Malicious
Signed MSI loader detected as ValleyRAT by multiple engines and community intel, with Defender tampering, process injection, and suspicious YARA hits confirming malicious loader behavior.
e17d12a3cb758a7cd5…bb91216fc4The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
A single tier-1 engine (Kaspersky) flags it as a loader alongside tier-2 ValleyRAT detection, bolstered by high-severity heuristics for Defender tampering and process injection. YARAify's 5 rule matches, including MSI LATAM Banker, align with community MalwareBazaar tagging as ValleyRAT. The clean tier-1 majority and lack of sandbox consensus provide some counterweight, but offensive MITRE techniques and direct IP contacts override. No signer history raises stolen certificate concerns for this new file.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
Kaspersky tier1 'Trojan.Win32.Loader.rmg'
Lionic 'Trojan.UKP.ValleyRAT.4!c'
triggeredHeuristics 'MalwareTips.Synth.DefenderTamper' fired high severity (powershell Add-MpPreference exclusion)
yaraify.rules 'Detect_MSI_LATAM_Banker_From_LatAm'
communityComments[0] MalwareBazaar ValleyRAT signature
- Valid Authenticode signature verified
- 16 tier-1 engines undetected
- No known malicious dropped children
- No malicious contacted hosts
- Disables Windows Defender real-time protection
- Process injection into legitimate explorer.exe
- LSASS memory access (credential dumping risk)
- Direct IP connections evading DNS blocks
- YARA matches for MSI banker malware
- ValleyRAT confirmed by community intel
Treat as confirmed malware: delete the file, run a full system scan with updated security software, and monitor for persistence from dropped files like GGSafe.exe. Avoid running disguised installers from untrusted sources.
loader corroborated by 3 sources
- 5 YARA rulesDebuggerCheck__API, DebuggerCheck__QueryInfo, Detect_MSI_LATAM_Banker_From_LatAm
- VT (75 engines)loader
- MT AI EngineValleyRAT
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 137.220.134.149
- 8.8.8.8
- 104.18.38.233
- 162.159.36.2
- http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQxgVcNvGEc6k3cMc%2F61dwEft%2FHpwQUz30soJB6mB3dtl6FwuDaFXHS5V4CEDd0Q0%2BetA4iH5I2yh8vJxc%3D
- http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQ9o3URkkDosDKNU0YpWwIkGi4lMwQUGnSkONe5tg6zW%2FrcXq4%2FtvBzPYgCEQCZ2JdMHqp76ZZYX%2FLeENOt
- http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQxgVcNvGEc6k3cMc/61dwEft/HpwQUz30soJB6mB3dtl6FwuDaFXHS5V4CEDd0Q0+etA4iH5I2yh8vJxc=
- http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEQDVs2ACiVmif4RlyeaxjbrL
- http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQ9o3URkkDosDKNU0YpWwIkGi4lMwQUGnSkONe5tg6zW/rcXq4/tvBzPYgCEQCZ2JdMHqp76ZZYX/LeENOt
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
- C:\Windows\Temp\~DFE3C20EB448AFCB36.TMP
- C:\Windows\Temp\~DFA417C4F3C073E029.TMP
- C:\Windows\Temp\~DF596CC6CADC6B6EA5.TMP
- C:\Windows\Temp\~DFBA497BF5190069F9.TMP
- C:\Config.Msi\CMPD97.tmp
- C:\Config.Msi
- C:\Config.Msi\CMP313C.tmp
- C:\Config.Msi\f4b2.rbs
- C:\Windows\Installer\f4b0.msi
- Global\_MSIExecute
- Local\SessionImmersiveColorMutex
- cversions.3.m
- MNLG_7799.5oo.im_7799_\x9ed8\x8ba4
- 2026. 4.25
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 96ad1146eb96877eab59…87dcf7Never scannednever seen before
- 948cb902afc324a169e6…294dd3Never scannednever seen before
- 13950b911243e13269ef…5be45eNever scannednever seen before
- 0cae2f454b329fb40864…77b11aNever scannednever seen before
- 0839b5aeb7a4dec2c728…22cd5aNever scannednever seen before
- 834e52e96306bdcf7a78…099444Never scannednever seen before
- 86ba0ba21daad93a03c2…534e79Never scannednever seen before
- 50c03a95e38fc3447faf…4345afNever scannednever seen before
- 260c6250ef9b57dca99b…1200aaNever scannednever seen before
- a519258084f649f1b27d…374d74Never scannednever seen before
1 corroborating signal from researcher-curated sources
- DebuggerCheck__API
- DebuggerCheck__QueryInfo
- Detect_MSI_LATAM_Banker_From_LatAm
- Excel_Hidden_Macro_Sheet
- mht_inside_wordby dPhishDetect embedded mht files inside microsfot word.
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
- DebuggerCheck__API
- DebuggerCheck__QueryInfo
- Detect_MSI_LATAM_Banker_From_LatAm
- Excel_Hidden_Macro_Sheet
- mht_inside_word
Sample disabled Windows Defender real-time protection or added an AV exclusion path. This is the blow-the-doors-off move malware makes right before dropping a second-stage payload.
Evidencepowershell.exe -Command Add-MpPreference -ExclusionPath 'C:\Users\Public\Documents'MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeSample contacted 4 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence137.220.134.149 · 8.8.8.8 · 104.18.38.233
4 detections across 75 engines
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- e17d12a3cb758a7cd55d9e0305bc1471d30a7125cb14f3574d47f1bb91216fc4.msi
- Size
- 20.75 MB
- MIME type
- (unknown)
- Detected type
- Windows Installer
- SHA-256
- e17d12a3cb758a7cd55d9e0305bc1471d30a7125cb14f3574d47f1bb91216fc4
- MD5
- 8a439d79b71266e40b932055916c0ce6
- SHA-1
- d88690194f2f9d6c0f85b675f758b7c9f507c8ef
- First seen (VT)
- 4/27/2026, 3:36:54 AM
- Last analysis (VT)
- 4/28/2026, 7:36:17 AM
- First scan (MalwareTips)
- 4/28/2026, 7:59:18 AM
- Last scan (MalwareTips)
- 4/28/2026, 7:59:18 AM
- Code signer
- MiniTool Software Limitedverified
- Community reputation
- -12flagged
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.