Is W-KemonoDownloader-4.3.0-x86_64-Portable.exe safe?Suspicious
This unsigned portable executable exhibits suspicious direct-IP network communication and is associated with multiple malware family reports in community research, despite low detection rates from high-trust antivirus engines.
- 2 of 74 antivirus engines flagged the file, including APEX and Bkav.
- The hash has a long, established submission history across 542 sources.
- The hash has been submitted 592 times from 542 sources.
4a9d373f2d2e828431…1ea983e5c1Before opening
Do not run it until the source and publisher can be verified independently.
If you already ran it
Close it, scan the device, and watch for unexpected processes or security alerts.
Coverage & freshness
A completed check means the source returned a result. It does not, by itself, guarantee that the file is safe.
Antivirus
Complete2 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial18 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Attack story
A bounded view of the runtime evidence saved with this scan. Connectors mean “also observed,” not a proven causal chain.
- File
W-KemonoDownloader-4.3.0-x86_64-Portable.exe
4a9d373f2d2e…83e5c1
Observed - Process
Observed process
"C:\Users\<USER>\Desktop\executable.exe"
Observed - Process
Observed process
C:\Windows\system32\cmd.exe /c "ver"
Observed - Written file
MSVCP140.dll
C:\Users\<USER>\AppData\Local\Temp\_MEI61162\PyQt6\Qt6\bin\MSVCP140.dll
Observed - Written file
MSVCP140_1.dll
C:\Users\<USER>\AppData\Local\Temp\_MEI61162\PyQt6\Qt6\bin\MSVCP140_1.dll
Observed - Contacted host
140.82.113.5
Contact observed during runtime.
Observed - Contacted host
23.46.228.41
Contact observed during runtime.
Observed
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
2 of 74 antivirus engines flagged the file, including APEX and Bkav.
Antivirus analysisView chapterVerdict inputObserved - 02
The hash has a long, established submission history across 542 sources.
Submission historyView chapterDerived - 03
The hash has been submitted 592 times from 542 sources.
Saved report factsView chapterDerived
Intelligence
The complete saved assessment, kept intact and grounded in the scan evidence.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Our analysis identifies this file as suspicious due to its lack of a digital signature and the use of direct-IP communication, which often bypasses security filters. While high-trust engines currently report it as clean, community research links this specific hash to known malware families, suggesting it may be a malicious component.
The file is unsigned and lacks a verifiable publisher, which is atypical for software of this nature. The detection of direct-IP communication without DNS resolution is a strong indicator of evasive behavior often seen in malicious software. Although the majority of antivirus engines do not flag the file, the combination of the 'MalwareTips.Synth.DirectIpC2' heuristic hit and external researcher annotations linking it to known threats creates a significant risk profile. We categorize this as suspicious due to these mixed signals and the potential for it to act as a downloader or dropper.
What We Detected
The file is an unsigned 64-bit portable executable. While 72 of 74 engines currently do not flag the file, it has been identified by community researchers as potentially related to various malware families, including infostealers and remote access tools.
Threat Behavior
The sample demonstrated suspicious network behavior by initiating connections to 15 distinct external IP addresses without performing any DNS lookups. This behavior is a common technique used by malicious software to evade domain-based reputation and blocking systems. Furthermore, the file is unsigned, preventing verification of its origin or integrity.
What To Do Now
Given the suspicious network activity and the lack of a valid digital signature, we recommend treating this file as untrusted. Do not execute it on production systems. If this file was obtained from an unofficial source, delete it immediately and perform a full system scan with updated security software.
Where this verdict could be wrong3 caveats
- The majority of engines (72/74) and all 17 tier-1 engines currently report the file as clean.
- No malicious sandbox verdict was returned during the analysis run.
- No malicious children were identified among the 10 inspected dropped files.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- No tier-1 engine detections
- No malicious sandbox verdict
- No malicious dropped children
- Unsigned executable
- Direct-IP C2 communication
- Community reports of malware association
- High entropy in sections
- Portable executable format
Do not execute this file. It is unsigned and exhibits evasive network behavior consistent with malicious software.
Behavior
Plain-English impact first, then the observed runtime evidence.
What this file does
Observed actions and their security significance
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Listed running processes; both legitimate software and malware may do this.
Note: Collects details about your system.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 140.82.113.5
- 23.46.228.41
- 23.196.145.221
- 23.32.75.29
- 192.168.0.33
- 23.55.140.42
- 23.220.75.246
- 23.221.103.220
- 20.69.140.28
- 217.20.54.36
- C:\Users\<USER>\AppData\Local\Temp\_MEI61162\PyQt6\Qt6\bin\MSVCP140.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI61162\PyQt6\Qt6\bin\MSVCP140_1.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI61162\PyQt6\Qt6\bin\MSVCP140_2.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI61162\PyQt6\Qt6\bin\Qt6Core.dll
- C:\Users\<USER>\AppData\Local\Temp\_MEI61162\PyQt6\Qt6\bin\Qt6Gui.dll
- Local\SessionImmersiveColorMutex
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- d06a91324ec9a9a68ea5…1425d5Never scannednever seen before
- c585918fb1d4821a054e…ac7e8fNever scannednever seen before
- 8c98b5ee246e18397d0d…5b34deNever scannednever seen before
- f41e33e1d790bd0d3eb1…e66867Never scannednever seen before
- 81da2f88cd624097581f…542d28Never scannednever seen before
- fc9e4146f33be3d09b23…3a61a7Never scannednever seen before
- 655f4f9afa55897a6df5…cf9485Never scannednever seen before
- 2ec955e662407ebcd8dc…43535fNever scannednever seen before
- c44e0313a9414cc0e490…92034fNever scannednever seen before
- ef6bf5f66c468d29ac6a…6c78dcNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
Category: generic-trojan
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Behavioral heuristics matched patterns associated with malware. Corroborating evidence determines how much weight they carry.
Sample contacted 15 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence140.82.113.5 · 23.46.228.41 · 23.196.145.221
2 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- W-KemonoDownloader-4.3.0-x86_64-Portable.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 51.3 MB
- Last analyzed
- Jul 23, 2026, 8:21 PM UTC
4a9d373f2d2e828431b1e41df097281a15a22a1e4754cf05f013051ea983e5c1Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
Don't run it unless you're certain it came from a source you trust.
Check where you got it — an email attachment or a random download link is a red flag.
If you're unsure, delete it. You can always re-download a clean copy from the official source.
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
- W-KemonoDownloader-4.3.0-x86_64-Portable.exe is suspicious — treat it as unsafe until you're sure. 2 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't run it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
- W-KemonoDownloader-4.3.0-x86_64-Portable.exe is a Windows executable program, about 51.3 MB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
- 2 of 74 antivirus engines flagged W-KemonoDownloader-4.3.0-x86_64-Portable.exe, 2 of them as outright malicious. A small number of detections can include false positives, so we weigh which engines flagged it and what else the file does, not just the raw count.
- Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
- To remove W-KemonoDownloader-4.3.0-x86_64-Portable.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original W-KemonoDownloader-4.3.0-x86_64-Portable.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
- W-KemonoDownloader-4.3.0-x86_64-Portable.exe is classified as a trojan — malware disguised as something harmless to trick you into running it. Knowing the family matters because it tells you the likely impact — data theft, remote control, file encryption, or unwanted ads — and guides the cleanup.
- The SHA-256 hash of W-KemonoDownloader-4.3.0-x86_64-Portable.exe is 4a9d373f2d2e828431b1e41df097281a15a22a1e4754cf05f013051ea983e5c1, and its MD5 is 4faaeb19d52702a31df08aed63a520f7. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on July 23, 2026. Because a file's hash never changes, the identity of W-KemonoDownloader-4.3.0-x86_64-Portable.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.