Is KralSMP-CurseForge.zip safe?
DrWeb alone identified Java.Muldrop.52, while 74 of 75 engines did not flag the newly submitted archive and no independent intelligence corroborated the label.
Only DrWeb flagged this ZIP as Java.Muldrop.52, with no family consensus or external-intelligence support. Because the archive is newly observed and no runtime analysis is available, the alert may be a false positive, but its contents should be verified before opening.
2d969322d2ad43cb4c…7755f85e11cbdbRecommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Only DrWeb flagged this ZIP as Java.Muldrop.52, with no family consensus or external-intelligence support. Because the archive is newly observed and no runtime analysis is available, the alert may be a false positive, but its contents should be verified before opening.
One of 75 engines flagged the archive, with DrWeb assigning the Java.Muldrop.52 label. Fifteen tier-1 engines reported no detection, and no other engine corroborated the Muldrop family. Researcher-curated sources supplied no matching rules or known-malware record. However, the file is newly observed with only one submission, which limits reputation-based reassurance. No completed runtime observation or complete contacted-host reputation result is available, so the archive's actual behavior remains unverified.
What We Detected
DrWeb was the only engine among 75 to flag the archive, identifying Java.Muldrop.52. The remaining engines did not corroborate that family, including 15 tier-1 products such as Kaspersky, Microsoft, BitDefender, ESET-NOD32, and Avast.
Threat Behavior
No completed sandbox observation is available, so there is no runtime evidence showing whether files inside the ZIP execute, drop additional components, or contact remote infrastructure. A complete contacted-host reputation result is also unavailable. Researcher-curated intelligence returned no matching YARA rules or known-malware records.
What To Do Now
Do not launch Java files, scripts, or executables from the archive until its source and contents are verified. Keep endpoint protection enabled, rescan after antivirus signatures update, and obtain a fresh copy from the official distribution channel if available.
Where this verdict could be wrong3 caveats
- DrWeb, a tier-1 engine, identified Java.Muldrop.52; although uncorroborated, this is more meaningful than a low-trust heuristic alert.
- The archive is zero days old with only one submission, leaving insufficient history to establish that the DrWeb detection is a false positive.
- The 5/5 prior safe similarHashes entries are filetype-only matches, so they establish little beyond the fact that other ZIP archives were benign.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 1/75 engines reported a detection.
- engines.tier1FamilyConsensus.strong=false, with only one engine naming Muldrop.
- Fifteen tier-1 engines reported no detection.
- YARAify, MalwareBazaar, and CIRCL supplied no corroborating hit.
- No malicious dropped child is reported.
- DrWeb detected Java.Muldrop.52.
- The archive is newly observed and has only one recorded submission.
- No completed runtime analysis is available.
- No complete contacted-host reputation result is available.
- ZIP archives can conceal executable Java components or scripts.
Quarantine the archive pending content inspection or a later rescan, and obtain it only from the expected official source. Keep antivirus and endpoint protection enabled.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 1 / 75engines flagged
- 1sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 of 75 antivirus engines flagged the file, including DrWeb.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
1 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 1 antivirus detection make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- KralSMP-CurseForge.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 18.4 MB
- Last analyzed
- Sep 11, 2026, 2:24 PM UTC
2d969322d2ad43cb4c055a984d27aac1a1a9a0b5bf69f1e0cc7755f85e11cbdbSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is KralSMP-CurseForge.zip safe, or is it malware?
What is KralSMP-CurseForge.zip?
How many antivirus engines detected KralSMP-CurseForge.zip?
What should I do if I already opened or extracted KralSMP-CurseForge.zip?
How do I remove KralSMP-CurseForge.zip?
What is the SHA-256 hash of KralSMP-CurseForge.zip?
How up to date is this analysis of KralSMP-CurseForge.zip?
Community
Member reviews and reports for this exact file hash.