File verdict·MT AI Engine assessment
Our call

Malicious

Installer signed by Softonic with 5 tier-1 engines flagging OfferCore PUP and 5 prior malicious verdicts on the same signer.

offercoreVerified · SOFTONIC INTERNATIONAL SA
Trust score15High risk
igi-2-covert-strike-single-player-demo-2-installer.exe
2.0 MB
865bfa64ec36faabc722bbd03e56
Antivirus engines
12 of 74 flagged
Code signing
Signed by SOFTONIC INTERNATIONAL SA
Age
First-seen today
MT AI Engine · Verdict analysis

The reasoning behind this verdict

This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.

82%Confidence
High
Reasoning

The combination of tier-1 detections on OfferCore/Softonic labels, a signer with exclusively malicious history, and matching prior verdicts on the same signer and imphash outweighs the absence of sandbox or network data. Prevalence as rare_new and the installer filename do not contradict the PUP classification. Low-trust detections are present but not required for the decision given the tier-1 and signer evidence.

Analyst conclusion

12 of 74 engines flagged the file, including 5 tier-1 detections naming OfferCore or Softonic downloader activity. The signer SOFTONIC INTERNATIONAL SA has a 0% safe rate across prior samples, and similar hashes consistently returned malicious verdicts for the same family.

Detailed assessment

What We Detected

12 of 74 engines reported malicious or PUP activity. Tier-1 engines DrWeb, ESET-NOD32, Kaspersky, Microsoft, and Symantec contributed detections naming OfferCore, Downware, or Softonic components. The executable is signed by SOFTONIC INTERNATIONAL SA with verified status but a 0/3 safe history.

Threat Behavior

OfferCore is a known adware/downloader framework frequently bundled with installers. The file shows high-entropy sections typical of packed or overlay-heavy installers but no confirmed packers. No sandbox execution or network contact data is available in this scan.

What To Do Now

Avoid executing the installer. If already run, review installed programs for OfferCore or Softonic entries and run a reputable anti-malware scan. Delete the file and obtain game software from official sources.

Key signals · 3

The strongest scan facts behind the verdict, preserved with their exact names and counts.

  1. 12 of 74 antivirus engines flagged the file, including AhnLab-V3, CrowdStrike, DrWeb.

  2. The file has a valid code signature from SOFTONIC INTERNATIONAL SA.

  3. The hash has been submitted 2 times from 2 sources.

Points in its favour
  • No sandbox malicious verdict available
  • No malicious contacted hosts recorded
  • No brand mismatch detected
Points against
  • 5 tier-1 engines flagged OfferCore/Softonic PUP
  • Signer SOFTONIC INTERNATIONAL SA has 0% safe rate
  • 5 similar hashes previously marked malicious for same family
  • rare_new prevalence with installer filename
Recommended action

Do not run this installer. The evidence from tier-1 engines and signer history indicates OfferCore PUP distribution.

Threat context

How bundlers & adware work

This is a bundler — a real-looking installer that hides extra software inside. When you run it, it quietly installs things you never asked for: ad injectors, browser toolbars, fake 'PC cleaner' apps, or even more bundlers. The people behind it get paid for every unwanted app they sneak on.

Bottom line:It's not usually built to destroy files, but it slows your PC, floods it with ads, and can be a real pain to fully remove.

What to do now

This file is dangerous. Treat it as harmful and remove it.

  1. Don't open or run this file. Delete it from your Downloads (or wherever you saved it), then empty the Recycle Bin.

  2. If you already opened it, disconnect from the internet and run a full scan with your antivirus — Windows Security, built into Windows, is sufficient.

  3. If you typed any passwords while it was open, change them from a device you trust.

  4. In future, only download software from the official website or an official app store.

Threat family attribution

offercore corroborated by 2 sources

  • VT (74 engines)
    offercore
  • MT AI Engine
    offercore
No researcher-database hits
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Antivirus engine breakdown

12 detections across 74 engines

12 malicious0 suspicious62 clean
Tier-117 engines
5flag
Top commercial AVs (low FP rate)
Tier-240 engines
5flag
Mainstream engines with mixed FP rates
Low-trust17 engines
2flag
Heuristic / generic-AI engines (high FP rate)
AhnLab-V3
malicious
PUP/Win.Generic.R752265
CrowdStrike
malicious
win/grayware_confidence_60% (D)
DrWeb
malicious
Adware.Downware.20879
Elastic
malicious
malicious (high confidence)
ESET-NOD32
malicious
Win32/OfferCore.E potentially unwanted application
K7AntiVirus
malicious
Adware ( 005693e61 )
K7GW
malicious
Adware ( 005693e61 )
Kaspersky
malicious
not-a-virus:HEUR:Downloader.Win32.Softonic.gen
Malwarebytes
malicious
PUP.Optional.Softonic
Microsoft
malicious
PUADlManager:Win32/OfferCore
Symantec
malicious
ML.Attribute.HighConfidence
Webroot
malicious
Win.Adware.Com
Hash 865bfa64ec36… cross-referenced against 74 AV engines via our AV network.
PE forensics

Section entropy & packers

No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.

ent 8.00Unpacked
Section entropy10 sections
.text
6.38
.itext
6.04
.data
5.18
.bss
0.00
.idata
4.82
.didata
2.76
.edata
1.34
.tls
0.00
.rdata
1.38
.reloc
6.70
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Barely seen in the wild and first surfaced recently. 12 antivirus detections make that low prevalence materially relevant, but rarity alone is not proof of malware.

Rare & new
Unique uploaders
2
Very few people have ever uploaded this — rare.
Total submissions
2
Includes repeat uploads by the same source.
First seen
0d ago
Jul 22, 2026
Prevalence quadrant
here
Rare · New
Needs evidence-led scrutiny
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Often established software
File identity

Forensic fingerprint

File biography
First seen (VT)
Jul 22, 2026, 11:09 AM UTC
First seen (MalwareBazaar)
Last analysis (VT)
Jul 22, 2026, 11:10 AM UTC
Scanned here
Jul 22, 2026, 2:40 PM UTC
File name
igi-2-covert-strike-single-player-demo-2-installer.exe
Size
2.03 MB
MIME type
application/x-msdownload
Detected type
Win32 EXE
SHA-256
865bfa64ec36faabc7bab043705667c400eb3ad9588ae6d75810c222bbd03e56
MD5
f9723384ded943ef2aece10f1b4ff5f0
SHA-1
ada1b018d628e3c7d13ca7012f46dd6aadae2b04
PE imphash
88016fcdef7f227c62171d0afad9aae4
First seen (VT)
Jul 22, 2026, 11:09 AM UTC
Last analysis (VT)
Jul 22, 2026, 11:10 AM UTC
First scan (MalwareTips)
Jul 22, 2026, 11:10 AM UTC
Last scan (MalwareTips)
Jul 22, 2026, 2:40 PM UTC
Code signer
SOFTONIC INTERNATIONAL SAverified
Behavior tags
signedoverlaypeexe
Frequently asked

Safety FAQ

Common questions about igi-2-covert-strike-single-player-demo-2-installer.exe, answered from the scan data above.

  • Yes — igi-2-covert-strike-single-player-demo-2-installer.exe is malicious, so do not run it, and delete it. 12 of 74 antivirus engines flag it (family: offercore). It behaves as adware or a potentially unwanted program (PUA) — not always destructive, but it bundles ads, trackers, or unwanted changes you didn't ask for. If you've already run it, see the removal and recovery steps below.
  • igi-2-covert-strike-single-player-demo-2-installer.exe is a Windows executable program (application/x-msdownload), about 2 MB. Our analysis identifies it as malicious (family: offercore) — adware or a potentially unwanted program (PUA) — not always destructive, but it bundles ads, trackers, or unwanted changes you didn't ask for. Because a file's name and icon can be faked, the safest way to identify it is by its cryptographic hash (below), not its filename.
  • 12 of 74 antivirus engines flagged igi-2-covert-strike-single-player-demo-2-installer.exe, 12 of them as outright malicious. A detection rate at this level is a reliable signal that the file is dangerous.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove igi-2-covert-strike-single-player-demo-2-installer.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original igi-2-covert-strike-single-player-demo-2-installer.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • igi-2-covert-strike-single-player-demo-2-installer.exe is classified as adware or a potentially unwanted program (PUA) — not always destructive, but it bundles ads, trackers, or unwanted changes you didn't ask for. Engines attribute it to the offercore family. Knowing the family matters because it tells you the likely impact — data theft, remote control, file encryption, or unwanted ads — and guides the cleanup.
  • Yes — igi-2-covert-strike-single-player-demo-2-installer.exe carries a valid digital signature from SOFTONIC INTERNATIONAL SA, which confirms the file hasn't been tampered with since that publisher signed it. A valid signature is a positive signal, but note that malware is occasionally signed with stolen or abused certificates, so it isn't proof of safety on its own.
  • The SHA-256 hash of igi-2-covert-strike-single-player-demo-2-installer.exe is 865bfa64ec36faabc7bab043705667c400eb3ad9588ae6d75810c222bbd03e56, and its MD5 is f9723384ded943ef2aece10f1b4ff5f0. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on July 22, 2026. Because a file's hash never changes, the identity of igi-2-covert-strike-single-player-demo-2-installer.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Unknown files are temporarily processed and submitted to VirusTotal. MalwareTips does not retain the binary after processing. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.