Is ACAD.EXE safe?
No antivirus engine detected this widely submitted file, while one runtime observation found no offensive behavior; generic YARA matches remain the main caution.
All 74 antivirus engines reported no threat, including 17 tier-1 contributors, after the file accumulated 210 submissions over roughly 890 days. One completed runtime observation produced no malicious verdict, but seven broad YARA matches and an unverified Autodesk signature warrant obtaining the executable from an official source.
4d201af35c6aa206df…e5eec368a128c6Recommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 antivirus engines reported no threat, including 17 tier-1 contributors, after the file accumulated 210 submissions over roughly 890 days. One completed runtime observation produced no malicious verdict, but seven broad YARA matches and an unverified Autodesk signature warrant obtaining the executable from an official source.
The strongest evidence is the absence of detections across 74 antivirus engines, with all 17 tier-1 contributors reporting no detection. The file is also well established, appearing from 185 sources in 210 submissions over roughly 890 days. One completed sandbox run produced no malicious verdict or offensive-only behavior, and both observed domains were covered by the host check without a known malicious or suspicious result. Seven community YARA rules matched, but the disclosed rules identify generic traits such as a Bitcoin-address pattern, debugger checks, .NET content, and TLS callbacks rather than a coherent malware family. The signature is unverified and cannot authenticate Autodesk, so provenance should still be checked before execution.
What We Detected
No antivirus product flagged the file: 0 of 74 engines reported it, including 17 tier-1 contributors. It has been submitted 210 times by 185 sources and has been known for about 890 days, making a broadly missed established threat unlikely.
Threat Behavior
One completed runtime observation produced no malicious sandbox verdict, no persistence indicators, no dropped-file hashes, and no offensive-only MITRE techniques. The two observed domains, res.public.onecdn.static.microsoft and www.microsoft.com, were both checked without known malicious or suspicious results. The additional contacted IP addresses were not fully covered by that host-reputation block. Seven YARA rules matched, but the listed rules describe broad static traits rather than a named malware family.
What To Do Now
The Autodesk signer claim is unverified, and the file also carries invalid-signature and corrupt metadata tags. Obtain ACAD.EXE through Autodesk's official installer or update channel, verify its digital signature locally, and keep endpoint protection enabled while opening it.
Where this verdict could be wrong4 caveats
- externalIntel.yaraify.ruleCount=7 is a strong static warning, but the exposed rule names are broad capability or format matches rather than a consistent named malware family.
- signing.verified=null and the file carries invalid-signature and corrupt tags, so the claimed Autodesk signer cannot be treated as authenticated.
- The contactedHosts block covers both domains but not every IP in behaviour.contactedIps, so no complete reputation result is available for all observed network contacts.
- The single runtime observation included input-capture, screenshot, obfuscation, and anti-analysis technique mappings, although behaviour.offensiveCount=0 and no malicious sandbox verdict resulted.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 engines reported malicious or suspicious results.
- All 17 tier-1 contributors reported no detection.
- One completed sandbox observation had behaviour.hasMaliciousSandboxVerdict=false and offensiveCount=0.
- The file has 210 submissions from 185 sources over 890 days.
- Both contactedDomains entries were inspected with no known malicious or suspicious host result.
- externalIntel.yaraify.ruleCount=7 produced multiple community-rule matches.
- signing.verified=null, so the Autodesk signer name is not authenticated.
- file.tags includes invalid-signature and corrupt.
- Observed IP contacts lack complete contactedHosts reputation coverage.
Use only a copy obtained through Autodesk's official distribution channel and verify its digital signature before execution. Keep antivirus and endpoint protection enabled.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial2 of 22 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete5 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 22MITRE ATT&CK techniques
- 6spawned processes
- 22network contacts
- 3filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- res.public.onecdn.static.microsoft
- www.microsoft.com
- 192.168.0.60
- 20.99.186.246
- 23.62.210.8
- 23.216.81.152
- 20.99.185.48
- 192.168.0.17
- 20.99.133.109
- 192.168.0.66
- 23.55.140.42
- 23.55.219.177
- C:\Windows\System32\wbem\Performance\WmiApRpl.h
- C:\Windows\System32\wbem\Performance\WmiApRpl.ini
- %USERPROFILE%\AppData\Local\Microsoft\Windows\INetCache\IE\KLT1I0ZU\update50[1].xml
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 5rule hits recorded
- 0 / 74engines flagged
- 185sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 185 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
5 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceObservedSourceSignature and behavior rulesObserved at - 04
Scanned file: ACAD.EXE — 4d201af35c6aa206df9ff049115c0974a9d14f40bb5822315fe5eec368a128c6
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — %SAMPLEPATH%\4d201af35c6aa206df9ff049115c0974a9d14f40bb5822315fe5eec368a128c6.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\System32\UI0Detect.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
Contacted host: res.public.onecdn.static.microsoft — Saved reputation verdict: safe.
ProvenanceDerivedSourceContacted-host cross-checkObserved at - 08
Contacted host: www.microsoft.com — Saved reputation verdict: safe.
ProvenanceDerivedSourceContacted-host cross-checkObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- BitcoinAddress
- DebuggerCheck__API
- golang_bin_JCorn_CSC846
- NET
- pe_detect_tls_callbacks
0 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- ACAD.EXE
- Format
- Win32 EXE
- Code signing
- Signature not verified: Autodesk
- Size
- 5.4 MB
- Last analyzed
- Sep 26, 2026, 2:33 PM UTC
4d201af35c6aa206df9ff049115c0974a9d14f40bb5822315fe5eec368a128c6Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is ACAD.EXE safe?
What is ACAD.EXE?
How many antivirus engines detected ACAD.EXE?
Is ACAD.EXE digitally signed?
What is the SHA-256 hash of ACAD.EXE?
Is it safe to run ACAD.EXE?
How up to date is this analysis of ACAD.EXE?
Community
Member reviews and reports for this exact file hash.