Is OpXOyuApWKTlFzrV.zip safe?
Only Malwarebytes identified GameHack riskware, but the new archive’s indirect DLL execution and defense-evasion technique warrant caution despite broad tier-1 silence.
Only 1 of 74 engines flagged this archive, and all 17 reporting tier-1 engines were silent, making a false positive plausible. However, the file is newly observed and its sandbox run used shortcut-driven DLL execution while registering T1562.001, so it should not be trusted without source verification.
405dab6e9e81d3dad6…8dd142fd4ff9e7Recommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Only 1 of 74 engines flagged this archive, and all 17 reporting tier-1 engines were silent, making a false positive plausible. However, the file is newly observed and its sandbox run used shortcut-driven DLL execution while registering T1562.001, so it should not be trusted without source verification.
Malwarebytes was the sole detector among 74 engines, labeling the archive RiskWare.GameHack, while no tier-1 engine identified malware. One completed sandbox run did not produce a malicious sandbox verdict or observe network contacts, but it did record T1562.001 and indirect execution through shortcuts and rundll32.exe. Eight extracted children were checked without a malicious child finding, although none received a conclusive child verdict. The archive is newly observed, rare, randomly named, and lacks signer history because signing is not applicable to the ZIP container. No CIRCL, MalwareBazaar, or YARAify corroboration was found, leaving mixed evidence weighted toward a likely PUA or false-positive scenario rather than confirmed malware.
What We Detected
Malwarebytes was the only detector among 74 engines and labeled the archive RiskWare.GameHack. None of the 17 reporting tier-1 engines raised a detection, and no named-family consensus or confirmed hacktool label exists.
Threat Behavior
One sandbox run extracted several files and executed an autoexec shortcut, followed by DLL loading through rundll32.exe. The run registered T1562.001, a defense-impairment technique, but produced no malicious sandbox verdict, persistence indicator, or observed network contact. Eight dropped children were inspected without a malicious result, though all eight remain unclassified rather than confirmed benign. No complete contacted-host reputation result is available because that cross-check was not saved.
What To Do Now
Do not run the archive on a primary system unless its origin and intended game-modification purpose can be verified. Keep endpoint protection enabled, obtain the software from an official source, and consider testing it only in an isolated environment.
Where this verdict could be wrong3 caveats
- Malwarebytes reported RiskWare.GameHack, a meaningful tier-2 PUA signal despite the absence of tier-1 corroboration.
- T1562.001 and DLL execution via rundll32.exe can indicate defense evasion, although the completed sandbox did not issue a malicious verdict.
- contactedHosts=null, so no complete host-reputation cross-check is available; the sandbox recorded no contacted domains, IPs, or URLs.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- No detections from 17 reporting tier-1 engines
- Only 1/74 engines flagged the archive
- behaviour.hasMaliciousSandboxVerdict=false
- droppedChildren.hasMaliciousChild=false
- No CIRCL, MalwareBazaar, or YARAify hits
- Newly observed archive with only 2 submissions from 2 sources
- Random-looking filename OpXOyuApWKTlFzrV.zip
- Malwarebytes RiskWare.GameHack detection
- T1562.001 defense-impairment behavior
- Shortcut-driven rundll32.exe DLL execution
- All 8 extracted children remain unclassified
Avoid executing the archive unless its source and purpose are verified, and keep endpoint protection enabled. Prefer an official distribution or inspect it within an isolated test environment.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 7MITRE ATT&CK techniques
- 6spawned processes
- 0network contacts
- 13filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Used an input-capture technique that can record credentials or keystrokes.
High concern: Attempted to impair or bypass security controls.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Reads your Windows user-account details.
Note: Collects details about your system.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
OpXOyuApWKTlFzrV.zip
405dab6e9e81d3dad65446a544eb9fa92d56d89e6c2d6547c48dd142fd4ff9e7
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\system32\cmd.exe" /c "cd ^"C:\Users\<USER>\AppData\Local\Temp^" && start /wait ^"^" ^"C:\Users\<USER>\AppData\Local\Temp\autoexec.lnk^"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\msvcp140.dll",#1
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Caches
C:\Users\user\AppData\Local\Microsoft\Windows\Caches
04Isolated runtime analysis - Written fileObserved
oh33vbfh.rzm
C:\Users\user\AppData\Local\Temp\oh33vbfh.rzm
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\user\AppData\Local\Microsoft\Windows\Caches
- C:\Users\user\AppData\Local\Temp\oh33vbfh.rzm
- C:\Users\user\AppData\Local\Temp\oh33vbfh.rzm\Potassium.exe
- C:\Users\user\AppData\Local\Temp\oh33vbfh.rzm\autoexec.lnk
- C:\Users\user\AppData\Local\Temp\oh33vbfh.rzm\msvcp140.dll
- \Sessions\1\BaseNamedObjects\Local\Shell.CMruPidlList
Files this sample writes at runtime
This file drops 8 children at runtime. None are currently flagged malicious in our cache.
- 24ab09465ffc09f89917…f7dbd4Never scannednever seen before
- 0f885b509a685d2bbfa6…460aa9Never scannednever seen before
- 006d6168d27c62c347d1…d2a745Never scannednever seen before
- 00ee5ac203f530c28523…edb4e1Never scannednever seen before
- 1f2d41c4aa5db0bc33eb…33093fNever scannednever seen before
- d5e4d9a3e835fa679450…0d9066Never scannednever seen before
- 79438908745f8a6bed18…9b522aNever scannednever seen before
- 301657720115142b52c2…e6332bNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 1 / 74engines flagged
- 2sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 of 74 antivirus engines flagged the file, including Malwarebytes.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 2 times from 2 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: OpXOyuApWKTlFzrV.zip — 405dab6e9e81d3dad65446a544eb9fa92d56d89e6c2d6547c48dd142fd4ff9e7
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Windows\system32\cmd.exe" /c "cd ^"C:\Users\<USER>\AppData\Local\Temp^" && start /wait ^"^" ^"C:\Users\<USER>\AppData\Local\Temp\autoexec.lnk^"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — "C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\msvcp140.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: Caches — C:\Users\user\AppData\Local\Microsoft\Windows\Caches
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: oh33vbfh.rzm — C:\Users\user\AppData\Local\Temp\oh33vbfh.rzm
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: pua
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
1 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 1 antivirus detection make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- OpXOyuApWKTlFzrV.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 10.4 MB
- Last analyzed
- Sep 16, 2026, 10:45 PM UTC
405dab6e9e81d3dad65446a544eb9fa92d56d89e6c2d6547c48dd142fd4ff9e7Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is OpXOyuApWKTlFzrV.zip safe, or is it malware?
What is OpXOyuApWKTlFzrV.zip?
How many antivirus engines detected OpXOyuApWKTlFzrV.zip?
What should I do if I already opened or extracted OpXOyuApWKTlFzrV.zip?
How do I remove OpXOyuApWKTlFzrV.zip?
What kind of malware is OpXOyuApWKTlFzrV.zip?
What is the SHA-256 hash of OpXOyuApWKTlFzrV.zip?
How up to date is this analysis of OpXOyuApWKTlFzrV.zip?
Community
Member reviews and reports for this exact file hash.