Is Unreal_Gold.exe safe?
No antivirus engine detected the signed executable, and its completed sandbox run produced no malicious determination, though one unchecked direct-IP contact warrants ordinary caution.
All 74 antivirus engines returned without a malicious or suspicious detection, including 17 tier-1 engines, and the executable has a verified signature. One sandbox run found no malicious outcome, although it observed T1134 and direct-IP traffic whose destination lacks a complete saved reputation check.
ce6c6e70812d682283…c66c4cf974ce8fRecommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 74 antivirus engines returned without a malicious or suspicious detection, including 17 tier-1 engines, and the executable has a verified signature. One sandbox run found no malicious outcome, although it observed T1134 and direct-IP traffic whose destination lacks a complete saved reputation check.
The strongest evidence is the complete absence of detections across 74 engines, including 17 tier-1 products. The executable is signed and its signature verifies, although the signer has no established history in the available records. A completed sandbox run did not produce a malicious determination, and no inspected child was confirmed malicious. The runtime trace did include T1134 and a connection to 162.159.36.2, but the connection heuristic was low severity and no complete host-reputation result is available. Static PE analysis found neither packing nor high-entropy code, while external intelligence produced no corroborating malware hit. The mixed prior imphash results carry little weight because none shares the signer and installer-framework imphashes commonly collide across unrelated software.
What We Detected
The file received 0 malicious and 0 suspicious detections out of 74 antivirus engines. All 17 reporting tier-1 engines were non-detecting. Its code signature verifies under “Stijn Volckaert,” although no publisher history or curated trusted-publisher match is available.
Threat Behavior
One completed sandbox run produced no malicious determination. It recorded one offensive-associated technique, T1134, among 15 benign-common techniques and contacted the IP address 162.159.36.2. Because contactedHosts is unavailable, no complete saved reputation result exists for that address. Two dropped files were inspected without a confirmed malicious child, but both child verdicts remain unknown. Static analysis found no packer, no likely packing, and no high-entropy code.
What To Do Now
Use the file only if it came from the expected distributor and the signer identity matches that source. Keep endpoint protection enabled and obtain a fresh copy from the official release channel if the download origin is uncertain.
Where this verdict could be wrong5 caveats
- T1134 was observed as behaviour.offensiveTechniques[0], although it appeared alongside 15 ambient techniques and no malicious sandbox determination.
- MalwareTips.Synth.DirectIpC2 recorded contact with 162.159.36.2; contactedHosts=null leaves that address without a complete saved reputation cross-check.
- signing.signerStats.found=false and signing.trustedPublisher.matched=false, so the verified 'Stijn Volckaert' signature lacks established historical support.
- Both inspected dropped children have unknown verdicts, so droppedChildren.hasMaliciousChild=false does not establish that those children are benign.
- similarHashes shows 3/5 suspicious and 2/5 safe prior verdicts, but all are imphash-only matches with signerMatchesSubject=false.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 antivirus engines reported a malicious or suspicious result.
- 17 tier-1 engines reported no detection.
- The 'Stijn Volckaert' code signature is verified.
- One completed sandbox run produced no malicious determination.
- No packing, high-entropy code, external-intelligence hit, or confirmed malicious child was found.
- T1134 appeared in the completed runtime trace.
- Direct-IP traffic to 162.159.36.2 triggered a low-severity heuristic.
- No complete contacted-host reputation result is available.
- The verified signer has no recorded sample history or curated publisher match.
- Two dropped children remain without individual verdicts.
Proceed only when the file came from its expected official source and the verified signer is appropriate for that source. Keep security protection enabled and rescan after future signature updates if provenance is uncertain.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 16MITRE ATT&CK techniques
- 1spawned processes
- 1network contacts
- 13filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- HKEY_USERS\S-1-5-21-4270068108-2931534202-3907561125-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids\exefile
- C:\Users\<USER>\AppData\Local\Temp\nseC2D5.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nseC2D5.tmp\nsDialogs.dll
- C:\Users\user\AppData\Local\Microsoft\Windows\Caches
- C:\Users\user\AppData\Local\Temp
- C:\Users\user\AppData\Local\Temp\
- C:\Users\<USER>\AppData\Local\Temp\nsoC13E.tmp
- C:\Users\<USER>\AppData\Local\Temp\nseC2D5.tmp
- C:\Users\user\AppData\Local\Temp\nsq6C74.tmp
- C:\Users\user\AppData\Local\Temp\nsx973E.tmp
Files this sample writes at runtime
This file drops 2 children at runtime. None are currently flagged malicious in our cache.
- 3ad2dc318056d0a2024a…056cf2Never scannednever seen before
- b1350f487692057c8ffd…551fc0Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 0 / 74engines flagged
- 65sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The file has a valid code signature from Stijn Volckaert.
ProvenanceObservedSourceCode-signing metadataObserved at - 03
The hash has been submitted 71 times from 65 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Unreal_Gold.exe — ce6c6e70812d6822832d220192d118588ad3c25dcc3b49f62bc66c4cf974ce8f
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\user\Desktop\Unreal_Gold.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: modern-wizard.bmp — C:\Users\<USER>\AppData\Local\Temp\nseC2D5.tmp\modern-wizard.bmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: nsDialogs.dll — C:\Users\<USER>\AppData\Local\Temp\nseC2D5.tmp\nsDialogs.dll
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Low-severity pattern matches — worth noting but not on their own cause for alarm.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence162.159.36.2
0 of 74 engines flagged this file
View all 74 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Unreal_Gold.exe
- Format
- Win32 EXE
- Code signing
- Signature valid: Stijn Volckaert
- Size
- 32.2 MB
- Last analyzed
- Sep 24, 2026, 7:38 AM UTC
ce6c6e70812d6822832d220192d118588ad3c25dcc3b49f62bc66c4cf974ce8fSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Unreal_Gold.exe safe?
What is Unreal_Gold.exe?
How many antivirus engines detected Unreal_Gold.exe?
Is Unreal_Gold.exe digitally signed?
What is the SHA-256 hash of Unreal_Gold.exe?
Is it safe to run Unreal_Gold.exe?
How up to date is this analysis of Unreal_Gold.exe?
Community
Member reviews and reports for this exact file hash.