Is boiii.exe safe?
Only Gridinsoft raised a generic heuristic detection, but unsigned provenance and sandbox mappings for process injection and archiving warrant caution pending source verification.
Only 1 of 75 engines flagged the executable, and no tier-1 engine identified malware or a named family. However, the file is unsigned and one sandbox mapped activity to T1055 process injection and T1560 archiving, so it should be used only after its download source and hash are independently verified.
06d897a6945a5fe8e8…55309c11ea97c7Recommended next actions
Before running
Do not run it until the source and publisher can be verified independently.
If you already ran it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the developer's official site or an official app store.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Only 1 of 75 engines flagged the executable, and no tier-1 engine identified malware or a named family. However, the file is unsigned and one sandbox mapped activity to T1055 process injection and T1560 archiving, so it should be used only after its download source and hash are independently verified.
Gridinsoft supplied the sole detection among 75 engines, using a generic heuristic label rather than a named malware family. No tier-1 engine flagged the sample, and researcher-curated intelligence produced no matching malware rules or known-family record. One completed sandbox run nevertheless mapped activity to T1055 process injection and T1560 archiving, which prevents treating the isolated detection as conclusively harmless. The sandbox issued no malicious verdict, and none of the five inspected children was identified as malicious, although every child remained unclassified. Because the executable is unsigned and no complete contacted-host reputation check exists, publisher identity and network risk are not fully resolved.
What We Detected
Gridinsoft was the only engine among 75 to flag the file, reporting the generic heuristic label “Trojan.Heur!.02056023.” No tier-1 engine detected it, no tier-1 family consensus exists, and external intelligence returned no MalwareBazaar family or YARAify rule match. This pattern makes a false positive plausible, but the unsigned executable lacks authenticated publisher provenance.
Threat Behavior
One completed sandbox observation mapped activity to T1055 process injection and T1560 archiving. These techniques can be used by malware, but the available mapping does not establish the injection method or intent, and the sandbox produced no malicious verdict. Five dropped children were inspected without a malicious result, although all five remain unclassified. No contacts were recorded in the saved behavior lists, but a complete contacted-host reputation result is unavailable.
What To Do Now
Obtain the executable only from the project's official release channel and compare its SHA-256 value with a publisher-provided checksum. Keep endpoint protection enabled, and avoid running this copy if its source or hash cannot be verified; testing in an isolated environment is preferable.
Where this verdict could be wrong4 caveats
- The T1055 process-injection mapping is a meaningful risk signal even though the sandbox did not issue a malicious verdict.
- The executable is unsigned, so its publisher and release provenance cannot be authenticated.
- Five dropped children were inspected without a malicious finding, but droppedChildren.rollup.unknown=5 means none received a conclusive benign classification.
- contactedHosts=null leaves host-reputation coverage unavailable, though the recorded sandbox contact lists were empty.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 1 of 75 engines reported a detection
- No tier-1 engine flagged the sample
- No tier-1 malware-family consensus
- No malicious sandbox verdict
- No MalwareBazaar or YARAify corroboration
- Unsigned Win32 executable with no established signer history
- Sandbox mapping to T1055 process injection
- Sandbox mapping to T1560 archiving
- Gridinsoft generic trojan heuristic detection
- Five dropped children remain unclassified
- No complete contacted-host reputation result
Verify SHA-256 06d897a6945a5fe8e8dd8312dcda34f963cf188dd596bc453855309c11ea97c7 against the official release source before use. Keep endpoint protection enabled and avoid execution when provenance cannot be confirmed.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 10MITRE ATT&CK techniques
- 6spawned processes
- 0network contacts
- 19filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Note: Collects details about your system.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
boiii.exe
06d897a6945a5fe8e8dd8312dcda34f963cf188dd596bc453855309c11ea97c7
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\Desktop\boiii.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Users\user\Desktop\boiii.exe"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
EZZ BOIII
C:\Users\user\AppData\Local\EZZ BOIII
04Isolated runtime analysis - Written fileObserved
WebView2
C:\Users\user\AppData\Local\EZZ BOIII\WebView2
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\user\AppData\Local\EZZ BOIII
- C:\Users\user\AppData\Local\EZZ BOIII\WebView2
- C:\Users\user\AppData\Local\EZZ BOIII\WebView2\EBWebView
- C:\Users\user\AppData\Local\EZZ BOIII\WebView2\EBWebView\84f07371-3097-435d-b74a-29d7d8488d57.tmp
- C:\Users\user\AppData\Local\EZZ BOIII\WebView2\EBWebView\BrowserMetrics
- \Sessions\1\BaseNamedObjects\ezz-boiii-auth-key-lock
- \Sessions\1\BaseNamedObjects\DBWinMutex
- \Sessions\1\BaseNamedObjects\Local\ChromeProcessSingletonStartup!
- \Sessions\1\BaseNamedObjects\__OMADM_NAMED_MUTEX__
Files this sample writes at runtime
This file drops 5 children at runtime. None are currently flagged malicious in our cache.
- e06bd26d16b6d7f09337…1339a1Never scannednever seen before
- 41c91a9c93d76295746a…1cc304Never scannednever seen before
- a0c9abae18599f0a65fc…e38e87Never scannednever seen before
- e54e9d1652848051e07a…4c8461Never scannednever seen before
- f7b24f2eb3d5eb055052…8b5fedNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 1 / 75engines flagged
- 213sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
1 of 75 antivirus engines flagged the file, including Gridinsoft.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 242 times from 213 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: boiii.exe — 06d897a6945a5fe8e8dd8312dcda34f963cf188dd596bc453855309c11ea97c7
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\Desktop\boiii.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\user\Desktop\boiii.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: EZZ BOIII — C:\Users\user\AppData\Local\EZZ BOIII
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: WebView2 — C:\Users\user\AppData\Local\EZZ BOIII\WebView2
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Users\<USER>\Desktop\boiii.exe"
1 of 75 engines flagged this file
View all 75 engine results
Section entropy & packers
No high-entropy executable section or known packer signature was detected. Data and resource sections can still have high entropy without indicating packed code.
How widely this file has been seen
Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.
Fingerprint and provenance
- File name
- boiii.exe
- Format
- Win32 EXE
- Code signing
- No verified publisher
- Size
- 5.7 MB
- Last analyzed
- Sep 10, 2026, 9:17 PM UTC
06d897a6945a5fe8e8dd8312dcda34f963cf188dd596bc453855309c11ea97c7Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't run it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Get a fresh copy from the developer's official site or an official app store.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is boiii.exe safe, or is it malware?
What is boiii.exe?
How many antivirus engines detected boiii.exe?
What should I do if I already ran boiii.exe?
How do I remove boiii.exe?
What is the SHA-256 hash of boiii.exe?
How up to date is this analysis of boiii.exe?
Community
Member reviews and reports for this exact file hash.