Is i3cperxt.exe safe?Suspicious
Unsigned executable disguised as a Word document with zero detections but extreme rarity.
- No completed runtime observation is available for this file.
- 0 of 74 antivirus engines flagged the file.
- The hash has been submitted 1 time from 1 source.
193ed51d140ba79d40…f52e34c69fBefore opening
Do not run it until the source and publisher can be verified independently.
If you already ran it
Close it, scan the device, and watch for unexpected processes or security alerts.
Coverage & freshness
A completed check means the source returned a result. It does not, by itself, guarantee that the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
No completed runtime observation is available for this file.
Runtime coverageView chapterDerived - 02
0 of 74 antivirus engines flagged the file.
Antivirus analysisView chapterObserved - 03
The hash has been submitted 1 time from 1 source.
Saved report factsView chapterDerived
Intelligence
The complete saved assessment, kept intact and grounded in the scan evidence.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The file presents as an Office Open XML document yet carries an .exe extension and is unsigned. No engine flagged it, but the combination of brand-new submission, missing signature, and filename mismatch warrants caution.
Zero detections across 74 engines is reassuring, yet the file is only hours old, has never been seen before, and is unsigned while masquerading as a document. The .exe extension on a docx file type is a classic delivery trick. Without signer history or prior benign samples, the risk cannot be dismissed.
What We Detected
74 engines scanned the sample; none returned a malicious, suspicious, or PUA label. The file metadata declares an Office Open XML Document, yet the submitted name ends in .exe and the payload is unsigned.
Threat Behavior
No sandbox execution data, dropped children, or contacted hosts are available. External intelligence sources (CIRCL, MalwareBazaar, YARAify) contain no matching rules or prior sightings.
What To Do Now
Do not open the file. If the document is expected from a trusted sender, request a re-submission with a correct .docx extension and digital signature. Otherwise treat it as potentially weaponised and delete or quarantine it.
Where this verdict could be wrong1 caveat
- Filename extension mismatch could be a packaging error rather than malice, but the combination of unsigned + rare_new + docx-vs-exe still outweighs that possibility.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Zero engine detections
- No malicious external-intel hits
- Filename claims executable while file type claims document
- Unsigned and brand new
- No prior benign history
Quarantine the file and request a properly signed, correctly named copy from the sender before any further handling.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 74 engines flagged this file
View all 74 engine results
PE structure
Not runThis looks like a Windows executable, but no completed PE structure result is saved.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. That limits reputation evidence, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- i3cperxt.exe
- Format
- Office Open XML Document
- Code signing
- No verified publisher
- Size
- 5.9 MB
- Last analyzed
- Jul 24, 2026, 12:43 AM UTC
193ed51d140ba79d4036bf57bd49ab4f40ce83456089dce8c5b91af52e34c69fSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
Don't run it unless you're certain it came from a source you trust.
Check where you got it — an email attachment or a random download link is a red flag.
If you're unsure, delete it. You can always re-download a clean copy from the official source.
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
- i3cperxt.exe is suspicious — treat it as unsafe until you're sure. 0 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't run it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
- i3cperxt.exe is a Windows executable program, about 5.9 MB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
- None — 0 of 74 antivirus engines flagged i3cperxt.exe. That's reassuring, though it is not proof that a file is safe, so we also weigh its behaviour, identity, and reputation.
- Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
- To remove i3cperxt.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original i3cperxt.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
- The SHA-256 hash of i3cperxt.exe is 193ed51d140ba79d4036bf57bd49ab4f40ce83456089dce8c5b91af52e34c69f, and its MD5 is c7cf8b18530228c4c2447f0811896361. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on July 24, 2026. Because a file's hash never changes, the identity of i3cperxt.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.