Is hsp351.zip safe?
Two tier-1 engines identify keygen or patcher functionality, including a confirmed hacktool label, although runtime and host-reputation evidence are unavailable.
Five of 75 engines flagged this archive, with Fortinet and Ikarus independently identifying keygen, riskware, or patcher functionality. The corroborated hacktool designation is decisive under the safety policy, despite several established engines reporting no detection and no completed sandbox run.
7dfcac70c0e586acd4…f34db48f728b65Recommended next actions
Before opening or extracting
Do not open or extract it. Delete this archive from the device, then empty the Recycle Bin or Trash.
If you already opened or extracted it
Close it. If it opened links, requested credentials, or triggered unexpected behavior, disconnect from the internet and run a full device scan.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
Five of 75 engines flagged this archive, with Fortinet and Ikarus independently identifying keygen, riskware, or patcher functionality. The corroborated hacktool designation is decisive under the safety policy, despite several established engines reporting no detection and no completed sandbox run.
Five of 75 engines detected the archive, including two independent tier-1 votes. Ikarus labeled it as a hacktool patcher, while Fortinet identified key-generator riskware, satisfying the corroborated-hacktool threshold. The labels indicate software intended to bypass licensing or modify protected programs rather than a conventional named trojan family. However, 11 tier-1 engines reported no detection, and external research sources supplied no corroborating matches. No completed sandbox execution or complete contacted-host reputation result is available, so runtime impact and network activity cannot be assessed.
What We Detected
Five of 75 antivirus engines flagged the archive. Fortinet reported Riskware/KeyGen and Ikarus reported PUA.HackTool.Patcher; these are two tier-1 detections and establish the confirmed hacktool signal. CAT-QuickHeal also identified KeygenRI, while Webroot reported generic adware.
Threat Behavior
The detection names indicate key-generator or patcher functionality commonly used to bypass licensing controls or alter protected software. No completed sandbox run is available, so there is no reliable runtime observation of processes, persistence, payload delivery, or network behavior. The contacted-host reputation check was not completed or saved.
What To Do Now
Do not extract, install, or execute the archive on a personal or production device. Keep endpoint protection enabled, remove the file, and obtain the intended application through its official publisher or an authorized distribution channel.
Where this verdict could be wrong3 caveats
- Only 5/75 engines detected the sample, while 11 tier-1 engines reported no detection.
- externalIntel.yaraify.ruleCount=0, externalIntel.malwareBazaar.hit=false, and externalIntel.circl.hit=false provide no researcher-intelligence corroboration.
- The sample has medium prevalence with prevalence.uniqueSources=77 and has been known for 1,811 days, rather than being newly observed.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Only 5/75 engines reported a detection
- 11 tier-1 engines reported no detection
- No YARAify, CIRCL, or MalwareBazaar intelligence hit
- Known for 1,811 days with 77 submitting sources
- engines.hacktoolConfirmed=true
- Two tier-1 detections identify keygen or patcher functionality
- Archive contains Android and PE-related content
- No completed runtime observation
- No complete contacted-host reputation result
Quarantine or delete the archive and obtain the software from an official, licensed source. Keep antivirus and endpoint protection enabled, and avoid running key generators or patchers.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete5 of 75 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Threat context
How hacktools are abused
This is a hacking or cracking tool — the kind used to bypass software licences, generate fake keys, or attack other systems. Even when the tool 'works', these downloads very often carry hidden malware.
Bottom line:Running one means trusting an anonymous author with full access to your PC — rarely worth the risk.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
hsp351.zip
7dfcac70c0e586acd45aad830f699c13d23c056708b17e6501f34db48f728b65
01Uploaded file
Files
Created or changed
- Written fileObserved
~DF0404AE0CA6B478DA.TMP
C:\Users\<USER>\AppData\Local\Temp\~DF0404AE0CA6B478DA.TMP
02Isolated runtime analysis
2 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 5 / 75engines flagged
- 77sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
5 of 75 antivirus engines flagged the file, including Bkav and CAT-QuickHeal.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 100 times from 77 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: hsp351.zip — 7dfcac70c0e586acd45aad830f699c13d23c056708b17e6501f34db48f728b65
ProvenanceObservedSourceUploaded fileObserved at - 04
File written: ~DF0404AE0CA6B478DA.TMP — C:\Users\<USER>\AppData\Local\Temp\~DF0404AE0CA6B478DA.TMP
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: hacktool
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
5 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- hsp351.zip
- Format
- Android
- Code signing
- Not applicable to this file type
- Size
- 63.4 MB
- Last analyzed
- Sep 23, 2026, 6:25 AM UTC
7dfcac70c0e586acd45aad830f699c13d23c056708b17e6501f34db48f728b65Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't open or extract this archive. Delete this archive from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already opened or extracted it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If you typed any passwords while it was open, change them from a device you trust.
- Recovery step 04
Get a fresh copy from the original trusted source and verify its exact hash when possible.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is hsp351.zip malware?
What is hsp351.zip?
How many antivirus engines detected hsp351.zip?
I already downloaded and opened or extracted hsp351.zip — what should I do?
How do I remove hsp351.zip?
What kind of malware is hsp351.zip?
What is the SHA-256 hash of hsp351.zip?
How up to date is this analysis of hsp351.zip?
Community
Member reviews and reports for this exact file hash.