Our call: Is NPE_free.exe safe?Safe
Signed NIUBI Partition Editor Free Edition installer is safe; single low-trust engine flag and sandbox heuristics are likely false positives for disk utility behavior.
- One or more independent reference checks were incomplete or unavailable.Derived · External-intelligence coverage
- The file has a valid code signature from Chongqing NIUBI Technology Co..Observed · Code-signing metadata
- 1 high-confidence signature or behavior rule matched this file.Derived · Signature and behavior rules
f5ae105cb0351be137…cdb1ad117bRecommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 of 16 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete4 signature or behavior rules matched.
External intel
Not runNo independent reference checks are recorded.
No timestamp recorded
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
NPE_free.exe
f5ae105cb0351be1375012c5bd0464aff334fbe262ae8234fdf064cdb1ad117b
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
C:\Windows\System32\RuntimeBroker.exe -Embedding
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\file.exe"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
nsvE59E.tmp
C:\Users\<USER>\AppData\Local\Temp\nsvE59E.tmp
04Isolated runtime analysis - Written fileObserved
System.dll
C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\System.dll
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
150.171.109.118
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
104.21.62.217
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
One or more independent reference checks were incomplete or unavailable.
ProvenanceDerivedSourceExternal-intelligence coverageObserved at - 02
The file has a valid code signature from Chongqing NIUBI Technology Co..
ProvenanceObservedSourceCode-signing metadataObserved at - 03
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 04
Scanned file: NPE_free.exe — f5ae105cb0351be1375012c5bd0464aff334fbe262ae8234fdf064cdb1ad117b
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — C:\Windows\System32\RuntimeBroker.exe -Embedding
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\<USER>\Desktop\file.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: nsvE59E.tmp — C:\Users\<USER>\AppData\Local\Temp\nsvE59E.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: System.dll — C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\System.dll
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 150.171.109.118 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 104.21.62.217 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Our antivirus network shows only one low-trust detection amid 17 tier-1 clean verdicts. The file installs properly to the expected NIUBI path, contacts its own version-check server, and exhibits no malicious runtime actions. Heuristic flags for injection and LSASS access fit low-level partition tools but lack corroboration.
With zero tier-1 malicious detections and only Bkav (low-trust) flagging generically, this aligns with false positive patterns. The verified signature from Chongqing NIUBI Technology Co. matches the self-install to NIUBISoft paths and outbound to niubi-tech.com/hdd-tool.com. Offensive MITRE techniques and synthesis heuristics fire due to driver install, system access, and direct IP resolution (CDNs/Google), common in partition editors. No malicious children, sandbox consensus, or external intel tips malicious. Medium prevalence supports commodity software.
What We Detected
Signed executable matching NIUBI Partition Editor Free Edition, a legitimate disk partitioning tool. Single low-trust flag from Bkav (W32.AIDetectMalware); all 17 tier-1 engines clean.
Threat Behavior
Installs to Program Files\NIUBISoft, drops DLLs/core files, checks versions at niubi-tech.com, opens tutorial in Edge. Heuristics flag T1055 injection (Explorer), LSASS access, direct IPs (Cloudflare/Google CDNs), driver persistence — typical for partition managers needing low-level hooks, not malware.
What To Do Now
Safe to run if from trusted source. Use official download from niubi-tech.com to verify.
Where this verdict could be wrong3 caveats
- triggeredHeuristics 'MalwareTips.Synth.ProcessInjection' (high sev, T1055 into Explorer.EXE) and 'MalwareTips.Synth.CredentialDumper' (lsass.exe) — unusual for legit software unless tool requires deep system access.
- signerStats.found=false, no historical safeRate — can't fully trust unknown signer.
- behaviour.contactedIps=15 direct IPs (e.g. '104.21.62.217' Cloudflare, no domains) flagged by 'MalwareTips.Synth.DirectIpC2' as potential C2 evasion.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Verified Authenticode signature
- Proper self-install to NIUBI Partition Editor path
- Contacts official niubi-tech.com/hdd-tool.com domains
- 17 tier-1 engines report clean
- Medium prevalence (359 submissions, 314 sources)
- Single low-trust engine detection (Bkav)
- High-severity heuristic for process injection (T1055)
- Heuristic flags LSASS access (credential dump shape)
- Direct IP contacts without DNS (15 IPs)
- No prior signer history (signerStats.found=false)
This is the legitimate NIUBI Partition Editor Free Edition. Safe to install and use for disk management. Download from official site to avoid tampered copies.
Behavior
Plain-English impact first, then the observed runtime evidence.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 150.171.109.118
- 104.21.62.217
- 150.171.73.13
- 104.26.13.42
- 172.67.151.113
- 188.166.63.236
- 150.171.109.116
- 216.239.34.181
- 206.189.5.60
- 50.28.107.46
- http://niubi-tech.com/cgi-bin/versions.py
- MDA_NTDRV
- C:\Users\<USER>\AppData\Local\Temp\nsvE59E.tmp
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\System.dll
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\ioSpecial.ini
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\InstallOptions.dll
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\InstallOptions.dll
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\ioSpecial.ini
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\modern-wizard.bmp
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\System.dll
- C:\Users\<USER>\AppData\Local\Temp\nskE5AE.tmp\
- cversions.3.m
- macrorit.mde
- macrorit.mw
- Global\OneSettingQueryMutex+compat+encapsulation
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- b7bb7f23fb83f9a6c028…a1f769Never scannednever seen before
- 1a29dfc359942a78dae3…abb3d6Never scannednever seen before
- d5fb09c97517a54cb63c…2d3e94Never scannednever seen before
- 5237ffe1150b279fde5a…732606Never scannednever seen before
- 847952dbaa195a631d74…894820Never scannednever seen before
- a1390a78533c47e55cc3…9dd0e1Never scannednever seen before
- af937d94c19c7d9deab1…faa2f8Never scannednever seen before
- 987582c690e221c80d48…57f9abNever scannednever seen before
- 76b8da4e687ce7d46365…084e19Never scannednever seen before
- fc64b31426ff0c2814c0…2f17d8Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
The available sources did not agree on a named threat category.
This legacy report does not record whether the independent reference checks completed.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
Sandbox flagged persistence indicators (registry Run keys / services / scheduled tasks).
EvidenceMDA_NTDRVMITRE T1055 (Process Injection) observed — CreateRemoteThread / APC / reflective-DLL injection. The payload is being smuggled into a legitimate process to bypass AV hooks.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeThe sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence150.171.109.118 · 104.21.62.217 · 150.171.73.13
1 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- NPE_free.exe
- Format
- Win32 EXE
- Code signing
- Signature valid: Chongqing NIUBI Technology Co.
- Size
- 12.3 MB
- Last analyzed
- Apr 27, 2026, 7:30 AM UTC
f5ae105cb0351be1375012c5bd0464aff334fbe262ae8234fdf064cdb1ad117bSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
Run it only when it came from the developer's official site or another source you independently trust.
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
Keep your antivirus and Windows updates switched on so you stay protected.