Safe
Ryujinx open-source emulator; 16 tier-1 engines silent; 362 submitters; Cloudflare IP contact benign.
24f7ebff5cf7766523…6f7a65b40fThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file exhibits no malicious detections across 69 reporting engines, with 16 tier-1 vendors (BitDefender, Kaspersky, ESET-NOD32, Fortinet, GData, Emsisoft, F-Secure, Avira, AVG, DrWeb, Avast, Ikarus, and others) all silent. The filename and 76.7 MB size match the official Ryujinx emulator distribution. A prior sample with the same imphash was verdicted safe (score 88). The triggered heuristic on direct-IP contact is a false positive: the IP 162.159.36.2 belongs to Cloudflare's anycast network, and legitimate software routinely uses DoH or direct CDN endpoints. The file's prevalence across 362 unique submitters in 10 days indicates widespread legitimate distribution. No external-intelligence hits, no malicious sandbox verdicts, and no malicious dropped children further support a clean classification.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
tier1Malicious=0; 16 tier-1 engines (Avast, BitDefender, Kaspersky, ESET-NOD32, Fortinet, GData, Emsisoft, F-Secure, Avira, AVG, DrWeb, Ikarus) all silent or undetected
Ryujinx is a legitimate open-source Nintendo Switch emulator (GitHub: Ryujinx/Ryujinx); filename and 76.7 MB size match official distribution
similarHashes: imphash 759a3c183e9207f0571ae8ae7b2a52e0 previously verdicted 'safe' (score 88, ai:low_trust_engines_only) on same filename
Contacted IP 162.159.36.2 is Cloudflare anycast (162.159.0.0/16); legitimate for DoH/CDN, not C2 indicator
prevalence: common_new (362 submitters, 401 submissions in 10 days); high volume indicates widespread legitimate distribution
- 16 tier-1 antivirus engines all silent or undetected
- Legitimate open-source project (Ryujinx Nintendo Switch emulator)
- High prevalence: 362 unique submitters, 401 submissions in 10 days
- Prior imphash verdict: safe (score 88)
- No external-intelligence malicious hits (CIRCL, YARAify, MalwareBazaar)
This file is safe. It is the legitimate Ryujinx open-source emulator, widely distributed and trusted. No action is required; you may use it without concern.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Humanizer.Core.nb-NO
- C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Avalonia.Controls.ColorPicker,11.3.12
- C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Open.NAT.Core,2.1.0.5
- C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Avalonia.Angle.Windows.Natives,2.1.25547.20250602
- C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,static
Files this sample writes at runtime
This file drops 1 child at runtime. None are currently flagged malicious in our cache.
- e3b0c44298fc1c149afb…52b855Never scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2
0 detections across 75 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Lots of people are uploading this but it's recent — typical of newly-released legitimate software. Low prior for malware.
Forensic fingerprint
- File name
- Ryujinx.dll
- Size
- 73.20 MB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 24f7ebff5cf7766523dee39955df823105b7ab690159c82485c0d46f7a65b40f
- MD5
- 8e69e98c1f30f742c2d908b823d61180
- SHA-1
- 5a90433590f6eb8ea58651366553e2bb5ffe6963
- PE imphash
- 759a3c183e9207f0571ae8ae7b2a52e0
- First seen (VT)
- 5/31/2026, 6:49:50 AM
- Last analysis (VT)
- 6/9/2026, 10:16:33 AM
- First scan (MalwareTips)
- 6/10/2026, 10:13:27 AM
- Last scan (MalwareTips)
- 6/10/2026, 10:13:27 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.