Is vrchat_avatar_scaler.zip safe?
Only DrWeb flagged this script archive, but silent BAT/VBS execution and T1562.001 warrant caution despite broad engine silence and no corroborated family.
DrWeb alone flagged the archive among 75 engines, using the generic label SCRIPT.Virus; no engine-family consensus or external intelligence corroborates it. However, sandbox execution involved silent BAT/VBS launchers and T1562.001, while all four extracted children remain unclassified, so the archive should not be trusted without further verification.
27158e67e579f28dc9…97ee1eca92feceRecommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
DrWeb alone flagged the archive among 75 engines, using the generic label SCRIPT.Virus; no engine-family consensus or external intelligence corroborates it. However, sandbox execution involved silent BAT/VBS launchers and T1562.001, while all four extracted children remain unclassified, so the archive should not be trusted without further verification.
The antivirus result is weakly adverse: 1 of 75 engines flagged the archive, although that detector is tier-1. Its SCRIPT.Virus label is generic, and there is no tier-1 family consensus or independent external-intelligence match. A completed sandbox observed BAT, VBS, and Python components executing silently and recorded T1562.001, but it did not issue a malicious sandbox verdict or observe persistence. None of the four inspected children was identified as malicious, though every child remains unclassified rather than confirmed benign. No complete contacted-host reputation result is available, so the mixed evidence supports caution rather than a definitive malware-family attribution.
What We Detected
DrWeb was the only engine to flag the archive, producing a generic SCRIPT.Virus label; the other reported results included 15 tier-1 engines without a detection. No tier-1 family consensus, YARAify rule match, MalwareBazaar record, or CIRCL record corroborated a named threat.
Threat Behavior
One completed sandbox run extracted and launched Install.bat, a silent VBS launcher, and a Python script. It recorded T1562.001, a defense-evasion technique, alongside nine more common techniques. The sandbox did not produce a malicious verdict, persistence indicators, or network contacts. Four extracted children were inspected without a malicious finding, but all four remain unclassified; no complete host-reputation cross-check is available.
What To Do Now
Do not run the archive on a primary system until its source and contents are independently verified. Keep endpoint protection enabled, inspect the BAT, VBS, and Python files in an isolated environment, and obtain a fresh copy from the project's official distribution channel if available.
Where this verdict could be wrong3 caveats
- DrWeb, a tier-1 engine, labeled the archive SCRIPT.Virus, so the detection cannot be dismissed as low-trust noise.
- The completed sandbox observed T1562.001 and silent BAT/VBS execution, which can indicate defense-evasion behavior despite the absence of a malicious sandbox verdict.
- All four extracted children have unknown verdicts, and contactedHosts=null leaves host-reputation coverage unavailable.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 1/75 engines reported a detection
- engines.tier1FamilyConsensus.strong=false
- behaviour.hasMaliciousSandboxVerdict=false
- droppedChildren.hasMaliciousChild=false
- No CIRCL, MalwareBazaar, or YARAify hit
- DrWeb tier-1 detection: SCRIPT.Virus
- Sandbox-observed T1562.001 defense-evasion technique
- Silent BAT and VBS execution chain
- Four extracted children remain unclassified
- No complete contacted-host reputation result
Quarantine the archive pending source verification and deeper review of its BAT, VBS, and Python contents. Keep endpoint protection enabled and test only in an isolated environment.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 10MITRE ATT&CK techniques
- 8spawned processes
- 0network contacts
- 7filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Attempted to impair or bypass security controls.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Reads your Windows user-account details.
Note: Collects details about your system.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
vrchat_avatar_scaler.zip
27158e67e579f28dc98b8628b988700c97cfad478b5c9e938297ee1eca92fece
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\system32\cmd.exe" /c "cd ^"C:\Users\<USER>\AppData\Local\Temp^" && start /wait ^"^" ^"C:\Users\<USER>\AppData\Local\Temp\Install.bat^"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\cmd.exe /K "C:\Users\<USER>\AppData\Local\Temp\Install.bat
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
httjkxlb.4lx
C:\Users\user\AppData\Local\Temp\httjkxlb.4lx
04Isolated runtime analysis - Written fileObserved
Install.bat
C:\Users\user\AppData\Local\Temp\httjkxlb.4lx\Install.bat
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\user\AppData\Local\Temp\httjkxlb.4lx
- C:\Users\user\AppData\Local\Temp\httjkxlb.4lx\Install.bat
- C:\Users\user\AppData\Local\Temp\httjkxlb.4lx\Launch Scaler (Silent).vbs
- C:\Users\user\AppData\Local\Temp\httjkxlb.4lx\vrchat_avatar_scaler.pyw
- C:\Users\user\AppData\Local\Temp\unarchiver.log
Files this sample writes at runtime
This file drops 4 children at runtime. None are currently flagged malicious in our cache.
- 62fa0b99c0154813e8fa…7f7327Never scannednever seen before
- 6ec2ac54741d7f25e3c5…dc2be6Never scannednever seen before
- 34ff653ab63649b5b6fa…f06b07Never scannednever seen before
- b3c3c07454269fbb3cc6…51eea9Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 1 / 75engines flagged
- 1sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 of 75 antivirus engines flagged the file, including DrWeb.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: vrchat_avatar_scaler.zip — 27158e67e579f28dc98b8628b988700c97cfad478b5c9e938297ee1eca92fece
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Windows\system32\cmd.exe" /c "cd ^"C:\Users\<USER>\AppData\Local\Temp^" && start /wait ^"^" ^"C:\Users\<USER>\AppData\Local\Temp\Install.bat^"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — C:\Windows\system32\cmd.exe /K "C:\Users\<USER>\AppData\Local\Temp\Install.bat
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: httjkxlb.4lx — C:\Users\user\AppData\Local\Temp\httjkxlb.4lx
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Install.bat — C:\Users\user\AppData\Local\Temp\httjkxlb.4lx\Install.bat
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
1 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- vrchat_avatar_scaler.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 32.3 KB
- Last analyzed
- Sep 19, 2026, 9:56 PM UTC
27158e67e579f28dc98b8628b988700c97cfad478b5c9e938297ee1eca92feceSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is vrchat_avatar_scaler.zip safe, or is it malware?
What is vrchat_avatar_scaler.zip?
How many antivirus engines detected vrchat_avatar_scaler.zip?
I already downloaded and opened or extracted vrchat_avatar_scaler.zip — what should I do?
How do I remove vrchat_avatar_scaler.zip?
What is the SHA-256 hash of vrchat_avatar_scaler.zip?
How up to date is this analysis of vrchat_avatar_scaler.zip?
Community
Member reviews and reports for this exact file hash.