Safe
Legitimate Core Temp installer signed by ALCPU with only a single low-trust grayware flag and clean sandbox behaviour.
26e9a2b20608f00f43…078d9b5606The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The single malicious detection comes from a low-trust engine with a generic grayware label and no tier-1 support. The file is properly signed by ALCPU, shows typical Inno-Setup installer behaviour (process injection, persistence, direct-IP contact during install), and has no malicious dropped children or sandbox verdicts. Prevalence is high (common_new) with explicit researcher confirmation of no threat. These factors outweigh the heuristic triggers.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines.onlyLowTrustFlagging=true and tier1Malicious=0 (CrowdStrike grayware only)
signing.verified=true signer=ALCPU
prevalence.classification=common_new (1507 submitters)
communityComments: FileScan.IO NO_THREAT 100/100 installer tags
behaviour.hasMaliciousSandboxVerdict=false and droppedChildren.hasMaliciousChild=false
- Verified signature by ALCPU
- High prevalence common_new
- Zero tier-1 malicious detections
- Clean sandbox and dropped children
Treat as safe; install only from the official ALCPU/Core Temp website.
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 192.185.41.230
- 162.159.36.2
- http://www.alcpu.com/CoreTemp/coretempver.xml
- ALSysIO
- C:\Users\<USER>\AppData\Local\Temp\is-MTBFD.tmp\program.tmp
- C:\Users\<USER>\AppData\Local\Temp\is-B3DT5.tmp\_isetup\_setup64.tmp
- C:\Program Files\Core Temp\Core Temp.exe
- C:\Program Files\Core Temp\unins000.dat
- C:\Program Files\Core Temp\is-4OLTM.tmp
- C:\Program Files\Core Temp\is-4OLTM.tmp
- C:\Program Files\Core Temp\is-ND3OM.tmp
- C:\Program Files\Core Temp\is-I6DOS.tmp
- C:\Program Files\Core Temp\is-U5VO0.tmp
- C:\Program Files\Core Temp\is-QF1AU.tmp
- cversions.3.m
- DebugHelper
- Global\Access_PCI
- Global\Access_APIC_Clk_Measure
- Global\Access_Intel_OC_Mailbox
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 9557fc1335568b246176…7db8a7Never scannednever seen before
- 0b15b30d1cee7aa1196b…9bc244Never scannednever seen before
- c2915702e142fa0da987…acf7ffNever scannednever seen before
- b4b2afd4eb3c7c7de0a2…5342fcNever scannednever seen before
- 673296a2ccf2322dc0be…b76493Never scannednever seen before
- 86cf59301dbc6f1eca8c…d1d51aNever scannednever seen before
- 88c7ffcca9585da2984a…13f500Never scannednever seen before
- c142c01eefa9d341543e…a956d0Never scannednever seen before
- f03c7d416242a4eee9e9…cb57f5Never scannednever seen before
- cd6c153ba40f50a290d1…97c07dNever scannednever seen before
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
Sandbox flagged persistence indicators (registry Run keys / services / scheduled tasks).
EvidenceALSysIOMITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeSample contacted 2 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence192.185.41.230 · 162.159.36.2
1 detection across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.
Forensic fingerprint
- File name
- Core-Temp-setup-v1.20.1.150.exe
- Size
- 1.61 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 26e9a2b20608f00f43a44d0f7fa57e70a832087c3d4a9aa1d8dc73078d9b5606
- MD5
- 7edd792d56093efe9b7ad08fe3dcaf13
- SHA-1
- 6159262aceeb14716e9027e99a2a3b12eb95d7e8
- PE imphash
- 20dd26497880c05caed9305b3c8b9109
- First seen (VT)
- 5/2/2026, 7:03:53 AM
- Last analysis (VT)
- 5/26/2026, 4:53:46 AM
- First scan (MalwareTips)
- 5/26/2026, 8:44:40 AM
- Last scan (MalwareTips)
- 5/26/2026, 8:44:40 AM
- Code signer
- ALCPUverified
- Community reputation
- +4trusted
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.