File verdict·MT AI Engine assessment

Our call: Is icarus_sfx.exe safe?Safe

Run with normal care
92Safety ratingLow observed risk

Legitimate Piriform (CCleaner) self-extracting installer signed by trusted Gen Digital, with one low-trust generic detection and clean runtime behavior.

Signature valid · Gen Digital Inc.
Evidence snapshot
  • The file has a valid code signature from Gen Digital Inc..Observed · Code-signing metadata
  • 1 of 76 antivirus engines flagged the file, including Webroot.Observed · Antivirus analysis
  • The hash has been submitted 20 times from 17 sources.Derived · Saved report facts
icarus_sfx.exe
1.7 MB
f865d2879b89045995116115dd16
Antivirus
1 of 76 flagged
Sandbox
Runtime complete
Code signing
Signed by Gen Digital Inc.
First seen
First seen 21 days ago
01

Before running

Run it only when it came from the developer's official site or another source you independently trust.

02

If you already ran it

Keep normal device protection enabled and stop if the file behaves unexpectedly.

Scan transparency

Coverage & freshness

5 of 5 complete

Complete means the check returned a usable result. It does not mean the file is safe.

  • Antivirus

    Complete

    1 of 76 engines flagged the file.

  • Sandbox

    Complete

    1 isolated runtime environment contributed observations.

  • Network

    Complete

    2 contacted hosts were cross-checked.

  • YARA

    Complete

    2 signature or behavior rules matched.

  • External intel

    Complete

    3 of 3 independent reference sources completed.

Recorded behavior

Attack story

Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.

ObservedDerived

7 recorded facts from one runtime window. Every fact remains independently traceable in the evidence ledger below.

Evidence provenance

Why these facts are shown

Each statement identifies whether it was directly recorded or derived from saved scan facts.

  1. 01

    The file has a valid code signature from Gen Digital Inc..

    ProvenanceObserved
    SourceCode-signing metadata
    Observed at
  2. 02

    1 of 76 antivirus engines flagged the file, including Webroot.

    Verdict inputView chapter
    ProvenanceObserved
    SourceAntivirus analysis
    Observed at
  3. 03

    The hash has been submitted 20 times from 17 sources.

    ProvenanceDerived
    SourceSaved report facts
    Observed at
  4. 04

    Scanned file: icarus_sfx.exe — f865d2879b890459952a1e6dd1d881e89d84325b3bf8035ba63ae3116115dd16

    ProvenanceObserved
    SourceUploaded file
    Observed at
  5. 05

    Observed process — "C:\Users\<USER>\Desktop\executable.exe"

    ProvenanceObserved
    SourceIsolated runtime analysis
    Observed at
  6. 06

    Observed process — C:\Windows\Temp\asw-46f80b95-0a6d-4866-8bb4-1bd76a4c6f39\common\icarus.exe /icarus-info-path:C:\Windows\Temp\asw-46f80b95-0a6d-4866-8bb4-1bd76a4c6f39\icarus-info.xml /install /sssid:6540

    ProvenanceObserved
    SourceIsolated runtime analysis
    Observed at
  7. 07

    File written: sfx.log — C:\ProgramData\Piriform\Icarus\Logs\sfx.log

    ProvenanceObserved
    SourceIsolated runtime analysis
    Observed at
  8. 08

    File written: sfx.log.tmp.4c87b095-2f54-41ae-b0d8-0f4cd90c108a — C:\ProgramData\Piriform\Icarus\Logs\sfx.log.tmp.4c87b095-2f54-41ae-b0d8-0f4cd90c108a

    ProvenanceObserved
    SourceIsolated runtime analysis
    Observed at
  9. 09

    Contacted host: 34.117.223.223 — Contact observed during runtime.

    ProvenanceObserved
    SourceIsolated runtime analysis
    Observed at
  10. 10

    Contacted host: 23.221.220.52 — Contact observed during runtime.

    ProvenanceObserved
    SourceIsolated runtime analysis
    Observed at
Chapter 02

Intelligence

The complete saved assessment, kept intact and grounded in the scan evidence.

MT AI Engine · Verdict analysis

The reasoning behind this verdict

This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.

92%Confidence
Very high
Analyst conclusion

Our analysis shows this as a verified Gen Digital-signed installer for Piriform Icarus/CCL components, downloading updates from official avcdn.net servers. A single low-trust engine flagged it generically, but no tier-1 detections or malicious behavior observed. Safe to use.

Where this verdict could be wrong3 caveats
  • triggeredHeuristics.MalwareTips.Synth.DirectIpC2 fired (medium severity) citing 7 contactedIps with no domains, but contactedUrls show avcdn.net domains — possible heuristic imprecision on CDN resolution.
  • signerStats.totalSamples=1 too low for autoTrusted=true, though trustedPublisher.matched overrides.
  • filenameAnalysis all false; 'icarus_sfx.exe' unclassified but matches observed piriform-ccl drops.

These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.

Recommended action

This is a safe, legitimate installer from Piriform (CCleaner ecosystem). Run if needed for updates; otherwise, remove unnecessary executables.

Chapter 03

Behavior

Plain-English impact first, then the observed runtime evidence.

Chapter 04

Detection & Forensics

Consensus, attribution, signatures, code structure, prevalence, and identity.

Chapter 05

Safety & FAQ

Complete recovery guidance and answers for the next decision.

What to do now

This file appears low risk based on the evidence available now.

  1. Run it only when it came from the developer's official site or another source you independently trust.

  2. A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.

  3. Keep your antivirus and Windows updates switched on so you stay protected.

Frequently asked

Safety FAQ

  • icarus_sfx.exe appears safe. 1 of 76 antivirus engines flagged it; the 1 detection were treated as non-decisive after the wider evidence was weighed. It carries a verified digital signature from Gen Digital Inc.. Run it only when it came from the developer's official site or another source you independently trust.
The raw file is processed temporarily and is not retained after processing. Its hash and report are public and permanent, so the next person who checks the same file gets an instant answer. Unknown files may be submitted to VirusTotal for analysis. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.