Is AirPodsDesktop-0.6.0-win64.exe safe?
No antivirus engine detected the executable, and its sandbox run produced no malicious verdict, though unsigned status and unchecked direct-IP traffic warrant source verification.
All 74 antivirus engines returned no malicious or suspicious detection, including 17 tier-1 engines, and the completed sandbox run issued no malicious verdict. The file is unsigned and contacted 162.159.36.2 without a completed host-reputation check, so obtain it from the project's official release channel and keep endpoint protection enabled.
45332fed375125ff50…031836d21e9437Recommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 antivirus engines returned no malicious or suspicious detection, including 17 tier-1 engines, and the completed sandbox run issued no malicious verdict. The file is unsigned and contacted 162.159.36.2 without a completed host-reputation check, so obtain it from the project's official release channel and keep endpoint protection enabled.
The strongest evidence is broad engine agreement: 0 of 74 engines flagged the executable, with all 17 participating tier-1 engines reporting no detection. One completed sandbox run did not issue a malicious verdict, and none of eight inspected dropped files was identified as malicious, although their individual status remains unknown. The run included T1134 and contacted 162.159.36.2, but this isolated low-severity signal does not establish command-and-control activity. A complete reputation result for that IP is unavailable because the contacted-host cross-check was not saved. The executable is unsigned and only eight days into its observation history, which limits publisher assurance. Five prior benign-looking imphash matches provide little additional support because they belong to different signers and may merely share an installer framework.
What We Detected
None of 74 antivirus engines flagged the executable as malicious or suspicious. This includes 17 tier-1 engines such as Avast, BitDefender, ESET-NOD32, Kaspersky, and Microsoft. Research feeds also supplied no MalwareBazaar, CIRCL, or YARAify match.
Threat Behavior
One completed sandbox run produced no malicious sandbox verdict. It recorded T1134 and direct-IP traffic to 162.159.36.2, but the related heuristic was low severity and does not establish command-and-control on its own. No complete host-reputation result is available for that IP because contactedHosts was not checked or saved. Eight dropped files were inspected without a malicious child finding, but each child remains individually unclassified.
What To Do Now
The lack of detections is reassuring, but the executable has no digital signature and has only a short observation history. Download it only from the project's official release channel, verify the SHA-256 value 45332fed375125ff5011653d53eb674cf8d23a62707fbfe226031836d21e9437 when the publisher provides one, and keep endpoint protection enabled.
Where this verdict could be wrong5 caveats
- signing.signed=false for this Win32 EXE, so no publisher identity or established signer history supports the file.
- triggeredHeuristics[0] recorded direct-IP traffic to 162.159.36.2, and contactedHosts=null leaves that address without a completed reputation cross-check.
- behaviour.offensiveTechniques includes T1134, although it was not accompanied by a malicious sandbox verdict.
- file.ageDays=8 and reputation=0 provide only a short observation history.
- droppedChildren.rollup reports 8 unknown children, so hasMaliciousChild=false does not mean those files were independently confirmed benign.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 engines reported malicious or suspicious detections
- 17 tier-1 engines reported no detection
- No malicious sandbox verdict in one completed run
- No malicious child found among eight inspected dropped files
- No MalwareBazaar, CIRCL, or YARAify hit
- Unsigned Win32 executable with no verifiable publisher
- Only eight days of observation history and reputation score 0
- Sandbox recorded offensive technique T1134
- Direct-IP contact to 162.159.36.2 lacks a completed reputation cross-check
- Eight dropped children remain individually unknown
Use the executable only if it came from the project's official release channel, and verify its SHA-256 hash against an official value when available. Keep endpoint protection enabled and rescan if the file changes.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 16MITRE ATT&CK techniques
- 1spawned processes
- 1network contacts
- 23filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
AirPodsDesktop-0.6.0-win64.exe
45332fed375125ff5011653d53eb674cf8d23a62707fbfe226031836d21e9437
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\user\Desktop\AirPodsDesktop-0.6.0-win64.exe"
02Isolated runtime analysis
Files
Created or changed
- Written fileObserved
UserInfo.dll
C:\Users\<USER>\AppData\Local\Temp\nsx497A.tmp\UserInfo.dll
03Isolated runtime analysis - Written fileObserved
ioSpecial.ini
C:\Users\<USER>\AppData\Local\Temp\nsx497A.tmp\ioSpecial.ini
04Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
162.159.36.2
Contact observed during runtime.
05Isolated runtime analysis
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Users\<USER>\AppData\Local\Temp\nsx497A.tmp\UserInfo.dll
- C:\Users\<USER>\AppData\Local\Temp\nsx497A.tmp\ioSpecial.ini
- C:\Users\<USER>\AppData\Local\Temp\nsx497A.tmp\InstallOptions.dll
- C:\Users\<USER>\AppData\Local\Temp\nsx497A.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nsx497A.tmp\modern-header.bmp
- C:\Users\<USER>\AppData\Local\Temp\nsk4320.tmp
- C:\Users\<USER>\AppData\Local\Temp\nsx497A.tmp
- C:\Users\<USER>\AppData\Local\Temp\nstD89.tmp
- C:\Users\<USER>\AppData\Local\Temp\nsk1191.tmp
- C:\Users\<USER>\AppData\Local\Temp\nszF2F.tmp
Files this sample writes at runtime
This file drops 8 children at runtime. None are currently flagged malicious in our cache.
- a921cc9cc4af332be961…5ff85eNever scannednever seen before
- 5f9be0ddc2e88699044a…5a5274Never scannednever seen before
- 89dd7d646278d8bfc41d…c7262aNever scannednever seen before
- 3ad2dc318056d0a2024a…056cf2Never scannednever seen before
- 766a893fe962aefd27c5…71aefcNever scannednever seen before
- 353344b78643f7b33bb6…97724bNever scannednever seen before
- 8fd1f6a5ca8f05027265…2e277fNever scannednever seen before
- a49f9403ab831155d141…686ba0Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 0 / 74engines flagged
- 35sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 36 times from 35 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: AirPodsDesktop-0.6.0-win64.exe — 45332fed375125ff5011653d53eb674cf8d23a62707fbfe226031836d21e9437
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Users\user\Desktop\AirPodsDesktop-0.6.0-win64.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
File written: UserInfo.dll — C:\Users\<USER>\AppData\Local\Temp\nsx497A.tmp\UserInfo.dll
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: ioSpecial.ini — C:\Users\<USER>\AppData\Local\Temp\nsx497A.tmp\ioSpecial.ini
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Low-severity pattern matches — worth noting but not on their own cause for alarm.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence162.159.36.2
0 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- AirPodsDesktop-0.6.0-win64.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 55.6 MB
- Last analyzed
- Sep 15, 2026, 4:31 AM UTC
45332fed375125ff5011653d53eb674cf8d23a62707fbfe226031836d21e9437Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is AirPodsDesktop-0.6.0-win64.exe safe?
What is AirPodsDesktop-0.6.0-win64.exe?
How many antivirus engines detected AirPodsDesktop-0.6.0-win64.exe?
What is the SHA-256 hash of AirPodsDesktop-0.6.0-win64.exe?
Is it safe to run AirPodsDesktop-0.6.0-win64.exe?
How up to date is this analysis of AirPodsDesktop-0.6.0-win64.exe?
Community
Member reviews and reports for this exact file hash.