Is gridctrl_demo.zip safe?
Six of 75 engines flagged this uncommon ZIP, but only one tier-1 engine detected it and the reported malware families lack strong consensus.
The archive has mixed static scan results: 6 of 75 engines detected a threat, with two naming Emotet, but only Fortinet flagged it among the tier-1 detectors. No runtime analysis, child-file result, or complete contacted-host reputation check is available, so the contents should not be opened without further verification.
0204c6650a33b096e2…f1a88f7d9be9c7Recommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The archive has mixed static scan results: 6 of 75 engines detected a threat, with two naming Emotet, but only Fortinet flagged it among the tier-1 detectors. No runtime analysis, child-file result, or complete contacted-host reputation check is available, so the contents should not be opened without further verification.
Six of 75 engines flagged the ZIP, including one tier-1 detection from Fortinet. ClamAV and Cyren both use Emotet labels, but the remaining detections are generic or nonspecific, and there is no strong tier-1 family consensus. Fifteen tier-1 engines reported no detection, including BitDefender, Kaspersky, ESET-NOD32, and Avast, creating substantial counter-evidence. The archive is uncommon, with only three recorded submissions since 2022. No completed runtime observation is available, and no complete contacted-host reputation result exists, leaving the conflicting static evidence unresolved.
What We Detected
Six of 75 antivirus engines flagged the archive. ClamAV and Cyren named Emotet, Fortinet reported PossibleThreat.FAI, and the other detections were generic or nonspecific. Fortinet was the only tier-1 detector, while 15 tier-1 engines reported no detection, so there is no strong high-trust consensus.
Threat Behavior
No completed sandbox observation or child-file analysis is available. A complete contacted-host reputation check was also not recorded, so network behavior cannot be characterized. The file is an uncommon ZIP containing a PE file and has only three recorded submissions since 2022.
What To Do Now
Do not extract or execute the contained program on a production system. Verify the archive's source and expected contents, rescan the extracted files individually, and use an isolated sandbox if execution is necessary.
Where this verdict could be wrong3 caveats
- ClamAV and Cyren both name Emotet, which is more specific than the other detections and could indicate a real threat.
- Most high-trust engines reported no detection, but static scanners can miss malicious files contained within archives.
- contactedHosts=null and behaviour=null leave network reputation and runtime behavior unresolved rather than clean.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 1 of 18 tier-1 engines reported a malicious detection.
- 15 tier-1 engines reported no detection.
- engines.tier1FamilyConsensus.strong=false.
- No confirmed malicious child file is present in the available evidence.
- No brand mismatch or adversarial-input flag was detected.
- 6/75 antivirus engines reported malicious detections.
- ClamAV and Cyren both supplied Emotet-family labels.
- The ZIP contains a PE executable.
- Only three submissions from three sources are recorded.
- No completed runtime observation is available.
- No complete contacted-host reputation result is available.
Keep endpoint protection enabled and avoid opening the archive until its source is verified. If needed, inspect and rescan each extracted file in an isolated environment.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete6 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 6 / 75engines flagged
- 3sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
6 of 75 antivirus engines flagged the file, including ClamAV and Cyren.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 3 times from 3 sources.
ProvenanceDerivedSourceSaved report factsObserved at
Detection sources at a glance
Category: generic-trojan
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
6 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Rarely uploaded, but has been around for a while. Often niche legitimate software or old internal tooling; not a strong malware signal on its own.
Fingerprint and provenance
- File name
- gridctrl_demo.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 361.9 KB
- Last analyzed
- Sep 14, 2026, 2:33 PM UTC
0204c6650a33b096e2320b09a6d39296592cb746363b54cd91f1a88f7d9be9c7Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is gridctrl_demo.zip safe, or is it malware?
What is gridctrl_demo.zip?
How many antivirus engines detected gridctrl_demo.zip?
I already downloaded and opened or extracted gridctrl_demo.zip — what should I do?
How do I remove gridctrl_demo.zip?
What kind of malware is gridctrl_demo.zip?
What is the SHA-256 hash of gridctrl_demo.zip?
How up to date is this analysis of gridctrl_demo.zip?
Community
Member reviews and reports for this exact file hash.