Is AdskNLM.exe safe?
A confirmed crack tool drew 43/75 detections, including 11 tier-1 engines, alongside malicious sandbox activity and four corroborating YARA rules.
The file is consistently identified as a crack or patching tool, with 43 of 75 engines detecting it and multiple reputable engines explicitly using hacktool labels. Runtime evidence includes process injection, defense evasion, destructive activity, and a malicious sandbox result, while four YARA rules provide further corroboration.
f582054f182d8443e7…5e451f00a40974Recommended next actions
Before running
Do not run it. Delete this file from the device, then empty the Recycle Bin or Trash.
If you already ran it
Disconnect from the internet, start a full or offline antivirus scan, then secure important accounts from a clean device.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The file is consistently identified as a crack or patching tool, with 43 of 75 engines detecting it and multiple reputable engines explicitly using hacktool labels. Runtime evidence includes process injection, defense evasion, destructive activity, and a malicious sandbox result, while four YARA rules provide further corroboration.
Detection is broad: 43 of 75 engines flagged the executable, including 11 tier-1 engines. ESET-NOD32 and Malwarebytes explicitly identify a crack hacktool, while Microsoft calls it a Win64 patcher. A completed sandbox run produced a malicious result and mapped activity to T1055, T1485, T1543.003, and T1562.001. Four YARA rules matched, including FreddyBearDropper, strengthening the dropper and command-execution concern. Although the two observed domains had no cached malicious reputation and one sandbox result was clean, those counter-signals do not outweigh the confirmed hacktool labeling and corroborating runtime evidence.
What We Detected
43 of 75 antivirus engines flagged AdskNLM.exe, including 11 tier-1 engines. ESET-NOD32 reported Win64/HackTool.Crack.DT, Malwarebytes reported HackTool.Crack, and Microsoft reported Trojan:Win64/Patcher!MTB. The executable is unsigned and packed with 7Z, which adds concern in combination with these detections.
Threat Behavior
A completed sandbox run returned a malicious result and recorded six offensive techniques, including process injection (T1055), destructive activity (T1485), service creation or modification (T1543.003), and impairment of defenses (T1562.001). Four YARA rules matched, including FreddyBearDropper and Sus_CMD_Powershell_Usage. The two contacted domains were fully checked and had no known-malicious or suspicious cache entries, but that does not negate the local system activity.
What To Do Now
Do not execute the file. Quarantine or remove it while keeping endpoint protection enabled; if it has already run, perform a full system scan and review services, scheduled startup points, PowerShell activity, and credentials used on the machine.
Where this verdict could be wrong4 caveats
- contactedHosts inspected both observed domains and found 0 known-malicious or suspicious hosts.
- droppedChildren inspected 10 extracted files, but all 10 remained unknown and none was confirmed malicious.
- One sandbox result was clean, while another was malicious, so runtime verdicts were not unanimous.
- One community comment claims the file was manually assessed as clean, but it has no votes and conflicts with the engine, runtime, and YARA evidence.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- contactedHosts inspected 2/2 observed domains with no cached malicious or suspicious matches
- droppedChildren.hasMaliciousChild=false across 10 inspected children
- brandMismatch.detected was not reported
- 43/75 antivirus detections
- 11 tier-1 malicious detections
- Confirmed crack/hacktool labeling
- Unsigned executable
- 7Z-packed payload
- Malicious sandbox verdict
Quarantine or delete the file and keep endpoint protection enabled. If it was executed, run a full scan and investigate persistence, PowerShell activity, services, and possible credential exposure.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete43 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Complete2 contacted hosts were cross-checked.
YARA
Complete8 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 36MITRE ATT&CK techniques
- 15spawned processes
- 2network contacts
- 26filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Used an input-capture technique that can record credentials or keystrokes.
High concern: Created or modified a system service, which can keep code running.
High concern: Changed an auto-start location that can make code run after sign-in or restart.
High concern: Attempted to impair or bypass security controls.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How hacktools are abused
This is a hacking or cracking tool — the kind used to bypass software licences, generate fake keys, or attack other systems. Even when the tool 'works', these downloads very often carry hidden malware.
Bottom line:Running one means trusting an anonymous author with full access to your PC — rarely worth the risk.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
AdskNLM.exe
f582054f182d8443e7ca21d65caf8233d548ddab7ff5b1f3365e451f00a40974
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\AdskNLM.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Windows\System32\reg.exe" delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Autodesk Access Service" /f
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
nlm.mst
C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\nlm.mst
04Isolated runtime analysis - Written fileObserved
delnowmic.ps1
C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\delnowmic.ps1
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
time.windows.com
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
assets.msn.com
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox; 1 returned "malicious".
Adversary techniques mapped to the MITRE ATT&CK framework.
- time.windows.com
- assets.msn.com
- HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\EncodedCtl
- HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate\LastSyncTime
- HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\Certificates\02FAF3E291435468607857694DF5E45B68851868\Blob
- HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43\Blob
- HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob
- HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54\Blob
- C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\nlm.mst
- C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\delnowmic.ps1
- C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\UnNamed.json
- C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\nlm11.19.9.0_ipv4_ipv6_win64.msi
- C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\licenses.lic
- C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\adskflex.exe
- C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\delnowmic.ps1
- C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\licenses.lic
- C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\nlm.mst
- C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\nlm11.19.9.0_ipv4_ipv6_win64.msi
- Local\MSCTF.Asm.MutexDefault1
- \Sessions\1\BaseNamedObjects\Microsoft.Windows.Health.TestInProduction.RegistryStore.AggregateResults
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 32ee791aa61bfe60a28a…62fcc1Never scannednever seen before
- 74b3152a28d4f1a4fff4…89ff70Never scannednever seen before
- 6f13e52d797a732435c8…6cc95fNever scannednever seen before
- 3a053653cd79ba09f459…01c28dNever scannednever seen before
- a304804cc2925febb602…880bd7Never scannednever seen before
- 90e413cd675ee085c441…672bdbNever scannednever seen before
- a9cedb4084f243ff831c…a9fbe7Never scannednever seen before
- fc54f6e88f569c5c32df…d43af7Never scannednever seen before
- 08bf71723f17bc3bb3d0…79af7eNever scannednever seen before
- 4b5ef379990a4663a334…ff92f9Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 8rule hits recorded
- 43 / 75engines flagged
- 272sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 isolated runtime environment classified the observed behavior as malicious.
Verdict inputView chapterProvenanceObservedSourceIsolated runtime analysisObserved at - 02
6 high-confidence signature or behavior rules matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 03
43 of 75 antivirus engines flagged the file, including alibabacloud and ALYac.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 04
Scanned file: AdskNLM.exe — f582054f182d8443e7ca21d65caf8233d548ddab7ff5b1f3365e451f00a40974
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\AdskNLM.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Windows\System32\reg.exe" delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Autodesk Access Service" /f
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: nlm.mst — C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\nlm.mst
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: delnowmic.ps1 — C:\Users\<USER>\AppData\Local\Temp\Adsk-NLM\delnowmic.ps1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: time.windows.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: assets.msn.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: hacktool
One or more independent reference databases matched this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
- dgaaga
- FreddyBearDropper
- SEH__vectored
- Sus_CMD_Powershell_Usage
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\System32\svchost.exe -k NetworkService -pPE is packed (high-entropy code or known packer) AND unsigned AND at least one engine flagged it. Packing alone is common in legit software; packing + unsigned + signal is the malware-dropper pattern.
Evidencepackers: 7ZSandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeUnsigned, packed PE with sandbox-observed network activity. The packing step hides the payload until execution; the network call fetches / reports for the next stage. Classic dropper / stager behaviour.
Evidencetime.windows.com
43 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
A known packer signature (UPX / Themida / VMProtect / etc.) matched this file. Packers aren't malicious on their own, but most malware uses them.
Packers compress or encrypt the executable and only unpack it at runtime. Legitimate commercial software uses them too — but if the file is also unsigned and rare, it's a strong malware signal.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- AdskNLM.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 7.9 MB
- Last analyzed
- Oct 3, 2026, 4:35 PM UTC
f582054f182d8443e7ca21d65caf8233d548ddab7ff5b1f3365e451f00a40974Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't run this file. Delete this file from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already ran it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
From a different, clean device, change the passwords on your important accounts (email and banking first) and turn on two-factor authentication.
- Recovery step 04
Get a fresh copy from the developer's official site or an official app store.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is AdskNLM.exe a virus?
What is AdskNLM.exe?
How many antivirus engines detected AdskNLM.exe?
What should I do if I already ran AdskNLM.exe?
How do I remove AdskNLM.exe?
What kind of malware is AdskNLM.exe?
What is the SHA-256 hash of AdskNLM.exe?
How up to date is this analysis of AdskNLM.exe?
Community
Member reviews and reports for this exact file hash.