File verdict·Decided by the MT AI Engine
Our call

Malicious

Unsigned Themida-packed executable showing process injection, credential dumping, and direct-IP C2 with 13 tier-1 detections.

themida
Trust score12Critical
MT AI confidence · 88%
Ronix-Installer (1).exe
5.4 MB
e8e7e6ed24bd6932c493cdf38634
Antivirus engines
49 of 74 flagged
Code signing
Unsigned
Age
First seen 3mo ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

88%Confidence
Very high
Reasoning

The engine set shows clear tier-1 consensus on a win64 family with 13 high-trust detections and only 3 clean tier-1 results. The file is unsigned and exhibits seven offensive MITRE techniques including credential access and process injection. Direct-IP C2 without DNS usage and a matching Themida YARA rule further support malicious classification. Medium prevalence does not offset the strong detection and behavioural signals.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines.tier1Malicious=13 with tier1FamilyConsensus.strong=true on win64

  2. behaviour.offensiveTechniques=[T1055,T1003,T1555,T1548,T1552.001] and MalwareTips.Synth.ProcessInjection fired

  3. externalIntel.yaraify.rules[0].name=INDICATOR_EXE_Packed_Themida

  4. signing.verified=false and signerStats.found=false

  5. file.tags contain themida and popularThreatLabel=trojan.themida/misc

Points in its favour
  • No malicious dropped children detected
  • No malicious sandbox verdicts recorded
Points against
  • 13 tier-1 malicious detections with strong family consensus
  • Unsigned executable
  • Themida packing confirmed by YARA and tags
  • Process injection and credential-dumping techniques observed
  • Direct-IP C2 bypassing DNS reputation systems
What to do

Treat as malicious; avoid execution and remove all associated files immediately.

Threat family attribution

themida corroborated by 3 sources

  • 1 YARA rule
    INDICATOR_EXE_Packed_Themida
  • VT (74 engines)
    themida
  • MT AI Engine
    themida
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
23

Adversary techniques mapped to the MITRE ATT&CK framework.

T1003T1005T1010T1012T1027T1027.002T1036T1055T1057T1059T1071T1082T1106T1129T1202T1497T1518.001T1548T1552T1552.001T1555T1555.003T1573
Spawned processes
15
$(unnamed)
C:\Windows\System32\RuntimeBroker.exe -Embedding
$(unnamed)
"C:\Users\<USER>\Desktop\Ronix-Installer.exe"
$(unnamed)
C:\Windows\Explorer.EXE
$(unnamed)
C:\Windows\system32\cmd.exe /c start "" "https://discord.gg/ronixstudios"
$(unnamed)
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument https://discord.gg/ronixstudios
$(unnamed)
"C:\Users\<USER>\Desktop\Ronix.exe"
$(unnamed)
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --do-not-de-elevate --single-argument https://discord.gg/ronixstudios
$(unnamed)
"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-chann…
+7 more processes captured.
Network activity
14
IP addresses14
  • 185.199.108.133
  • 140.82.116.3
  • 162.159.133.234
  • 13.107.226.70
  • 150.171.74.13
  • 162.159.130.233
  • 150.171.110.147
  • 173.194.203.132
  • 13.107.253.70
  • 35.190.80.1
+4 more
Filesystem & mutexes
19
Files written15
  • C:\Users\<USER>\AppData\Roaming\Ronix\Bin\Loader.exe.download
  • C:\Users\<USER>\AppData\Roaming\Ronix\Bin\Loader.exe
  • C:\Users\<USER>\AppData\Roaming\Ronix\Bin\Ronix-Module.dll.download
  • C:\Users\<USER>\AppData\Roaming\Ronix\Bin\Ronix-Module.dll
  • C:\Users\<USER>\Desktop\Ronix.exe.download
+10 more
Files deleted3
  • C:\Users\<USER>\AppData\Roaming\Ronix\Bin\Loader.exe.download
  • C:\Users\<USER>\AppData\Roaming\Ronix\Bin\Ronix-Module.dll.download
  • C:\Users\<USER>\Desktop\Ronix.exe.download
Mutexes created1
  • cversions.3.m
Dropped payload

Files this sample writes at runtime

This file drops 10 children at runtime. None are currently flagged malicious in our cache.

10 unseen
  • f3314853dd50e35c78c50a297fNever scanned
    never seen before
  • ac3706ebbb78cfba74e50aba8fNever scanned
    never seen before
  • bfec2e34583ada7e6af2577b90Never scanned
    never seen before
  • b028630e5de06dc376ef1481d2Never scanned
    never seen before
  • bb8fa7341fb84d9e7fcf8842d5Never scanned
    never seen before
  • 617bf538df6b4ba8c168d5a771Never scanned
    never seen before
  • e23040951e464b53b84b09bc25Never scanned
    never seen before
  • 5557080d062f953443f6af77a4Never scanned
    never seen before
  • 0cf13ed4ab8567b81b796953b2Never scanned
    never seen before
  • d8fee07da968a492fd1bb259c2Never scanned
    never seen before
External threat intelligence

1 corroborating signal from researcher-curated sources

YARAify HIT·1 community rule matchedView on YARAify
  • INDICATOR_EXE_Packed_Themidaby ditekSHen
    Detects executables packed with Themida
Cross-referenced against MalwareBazaar (abuse.ch), YARAify, and the CIRCL hashlookup reference DB.
Signature matches

YARA + heuristic rules that fired

A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.

1 YARAify3 synthesis
MITRE ATT&CK profile
Defense evasion× 1Cred access× 1C2× 1
YARAify (community)
Researcher-authored rules via abuse.ch
  • INDICATOR_EXE_Packed_Themida
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • ProcessInjectionhigh

    MITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.

    Evidence
    C:\Windows\Explorer.EXE
  • CredentialDumpermedium

    Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.

    Evidence
    C:\Windows\system32\lsass.exe
  • DirectIpC2medium

    Sample contacted 14 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    185.199.108.133 · 140.82.116.3 · 162.159.133.234
Antivirus engine breakdown

49 detections across 74 engines

49 malicious0 suspicious25 clean
Tier-117 engines
13flag
Top commercial AVs (low FP rate)
Tier-238 engines
22flag
Mainstream engines with mixed FP rates
Low-trust19 engines
14flag
Heuristic / generic-AI engines (high FP rate)
Alibaba
malicious
Trojan:Win64/Themida.d68d34ed
alibabacloud
malicious
VirTool:Win/Wacatac.B9nj
ALYac
malicious
Trojan.GenericKD.79963068
APEX
malicious
Malicious
Arcabit
malicious
Trojan.Generic.D4C423BC
Avast
malicious
Win64:MalwareX-gen [Misc]
AVG
malicious
Win64:MalwareX-gen [Misc]
Avira
malicious
TR/W64.Agent
BitDefender
malicious
Trojan.GenericKD.79963068
Bkav
malicious
W32.Malware.124015EF
CrowdStrike
malicious
win/malicious_confidence_100% (W)
CTX
malicious
exe.trojan.themida
Cylance
malicious
Unsafe
Cynet
malicious
Malicious (score: 99)
Elastic
malicious
malicious (high confidence)
Emsisoft
malicious
Trojan.GenericKD.79963068 (B)
ESET-NOD32
malicious
Win64/Packed.Themida.L suspicious application
F-Secure
malicious
Trojan.TR/W64.Agent
Fortinet
malicious
Riskware/Application
GData
malicious
Trojan.GenericKD.79963068
Google
malicious
Detected
Gridinsoft
malicious
Trojan.Heur!.032100A3
K7AntiVirus
malicious
Unwanted-Program ( 005ce11a1 )
K7GW
malicious
Unwanted-Program ( 005ce11a1 )
Lionic
malicious
Trojan.Win32.Themida.4!c
Malwarebytes
malicious
Trojan.MalPack
MaxSecure
malicious
Trojan.Malware.328690006.susgen
McAfeeD
malicious
ti!E8E7E6ED24BD
Microsoft
malicious
Trojan:Win32/Kepavll!rfn
MicroWorld-eScan
malicious
Trojan.GenericKD.79963068
Paloalto
malicious
generic.ml
Panda
malicious
Trj/Agent.FUM
Rising
malicious
Trojan.Kryptik@AI.82 (RDML:cPdQS/2ap7SL041Cj/L21w)
Sangfor
malicious
Suspicious.Win32.Save.a
SentinelOne
malicious
Static AI - Malicious PE
Skyhigh
malicious
BehavesLike.Win64.Dropper.tc
Sophos
malicious
Mal/Generic-S
tehtris
malicious
Generic.Malware
Trapmine
malicious
suspicious.low.ml.score
TrellixENS
malicious
Artemis!00E7C93D6108
TrendMicro
malicious
Trojan.Win32.ZYX.USBLEA26
TrendMicro-HouseCall
malicious
Trojan.Win32.ZYX.USBLEA26
Varist
malicious
W64/ABRisk.TUVN-3775
VIPRE
malicious
Trojan.GenericKD.79963068
ViRobot
malicious
Trojan.Win.Z.Agent.5610520
Webroot
malicious
W32.Malware.gen
Yandex
malicious
Riskware.Themida!tbySao0a58I
Zillya
malicious
Trojan.Themida.Win64.20656
Zoner
malicious
Probably Heur.ExeHeaderL
Hash e8e7e6ed24bd… cross-referenced against 74 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

Unpacked
Section entropy10 sections
(unnamed)
7.98
(unnamed)
7.97
(unnamed)
7.91
(unnamed)
7.68
(unnamed)
2.58
(unnamed)
7.07
(unnamed)
7.95
.imports
3.22
.rsrc
4.72
.themida
0.00
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
2,695
Hundreds of people have uploaded this — common.
Total submissions
3,412
Includes repeat uploads by the same source.
First seen by VT
3mo ago
Apr 19, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
4/19/2026, 2:38:06 PM
First seen (MalwareBazaar)
Last analysis (VT)
7/2/2026, 10:06:05 AM
Scanned here
7/3/2026, 2:05:00 PM
File name
Ronix-Installer (1).exe
Size
5.35 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
e8e7e6ed24bd6932c402828334cdb17d08eb4ce9b2afc30b49b73e93cdf38634
MD5
00e7c93d610841d179eb75683b05f1f7
SHA-1
fa51d17b3e8edc2315341f46c72201fa3506b564
PE imphash
cfaae10b77b9dd6fdce0b44fb5150a2f
First seen (VT)
4/19/2026, 2:38:06 PM
Last analysis (VT)
7/2/2026, 10:06:05 AM
First scan (MalwareTips)
7/3/2026, 2:05:00 PM
Last scan (MalwareTips)
7/3/2026, 2:05:00 PM
Community reputation
-1flagged
Behavior tags
corrupt64bitsdetect-debug-environmentthemidaspreaderpeexe
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.