Is BeamNG.supportHelper safe?
No engine detected malware, the BeamNG GmbH signature verifies, and the completed runtime observation produced no malicious sandbox or contacted-host finding.
All 76 antivirus engines returned no malicious or suspicious detection, including 17 tier-1 engines. The executable is validly signed by BeamNG GmbH, is not packed, and its completed sandbox run produced no malicious verdict; the two observed domains also had no cached threat finding.
9820a2c5548846e155…39df6a3b3a17d1Recommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 76 antivirus engines returned no malicious or suspicious detection, including 17 tier-1 engines. The executable is validly signed by BeamNG GmbH, is not packed, and its completed sandbox run produced no malicious verdict; the two observed domains also had no cached threat finding.
The strongest evidence is unanimous antivirus silence: 0 of 76 engines flagged the executable, including all 17 reporting tier-1 engines. Its code signature verifies as BeamNG GmbH, with no detected conflict between the claimed brand and signer. One completed sandbox run recorded diagnostic and archive-related activity but issued no malicious verdict, while the reputation check covering both contacted domains found no malicious or suspicious entry. Static analysis found no likely packing, and no external intelligence source supplied a malware family or matching research rule. T1560 and T1562.001 are cautionary behavior mappings, but they lack corroboration from engine detections, persistence, malicious children, or hostile infrastructure. The five dropped files remain independently unresolved, which modestly limits certainty without outweighing the broader evidence.
What We Detected
None of 76 antivirus engines flagged the executable, and all 17 reporting tier-1 engines returned no detection. The file carries a verified BeamNG GmbH signature, no brand mismatch was detected, and static PE analysis found neither likely packing nor high-entropy code.
Threat Behavior
One completed sandbox run observed system diagnostics, archive handling, and writes under the BeamNG.drive application-data directory. It mapped T1560 and T1562.001, but produced no malicious sandbox verdict or persistence indicators. The reputation check covered both contacted domains and found no malicious or suspicious entry. Five dropped files were inspected without a malicious result, although their individual status remains unknown.
What To Do Now
Use the file only if it came from BeamNG's official software or support channel, and confirm that Windows still reports the BeamNG GmbH signature as valid. Keep endpoint protection enabled and rescan if the signature changes, the file came from an unofficial source, or unexpected behavior appears.
Where this verdict could be wrong3 caveats
- behaviour.offensiveTechniques includes T1560 and T1562.001; these mappings warrant caution, although the completed sandbox issued no malicious verdict.
- signing.signerStats.found=false, so the valid 'BeamNG GmbH' signature is not backed by historical signer statistics in this dataset.
- droppedChildren.inspected=5 found no malicious child, but droppedChildren.rollup.unknown=5 means none of those children received a conclusive independent assessment.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/76 engines reported a malicious or suspicious detection.
- All 17 reporting tier-1 engines returned no detection.
- Verified code signature from BeamNG GmbH with no brand mismatch.
- No malicious sandbox verdict or persistence indicators were observed.
- No likely packing, YARAify match, or malicious contacted-host entry was found.
- Runtime mappings include T1560 and T1562.001.
- No historical signer statistics are available for BeamNG GmbH.
- All five inspected dropped children remain individually unknown.
If obtained through an official BeamNG channel, normal use is reasonable after confirming the valid BeamNG GmbH signature. Keep security protection enabled and avoid copies from unofficial download sites.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 76 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial2 of 8 contacted hosts were cross-checked; coverage is incomplete.
YARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 24MITRE ATT&CK techniques
- 15spawned processes
- 8network contacts
- 28filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- g-bing-com.ax-0001.ax-msedge.net
- g.bing.com
- 74.125.202.94
- a83f:8110:2002:0:0:0:0:0
- 151.101.22.172
- 23.216.81.152
- 192.168.0.9
- 20.99.133.109
- HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\LangID
- HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Windows\SysWOW64\unarchiver.exe.FriendlyAppName
- HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\C:\Windows\SysWOW64\unarchiver.exe.ApplicationCompany
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DxDiag.DxDiagClassObject.1
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DxDiag.DxDiagClassObject.1\CLSID
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DxDiag.DxDiagClassObject
- C:\Users\<USER>\AppData\Local\BeamNG.drive\0.34\vfsWriteTest.tmp
- C:\Users\user\AppData\Local\BeamNG.drive
- C:\Users\user\AppData\Local\BeamNG.drive\0.34
- C:\Users\user\AppData\Local\BeamNG.drive\0.34\
- C:\Users\user\AppData\Local\BeamNG.drive\0.34\beamng-dxDiag.txt
- C:\Windows\System32\wbem\Performance\WmiApRpl.h
- C:\Windows\System32\wbem\Performance\WmiApRpl.ini
- C:\Users\user\AppData\Local\BeamNG.drive\0.34\vfsWriteTest.tmp
- \Sessions\1\BaseNamedObjects\Global\SyncRootManager
- \Sessions\1\BaseNamedObjects\Local\DirectSound DllMain mutex (0x000010D8)
- \Sessions\1\BaseNamedObjects\Local\__DDrawExclMode__
- \Sessions\1\BaseNamedObjects\Local\__DDrawCheckExclMode__
- \Sessions\1\BaseNamedObjects\Local\DDrawWindowListMutex
Files this sample writes at runtime
This file drops 5 children at runtime. None are currently flagged malicious in our cache.
- 74736fd31f3316e348ea…26efe8Never scannednever seen before
- 7852fce59c67ddf1d6b8…011fbaNever scannednever seen before
- 32f072c6f7b29efc9bdb…117573Never scannednever seen before
- d8a461dc7419f62319dd…30dbe9Never scannednever seen before
- 471254748ff7f61ebf77…981d04Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 76engines flagged
- 33sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 76 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The file has a valid code signature from BeamNG GmbH.
ProvenanceObservedSourceCode-signing metadataObserved at - 03
The hash has been submitted 34 times from 33 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: BeamNG.supportHelper — 9820a2c5548846e155b9174e404f28a5cf75c8879dd3814e3f39df6a3b3a17d1
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\support.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — %SAMPLEPATH%\support.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: vfsWriteTest.tmp — C:\Users\<USER>\AppData\Local\BeamNG.drive\0.34\vfsWriteTest.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: BeamNG.drive — C:\Users\user\AppData\Local\BeamNG.drive
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: g-bing-com.ax-0001.ax-msedge.net — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: g.bing.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 76 engines flagged this file
View all 76 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- BeamNG.supportHelper
- Format
- Win32 EXE
- Code signing
- Signature valid: BeamNG GmbH
- Size
- 4.4 MB
- Last analyzed
- Sep 29, 2026, 4:51 PM UTC
9820a2c5548846e155b9174e404f28a5cf75c8879dd3814e3f39df6a3b3a17d1Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is BeamNG.supportHelper safe?
What is BeamNG.supportHelper?
How many antivirus engines detected BeamNG.supportHelper?
Is BeamNG.supportHelper digitally signed?
What is the SHA-256 hash of BeamNG.supportHelper?
Is it safe to open BeamNG.supportHelper?
How up to date is this analysis of BeamNG.supportHelper?
Community
Member reviews and reports for this exact file hash.