Is Lоader.zip safe?
Four tier-1 engines and six additional scanners flag this archive, with repeated Trojan-downloader labels centered on document, RTF, and Agent variants.
Ten of 74 engines detected the archive, including four tier-1 products that repeatedly identify Trojan-downloader or Trojan.Agent content. Although exact family consensus is limited and no completed runtime evidence is available, the independent high-trust detections make opening or extracting it unsafe.
21101aa4c41d85b1ae…80c848b18e0686Recommended next actions
Before opening or extracting
Do not open or extract it. Delete this archive from the device, then empty the Recycle Bin or Trash.
If you already opened or extracted it
Close it. If it opened links, requested credentials, or triggered unexpected behavior, disconnect from the internet and run a full device scan.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Ten of 74 engines detected the archive, including four tier-1 products that repeatedly identify Trojan-downloader or Trojan.Agent content. Although exact family consensus is limited and no completed runtime evidence is available, the independent high-trust detections make opening or extracting it unsafe.
The strongest evidence is the 10/74 detection ratio, including four tier-1 engines. ESET-NOD32, Ikarus, and Kaspersky independently describe document or RTF Trojan-downloader variants, while GData identifies an archive-based Trojan.Agent variant. The exact family names differ, so attribution beyond TrojanDownloader.Agent remains uncertain, but the labels converge on downloader activity. No completed sandbox observation is stored, and no complete contacted-host reputation check is available. The absence of CIRCL, MalwareBazaar, and YARAify hits is counter-evidence, but it does not outweigh multiple high-trust detections and the negative reputation score.
What We Detected
Ten of 74 antivirus engines flagged this 1,172-byte RAR archive. Four tier-1 products detected it: ESET-NOD32 reported DOC/TrojanDownloader.Agent.FQS, Ikarus reported Trojan-Downloader.DOC.Agent, Kaspersky reported Trojan-Downloader.RTF.Agent, and GData reported Archive.Trojan.Agent.VGEGIX. Tencent also used the Dtgl downloader name reflected in the file's popular threat label.
Threat Behavior
The engine labels indicate an archive containing or representing document/RTF downloader content designed to retrieve or launch another payload. Exact family attribution is not strongly established, and the isolated XMRig label from Gridinsoft is not sufficiently corroborated to identify this specifically as a miner. No completed runtime observation is available, and contacted-host reputation was not fully checked, so network or execution behavior cannot be confirmed from the stored evidence.
What To Do Now
Do not open, extract, or forward the archive. Quarantine or delete it while keeping endpoint protection enabled; if it was already opened, run a full system scan and review the host for unexpected processes, persistence, and downloaded files.
Where this verdict could be wrong5 caveats
- 13 of 17 tier-1 engines did not detect the archive, including Microsoft, BitDefender, Avast, Avira, and Fortinet.
- engines.tier1FamilyConsensus.strong=false; only one tier-1 engine maps to the normalized 'trojandownloader' family.
- externalIntel.yaraify.ruleCount=0, externalIntel.circl.hit=false, and externalIntel.malwareBazaar.hit=false.
- The archive is widely submitted, with prevalence.uniqueSources=3494 and prevalence.timesSubmitted=5844, but prevalence alone does not establish safety.
- communityComments contain conflicting, unverified assessments and are not treated as authoritative runtime evidence.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 13 of 17 tier-1 engines did not detect the archive
- No strong exact-family tier-1 consensus
- No YARAify, CIRCL, or MalwareBazaar corroboration
- No malicious dropped child is recorded
- 10/74 antivirus detections
- Four tier-1 engine detections
- Repeated Trojan-downloader labels
- Negative file reputation of -16
- Archive may conceal document or RTF payload content
- No completed runtime observation
Quarantine or delete the archive without extracting it, and keep endpoint protection enabled. If it was opened, perform a full scan and investigate any newly created files or processes.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete10 of 74 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Threat context
How downloaders work
This file is a delivery vehicle. On its own it can look small and harmless, but its job is to quietly pull down and install the REAL payload — often a stealer, ransomware, or bot — from a server the attacker controls.
Bottom line:Because the dangerous part arrives later, early scans can look cleaner than the threat really is.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 10 / 74engines flagged
- 3,494sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
10 of 74 antivirus engines flagged the file, including alibabacloud and ESET-NOD32.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 3,494 sources.
ProvenanceDerivedSourceSubmission historyObserved at - 03
The hash has been submitted 5,844 times from 3,494 sources.
ProvenanceDerivedSourceSaved report factsObserved at
Detection sources at a glance
Category: downloader
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
10 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- Lоader.zip
- Format
- RAR
- Code signing
- Not applicable to this file type
- Size
- 1.1 KB
- Last analyzed
- Sep 18, 2026, 6:27 PM UTC
21101aa4c41d85b1ae264c020d4ba96041b1283bb7d629795b80c848b18e0686Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't open or extract this archive. Delete this archive from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already opened or extracted it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the original trusted source and verify its exact hash when possible.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Lоader.zip malware?
What is Lоader.zip?
How many antivirus engines detected Lоader.zip?
I already downloaded and opened or extracted Lоader.zip — what should I do?
How do I remove Lоader.zip?
What kind of malware is Lоader.zip?
What is the SHA-256 hash of Lоader.zip?
How up to date is this analysis of Lоader.zip?
Community
Member reviews and reports for this exact file hash.