Is Kemono.Downloader.exe safe?
Only 2 of 75 engines raised generic low-trust detections, while tier-one engines and the completed sandbox run found no corroborating malware activity.
APEX and Bkav flagged the file, but all 17 tier-one engines that reported results did not detect it. One completed sandbox run found no offensive behavior, persistence, or dropped payloads, although the unsigned status and an unchecked direct-IP contact warrant ordinary caution.
f6f16b7b8fcf70893d…cf2da757342bd6Recommended next actions
Before running
Run it only when it came from the developer's official site or another source you independently trust.
If you already ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
APEX and Bkav flagged the file, but all 17 tier-one engines that reported results did not detect it. One completed sandbox run found no offensive behavior, persistence, or dropped payloads, although the unsigned status and an unchecked direct-IP contact warrant ordinary caution.
The detection pattern is dominated by two generic low-trust alerts out of 75 engines, with no tier-one detections or family consensus. The completed sandbox observation produced no malicious verdict, offensive techniques, persistence indicators, or dropped files. It did contact 162.159.36.2 directly, but no complete host-reputation result is available, so that connection cannot be characterized as benign or hostile. The executable is unsigned and has no established signer history, reducing confidence compared with authenticated software. Similar-file decisions are mixed, but their imphash-only matches lack signer co-matches and therefore provide little reliable identity evidence.
What We Detected
APEX and Bkav flagged the sample, giving 2 detections among 75 engines. Both are low-trust detections with generic labels; all 17 tier-one engines that reported results were silent, and no engine consensus identified a malware family.
Threat Behavior
One completed sandbox run recorded no offensive techniques, persistence indicators, dropped files, or malicious sandbox verdict. The file contacted 162.159.36.2 without an application domain; because the contacted-host reputation check was not completed or saved, no conclusion can be drawn about that address. Static PE analysis found no high-entropy code or recognized packer.
What To Do Now
Obtain the executable from the project's official release channel and verify its hash where the publisher supplies one. Keep endpoint protection enabled, and avoid running this unsigned copy if its download source cannot be confirmed.
Where this verdict could be wrong3 caveats
- The executable is unsigned, so no authenticated publisher can be tied to this copy.
- The observed contact to 162.159.36.2 was not covered by a saved host-reputation cross-check.
- Four of five imphash-only precedents received suspicious verdicts, although the absent signer co-match makes those similarities weak.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- engines.tier1Malicious=0 across 17 reporting tier-one engines
- engines.onlyLowTrustFlagging=true
- behaviour.offensiveCount=0 in one completed sandbox
- No persistence indicators or dropped file hashes were recorded
- peAnalysis.highEntropyCode=false and peAnalysis.likelyPacked=false
- Unsigned Win32 executable with no authenticated publisher
- Direct-IP contact to 162.159.36.2 lacks a complete reputation check
- APEX and Bkav produced 2/75 generic detections
- Only 14 days of observed submission history
Use only a copy obtained from the official project release channel and retain endpoint protection. If the source or hash cannot be verified, quarantine this unsigned copy rather than executing it.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete2 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 runtime contact was observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 9MITRE ATT&CK techniques
- 2spawned processes
- 1network contacts
- 0filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 2 / 75engines flagged
- 47sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
2 of 75 antivirus engines flagged the file, including APEX and Bkav.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 48 times from 47 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: Kemono.Downloader.exe — f6f16b7b8fcf70893d86d704380abdd06be9fc3d23f0e4905ccf2da757342bd6
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Users\<USER>\Desktop\8fcf70893d86d704380abdd06be9fc3d23f0e4905ccf2da757342bd6.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — "C:\Users\user\Desktop\8fcf70893d86d704380abdd06be9fc3d23f0e4905ccf2da757342bd6.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Low-severity pattern matches — worth noting but not on their own cause for alarm.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence162.159.36.2
2 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Kemono.Downloader.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 14.6 MB
- Last analyzed
- Oct 3, 2026, 12:08 AM UTC
f6f16b7b8fcf70893d86d704380abdd06be9fc3d23f0e4905ccf2da757342bd6Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Run it only when it came from the developer's official site or another source you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Kemono.Downloader.exe safe?
What is Kemono.Downloader.exe?
How many antivirus engines detected Kemono.Downloader.exe?
What is the SHA-256 hash of Kemono.Downloader.exe?
Is it safe to run Kemono.Downloader.exe?
How up to date is this analysis of Kemono.Downloader.exe?
Community
Member reviews and reports for this exact file hash.