Safe
Signed NIUBI Partition Editor Free Edition installer is safe; single low-trust engine flag and sandbox heuristics are likely false positives for disk utility behavior.
f5ae105cb0351be137…cdb1ad117bThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
With zero tier-1 malicious detections and only Bkav (low-trust) flagging generically, this aligns with false positive patterns. The verified signature from Chongqing NIUBI Technology Co. matches the self-install to NIUBISoft paths and outbound to niubi-tech.com/hdd-tool.com. Offensive MITRE techniques and synthesis heuristics fire due to driver install, system access, and direct IP resolution (CDNs/Google), common in partition editors. No malicious children, sandbox consensus, or external intel tips malicious. Medium prevalence supports commodity software.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
Bkav (low_trust) 'W32.AIDetectMalware' only malicious out of 70 reporting
signing.signer='Chongqing NIUBI Technology Co.', verified=true
behaviour.processes include '"C:\Program Files\NIUBISoft\NIUBI Partition Editor Free Edition\npe.exe"'
behaviour.contactedUrls='http://niubi-tech.com/cgi-bin/versions.py'
engines.tier1Malicious=0, tier1ReportedClean=17
- Verified Authenticode signature
- Proper self-install to NIUBI Partition Editor path
- Contacts official niubi-tech.com/hdd-tool.com domains
- 17 tier-1 engines report clean
- Medium prevalence (359 submissions, 314 sources)
- Single low-trust engine detection (Bkav)
- High-severity heuristic for process injection (T1055)
- Heuristic flags LSASS access (credential dump shape)
- Direct IP contacts without DNS (15 IPs)
- No prior signer history (signerStats.found=false)
This is the legitimate NIUBI Partition Editor Free Edition. Safe to install and use for disk management. Download from official site to avoid tampered copies.
1 contradiction resolved by the scoring engine
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 150.171.109.118
- 104.21.62.217
- 150.171.73.13
- 104.26.13.42
- 172.67.151.113
- 188.166.63.236
- 150.171.109.116
- 216.239.34.181
- 206.189.5.60
- 50.28.107.46
- http://niubi-tech.com/cgi-bin/versions.py
- MDA_NTDRV
- C:\Users\<USER>\AppData\Local\Temp\nsvE59E.tmp
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\System.dll
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\ioSpecial.ini
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\InstallOptions.dll
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\InstallOptions.dll
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\ioSpecial.ini
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\System.dll
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\
- cversions.3.m
- macrorit.mde
- macrorit.mw
- Global\OneSettingQueryMutex+compat+encapsulation
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- b7bb7f23fb83f9a6c028…a1f769Never scannednever seen before
- 1a29dfc359942a78dae3…abb3d6Never scannednever seen before
- d5fb09c97517a54cb63c…2d3e94Never scannednever seen before
- 5237ffe1150b279fde5a…732606Never scannednever seen before
- 847952dbaa195a631d74…894820Never scannednever seen before
- a1390a78533c47e55cc3…9dd0e1Never scannednever seen before
- af937d94c19c7d9deab1…faa2f8Never scannednever seen before
- 987582c690e221c80d48…57f9abNever scannednever seen before
- 76b8da4e687ce7d46365…084e19Never scannednever seen before
- fc64b31426ff0c2814c0…2f17d8Never scannednever seen before
YARA + heuristic rules that fired
A researcher-curated or high-severity heuristic rule matched this sample. These rules target specific malware families and are near-definitive.
Sandbox flagged persistence indicators (registry Run keys / services / scheduled tasks).
EvidenceMDA_NTDRVMITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeSample contacted 15 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence150.171.109.118 · 104.21.62.217 · 150.171.73.13
1 detection across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- NPE_free.exe
- Size
- 12.27 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- f5ae105cb0351be1375012c5bd0464aff334fbe262ae8234fdf064cdb1ad117b
- MD5
- 9646f6c899c5c4b6bd274864e209a405
- SHA-1
- 9cac864a2d9c6840477685d4107a92548bebfb14
- PE imphash
- 57e98d9a5a72c8d7ad8fb7a6a58b3daf
- First seen (VT)
- 2/15/2026, 2:21:44 AM
- Last analysis (VT)
- 4/26/2026, 6:43:03 AM
- First scan (MalwareTips)
- 4/27/2026, 3:30:26 AM
- Last scan (MalwareTips)
- 4/27/2026, 3:30:26 AM
- Code signer
- Chongqing NIUBI Technology Co.verified
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.