Is GTAIV-Remix-CompMod-Installer.exe safe?
Only Trapmine raised a generic machine-learning alert among 75 engines, with no tier-1 detection or independent malware-intelligence corroboration.
Trapmine alone flagged the file with a generic machine-learning label; none of the tier-1 engines detected it. One sandbox recorded a direct IP connection and T1005, but issued no malicious assessment, and the connection lacks a completed host-reputation check.
f0a2dd89bbf9d6ae38…5676eab7a1f15bRecommended next actions
Before installing
Install it only when it came from the developer's official site or an official app store.
If you already installed it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Trapmine alone flagged the file with a generic machine-learning label; none of the tier-1 engines detected it. One sandbox recorded a direct IP connection and T1005, but issued no malicious assessment, and the connection lacks a completed host-reputation check.
The strongest evidence is the detection distribution: only 1 of 75 engines flagged the sample, and that result came from low-trust Trapmine using a generic machine-learning label. All 17 reporting tier-1 engines were clean, with no family consensus. One completed sandbox observed T1005 and a direct connection to 162.159.36.2, but it produced no malicious assessment or persistence indicators. Because no complete host-reputation result was saved, the direct-no complete contacted-host reputation result was available. The unsigned status warrants source verification, but broad submission prevalence, ordinary PE structure, and absent external-intelligence matches favor a false alarm.
What We Detected
Only 1 of 75 engines raised an alert. Trapmine reported the generic label malicious.moderate.ml.score, while all 17 reporting tier-1 engines produced no detection and no malware family consensus formed.
Threat Behavior
One sandbox run recorded T1005 among nine more commonly observed techniques and contacted the IP address 162.159.36.2. The sandbox issued no malicious assessment, recorded no persistence indicators, and listed no dropped hashes. However, the contacted-host reputation check was not completed or saved, so the IP connection remains unresolved. Static PE analysis found no packer, no likely packing, and no high-entropy code.
What To Do Now
Obtain the installer from the mod project's established release page and compare its SHA-256 value before running it. Because the executable is unsigned, keep endpoint protection enabled and avoid granting unnecessary administrator privileges.
Where this verdict could be wrong3 caveats
- The executable is unsigned despite signing.applicable=true, leaving its claimed origin unauthenticated.
- T1005 appeared during runtime analysis, although it was the only offensive technique and no sandbox issued a malicious assessment.
- MalwareTips.Synth.DirectIpC2 fired for 162.159.36.2, but contactedHosts=null means the address did not receive a complete saved reputation cross-check.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- All 17 reporting tier-1 engines produced no detection
- Only 1/75 engines flagged the sample
- No malicious sandbox assessment or persistence indicators
- No YARAify, MalwareBazaar, or CIRCL match
- peAnalysis.likelyPacked=false and peAnalysis.highEntropyCode=false
- Unsigned Win32 executable with no authenticated publisher
- T1005 recorded in one sandbox run
- Direct connection to 162.159.36.2 without a completed host-reputation result
- One generic low-trust machine-learning detection from Trapmine
Verify SHA-256 f0a2dd89bbf9d6ae38c4a1facf31212c7055ef56994f7f42e15676eab7a1f15b against the project's official release source. Keep endpoint protection enabled, especially because the installer is unsigned and its direct IP contact was not reputation-checked.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 10MITRE ATT&CK techniques
- 2spawned processes
- 1network contacts
- 15filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
GTAIV-Remix-CompMod-Installer.exe
f0a2dd89bbf9d6ae38c4a1facf31212c7055ef56994f7f42e15676eab7a1f15b
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\user\Desktop\GTAIV-Remix-CompMod-Installer.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Caches
C:\Users\user\AppData\Local\Microsoft\Windows\Caches
04Isolated runtime analysis - Written fileObserved
Explorer
C:\Users\user\AppData\Local\Microsoft\Windows\Explorer
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
162.159.36.2
Contact observed during runtime.
06Isolated runtime analysis
6 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Users\user\AppData\Local\Microsoft\Windows\Caches
- C:\Users\user\AppData\Local\Microsoft\Windows\Explorer
- C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
- \Device\ConDrv
- \Device\ConDrv\\Connect
- Local\Shell.CMruPidlList
- Local\SHResolveLibrary:C:/Users/<USER>/AppData/Roaming/Microsoft/Windows/Libraries/Documents.library-ms
- \Sessions\1\BaseNamedObjects\Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:iconcache_idx.db!rwWriterMutex
- \Sessions\1\BaseNamedObjects\Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:iconcache_16.db!dfMaintainer
- \Sessions\1\BaseNamedObjects\Global\C::Users:user:AppData:Local:Microsoft:Windows:Explorer:iconcache_32.db!dfMaintainer
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 1 / 75engines flagged
- 176sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 of 75 antivirus engines flagged the file, including Trapmine.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 195 times from 176 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: GTAIV-Remix-CompMod-Installer.exe — f0a2dd89bbf9d6ae38c4a1facf31212c7055ef56994f7f42e15676eab7a1f15b
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Users\user\Desktop\GTAIV-Remix-CompMod-Installer.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: Caches — C:\Users\user\AppData\Local\Microsoft\Windows\Caches
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Explorer — C:\Users\user\AppData\Local\Microsoft\Windows\Explorer
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Low-severity pattern matches — worth noting but not on their own cause for alarm.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence162.159.36.2
1 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.
Fingerprint and provenance
- File name
- GTAIV-Remix-CompMod-Installer.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 573.0 KB
- Last analyzed
- Sep 22, 2026, 8:20 AM UTC
f0a2dd89bbf9d6ae38c4a1facf31212c7055ef56994f7f42e15676eab7a1f15bSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Install it only when it came from the developer's official site or an official app store.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is GTAIV-Remix-CompMod-Installer.exe safe?
What is GTAIV-Remix-CompMod-Installer.exe?
How many antivirus engines detected GTAIV-Remix-CompMod-Installer.exe?
What is the SHA-256 hash of GTAIV-Remix-CompMod-Installer.exe?
Is it safe to install GTAIV-Remix-CompMod-Installer.exe?
How up to date is this analysis of GTAIV-Remix-CompMod-Installer.exe?
Community
Member reviews and reports for this exact file hash.