Is CarX-Drift-Racing-Online-Windows-2-18-1-en.exe safe?
The verified Valve-signed installer has 0/75 detections, extensive long-term prevalence, clean corroborating history, and runtime artifacts consistent with installing Steam.
No antivirus engine detected this verified Valve-signed file, including all 17 tier-1 engines. Its extensive history, three matching prior benign decisions, Steam installation artifacts, and fully checked network contacts strongly outweigh the uncorroborated behavioral alerts.
3b616cb0beaacffb53…b251125fb281a1Recommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
No antivirus engine detected this verified Valve-signed file, including all 17 tier-1 engines. Its extensive history, three matching prior benign decisions, Steam installation artifacts, and fully checked network contacts strongly outweigh the uncorroborated behavioral alerts.
The sample received no malicious or suspicious detection from 75 engines, with all 17 tier-1 engines reporting no detection. Its signature verifies to Valve Corp., and the available signer history contains three safe samples and no malicious ones. The file is established commodity software, with 104,950 submissions from 3,750 sources since March 2022, while three relevant similar files were previously assessed as benign. Runtime evidence shows Steam being installed, including SteamService.exe, the Steam startup entry, and Valve registry paths; the completed sandbox did not issue a malicious verdict. Although behavioral mappings mention process injection, LSASS access, ransomware-associated techniques, and two YARA matches, these findings lack independent corroboration and the YARA rules merely identify NSIS and a digital certificate. All 20 distinct observed domains and IPs were covered by the host-reputation check, with none known as malicious or suspicious, and none of the ten inspected dropped children was identified as malicious.
What We Detected
The file is a verified executable signed by Valve Corp. None of 75 antivirus engines flagged it, including all 17 tier-1 engines. It is also widely established: the sample has been submitted 104,950 times by 3,750 sources since March 2022, and three relevant Valve-signed or matching-installer samples previously received benign assessments.
Threat Behavior
The runtime record shows installation and startup activity associated with Steam, including SteamService.exe, Valve registry paths, and a Steam startup entry. Some automated mappings associated activity with T1055, LSASS access, persistence, and destructive techniques such as T1485 and T1486; however, the completed sandbox issued no malicious verdict, and no engine corroborated those alerts. The two YARA matches identify an NSIS installer and a digital certificate rather than a malware family. Reputation coverage included all 20 distinct observed domains and IPs, with no malicious or suspicious hosts, while ten inspected dropped files produced no malicious child finding.
What To Do Now
Prefer obtaining Steam and games from the official Steam client or the publisher's authorized channel, especially because the filename appears to advertise a game rather than Steam itself. Keep endpoint protection enabled and verify that the file's digital signature still reports Valve Corp. before running it.
Where this verdict could be wrong4 caveats
- behaviour.offensiveTechniques includes T1055, T1485, T1486, T1547.001, and T1562.001, although the sole sandbox verdict was clean and the recorded artifacts primarily describe Steam installation.
- MalwareTips.Synth.CredentialDumper reports an LSASS-related process indicator, but the payload provides no corroborating malicious sandbox verdict or engine detection.
- externalIntel.yaraify.ruleCount=2, but the matching rules are 'Detect_NSIS_Nullsoft_Installer' and 'PE_Digital_Certificate', which identify installer and signing structure rather than a malware family.
- Two community annotations characterize the sample as suspicious or threatening, but they have zero votes and conflict with 0/75 engine detections, the verified Valve signature, and established prevalence.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 engines reported malicious or suspicious results.
- All 17 tier-1 engines reported no detection.
- The digital signature verifies to 'Valve Corp.'.
- Prevalence records 104,950 submissions from 3,750 sources since 2022.
- Three of three relevant similar hashes have prior safe verdicts.
- behaviour.offensiveCount=9 includes T1055, T1485, T1486, T1547.001, and T1562.001.
- MalwareTips.Synth.CredentialDumper records an LSASS-related process indicator without independent corroboration.
- The filename advertises a specific game while runtime artifacts primarily install or update Steam.
- Two zero-vote community annotations characterize the hash as suspicious or threatening.
Use the official Steam client or an authorized publisher source when possible, and confirm the Valve Corp. signature before execution. Keep antivirus and endpoint protection enabled.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial20 of 40 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete5 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 37MITRE ATT&CK techniques
- 15spawned processes
- 60network contacts
- 40filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- media.steampowered.com
- client-update.steamstatic.com
- r12.c.lencr.org
- query.prod.cms.rt.microsoft.com
- www.microsoft.com
- res.public.onecdn.static.microsoft
- ax-0001.ax-msedge.net
- windowsupdatebg.s.llnwi.net
- windows.msn.com.edgesuite.net
- a1062.dscd.akamai.net
- 23.205.106.180
- 199.232.211.82
- 104.18.20.213
- 23.216.147.64
- a83f:8110:2d01:0:e807:f99e:2d01:0
- a83f:8110:7400:7400:7500:7000:6500:6c00
- 23.216.147.76
- a83f:8110:0:0:100:0:1800:0
- 13.107.4.50
- a83f:8110:4000:0:0:0:0:0
- http://media.steampowered.com/client/steam_client_win32
- http://media.steampowered.com/client/tenfoot_images_all.zip.vz.193cb8c4eb4446698ea2c0a9e8c4e6b6a623dac7_5572671
- http://media.steampowered.com/client/steamui_websrc_all.zip.vz.26a3a67dfbfa1e1de01fd9d5372314de906efd81_25030895
- http://media.steampowered.com/client/resources_misc_all.zip.vz.e86a975545f3ab21a77373870cb311ef93934b8c_2224876
- http://media.steampowered.com/client/resources_hidpi_all.zip.vz.3de815c3117712cb9eeb7ea4c8b275faf481dcfd_56342
- http://media.steampowered.com/client/resources_all.zip.vz.3c8b3203e5c69d75ea0684c2409b86fe4d0d6f83_2856188
- Steam Client Service
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Steam
- HKEY_CURRENT_USER\SOFTWARE\Valve\Steam\Language
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Valve\Steam\Language
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Steam
- HKEY_CURRENT_USER\SOFTWARE\Valve\Steam\SteamInstaller
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Valve\Steam\NSIS\Path
- HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Valve\Steam\InstallPath
- C:\Users\<USER>\AppData\Local\Temp\nskD811.tmp
- C:\Users\<USER>\AppData\Local\Temp\nspD831.tmp\System.dll
- C:\Users\<USER>\AppData\Local\Temp\nspD831.tmp\modern-header.bmp
- C:\Users\<USER>\AppData\Local\Temp\nspD831.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nspD831.tmp\nsDialogs.dll
- C:\Users\<USER>\AppData\Local\Temp\nspD831.tmp\modern-header.bmp
- C:\Users\<USER>\AppData\Local\Temp\nspD831.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nspD831.tmp\nsDialogs.dll
- C:\Users\<USER>\AppData\Local\Temp\nspD831.tmp\nsExec.dll
- C:\Users\<USER>\AppData\Local\Temp\nspD831.tmp\nsProcess.dll
- SteamSingleInstance
- Local\InternetShortcutMutex
- cversions.3.m
- Global\OneSettingQueryMutex+compat+encapsulation
- oleacc-msaa-loaded
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 067c77d51df034b4a614…ad085aNever scannednever seen before
- 637cda9c10ab423071f3…159185Never scannednever seen before
- 16e0edc9f47e6e95a9bc…c8d49bNever scannednever seen before
- 7b51372117960e84d6f5…cb8ea7Never scannednever seen before
- e2ad7736209d62909a35…77ad48Never scannednever seen before
- 30c6c3dd3cc7fcea6e60…eb4d11Never scannednever seen before
- fd176529b30f2b9779bb…c8b1b3Never scannednever seen before
- d93b76d51bd2214fa6e9…1f4624Never scannednever seen before
- 2e226715419a5882e2e1…1962bcNever scannednever seen before
- 4681db4d19b6c46d1b8f…98c959Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 5rule hits recorded
- 0 / 75engines flagged
- 3,750sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 3,750 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The file has a valid code signature from Valve Corp..
ProvenanceObservedSourceCode-signing metadataObserved at - 04
Scanned file: CarX-Drift-Racing-Online-Windows-2-18-1-en.exe — 3b616cb0beaacffb53884b5ba0453312d2577db598d2a877a3b251125fb281a1
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\file.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\Explorer.EXE
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: nskD811.tmp — C:\Users\<USER>\AppData\Local\Temp\nskD811.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: System.dll — C:\Users\<USER>\AppData\Local\Temp\nspD831.tmp\System.dll
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: media.steampowered.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: client-update.steamstatic.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- Detect_NSIS_Nullsoft_Installer
- PE_Digital_Certificate
Sandbox flagged persistence indicators (registry Run keys / services / scheduled tasks).
EvidenceSteam Client Service · HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SteamThe saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
0 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- CarX-Drift-Racing-Online-Windows-2-18-1-en.exe
- Format
- Win32 EXE
- Code signing
- Signature valid: Valve Corp.
- Size
- 2.2 MB
- Last analyzed
- Sep 30, 2026, 5:20 PM UTC
3b616cb0beaacffb53884b5ba0453312d2577db598d2a877a3b251125fb281a1Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is CarX-Drift-Racing-Online-Windows-2-18-1-en.exe safe?
What is CarX-Drift-Racing-Online-Windows-2-18-1-en.exe?
How many antivirus engines detected CarX-Drift-Racing-Online-Windows-2-18-1-en.exe?
Is CarX-Drift-Racing-Online-Windows-2-18-1-en.exe digitally signed?
What is the SHA-256 hash of CarX-Drift-Racing-Online-Windows-2-18-1-en.exe?
Is it safe to run CarX-Drift-Racing-Online-Windows-2-18-1-en.exe?
How up to date is this analysis of CarX-Drift-Racing-Online-Windows-2-18-1-en.exe?
Community
Member reviews and reports for this exact file hash.