Is SolaraV3.exe safe?
Ten high-trust engines and 43 of 74 overall detect this Sbadur trojan, reinforced by injection-related runtime activity and extensive YARA matches.
The sample has strong, independent Sbadur detections from Microsoft, Kaspersky, TrendMicro, and other high-trust engines. Runtime evidence includes process injection, LSASS targeting, and defense impairment, while the verified signer's entire recorded history consists of harmful samples. Do not run it.
f07e7c06d1a66307bc…678e0735b6ba99Recommended next actions
Before running
Do not run it. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already ran it
Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The sample has strong, independent Sbadur detections from Microsoft, Kaspersky, TrendMicro, and other high-trust engines. Runtime evidence includes process injection, LSASS targeting, and defense impairment, while the verified signer's entire recorded history consists of harmful samples. Do not run it.
Forty-three of 74 engines detected the file, with ten high-trust detections and three high-trust engines agreeing on Sbadur. Microsoft, Kaspersky, and TrendMicro specifically identify the Sbadur family, reducing the likelihood of unrelated generic false positives. The completed sandbox run recorded T1055 process-injection evidence, T1562.001 defense impairment, T1485 data destruction, and activity targeting LSASS. Twenty-two community YARA rules matched, including injection and command-and-control-oriented rules. Although the executable has a verified signature, CMD Softworks LLC is not a trusted publisher and all three recorded samples under that signer were harmful. The observed IP was not fully reputation-checked, but the remaining evidence is already decisive.
What We Detected
43 of 74 antivirus engines flagged SolaraV3.exe. Ten high-trust engines detected it, and three independently converged on the Sbadur family; Microsoft reported Trojan:Win64/Sbadur.AB!MTB, Kaspersky reported UDS:Trojan.Win64.SBadur.gen, and TrendMicro reported Trojan.Win32.SBADUR.USBLHN26.
Threat Behavior
The completed sandbox observation mapped activity to T1055 process injection, T1485 data destruction, and T1562.001 impairment of defenses. Additional evidence indicates activity targeting LSASS, which is associated with credential access. Twenty-two YARA rules matched, including CP_Script_Inject_Detector and command_and_control. One external IP, 150.171.27.11, was contacted, but no complete host-reputation cross-check is available.
What To Do Now
Do not execute the file, and keep endpoint protection enabled. Quarantine or delete it; if it already ran, isolate the affected system, perform a full security scan, review credentials used on that device, and investigate signs of injection or credential access.
Where this verdict could be wrong4 caveats
- signing.verified=true for 'CMD Softworks LLC', but signing.trustedPublisher.matched=false and the same signer's recorded history is 3/3 malicious.
- behaviour.hasMaliciousSandboxVerdict=false and droppedChildren.hasMaliciousChild=false, although all 10 inspected children remain unknown rather than confirmed benign.
- Two tier-1 engines reported the sample clean, and ESET-NOD32 characterized it as a potentially unwanted application rather than a trojan.
- contactedHosts=null, so the observed connection to 150.171.27.11 lacks a completed host-reputation cross-check.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- The executable signature verifies cryptographically
- brandMismatch.detected is not present
- peAnalysis.likelyPacked=false and peAnalysis.highEntropyCode=false
- droppedChildren.hasMaliciousChild=false, though all 10 child verdicts remain unknown
- behaviour.hasMaliciousSandboxVerdict=false
- 43/74 antivirus detections
- 10 high-trust engine detections
- Strong three-engine Sbadur family consensus
- T1055 process-injection evidence
- LSASS-targeting activity
- T1485 and T1562.001 runtime techniques
Quarantine or remove the file without running it, and keep antivirus protection enabled. If execution already occurred, isolate the device and investigate credential exposure, process injection, and defense-tampering activity.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete43 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete9 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 18MITRE ATT&CK techniques
- 15spawned processes
- 1network contacts
- 36filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Used an input-capture technique that can record credentials or keystrokes.
High concern: Attempted to impair or bypass security controls.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
SolaraV3.exe
f07e7c06d1a66307bc38a5b50c3b2a2308ebdbfbb2edcc8132678e0735b6ba99
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\SolaraV3.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\122.0.2365.92\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=SolaraV3.exe --webview-exe-version=0.1.0 --user-data-dir="C:\Users\<USER>\AppData\Local\com.solara.v3\EBWebView" --noerrdialogs --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --autoplay-policy=no-user-gesture-required --disable-features=msWebOOUI,msPdfOOUI,msSmartScreenProtection --enable-features=MojoIpcz --lang=en-US --accept-lang=en-US --mojo-named-platform-channel-pipe=5520.3740.3789665130043430528
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
BIT672C.tmp
C:\Users\<USER>\AppData\Local\Temp\edge_BITS_3812_750879224\BIT672C.tmp
04Isolated runtime analysis - Written fileObserved
86061e48-63b3-483f-8dac-609df0cbb238
C:\Users\<USER>\AppData\Local\Temp\edge_BITS_3812_750879224\86061e48-63b3-483f-8dac-609df0cbb238
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
150.171.27.11
Contact observed during runtime.
06Isolated runtime analysis
6 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 150.171.27.11
- C:\Users\<USER>\AppData\Local\Temp\edge_BITS_3812_750879224\BIT672C.tmp
- C:\Users\<USER>\AppData\Local\Temp\edge_BITS_3812_750879224\86061e48-63b3-483f-8dac-609df0cbb238
- C:\Users\<USER>\Desktop\bin\UIDEBUG.txt
- C:\Users\<USER>\AppData\Local\com.solara.v3\.cookies
- C:\Users\<USER>\AppData\Local\com.solara.v3\EBWebView\Crashpad\throttle_store.dat
- C:\Users\<USER>\Desktop\bin\UIDEBUG.txt
- C:\Users\<USER>\AppData\Local\com.solara.v3\EBWebView\BrowserMetrics-spare.pma
- C:\Users\<USER>\AppData\Local\com.solara.v3\EBWebView\5480d68c-0098-4b14-9ff9-c3beed4729d3.tmp
- C:\Users\<USER>\AppData\Local\com.solara.v3\EBWebView\Default\Code Cache\js\index-dir\the-real-index
- C:\Users\<USER>\AppData\Local\com.solara.v3\EBWebView\Default\Code Cache\wasm\index-dir\the-real-index
- Local\ChromeProcessSingletonStartup!
- __OMADM_NAMED_MUTEX__
- Global\OneSettingQueryMutex+compat+encapsulation
- \Sessions\1\BaseNamedObjects\DBWinMutex
- \Sessions\1\BaseNamedObjects\Local\ChromeProcessSingletonStartup!
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- fbcfe23a2ecb82b7100c…dc0f2dNever scannednever seen before
- 83041e74a4c2db3eb679…5bbb10Never scannednever seen before
- a0c9abae18599f0a65fc…e38e87Never scannednever seen before
- b1e963d702392fb72247…c0cdecNever scannednever seen before
- 5dfc321417fc31359f23…4a2026Never scannednever seen before
- 908c22ae4614580be69f…4ddc9dNever scannednever seen before
- 0f1bad70c7bd1e0a6956…780443Never scannednever seen before
- 4f53cda18c2baa0c0354…02b945Never scannednever seen before
- d2d404074c30a31f4de9…55e3d8Never scannednever seen before
- deba77bc71479c2e98a7…e1c573Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 9rule hits recorded
- 43 / 74engines flagged
- 3,525sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
6 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
43 of 74 antivirus engines flagged the file, including AhnLab-V3 and Alibaba.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The file has a valid code signature from CMD Softworks LLC.
ProvenanceObservedSourceCode-signing metadataObserved at - 04
Scanned file: SolaraV3.exe — f07e7c06d1a66307bc38a5b50c3b2a2308ebdbfbb2edcc8132678e0735b6ba99
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\SolaraV3.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\122.0.2365.92\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=SolaraV3.exe --webview-exe-version=0.1.0 --user-data-dir="C:\Users\<USER>\AppData\Local\com.solara.v3\EBWebView" --noerrdialogs --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --autoplay-policy=no-user-gesture-required --disable-features=msWebOOUI,msPdfOOUI,msSmartScreenProtection --enable-features=MojoIpcz --lang=en-US --accept-lang=en-US --mojo-named-platform-channel-pipe=5520.3740.3789665130043430528
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: BIT672C.tmp — C:\Users\<USER>\AppData\Local\Temp\edge_BITS_3812_750879224\BIT672C.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: 86061e48-63b3-483f-8dac-609df0cbb238 — C:\Users\<USER>\AppData\Local\Temp\edge_BITS_3812_750879224\86061e48-63b3-483f-8dac-609df0cbb238
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 150.171.27.11 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: generic-trojan
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- Check_OutputDebugStringA_iat
- command_and_control
- CP_Script_Inject_Detector
- Detect_Golang_Binary
- DetectEncryptedVariants
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeThe sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence150.171.27.11Signed by "CMD Softworks LLC" — short generic company CN. Paired with 43 engine hit(s); possible stolen, fraudulent, or reseller-purchased code-signing certificate.
EvidenceCMD Softworks LLC
43 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- SolaraV3.exe
- Format
- Win32 EXE
- Code signing
- Signature valid: CMD Softworks LLC
- Size
- 18.4 MB
- Last analyzed
- Sep 20, 2026, 10:59 PM UTC
f07e7c06d1a66307bc38a5b50c3b2a2308ebdbfbb2edcc8132678e0735b6ba99Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't run this file. Delete this file from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already ran it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
From a different, clean device, change the passwords on your important accounts (email and banking first) and turn on two-factor authentication.
- Recovery step 04
Get a fresh copy from the developer's official site or an official app store.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is SolaraV3.exe malware?
What is SolaraV3.exe?
How many antivirus engines detected SolaraV3.exe?
I already downloaded and ran SolaraV3.exe — what should I do?
How do I remove SolaraV3.exe?
What kind of malware is SolaraV3.exe?
Is SolaraV3.exe digitally signed?
What is the SHA-256 hash of SolaraV3.exe?
How up to date is this analysis of SolaraV3.exe?
Community
Member reviews and reports for this exact file hash.