Is DarthFN.zip safe?
A lone riskware detection conflicts with observed process-injection, defense-evasion, persistence, and direct-IP activity, leaving this portable archive unsuitable for routine execution.
Fortinet alone identified the archive as Riskware/Application, with no named-family consensus among 75 engines. However, the sandbox recorded T1055 process injection, T1562.001 defense impairment, a persistence indicator, and direct-IP traffic whose reputation was not checked, so execution should be avoided pending source verification.
33a98b92bebf8b97c4…029b63bbf6bc1cRecommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Fortinet alone identified the archive as Riskware/Application, with no named-family consensus among 75 engines. However, the sandbox recorded T1055 process injection, T1562.001 defense impairment, a persistence indicator, and direct-IP traffic whose reputation was not checked, so execution should be avoided pending source verification.
Only 1 of 75 engines flagged the archive, and the sole label is the broad Fortinet Riskware/Application designation rather than a named malware family. That weak detection footprint is offset by runtime evidence mapped to T1055 and T1562.001, plus a service-style persistence indicator. The sample also made direct connections to 13 IP addresses, but no complete host-reputation result is available because contactedHosts is null. The sandbox did not issue a malicious verdict, and no inspected child was identified as malicious, although all ten child verdicts remain unresolved. With no curated intelligence hit or family consensus, the evidence supports caution rather than a definitive malware attribution.
What We Detected
Fortinet was the only engine among 75 to flag the archive, using the broad label Riskware/Application. No tier-1 family consensus, confirmed hacktool label, or researcher-curated intelligence match identifies a specific malware family.
Threat Behavior
One completed sandbox run recorded activity mapped to T1055 process injection and T1562.001 impairment of defenses, along with a service-style persistence indicator. The archive also contacted 13 IP addresses directly. Their reputation was not fully assessed because no contacted-host cross-check was saved. Ten dropped children were inspected; none was identified as malicious, but every child remains without a resolved verdict.
What To Do Now
Do not run the archive on a production system. Verify its origin and expected purpose, keep endpoint protection enabled, and test it only in an isolated environment if business use requires further validation.
Where this verdict could be wrong4 caveats
- Only Fortinet flagged the file, and its Riskware/Application label denotes broad riskware or PUA behavior rather than a named malware family.
- behaviour.hasMaliciousSandboxVerdict=false, so the completed sandbox run did not independently issue a malicious determination.
- externalIntel.malwareBazaar.hit=false, externalIntel.circl.hit=false, and externalIntel.yaraify.ruleCount=0 provide no curated corroboration, though absence may reflect coverage gaps.
- Fifteen tier-1 engines reported no detection, including Kaspersky, BitDefender, ESET-NOD32, Avast, and Microsoft-independent peers.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 1/75 engines reported a detection.
- tier1FamilyConsensus.strong=false and no named family was identified.
- behaviour.hasMaliciousSandboxVerdict=false.
- droppedChildren.hasMaliciousChild=false after 10 children were inspected.
- YARAify, CIRCL, and MalwareBazaar supplied no corroborating hit.
- MITRE T1055 process-injection activity was recorded.
- MITRE T1562.001 defense-impairment activity was recorded.
- A service-style persistence indicator, ServiceExample, was observed.
- The sample contacted 13 IP addresses without a completed reputation cross-check.
- All 10 dropped-child verdicts remain unknown.
- The archive contains executable content and exhibits long-sleep and debug-environment-detection traits.
Avoid executing DarthFN.zip unless its source and purpose can be independently verified. Keep endpoint protection enabled and use an isolated sandbox for any necessary follow-up testing.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial13 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete3 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 10MITRE ATT&CK techniques
- 15spawned processes
- 13network contacts
- 31filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Attempted to impair or bypass security controls.
High concern: Installs itself to survive restarts (persistence).
Moderate concern: Removed execution artefacts or logs, which can conceal activity.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Listed running processes; both legitimate software and malware may do this.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
DarthFN.zip
33a98b92bebf8b97c4148422714bbf4f2a0a5f92dd2d703b3d029b63bbf6bc1c
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\DarthFN/clrjit.dll",#1
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\DarthFN/coreclr.dll",#1
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Temp
C:\ProgramData\Microsoft\Windows\WER\Temp
04Isolated runtime analysis - Written fileObserved
adb839c0-6bd8-4bbb-82e1-5e068eb396b1
C:\ProgramData\Microsoft\Windows\WER\Temp\adb839c0-6bd8-4bbb-82e1-5e068eb396b1
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
172.67.179.49
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
150.171.73.13
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 172.67.179.49
- 150.171.73.13
- 151.101.194.137
- 104.16.80.73
- 104.21.85.107
- 104.26.2.199
- 104.16.79.73
- 35.190.80.1
- 104.18.10.207
- 172.67.169.22
- ServiceExample
- C:\ProgramData\Microsoft\Windows\WER\Temp
- C:\ProgramData\Microsoft\Windows\WER\Temp\adb839c0-6bd8-4bbb-82e1-5e068eb396b1
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue
- C:\ProgramData\Microsoft\Windows\WER\Temp\1c5b1274-5ce0-4c65-b0f0-c51a809bafe1
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERF906.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERD4A.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER11C0.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERF906.tmp.dmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERD4A.tmp.WERInternalMetadata.xml
- Local\WERReportingForProcess860
- Global\AmiProviderMutex_InventoryApplicationFile
- Global\e1d0afb7-0e8c-498f-bf9b-48c86213efe1
- Local\!BrowserEmulation!SharedMemory!Mutex
- Local\VERMGMTBlockListFileMutex
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- dd9729a2f62a8c742aac…b9c1eeNever scannednever seen before
- 6fc60adc117431c23aeb…c31d45Never scannednever seen before
- b4375494bb10be11db61…e66de7Never scannednever seen before
- 9c506c9347f872c33752…f73c22Never scannednever seen before
- a166041b2627a95b2e6a…ec8838Never scannednever seen before
- 001dc22d5205f5cdc3ba…7b4ef6Never scannednever seen before
- 5b20181ee4e188aa6b32…aa1211Never scannednever seen before
- 0761aa90038ef2975b38…4aeb64Never scannednever seen before
- 1d393bc4164e01d0229d…ec55e4Never scannednever seen before
- c07fc9fbf4dd7897bbb0…410589Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 3rule hits recorded
- 1 / 75engines flagged
- 190sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
1 of 75 antivirus engines flagged the file, including Fortinet.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 215 times from 190 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: DarthFN.zip — 33a98b92bebf8b97c4148422714bbf4f2a0a5f92dd2d703b3d029b63bbf6bc1c
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\DarthFN/clrjit.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\DarthFN/coreclr.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Temp — C:\ProgramData\Microsoft\Windows\WER\Temp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: adb839c0-6bd8-4bbb-82e1-5e068eb396b1 — C:\ProgramData\Microsoft\Windows\WER\Temp\adb839c0-6bd8-4bbb-82e1-5e068eb396b1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 172.67.179.49 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 150.171.73.13 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: pua
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
Sandbox flagged persistence indicators (registry Run keys / services / scheduled tasks).
EvidenceServiceExampleThe saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\DarthFN/clrjit.dll",#1The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence172.67.179.49 · 150.171.73.13 · 151.101.194.137
1 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- DarthFN.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 12.2 MB
- Last analyzed
- Sep 10, 2026, 10:16 AM UTC
33a98b92bebf8b97c4148422714bbf4f2a0a5f92dd2d703b3d029b63bbf6bc1cSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is DarthFN.zip safe, or is it malware?
What is DarthFN.zip?
How many antivirus engines detected DarthFN.zip?
What should I do if I already opened or extracted DarthFN.zip?
How do I remove DarthFN.zip?
What kind of malware is DarthFN.zip?
What is the SHA-256 hash of DarthFN.zip?
How up to date is this analysis of DarthFN.zip?
Community
Member reviews and reports for this exact file hash.