Is Legacinator.rar safe?
No engine detected the widely submitted archive, while one sandbox mapped potentially offensive techniques without issuing a malware conclusion or finding a malicious child.
The archive has substantial history and received no detections from 74 antivirus engines, including 17 tier-1 engines. One sandbox mapped process-injection and defense-impairment techniques, so it should still be obtained from its official source and used with endpoint protection enabled.
3c964f56a2c8cff48a…4527362ee4569dRecommended next actions
Before opening or extracting
Open or extract it only when its sender or download source has been independently verified.
If you already opened or extracted it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The archive has substantial history and received no detections from 74 antivirus engines, including 17 tier-1 engines. One sandbox mapped process-injection and defense-impairment techniques, so it should still be obtained from its official source and used with endpoint protection enabled.
No antivirus engine flagged the archive, and all 17 reporting tier-1 engines found no known threat. It has also circulated broadly for more than two years, with 641 sources and 676 submissions, without accumulating detections. A completed sandbox run mapped T1055 and T1562.001, but produced no malicious sandbox conclusion and no persistence indicators. Four extracted children were inspected without a malicious child result, although their individual dispositions remain unknown. Reputation checks found no adverse entries for the three contacted domains, but coverage did not clearly encompass every listed IP and URL.
What We Detected
None of 74 antivirus engines flagged the RAR archive, including 17 tier-1 engines. The sample has been observed for 852 days across 641 sources and 676 submissions, which gives the engines substantial exposure to it.
Threat Behavior
One sandbox run mapped activity to T1055 (Process Injection) and T1562.001 (Impair Defenses). These mappings are noteworthy, but the sandbox issued no malicious conclusion, recorded no persistence indicators, and did not identify a malicious extracted child. Checks of the three contacted domains found no adverse reputation entries; however, the listed IP address and URLs were not clearly covered, so the network reputation result is not complete.
What To Do Now
Download the archive only from the project's official release channel and verify its SHA-256 value before extraction. Keep antivirus and endpoint protection enabled, and rescan the extracted executable before running it.
Where this verdict could be wrong3 caveats
- The sandbox mapped activity to T1055 process injection and T1562.001 impairment of defenses; these are meaningful offensive-technique signals despite the absence of an adverse sandbox conclusion.
- All four extracted children have unknown individual verdicts, so droppedChildren.hasMaliciousChild=false does not establish that each child is benign.
- Host-reputation inspection covered three domains, but the evidence also lists IP 38.242.217.201 and two URLs; therefore, no complete host-reputation result is available for every distinct contact.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/74 antivirus engines reported a detection.
- All 17 tier-1 engines reported no detection.
- Observed for 852 days across 641 sources and 676 submissions.
- No malicious sandbox conclusion was recorded.
- No inspected child was identified as malicious.
- Sandbox evidence mapped T1055 process injection.
- Sandbox evidence mapped T1562.001 impairment of defenses.
- Four extracted children lack individual verdicts.
- Host-reputation coverage is incomplete for all listed network contacts.
Use only a copy obtained from the official project channel, verify SHA-256 3c964f56a2c8cff48ac088f80ec072c7bc3fc6749aa07d77624527362ee4569d, and keep endpoint protection enabled during extraction and execution.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial3 of 4 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete1 signature or behavior rule matched.
External intel
PartialIndependent reference checks were attempted but are incomplete.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 18MITRE ATT&CK techniques
- 7spawned processes
- 6network contacts
- 17filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- google.com
- aiu.api.nefarius.systems
- vmi1289037.nefarius.systems
- 38.242.217.201
- https://aiu.api.nefarius.systems:443/api/github/nefarius/Legacinator/updates?asJson=true&allowAny=true
- https://aiu.api.nefarius.systems/api/github/nefarius/Legacinator/updates?asJson=true&allowAny=true
- HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Legacinator_RASMANCS\FileDirectory
- HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Legacinator_RASMANCS\MaxFileSize
- HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Legacinator_RASMANCS\ConsoleTracingMask
- HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Legacinator_RASMANCS\FileTracingMask
- HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Legacinator_RASMANCS\EnableConsoleTracing
- HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\Legacinator_RASMANCS\EnableFileTracing
- C:\Users\<USER>\Desktop\Legacinator.log
- C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\System.Memory, Culture=neutral, PublicKeyToken=cc7b13ffcd2ddd51
- C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\System.Memory, Version=4.0.1.2, Culture=neutral, PublicKeyToken=cc7b13ffcd2ddd51
- C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\System.Numerics.Vectors, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
- C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\System.Numerics.Vectors, Version=4.1.4.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
- Local\__DDrawExclMode__
- Local\__DDrawCheckExclMode__
- \Sessions\1\BaseNamedObjects\Local\__DDrawExclMode__
- \Sessions\1\BaseNamedObjects\Local\__DDrawCheckExclMode__
Files this sample writes at runtime
This file drops 4 children at runtime. None are currently flagged malicious in our cache.
- d278eb441c7daffe2c53…6e06adNever scannednever seen before
- f52ea9bac69b15d77a73…cda774Never scannednever seen before
- deac7a70df1c94a898d2…be33bcNever scannednever seen before
- cf7c765b4b481d2799d0…0aed31Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 0 / 74engines flagged
- 641sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 641 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
One or more independent reference checks were incomplete or unavailable.
ProvenanceDerivedSourceExternal-intelligence coverageObserved at - 04
Scanned file: Legacinator.rar — 3c964f56a2c8cff48ac088f80ec072c7bc3fc6749aa07d77624527362ee4569d
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — C:\Windows\system32\services.exe
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Users\<USER>\AppData\Local\Temp\Legacinator.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Legacinator.log — C:\Users\<USER>\Desktop\Legacinator.log
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: System.Memory, Culture=neutral, PublicKeyToken=cc7b13ffcd2ddd51 — C:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\System.Memory, Culture=neutral, PublicKeyToken=cc7b13ffcd2ddd51
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: google.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: aiu.api.nefarius.systems — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\system32\services.exe
0 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- Legacinator.rar
- Format
- RAR
- Code signing
- Not applicable to this file type
- Size
- 2.9 MB
- Last analyzed
- Oct 5, 2026, 2:29 AM UTC
3c964f56a2c8cff48ac088f80ec072c7bc3fc6749aa07d77624527362ee4569dSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open or extract it only when its sender or download source has been independently verified.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Legacinator.rar safe?
What is Legacinator.rar?
How many antivirus engines detected Legacinator.rar?
What is the SHA-256 hash of Legacinator.rar?
Is it safe to open or extract Legacinator.rar?
How up to date is this analysis of Legacinator.rar?
Community
Member reviews and reports for this exact file hash.