File verdict·Evidence-based file assessment

Our call: Is JOAT(DEMOBUILD).exe safe?Malicious

Do not run this file
18Safety ratingHigh risk
Wacatac
Evidence snapshot
  • 2 of 75 antivirus engines flagged the file, including Microsoft and Symantec.Observed · Antivirus analysis
  • The hash has been submitted 3 times from 1 source.Derived · Saved report facts
JOAT(DEMOBUILD).exe
2.8 MB
1eea7acbe25fa162f14ceace75af
Antivirus
2 of 75 flagged
Sandbox
Runtime complete
Code signing
Unsigned
First seen
First-seen today
01

Before running

Do not run it. Delete the file from the device.

02

If you already ran it

Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.

Scan transparency

Coverage & freshness

4 of 5 complete

Complete means the check returned a usable result. It does not mean the file is safe.

  • Antivirus

    Complete

    2 of 75 engines flagged the file.

  • Sandbox

    Complete

    1 isolated runtime environment contributed observations.

  • Network

    Not run

    No contacted-host reputation check is recorded.

    No timestamp recorded
  • YARA

    Complete

    Rule evaluation completed with no recorded matches.

  • External intel

    Complete

    3 of 3 independent reference sources completed.

Recorded behavior

Attack story

Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.

ObservedDerived

4 recorded facts from one runtime window. Every fact remains independently traceable in the evidence ledger below.

Evidence provenance

Why these facts are shown

Each statement identifies whether it was directly recorded or derived from saved scan facts.

  1. 01

    2 of 75 antivirus engines flagged the file, including Microsoft and Symantec.

    Verdict inputView chapter
    ProvenanceObserved
    SourceAntivirus analysis
    Observed at
  2. 02

    The hash has been submitted 3 times from 1 source.

    ProvenanceDerived
    SourceSaved report facts
    Observed at
  3. 03

    Scanned file: JOAT(DEMOBUILD).exe — 1eea7acbe25fa162f1dd4a1fef0575d53b1d273226280a54b917db4ceace75af

    ProvenanceObserved
    SourceUploaded file
    Observed at
  4. 04

    Observed process — C:\Windows\system32\cmd.exe /c bcdedit /set testsigning on

    ProvenanceObserved
    SourceIsolated runtime analysis
    Observed at
  5. 05

    Observed process — bcdedit /set testsigning on

    ProvenanceObserved
    SourceIsolated runtime analysis
    Observed at
  6. 06

    File written: Connect — \Device\ConDrv\\Connect

    ProvenanceObserved
    SourceIsolated runtime analysis
    Observed at
Chapter 02

Intelligence

The complete saved assessment, kept intact and grounded in the scan evidence.

No saved analyst narrative

This report keeps the verified scan facts available below without inventing an analysis that was not saved with the scan.

Chapter 03

Behavior

Plain-English impact first, then the observed runtime evidence.

What this file does

Observed actions and their security significance

  • High concern: Attempted to remove recovery data such as backups or shadow copies.

  • High concern: Attempted to impair or bypass security controls.

These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.

Threat context

How info-stealers work

An info-stealer runs quietly in the background and copies your private data — saved passwords, browser cookies, autofill details, and crypto wallets — then sends it to criminals. You usually won't notice anything is wrong.

Bottom line:Stolen logins are used to break into your accounts or sold in bulk on criminal markets.

Chapter 04

Detection & Forensics

Consensus, attribution, signatures, code structure, prevalence, and identity.

Chapter 05

Safety & FAQ

Complete recovery guidance and answers for the next decision.

What to do now

This file is dangerous. Treat it as harmful and remove it.

  1. Don't run this file. Delete it from your Downloads (or wherever you saved it), then empty the Recycle Bin.

  2. If you already ran it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.

  3. If any of your files were locked or renamed, do NOT pay the ransom — payment rarely restores files. Recover them from a backup instead.

  4. Get a fresh copy from the developer's official site or an official app store.

Frequently asked

Safety FAQ

  • Yes — JOAT(DEMOBUILD).exe is malicious, so do not run it, and delete it. 2 of 75 antivirus engines flag it (family: Wacatac). It behaves as an information stealer/spyware, built to harvest passwords, cookies, and wallet data. If you've already run it, see the removal and recovery steps below.
The raw file is processed temporarily and is not retained after processing. Its hash and report are public and permanent, so the next person who checks the same file gets an instant answer. Unknown files may be submitted to VirusTotal for analysis. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.