File verdict·Decided by the MT AI Engine
Our call

Suspicious

Unsigned installer with offensive sandbox techniques (process injection, LSASS access) but zero tier-1 detections and no malicious sandbox verdict — mixed signals warrant caution.

Trust score52Caution
MT AI confidence · 62%
PolarInstaller.exe
2.8 MB
de6a60745bc1023d1571d2a85dac
Antivirus engines
0 of 75 flagged
Code signing
Unsigned
Age
First seen 1 day ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

62%Confidence
Moderate
Reasoning

The evidence presents a mixed picture. On one hand, zero tier-1 detections and no malicious sandbox consensus suggest the file is not actively flagged as malware by high-trust vendors. On the other hand, the sandbox observed offensive MITRE techniques — process injection into svchost.exe and LSASS memory access — which are typical of credential-stealing malware or offensive tools. The file is unsigned and lacks publisher reputation history, which increases uncertainty. The RAG history shows prior files with the same imphash were verdicted as suspicious or borderline, not safe or malicious, reinforcing the mixed-signals classification. The absence of contacted malicious hosts and dropped malicious children further suggests the file did not execute a full attack chain in the sandbox.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. tier1Malicious=0; 17 tier-1 engines (Avast, BitDefender, ESET, Kaspersky, Fortinet, Ikarus, Emsisoft, DrWeb, F-Secure, GData, Kaspersky, Avira, AVG) all undetected

  2. triggeredHeuristics: MalwareTips.Synth.ProcessInjection (T1055, CreateRemoteThread into svchost.exe) and MalwareTips.Synth.CredentialDumper (LSASS access) — offensive techniques present but no malicious sandbox verdict

  3. similarHashes imphash match: 3/5 prior verdicts suspicious (ai:borderline_mixed_signals, ai:signed_but_unusual_behaviour×2); 1 safe (Microsoft-signed); 1 unknown — mixed history, no malicious consensus

  4. signing.verified=false, unsigned; no signer history; filename 'PolarInstaller.exe' with hasInstallerHint=true — installer-shaped but unverified

  5. behaviour.hasMaliciousSandboxVerdict=false; no malicious contacted hosts; no dropped malicious children — runtime behaviour did not trigger malicious consensus despite offensive techniques

Points in its favour
  • Zero tier-1 antivirus detections across 17 high-trust engines (Avast, BitDefender, ESET, Kaspersky, Fortinet, etc.)
  • No malicious sandbox verdict issued despite offensive techniques observed
  • No malicious contacted hosts or dropped malicious children
  • Filename and metadata consistent with legitimate installer (hasInstallerHint=true, no brand mismatch)
Points against
  • Process injection (T1055) into system process (svchost.exe) — typical of malware evasion
  • LSASS credential-dumping activity (T1547.001, T1562.001) — hallmark of credential-stealing malware
  • Unsigned executable — no publisher verification
  • 1 day old, medium prevalence — could be newly-distributed malware or legitimate software not yet widely known
  • Triggered heuristics for process injection and credential-dumper patterns
What to do

Do not execute this file unless you can verify its source and legitimacy directly with the publisher. If you received it from an untrusted source, delete it. If you believe it is legitimate, contact the publisher or run it in an isolated sandbox environment before allowing it on production systems.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
23

Adversary techniques mapped to the MITRE ATT&CK framework.

T1012T1027T1033T1047T1055T1057T1059T1070T1070.006T1071T1082T1083T1106T1112T1124T1129T1496T1497T1547.001T1562T1562.001T1573T1574
Spawned processes
10
$(unnamed)
"C:\Users\<USER>\Desktop\PolarInstaller_6.0.2.exe"
$(unnamed)
C:\Windows\system32\services.exe
$(unnamed)
C:\Windows\System32\svchost.exe -k NetworkService -p
$(unnamed)
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
$(unnamed)
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
$(unnamed)
C:\Windows\system32\lsass.exe
$(unnamed)
C:\Windows\system32\svchost.exe -k LocalService -s W32Time
$(unnamed)
"C:\Users\user\Desktop\PolarInstaller_6.0.2.exe" -install
+2 more processes captured.
Filesystem & mutexes
5
Files written3
  • C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
  • C:\Windows\System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
  • C:\Users\user\AppData\Roaming
Mutexes created2
  • \Sessions\1\BaseNamedObjects\Local\__DDrawExclMode__
  • \Sessions\1\BaseNamedObjects\Local\__DDrawCheckExclMode__
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

2 synthesis
MITRE ATT&CK profile
Defense evasion× 1Cred access× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    C:\Windows\System32\svchost.exe -k NetworkService -p
  • CredentialDumpermedium

    Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.

    Evidence
    C:\Windows\system32\lsass.exe
Antivirus engine breakdown

0 detections across 75 engines

0 malicious0 suspicious75 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 75 engines report this file as clean.
Hash de6a60745bc1… cross-referenced against 75 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 7.66Unpacked
Section entropy3 sections
.text
6.36
.rsrc
5.80
.reloc
0.10
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
6
Moderate upload volume.
Total submissions
7
Includes repeat uploads by the same source.
First seen by VT
0d ago
Jun 8, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
6/8/2026, 5:36:08 PM
First seen (MalwareBazaar)
Last analysis (VT)
6/9/2026, 2:31:01 AM
Scanned here
6/9/2026, 11:56:34 AM
File name
PolarInstaller.exe
Size
2.81 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
de6a60745bc1023d157bd72c0d80142a74826f7ad9c1f7d1cc1b0571d2a85dac
MD5
7b4280b8c7b875e4574bcfca797d0741
SHA-1
c5724a55f8154b94ff0d6cf31cc52909db34cc07
PE imphash
f34d5f2d4577ed6d9ceec516c1f5a744
First seen (VT)
6/8/2026, 5:36:08 PM
Last analysis (VT)
6/9/2026, 2:31:01 AM
First scan (MalwareTips)
6/9/2026, 11:56:34 AM
Last scan (MalwareTips)
6/9/2026, 11:56:34 AM
Behavior tags
assemblysignedoverlaydetect-debug-environmentidleinvalid-signaturepeexe
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Scanned by
harlan4096Staff
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.