Safe
Clean RAR archive of an RPG Maker game with zero engine detections and no malicious runtime indicators.
4b72f0f8e6184a54b8…054605f5a7The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Zero malicious detections across a broad engine set, including full tier-1 coverage, is the dominant signal. The single offensive MITRE technique and debug-evasion tags are outweighed by the complete lack of sandbox malice, external intelligence hits, or malicious child files. The extracted contents match a typical RPG Maker 2000/2003 title, consistent with the medium-prevalence commodity pattern observed.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines.tier1Malicious=0 and tier1ReportedClean=17
behaviour.hasMaliciousSandboxVerdict=false
droppedChildren.hasMaliciousChild=false
prevalence.classification=medium
- 0 malicious engines out of 64
- 17 tier-1 clean reports
- no malicious sandbox verdict
- medium prevalence, no external hits
- T1562.001 technique observed
- debug-environment detection tag
Treat as safe for normal use; the archive contains a legitimate RPG Maker title with no confirmed malicious payload.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\user\AppData\Local\Temp\rqav3pqc.v4e
- C:\Users\user\AppData\Local\Temp\rqav3pqc.v4e\7SU
- C:\Users\user\AppData\Local\Temp\rqav3pqc.v4e\7SU\Backdrop
- C:\Users\user\AppData\Local\Temp\rqav3pqc.v4e\7SU\Backdrop\Mirage.png
- C:\Users\user\AppData\Local\Temp\rqav3pqc.v4e\7SU\Backdrop\beach.png
- DirectSound Administrator shared thread array (lock
- DirectInput.{89521361-AA8A-11CF-BFC7-444553540000}
- DirectInput.{5944E682-C92E-11CF-BFC7-444553540000}
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 14e1652ee0bda8d425b9…d969e6Never scannednever seen before
- 50d9e9eb48fac59e48e9…5c9c3bNever scannednever seen before
- 546abce7b3e4e84ce589…62191fNever scannednever seen before
- 2bf0e599b4c5ebec7b14…dfcd79Never scannednever seen before
- 803439eef85287043632…0ea8cdNever scannednever seen before
- d131abe3129907799d4d…300bb0Never scannednever seen before
- e43b41b2ebcedfc849ef…f95ea9Never scannednever seen before
- cc0ab71df327cf827c0b…3d7ea0Never scannednever seen before
- 253fb1389c3d72d46b5e…765e0aNever scannednever seen before
- 66ff4d3e1c39b1c84f78…f9edfcNever scannednever seen before
0 detections across 75 engines
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- 7SU2.6_DQIII.rar
- Size
- 19.86 MB
- MIME type
- (unknown)
- Detected type
- RAR
- SHA-256
- 4b72f0f8e6184a54b83e2a0ead2c2f14f6b7d0c97d4f3dffca497e054605f5a7
- MD5
- 4d469aee981b82e3cf321a2167bdbfaf
- SHA-1
- d40c118575d790602bf236eaf734ec65b8d31f91
- First seen (VT)
- 1/26/2026, 10:41:24 AM
- Last analysis (VT)
- 5/10/2026, 2:48:12 AM
- First scan (MalwareTips)
- 5/15/2026, 8:25:48 PM
- Last scan (MalwareTips)
- 5/15/2026, 8:25:48 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.