Safe
Dead Cells game executable; 16 tier-1 engines silent; 615 submissions over 678 days; zero malicious consensus.
06489415f452556dd2…d1763c1e4aThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file exhibits a classic benign-software profile: zero malicious detections across 69 engines, including 16 high-trust vendors (Avast, BitDefender, Kaspersky, ESET-NOD32, Fortinet, F-Secure, Emsisoft, GData, Avira, AVG, DrWeb). Its prevalence classification (common_old, 615 submissions, 678 days) indicates an established, widely-distributed executable. The MITRE techniques observed (T1027, T1056, T1059, T1071, T1082, T1129, T1496, T1497.001, T1574.002) are ambient and consistent with game runtime, anti-cheat, and DRM systems. The MalwareTips.Synth.DirectIpC2 heuristic fired due to direct-IP contact without DNS, but this is routine for game asset delivery and update infrastructure; the absence of any malicious sandbox verdict or contacted-malicious-hosts hits contradicts a C2 interpretation. The filename matches the known Dead Cells indie game title, and no adversarial flags or brand mismatches are present.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
tier1Malicious=0; 16 tier-1 engines (Avast, BitDefender, Kaspersky, ESET-NOD32, Fortinet, F-Secure, Emsisoft, GData, Avira, AVG, DrWeb) all silent
prevalence: common_old, 565 unique submitters, 615 submissions, first seen 2024-08-20 — established benign software
behaviour: 0 offensive MITRE techniques; 9 ambient (T1027, T1056, T1059, T1071, T1082, T1129, T1496, T1497.001, T1574.002) consistent with game runtime
triggeredHeuristics: MalwareTips.Synth.DirectIpC2 fired but is evidence-only; direct-IP contact to CDNs/update servers is benign for games; no malicious sandbox verdict or contacted-hosts hits corroborate C2 interpretation
filename 'deadcells_gl.exe' matches Dead Cells game executable; no adversarial flags; no brand mismatch
- 16 tier-1 antivirus engines (Avast, AVG, Avira, BitDefender, DrWeb, Emsisoft, ESET-NOD32, F-Secure, Fortinet, GData, Kaspersky) all report clean
- Common_old prevalence: 615 submissions, 565 unique sources, 678 days without malicious consensus
- Zero offensive MITRE techniques; 9 ambient techniques consistent with game runtime and anti-cheat systems
- No malicious sandbox verdict; no dropped malicious children; no contacted malicious hosts
- Filename matches known Dead Cells indie game title; no adversarial flags or brand mismatch
This file is safe. It is the legitimate Dead Cells game executable, confirmed by zero malicious detections across 69 engines and 678 days of benign prevalence. You can download and run it from official sources (Steam, Epic Games Store, GOG, Motion Twin) without concern.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- a83f:8110:bf9a:62ff:c29b:64ff:c39e:66ff
- 192.168.0.45
- 23.216.81.152
- 192.168.0.43
- 184.27.218.92
- 192.168.0.1
- 192.168.0.64
- 20.99.133.109
- 23.55.140.42
- 23.215.176.123
- \Device\ConDrv\\Connect
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 11 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidencea83f:8110:bf9a:62ff:c29b:64ff:c39e:66ff · 23.216.81.152 · 184.27.218.92
0 detections across 74 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- deadcells_gl.exe
- Size
- 17.24 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 06489415f452556dd2fd6e211924934a6d94b440e92afd2add0720d1763c1e4a
- MD5
- bcbfc2b945878d591b8cadd76d0cbafc
- SHA-1
- 5682ca5c8dce80e024896ad0db6e9e2bf3d3054a
- PE imphash
- 6f3a01b9e56529b5162f87102fb6271c
- First seen (VT)
- 8/19/2024, 9:56:08 PM
- Last analysis (VT)
- 6/23/2026, 1:07:18 AM
- First scan (MalwareTips)
- 6/29/2026, 9:49:33 AM
- Last scan (MalwareTips)
- 6/29/2026, 9:49:33 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.