Is Unconfirmed 184856.crdownload safe?
Three of 74 engines flagged this new unsigned executable, but no tier-1 engine or independent intelligence source corroborated the lone XWorm identification.
The file warrants caution because it is a newly observed, unsigned executable and Zillya identified XWorm. However, only 3 of 74 engines detected it, all 17 reporting tier-1 engines were undetected, and no runtime or independent intelligence corroboration is available.
64682587fc11972646…fcdb63aadbfb36Recommended next actions
Before opening
Do not open it until the source can be verified independently.
If you already opened it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The file warrants caution because it is a newly observed, unsigned executable and Zillya identified XWorm. However, only 3 of 74 engines detected it, all 17 reporting tier-1 engines were undetected, and no runtime or independent intelligence corroboration is available.
Three of 74 engines flagged the sample, but none of the 17 reporting tier-1 engines detected it. Zillya supplied the only XWorm-specific label; APEX and Bkav used generic malware labels, so the family attribution is not established. The file is newly observed, scarcely submitted, unsigned, and has an incomplete-download filename, which limits confidence in its origin. No completed sandbox observation exists, and no complete contacted-host reputation result is available. Independent intelligence sources returned no hits, while same-imphash history is mostly cautionary but consists only of weak matches without signer co-matching.
What We Detected
Three of 74 antivirus engines flagged the executable. Zillya named Backdoor.XWorm.Win32.3294, while APEX and Bkav returned generic malware labels. None of the 17 reporting tier-1 engines detected it, so there is no high-trust consensus for XWorm or another family.
Threat Behavior
No completed sandbox run is available, so execution behavior, persistence, credential access, and command-and-control activity were not observed. The contacted-host reputation cross-check was also unavailable. Static analysis did not identify packed or high-entropy executable code, although the sample is unsigned, newly observed, and scarcely submitted.
What To Do Now
Do not run the file unless its source and expected download can be independently verified. Keep endpoint protection enabled, delete the partial download if it was unexpected, and obtain a fresh copy from the publisher's official channel before rescanning.
Where this verdict could be wrong3 caveats
- All 17 reporting tier-1 engines were undetected, including BitDefender, ESET-NOD32, Kaspersky, and Fortinet.
- externalIntel.yaraify.ruleCount=0, externalIntel.malwareBazaar.hit=false, and externalIntel.circl.hit=false provide no independent corroboration.
- peAnalysis.highEntropyCode=false and peAnalysis.likelyPacked=false do not show suspicious packing in executable code.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- All 17 reporting tier-1 engines were undetected
- Only 3 of 74 engines flagged the file
- No YARAify, MalwareBazaar, or CIRCL hit
- peAnalysis.highEntropyCode=false and likelyPacked=false
- Unsigned Win32 executable
- Newly observed with only one submission
- Zillya identified Backdoor.XWorm.Win32.3294
- Incomplete-download .crdownload filename
- No completed runtime analysis
- No complete contacted-host reputation result
Avoid executing this partial download until its origin is verified and a fresh copy is obtained from the official publisher. Keep endpoint protection enabled and rescan the completed download.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete3 of 74 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 3 / 74engines flagged
- 1sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
3 of 74 antivirus engines flagged the file, including APEX and Bkav.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at
Detection sources at a glance
Category: generic-trojan
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
3 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 3 antivirus detections make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- Unconfirmed 184856.crdownload
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 26.5 MB
- Last analyzed
- Sep 20, 2026, 5:48 AM UTC
64682587fc11972646bd2141cf75bc9bd6ec350aa85bfc2e20fcdb63aadbfb36Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Unconfirmed 184856.crdownload safe, or is it malware?
What is Unconfirmed 184856.crdownload?
How many antivirus engines detected Unconfirmed 184856.crdownload?
What should I do if I already opened Unconfirmed 184856.crdownload?
How do I remove Unconfirmed 184856.crdownload?
What kind of malware is Unconfirmed 184856.crdownload?
What is the SHA-256 hash of Unconfirmed 184856.crdownload?
How up to date is this analysis of Unconfirmed 184856.crdownload?
Community
Member reviews and reports for this exact file hash.