Is HackerAI-windows-x64.exe safe?
Only VBA32 detected the signed installer, but reported process-injection and LSASS-related activity warrants caution despite otherwise reassuring scan and network evidence.
Only 1 of 74 engines flagged this file, with no tier-1 detections, so the isolated Trojan.Win32.Evasion label is likely a false positive. However, one sandbox run mapped activity to process injection, token manipulation, data destruction, and LSASS access, while the verified signer has no established history; avoid running it until its source is confirmed.
0e76a606122317da33…c8eb276a0cb099Recommended next actions
Before running
Do not run it until the source and publisher can be verified independently.
If you already ran it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the developer's official site or an official app store.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Only 1 of 74 engines flagged this file, with no tier-1 detections, so the isolated Trojan.Win32.Evasion label is likely a false positive. However, one sandbox run mapped activity to process injection, token manipulation, data destruction, and LSASS access, while the verified signer has no established history; avoid running it until its source is confirmed.
The antivirus result is largely reassuring: VBA32 was the only detector among 74 engines, and all 17 tier-1 engines were silent. The executable has a valid HACKERAI LLC signature, but that publisher is neither curated nor supported by historical sample statistics. Runtime evidence raises the main concern because it maps activity to T1055, T1134, and T1485 and reports LSASS-related process activity. Conversely, the completed sandbox did not issue a malicious verdict, all three observed domains received full host-reputation coverage without a cache hit, and no inspected child was identified as malicious. The three YARA rules merely identify NSIS and certificate structures, so they do not independently corroborate a malware family. These conflicting signals support caution rather than treating the lone detection as conclusive.
What We Detected
VBA32 was the only engine among 74 to flag the file, labeling it Trojan.Win32.Evasion. No tier-1 engine detected it, and no engine consensus identified a specific malware family. The file carries a verified HACKERAI LLC signature, but the publisher is not on the curated trusted list and has no recorded sample history.
Threat Behavior
One completed sandbox run mapped activity to T1055 (Process Injection), T1134 (Access Token Manipulation), and T1485 (Data Destruction). A heuristic also associated process activity with LSASS, which can indicate credential-access behavior, although the available record does not prove memory dumping. The sandbox itself returned a clean assessment. All three observed domains were covered by the host-reputation check without malicious or suspicious cache matches, and none of the ten inspected children was identified as malicious; however, those child files remain individually unclassified.
What To Do Now
Verify that the download came directly from the publisher's official release channel and confirm the HACKERAI LLC signature in Windows before execution. Keep endpoint protection enabled, and if the source or signature cannot be independently verified, quarantine or remove the file rather than testing it on a production system.
Where this verdict could be wrong4 caveats
- All 17 tier-1 engines reported no detection, and VBA32 supplied the only malicious result among 74 engines.
- The completed sandbox labeled the run clean, and contactedHosts inspected all 3 observed domains without a malicious or suspicious cache hit.
- The three YARA matches identify an NSIS installer and digital certificate rather than a malware family.
- The signature verifies as 'HACKERAI LLC', but there is no historical signer record to establish whether this publisher is consistently trustworthy.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 1 of 74 engines detected the sample, and that detector is low-trust.
- All 17 tier-1 engines reported no detection.
- The HACKERAI LLC code signature verifies successfully.
- The sandbox did not return a malicious verdict.
- All 3 observed domains were checked with no malicious or suspicious host-cache hits.
- Runtime mapping includes T1055 process injection.
- Runtime mapping includes T1134 access-token manipulation.
- Runtime mapping includes T1485 data destruction.
- A heuristic reports LSASS-related process activity.
- HACKERAI LLC has no historical signer statistics.
- The file was first observed only 39 days ago.
Do not execute the file unless its official source and HACKERAI LLC signature are independently confirmed. Keep endpoint protection enabled and quarantine it if verification fails.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Complete3 contacted hosts were cross-checked.
YARA
Complete6 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 21MITRE ATT&CK techniques
- 11spawned processes
- 3network contacts
- 23filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Changed an auto-start location that can make code run after sign-in or restart.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
HackerAI-windows-x64.exe
0e76a606122317da3345f986c0c4e02ac8b49c36e9328ab1a8c8eb276a0cb099
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\HackerAI-windows-x64.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\Explorer.EXE
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
nskF175.tmp
C:\Users\<USER>\AppData\Local\Temp\nskF175.tmp
04Isolated runtime analysis - Written fileObserved
System.dll
C:\Users\<USER>\AppData\Local\Temp\nsaF186.tmp\System.dll
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
cl-glcb907925.gcdn.co
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
eip-terr-na.cdp1.digicert.com.akahost.net
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- cl-glcb907925.gcdn.co
- eip-terr-na.cdp1.digicert.com.akahost.net
- nexusrules.officeapps.live.com
- HKEY_CURRENT_USER\Software\Classes\hackerai\(Default)
- HKEY_CURRENT_USER\Software\Classes\hackerai\DefaultIcon\(Default)
- HKEY_CURRENT_USER\Software\Classes\hackerai\shell\open\command\(Default)
- HKEY_CURRENT_USER\SOFTWARE\hackerai\HackerAI\(Default)
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HackerAI\MainBinaryName
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HackerAI\DisplayName
- C:\Users\<USER>\AppData\Local\Temp\nskF175.tmp
- C:\Users\<USER>\AppData\Local\Temp\nsaF186.tmp\System.dll
- C:\Users\<USER>\AppData\Local\Temp\nsaF186.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nsaF186.tmp\nsDialogs.dll
- C:\Users\<USER>\AppData\Local\Temp\nsaF186.tmp\nsis_tauri_utils.dll
- C:\Users\<USER>\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\KnownGameList.bin
- C:\Users\<USER>\AppData\Local\Microsoft\GameDVR\KnownGameList.update
- C:\Users\<USER>\AppData\Local\Temp\nssF202.tmp
- C:\Users\<USER>\AppData\Local\Temp\nssF252.tmp
- C:\Users\user\AppData\Local\Temp\nss29D6.tmp
- cversions.3.m
- Global\OneSettingQueryMutex+compat+encapsulation
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 7cf33667ce6512929249…3b2367Never scannednever seen before
- b1350f487692057c8ffd…551fc0Never scannednever seen before
- 9baee42d66f715bba878…b40256Never scannednever seen before
- 8b4c47c4cf5e76ec57dd…90d37cNever scannednever seen before
- 32b74940cc8ed409cc71…bfb404Never scannednever seen before
- 026ac270f4e96c7527ef…08f987Never scannednever seen before
- 55b6057185d070e8baaa…4bff24Never scannednever seen before
- 5ba143b5db4a87d32d6e…ad4709Never scannednever seen before
- 8dda0c6652c5af955805…e7f8adNever scannednever seen before
- d5270ba8e04eb0190a6c…2ffb39Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 6rule hits recorded
- 1 / 74engines flagged
- 143sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
4 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
1 of 74 antivirus engines flagged the file, including VBA32.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The file has a valid code signature from HACKERAI LLC.
ProvenanceObservedSourceCode-signing metadataObserved at - 04
Scanned file: HackerAI-windows-x64.exe — 0e76a606122317da3345f986c0c4e02ac8b49c36e9328ab1a8c8eb276a0cb099
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\HackerAI-windows-x64.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\Explorer.EXE
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: nskF175.tmp — C:\Users\<USER>\AppData\Local\Temp\nskF175.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: System.dll — C:\Users\<USER>\AppData\Local\Temp\nsaF186.tmp\System.dll
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: cl-glcb907925.gcdn.co — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: eip-terr-na.cdp1.digicert.com.akahost.net — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- Detect_NSIS_Nullsoft_Installer
- NSIS
- PE_Digital_Certificate
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeSigned by "HACKERAI LLC" — short generic company CN. Paired with 1 engine hit(s); possible stolen, fraudulent, or reseller-purchased code-signing certificate.
EvidenceHACKERAI LLC
1 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- HackerAI-windows-x64.exe
- Format
- Win32 EXE
- Code signing
- Signature valid: HACKERAI LLC
- Size
- 2.7 MB
- Last analyzed
- Sep 26, 2026, 11:16 AM UTC
0e76a606122317da3345f986c0c4e02ac8b49c36e9328ab1a8c8eb276a0cb099Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't run it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Get a fresh copy from the developer's official site or an official app store.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is HackerAI-windows-x64.exe safe, or is it malware?
What is HackerAI-windows-x64.exe?
How many antivirus engines detected HackerAI-windows-x64.exe?
I already downloaded and ran HackerAI-windows-x64.exe — what should I do?
How do I remove HackerAI-windows-x64.exe?
Is HackerAI-windows-x64.exe digitally signed?
What is the SHA-256 hash of HackerAI-windows-x64.exe?
How up to date is this analysis of HackerAI-windows-x64.exe?
Community
Member reviews and reports for this exact file hash.