Safe
Legitimate signed CurseForge installer from Overwolf Ltd with one low-trust AV flag and no supporting tier-1 detections or malicious behavior.
2322168b25cad7c8cd…9acf590040The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
With zero tier-1 malicious detections and onlyLowTrustFlagging=true from DeepInstinct, this matches a common false positive pattern. The verified Overwolf Ltd signature aligns perfectly with the CurseForge installer filename, despite a low-severity heuristic noting the generic CN. Behavior shows typical installer techniques (T1134 among ambient ones) but nothing malicious in sandboxes or contacts. No external intel, RAG, or drops reinforce safety for this rare_new file.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
DeepInstinct (low_trust) single malicious detection; 17/17 tier1ReportedClean
signing.signer='Overwolf Ltd'; verified=true; filenameAnalysis.hasInstallerHint=true
behaviour.mitreTechniques includes T1134 (offensive) but no malicious sandboxVerdicts or contactedHosts.maliciousHosts
triggeredHeuristics[0].rule='MalwareTips.Synth.SuspiciousSignerCN'; fired=true; severity='low'
- Verified Authenticode signature
- 17/17 tier-1 engines clean; no family consensus
- Installer-appropriate filename and MITRE profile
- No malicious behavior, contacts, or drops
- No external intel or YARAify hits
- Single low-trust malicious detection (DeepInstinct)
- New file (ageDays=0, rare_new prevalence)
- Signer 'Overwolf Ltd' has no historical stats; generic CN heuristic
- High overall entropy (7.99) but no packing
This is a safe, legitimate CurseForge installer. Proceed with installation if downloaded from official Overwolf/CurseForge channels; monitor for unexpected behavior.
1 contradiction resolved by the scoring engine
YARA + heuristic rules that fired
Low-severity pattern matches — worth noting but not on their own cause for alarm.
Signed by "Overwolf Ltd" — short generic company CN. Paired with 1 engine hit(s); possible stolen, fraudulent, or reseller-purchased code-signing certificate.
EvidenceOverwolf Ltd
1 detection across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Barely seen in the wild and first surfaced recently. This is the footprint of targeted malware the AV industry hasn't signatured yet — extra scrutiny is warranted.
Forensic fingerprint
- File name
- CurseForge Windows - Installer.exe
- Size
- 2.66 MB
- MIME type
- application/x-msdownload
- Detected type
- Win32 EXE
- SHA-256
- 2322168b25cad7c8cd1d5e2c396da72da4cf2d3e3b72423e5bfc799acf590040
- MD5
- fb6a288aac2548d2c608a3c588d04de8
- SHA-1
- c02bcd9586251f37f91aa378cc9d359d3b9c69ff
- PE imphash
- 56a78d55f3f7af51443e58e0ce2fb5f6
- First seen (VT)
- 5/11/2026, 9:47:03 AM
- Last analysis (VT)
- 5/11/2026, 9:48:16 AM
- First scan (MalwareTips)
- 5/11/2026, 9:47:59 AM
- Last scan (MalwareTips)
- 5/11/2026, 9:50:20 AM
- Code signer
- Overwolf Ltdverified
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.