Is NBTExplorer-2.8.0.msi safe?
No antivirus engine detected this long-established installer, while the isolated behavioral warnings lack concrete corroboration and appear consistent with noisy installer telemetry.
The installer received no malicious or suspicious detections from 75 engines and has circulated broadly since 2017. One sandbox produced process-injection and credential-access mappings, but no malicious sandbox verdict, explicit LSASS memory read, malicious child, or persistence indicator corroborated those mappings.
696f25232ddc22392f…763727a5e31e13Recommended next actions
Before installing
Install it only when it came from the developer's official site or an official app store.
If you already installed it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The installer received no malicious or suspicious detections from 75 engines and has circulated broadly since 2017. One sandbox produced process-injection and credential-access mappings, but no malicious sandbox verdict, explicit LSASS memory read, malicious child, or persistence indicator corroborated those mappings.
All 75 engines avoided malicious and suspicious classifications, including 16 reporting tier-1 engines. The sample is more than eight years old and has been submitted 5,625 times by 3,474 sources, which strongly supports ordinary established software. One completed sandbox mapped activity to T1055, T1543.003, and T1547.001, but it issued no malicious sandbox verdict and recorded no persistence indicators. The credential-dumper heuristic appears to rely on lsass.exe being present in the process list rather than evidence of memory access. The unsigned installer and incomplete host-reputation coverage remain limitations, but they do not outweigh the broad detection and prevalence evidence.
What We Detected
No malicious or suspicious result was reported among 75 antivirus engines. The installer has also been known since 2017, with 5,625 submissions from 3,474 sources, indicating broad and long-standing circulation. It is unsigned, so its publisher identity cannot be authenticated through a code-signing certificate.
Threat Behavior
One sandbox run mapped activity to T1055, T1543.003, and T1547.001. However, it produced no malicious sandbox verdict, no recorded persistence indicators, and no confirmed malicious child among 10 inspected files. The credential-access warning was based on lsass.exe appearing in the observed process list; the evidence provided does not show an LSASS memory read. No complete contacted-host reputation result is available, and external-intelligence coverage was unavailable.
What To Do Now
Use the installer only if its hash and download source match the project's official release channel. Keep endpoint protection enabled and rescan if the file behaves differently, requests unusual privileges, or originates from an untrusted mirror.
Where this verdict could be wrong4 caveats
- The saved runtime mapping includes T1055 process injection and the MalwareTips.Synth.CredentialDumper heuristic, although the supplied process evidence does not establish an LSASS memory read.
- signing.signed=false provides no authenticated publisher identity for this installer.
- contactedHosts=null and externalIntel availability is unknown, so no complete host-reputation or researcher-intelligence cross-check is available.
- All 10 inspected dropped children have unknown individual verdicts rather than confirmed benign results.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 engines reported a malicious or suspicious detection.
- Sixteen tier-1 engines reported no detection.
- The sample has circulated since 2017 across 3,474 sources and 5,625 submissions.
- behaviour.hasMaliciousSandboxVerdict=false.
- droppedChildren.hasMaliciousChild=false and behaviour.persistenceIndicators is empty.
- The Windows Installer is unsigned despite signing.applicable=true.
- One sandbox mapped activity to T1055, T1543.003, and T1547.001.
- The contacted-host reputation cross-check was not completed or saved.
- All 10 dropped children lack individual verdicts.
- External-intelligence coverage was unavailable.
Obtain the installer from the project's official release channel and verify SHA-256 696f25232ddc22392f3e73fb0cd266dd60d16278d5f579fa4a763727a5e31e13. Keep endpoint protection enabled during installation.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 14MITRE ATT&CK techniques
- 15spawned processes
- 0network contacts
- 40filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
NBTExplorer-2.8.0.msi
696f25232ddc22392f3e73fb0cd266dd60d16278d5f579fa4a763727a5e31e13
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\system32\msiexec.exe" /I "C:\Users\<USER>\Desktop\install.msi" /qb ACCEPTEULA=1 LicenseAccepted=1
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\services.exe
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
ngen.log
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
04Isolated runtime analysis - Written fileObserved
~DF654A723F51D941F3.TMP
C:\Windows\Temp\~DF654A723F51D941F3.TMP
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
- C:\Windows\Temp\~DF654A723F51D941F3.TMP
- C:\Windows\Temp\~DF9C8BF490863853A9.TMP
- C:\Windows\Temp\~DF4074EF668BFE9FBB.TMP
- C:\Windows\Temp\~DFED31CBD50DE88729.TMP
- C:\Config.Msi\CMPD8FA.tmp
- C:\Config.Msi
- C:\Windows\Installer\d4e7.msi
- C:\Config.Msi\CMPDAB0.tmp
- C:\Config.Msi\d4e6.rbs
- Global\_MSIExecute
- \Sessions\1\BaseNamedObjects\Global\_MSIExecute
- \BaseNamedObjects\Local\SM0:828:304:WilStaging_02
- \BaseNamedObjects\Local\RstrMgr3887CAB8-533F-4C85-B0DC-3E5639F8D511
- \BaseNamedObjects\Local\RstrMgr-3887CAB8-533F-4C85-B0DC-3E5639F8D511-Session0000
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- c5e26b88085ad4aa60a4…6d6a3fNever scannednever seen before
- 284a1aa9cbf32d2c6ba0…4c76dbNever scannednever seen before
- 4629048e0a42a0ae3f3b…73fcbcNever scannednever seen before
- 4392f8102f5236e50171…7e8a89Never scannednever seen before
- 7a7a25abf56da8f0f3ed…497b64Never scannednever seen before
- 2c41d4082a4018396528…babe6dNever scannednever seen before
- b86e90b2708f955eedaa…af3253Never scannednever seen before
- 47953ef30b5917c544ac…5c345eNever scannednever seen before
- aea0f6715e4cadef3715…2a6974Never scannednever seen before
- cbd941ca8c1e1171a210…051d8aNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 0 / 75engines flagged
- 3,474sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 3,474 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 04
Scanned file: NBTExplorer-2.8.0.msi — 696f25232ddc22392f3e73fb0cd266dd60d16278d5f579fa4a763727a5e31e13
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\system32\msiexec.exe" /I "C:\Users\<USER>\Desktop\install.msi" /qb ACCEPTEULA=1 LicenseAccepted=1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\services.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: ngen.log — C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: ~DF654A723F51D941F3.TMP — C:\Windows\Temp\~DF654A723F51D941F3.TMP
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- NBTExplorer-2.8.0.msi
- Format
- Windows Installer
- Code signing
- No verified publisher
- Size
- 820.0 KB
- Last analyzed
- Sep 14, 2026, 10:04 PM UTC
696f25232ddc22392f3e73fb0cd266dd60d16278d5f579fa4a763727a5e31e13Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Install it only when it came from the developer's official site or an official app store.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is NBTExplorer-2.8.0.msi safe?
What is NBTExplorer-2.8.0.msi?
How many antivirus engines detected NBTExplorer-2.8.0.msi?
What is the SHA-256 hash of NBTExplorer-2.8.0.msi?
Is it safe to install NBTExplorer-2.8.0.msi?
How up to date is this analysis of NBTExplorer-2.8.0.msi?
Community
Member reviews and reports for this exact file hash.