Is vlc-media-player-3.0.23-installer.exe safe?Malicious
Installer spoofing VLC Media Player, signed by unknown publisher, flagged as OfferCore adware by tier-1 engines.
- 12 of 75 antivirus engines flagged the file, including AhnLab-V3 and CrowdStrike.
- No completed runtime observation is available for this file.
- The file has a valid code signature from SOFTONIC INTERNATIONAL SA.
b5cea4d097ed872fa4…aa447c1263Before opening
Do not open or run it. Delete the file from the device.
If you already ran it
Disconnect from the internet, run a full antivirus scan, then secure important accounts from a clean device.
Coverage & freshness
A completed check means the source returned a result. It does not, by itself, guarantee that the file is safe.
Antivirus
Complete12 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
12 of 75 antivirus engines flagged the file, including AhnLab-V3 and CrowdStrike.
Antivirus analysisView chapterVerdict inputObserved - 02
No completed runtime observation is available for this file.
Runtime coverageView chapterDerived - 03
The file has a valid code signature from SOFTONIC INTERNATIONAL SA.
Code-signing metadataView chapterObserved
Intelligence
The complete saved assessment, kept intact and grounded in the scan evidence.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Three tier-1 antivirus engines (Microsoft, ESET-NOD32, DrWeb) independently identified this file as OfferCore, a known potentially unwanted application (PUA) family. The file claims to be VLC Media Player but is signed by Softonic International SA, an unknown publisher with no submission history. This signer-filename mismatch combined with tier-1 consensus on a PUA family indicates adversarial repackaging.
The file exhibits a classic brand-spoofing pattern: the filename claims 'vlc-media-player-3.0.23-installer.exe', but the Authenticode signature is from 'SOFTONIC INTERNATIONAL SA', not VideoLAN (the legitimate VLC publisher). Three tier-1 engines (Microsoft, ESET-NOD32, DrWeb) converged on OfferCore, a known adware/PUA family, indicating genuine consensus rather than heuristic false positives. The signer has zero historical samples in our database, suggesting a newly registered or compromised certificate. The file is rare and brand-new (1 submission, 0 days old), consistent with a fresh adversarial campaign. Absence of sandbox behaviour data does not mitigate the tier-1 consensus on a known PUA family combined with clear brand spoofing.
What We Detected
Three tier-1 antivirus engines flagged this file as OfferCore, a potentially unwanted application (PUA) family known for bundling unwanted offers and download managers. The file claims to be VLC Media Player 3.0.23 but is signed by Softonic International SA, not VideoLAN (the legitimate VLC publisher).
Threat Behavior
OfferCore is classified as adware/PUA and typically bundles unwanted software offers, download managers, or browser toolbars with legitimate installers. The signer mismatch (Softonic instead of VideoLAN) indicates the file is a repackaged or spoofed version. The signer 'SOFTONIC INTERNATIONAL SA' has no prior submission history in our database, suggesting either a newly registered certificate or a compromised signing identity. The file is brand-new (submitted 0 days ago) and rare (1 submission), consistent with a fresh distribution campaign.
What To Do Now
Do not execute this file. If you downloaded it, delete it immediately. Download VLC Media Player only from the official VideoLAN website (videolan.org) or verified distribution channels. Be cautious of installers from third-party repackagers, as they may bundle unwanted software. If this file was already executed, run a full system scan with your antivirus software and monitor for unexpected browser toolbars, download managers, or system changes.
Where this verdict could be wrong3 caveats
- If Softonic legitimately repackages VLC with bundled offers (as some distributors do), the signer would be correct and the PUA labels reflect optional bundled software, not malware. However, signerStats.found=false contradicts this — a legitimate repackager would have submission history.
- triggeredHeuristics flagged 'security_tool_classifier', which could indicate a false positive if the file were genuinely a security tool. However, the dominant labels (Win32/OfferCore, PUADlManager, Unwanted-Program) are PUA/adware, not security software, so this heuristic misfired.
- No sandbox behaviour data available; if the file executed cleanly without malicious C2 or file-drop activity, that would weigh toward 'suspicious' rather than 'malicious'. However, tier-1 consensus on a known PUA family + signer mismatch is sufficient for malicious classification even without runtime confirmation.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- File is signed (Authenticode verified=true) — not unsigned malware
- No malicious sandbox verdicts available (behaviour=null)
- No malicious dropped children or contacted hosts detected
- No external intelligence hits (CIRCL, MalwareBazaar, YARAify all negative)
- Tier-1 consensus on OfferCore PUA family (Microsoft, ESET-NOD32, DrWeb)
- Signer mismatch: claims VLC but signed by Softonic International SA
- Unknown signer with zero historical samples (signerStats.found=false)
- Brand-new file (0 days old, 1 submission) — fresh distribution campaign
- Rare prevalence (rare_new classification)
- Filename spoofing legitimate software (VLC Media Player)
Block and quarantine this file. Do not execute it. Download VLC Media Player only from the official VideoLAN website or trusted distribution channels. If already executed, perform a full system scan and monitor for unwanted software installations.
Behavior
Plain-English impact first, then the observed runtime evidence.
Threat context
How bundlers & adware work
This is a bundler — a real-looking installer that hides extra software inside. When you run it, it quietly installs things you never asked for: ad injectors, browser toolbars, fake 'PC cleaner' apps, or even more bundlers. The people behind it get paid for every unwanted app they sneak on.
Bottom line:It's not usually built to destroy files, but it slows your PC, floods it with ads, and can be a real pain to fully remove.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
Category: pua
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
12 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 12 antivirus detections make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- vlc-media-player-3.0.23-installer.exe
- Format
- Win32 EXE
- Code signing
- Signature valid: SOFTONIC INTERNATIONAL SA
- Size
- 2.0 MB
- Last analyzed
- Jun 8, 2026, 7:02 PM UTC
b5cea4d097ed872fa4340efd32cea499ce311ce76997f374d7aa54aa447c1263Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
Don't open or run this file. Delete it from your Downloads (or wherever you saved it), then empty the Recycle Bin.
If you already opened it, disconnect from the internet and run a full scan with your antivirus — Windows Security, built into Windows, is sufficient.
If you typed any passwords while it was open, change them from a device you trust.
In future, only download software from the official website or an official app store.
Safety FAQ
- Yes — vlc-media-player-3.0.23-installer.exe is malicious, so do not run it, and delete it. 12 of 75 antivirus engines flag it (family: OfferCore). It behaves as adware or a potentially unwanted program (PUA) — not always destructive, but it bundles ads, trackers, or unwanted changes you didn't ask for. If you've already run it, see the removal and recovery steps below.
- vlc-media-player-3.0.23-installer.exe is a Windows executable program (application/x-msdownload), about 2 MB. Our analysis identifies it as malicious (family: OfferCore) — adware or a potentially unwanted program (PUA) — not always destructive, but it bundles ads, trackers, or unwanted changes you didn't ask for. Because a file's name and icon can be faked, the safest way to identify it is by its cryptographic hash (below), not its filename.
- 12 of 75 antivirus engines flagged vlc-media-player-3.0.23-installer.exe, 12 of them as outright malicious. A detection rate at this level is a reliable signal that the file is dangerous.
- Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
- To remove vlc-media-player-3.0.23-installer.exe: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original vlc-media-player-3.0.23-installer.exe file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
- vlc-media-player-3.0.23-installer.exe is classified as adware or a potentially unwanted program (PUA) — not always destructive, but it bundles ads, trackers, or unwanted changes you didn't ask for. Engines attribute it to the OfferCore family. Knowing the family matters because it tells you the likely impact — data theft, remote control, file encryption, or unwanted ads — and guides the cleanup.
- Yes — vlc-media-player-3.0.23-installer.exe carries a valid digital signature from SOFTONIC INTERNATIONAL SA, which confirms the file hasn't been tampered with since that publisher signed it. A valid signature is a positive signal, but note that malware is occasionally signed with stolen or abused certificates, so it isn't proof of safety on its own.
- The SHA-256 hash of vlc-media-player-3.0.23-installer.exe is b5cea4d097ed872fa4340efd32cea499ce311ce76997f374d7aa54aa447c1263, and its MD5 is 556748955f650c6edb9b888eceb95f35. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
- This report reflects the scan run on June 8, 2026. Because a file's hash never changes, the identity of vlc-media-player-3.0.23-installer.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.