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2
25 detections across 76 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- HeliosSetup.exe
- Size
- 18.69 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- d6ba6bf6cff69a19d823a53860476f270f21babc082c52202c341bc8f82fb371
- MD5
- a37571ab241f01bfc887d35dcf527fc2
- SHA-1
- 98d14e41154b0455d90466f3411ffdf3375d2cc7
- PE imphash
- 0713d6f3e857162ba251346743ca9437
- First seen (VT)
- 3/31/2026, 1:55:34 PM
- Last analysis (VT)
- 4/23/2026, 4:40:27 PM
- First scan (MalwareTips)
- 4/20/2026, 1:46:14 PM
- Last scan (MalwareTips)
- 4/24/2026, 2:10:36 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.