Is crack.zip safe?
Thirty-one of 75 engines flagged this archive, including seven tier-1 detections, while runtime evidence recorded process injection and security-control impairment techniques.
The archive drew 31 detections among 75 engines, including seven tier-1 engines and two specific Filesponger identifications. A completed sandbox run also recorded T1055 process injection and T1562.001 security-control impairment, with a DLL launched through rundll32.exe from a temporary directory.
40bc185976c0f2fd1f…6eca7220aa9c06Recommended next actions
Before opening or extracting
Do not open or extract it. Delete this archive from the device, then empty the Recycle Bin or Trash.
If you already opened or extracted it
Close it. If it opened links, requested credentials, or triggered unexpected behavior, disconnect from the internet and run a full device scan.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The archive drew 31 detections among 75 engines, including seven tier-1 engines and two specific Filesponger identifications. A completed sandbox run also recorded T1055 process injection and T1562.001 security-control impairment, with a DLL launched through rundll32.exe from a temporary directory.
Thirty-one of 75 engines detected the archive, and seven high-trust engines contributed independent malicious votes. ESET-NOD32 and Fortinet specifically named Filesponger, while Avira and F-Secure used CryptoSteale-related labels and several others reported generic trojans. Runtime evidence recorded T1055 and T1562.001, including rundll32.exe loading APMonUI.dll from a temporary extraction path. The eight extracted child hashes were not confirmed malicious, but they all remain unclassified rather than benign. Two contacted domains lacked cached adverse findings, although host-reputation coverage was incomplete because the observed IP address was not inspected. The detection breadth and offensive runtime activity substantially outweigh the sample's age and prevalence.
What We Detected
31 of 75 antivirus engines flagged the archive, including seven tier-1 detections. ESET-NOD32 and Fortinet identified the Filesponger family, while Avira and F-Secure reported CryptoSteale-related trojan labels; BitDefender, Emsisoft, GData, and several others used generic trojan signatures.
Threat Behavior
One completed sandbox run recorded T1055 process injection and T1562.001 security-control impairment. The extracted Activator.exe launched APMonUI.dll through rundll32.exe from a temporary directory, a pattern consistent with concealed code execution. Eight dropped hashes were inspected, but all remain unclassified, so they cannot be treated as benign. The two observed domains had no cached adverse result, but the associated IP address was not covered by the host-reputation check.
What To Do Now
Do not extract or execute the archive. Quarantine or delete it while keeping endpoint protection enabled; if it was already opened, disconnect the affected system from sensitive networks and run a full security scan.
Where this verdict could be wrong5 caveats
- engines.tier1FamilyConsensus.strong=false because only two tier-1 engines agreed specifically on Filesponger.
- behaviour.hasMaliciousSandboxVerdict=false, despite the offensive techniques recorded during the completed run.
- droppedChildren.hasMaliciousChild=false, although all eight inspected child hashes have unknown verdicts rather than confirmed benign results.
- The sample has 148 submitters and 175 submissions since 2022, indicating it is established rather than newly observed.
- contactedHosts found no cached malicious or suspicious result for the two inspected domains, but the observed IP address was not covered.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- engines.tier1FamilyConsensus.strong=false
- behaviour.hasMaliciousSandboxVerdict=false
- droppedChildren.hasMaliciousChild=false
- The sample has been observed since 2022 across 148 sources
- contactedHosts reported no adverse cache hits for the two inspected domains
- 31/75 antivirus engines reported malicious content
- Seven tier-1 engines flagged the sample
- ESET-NOD32 and Fortinet identified Filesponger
- Runtime evidence includes T1055 process injection
- Runtime evidence includes T1562.001 security-control impairment
- rundll32.exe loaded APMonUI.dll from a temporary directory
Quarantine or delete the archive without extracting it, and keep endpoint protection enabled. If any included executable was launched, isolate the device and perform a full scan plus credential review.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete31 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial2 of 3 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete1 signature or behavior rule matched.
External intel
PartialIndependent reference checks were attempted but are incomplete.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 9MITRE ATT&CK techniques
- 7spawned processes
- 3network contacts
- 12filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Attempted to impair or bypass security controls.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Removed execution artefacts or logs, which can conceal activity.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Moderate concern: Checks which security software you have installed.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
crack.zip
40bc185976c0f2fd1ff91f76c9d485d60345319fb09c92569a6eca7220aa9c06
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\Activator.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\APMonUI.dll",#1
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
iiburi5j.fk0
C:\Users\user\AppData\Local\Temp\iiburi5j.fk0
04Isolated runtime analysis - Written fileObserved
APMonUI.dll
C:\Users\user\AppData\Local\Temp\iiburi5j.fk0\APMonUI.dll
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
fp2e7a.wpc.phicdn.net
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
fp2e7a.wpc.2be4.phicdn.net
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- fp2e7a.wpc.phicdn.net
- fp2e7a.wpc.2be4.phicdn.net
- 173.194.195.94
- C:\Users\user\AppData\Local\Temp\iiburi5j.fk0
- C:\Users\user\AppData\Local\Temp\iiburi5j.fk0\APMonUI.dll
- C:\Users\user\AppData\Local\Temp\iiburi5j.fk0\Activator.exe
- C:\Users\user\AppData\Local\Temp\iiburi5j.fk0\DS.CATIA.P3.V5-6R2021.Doc.English.txt
- C:\Users\user\AppData\Local\Temp\iiburi5j.fk0\DS.CATIA.P3.V5-6R2021.txt
- \Sessions\1\BaseNamedObjects\DBWinMutex
Files this sample writes at runtime
This file drops 8 children at runtime. None are currently flagged malicious in our cache.
- ff0f1eb2cb5ab5540db7…5129d1Never scannednever seen before
- f1947940cc6688f502f0…386b2fNever scannednever seen before
- 7a3e61aafebd3dccb3a6…f1d262Never scannednever seen before
- c2b39f4547531ebc6ec0…13ab54Never scannednever seen before
- 76f3b4c065aaf14d2d70…b69a37Never scannednever seen before
- 2c1ce194e81b81147dab…a9266aNever scannednever seen before
- 9fed8e64d904c06bd527…1a8a8bNever scannednever seen before
- f1f31dcdc80c17478c27…300926Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 31 / 75engines flagged
- 148sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
31 of 75 antivirus engines flagged the file, including AhnLab-V3 and alibabacloud.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has a long, established submission history across 148 sources.
ProvenanceDerivedSourceSubmission historyObserved at - 04
Scanned file: crack.zip — 40bc185976c0f2fd1ff91f76c9d485d60345319fb09c92569a6eca7220aa9c06
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\Activator.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\APMonUI.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: iiburi5j.fk0 — C:\Users\user\AppData\Local\Temp\iiburi5j.fk0
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: APMonUI.dll — C:\Users\user\AppData\Local\Temp\iiburi5j.fk0\APMonUI.dll
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: fp2e7a.wpc.phicdn.net — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: fp2e7a.wpc.2be4.phicdn.net — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: generic-trojan
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\APMonUI.dll",#1
31 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- crack.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 27.8 MB
- Last analyzed
- Oct 3, 2026, 7:48 AM UTC
40bc185976c0f2fd1ff91f76c9d485d60345319fb09c92569a6eca7220aa9c06Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't open or extract this archive. Delete this archive from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already opened or extracted it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the original trusted source and verify its exact hash when possible.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is crack.zip a virus?
What is crack.zip?
How many antivirus engines detected crack.zip?
What should I do if I already opened or extracted crack.zip?
How do I remove crack.zip?
What kind of malware is crack.zip?
What is the SHA-256 hash of crack.zip?
How up to date is this analysis of crack.zip?
Community
Member reviews and reports for this exact file hash.